2022-09-20 | 17/SEOJK.04/2022Added · Updated
Financial Services Authority Circular No. 17/SEOJK.04/2022 mandates information technology-based crowdfunding service providers to implement a risk-based Anti-Money Laundering and Counter-Terrorism Financing program. This requirement includes active oversight by the Board of Directors and Board of Commissioners, internal controls, information management systems, and employee training. Providers must conduct self-assessments of money laundering and terrorism financing risks, aligning their mitigation strategies with national and sectoral risk assessments.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
Crowdfunding Service Providers
At your location.
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 17 /SEOJK.04/2022 CONCERNING GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS FOR INFORMATION TECHNOLOGY-BASED CROWDFUNDING SERVICE PROVIDERS
In relation to the provisions of Article 82 of Financial Services Authority Regulation Number 57/POJK.04/2020 concerning the Offering of Securities through Information Technology-Based Crowdfunding Services (State Gazette of the Republic of Indonesia Year 2020 Number 281, Supplement to the State Gazette of the Republic of Indonesia Number 6594) as amended by Financial Services Authority Regulation Number 16/POJK.04/2020 concerning Amendments to Financial Services Authority Regulation Number 57/POJK.04/2020 on the Offering of Securities through Information Technology-Based Crowdfunding Services (State Gazette of the Republic of Indonesia Year 2021 Number 193, Supplement to the State Gazette of the Republic of Indonesia Number 6714), it is necessary to regulate provisions regarding guidelines for the implementation of anti-money laundering and counter-terrorism financing programs for information technology-based crowdfunding service providers, in this Financial Services Authority Circular as follows:
I. GENERAL PROVISIONS
a. Offering of Securities through Information Technology-Based Crowdfunding Services, hereinafter referred to as Crowdfunding Services, is the provision of securities offering services conducted by issuers to sell securities directly to investors through an open electronic system network.
b. Securities are negotiable instruments, namely debt acknowledgment instruments, commercial paper, shares, bonds, debt certificates, units of participation in collective investment contracts, futures contracts on Securities, and any derivatives of Securities.
c. Crowdfunding Service Provider, hereinafter referred to as the Provider, is an Indonesian legal entity that provides, manages, and operates Crowdfunding Services.
d. Crowdfunding Service User, hereinafter referred to as the User, is the issuer and the investor.
e. Issuer is an Indonesian business entity, whether in the form of a limited liability company or other business entities, that issues Securities through Crowdfunding Services.
f. Investor is a party that purchases Issuer Securities through Crowdfunding Services.
g. Prospective Customer is a Prospective User who will use the Provider's services.
h. Customer is a User who uses the Provider's services.
i. Board of Directors:
j. Board of Commissioners:
k. Money Laundering is money laundering as referred to in the Law concerning the prevention and eradication of the criminal act of Money Laundering.
l. Terrorism Financing is terrorism financing as referred to in the Law concerning the prevention and eradication of the criminal act of Terrorism Financing.
m. Proliferation of Weapons of Mass Destruction is the spread of nuclear, biological, and chemical weapons.
n. Anti-Money Laundering and Counter-Terrorism Financing, hereinafter abbreviated as AML and CFT, are efforts to prevent and eradicate the criminal acts of Money Laundering and Terrorism Financing.
o. Electronic System of Financial Services, hereinafter referred to as Electronic System, is a series of electronic devices and procedures that function to prepare, collect, process, analyze, store, display, announce, send, and/or disseminate electronic information in the field of financial services.
p. Financial Services Information Technology, hereinafter referred to as Information Technology, is a technique to collect, prepare, store, process, announce, analyze, and/or disseminate information in the field of financial services.
q. Customer Due Diligence, hereinafter abbreviated as CDD, is an activity consisting of identification, verification, and monitoring conducted by the Provider to ensure transactions align with the profile, characteristics, and/or transaction patterns of Prospective Customers and Customers.
r. Enhanced Due Diligence, hereinafter abbreviated as EDD, is more in-depth CDD actions conducted by the Provider against Prospective Customers or Customers with high risk, including politically exposed persons and/or in high-risk areas.
s. High Risk Customers are Customers who, based on their background, identity, and history, are considered to have a high risk of engaging in activities related to the criminal acts of Money Laundering and/or Terrorism Financing.
t. Suspicious Financial Transaction, hereinafter abbreviated as SFT, is a suspicious financial transaction as referred to in the Law concerning the prevention and eradication of the criminal act of Money Laundering and the Law concerning the prevention and eradication of the criminal act of Terrorism Financing.
u. Beneficial Owner is every person who:
v. Politically Exposed Person, hereinafter abbreviated as PEP, includes:
w. Money Laundering Criminal Act, hereinafter abbreviated as MLCA, is the criminal act of money laundering as referred to in the Law concerning the prevention and eradication of the criminal act of money laundering.
x. Terrorism Financing Criminal Act, hereinafter abbreviated as TFCA, is the criminal act of terrorism financing as referred to in the Law concerning the prevention and eradication of the criminal act of terrorism financing.
y. Financial Transaction Reports and Analysis Center, hereinafter abbreviated as PPATK, is the PPATK as referred to in the Law concerning the prevention and eradication of MLCA.
z. Financial Action Task Force Recommendations, hereinafter referred to as FATF Recommendations, are standards for the prevention and eradication of Money Laundering and/or Terrorism Financing issued by FATF.
Providers are highly vulnerable to the possibility of being used as a means of Money Laundering and/or Terrorism Financing. Providers may become an entry point for wealth that is the proceeds of MLCA and/or TFCA into the financial system, which can subsequently be utilized for the benefit of criminals. For example, for Money Laundering perpetrators, such wealth can be withdrawn back as wealth that appears legitimate and can no longer be traced to its origin. Whereas for Terrorism Financing or Weapons of Mass Destruction Proliferation financing perpetrators, such wealth can be used to finance terrorist activities or fund the development of weapons of mass destruction.
The increasing complexity of financial service products and services, including their marketing (multi-channel marketing), and the increasing use of Information Technology in the financial services industry, result in a higher risk of Providers being used as a means of Money Laundering and/or Terrorism Financing.
In this regard, there is a need to improve the quality of the implementation of AML and CFT programs based on a risk-based approach in accordance with generally accepted international principles and in line with national risk assessment (NRA) and sectoral risk assessment (SRA).
Overview of Money Laundering
a. On the basis, the process of Money Laundering can be grouped into 3 (three) stages of activities, including:
b. Some money laundering modus operandi and typologies, including:
utilization of corporations or use of shell companies, where funds from criminal acts are channeled into legal corporate entities that are essentially shell companies to facilitate their activities. Shell companies are established only to conduct fictitious transactions and aim to obscure criminal funds.
As an example: criminals legitimize their criminal funds by making shell companies as Investors purchasing Securities through Crowdfunding Services or as Issuers offering Securities through Crowdfunding Services.
structuring, which is the effort to break transactions into several transactions with relatively small transaction values intended to avoid reporting.
As an example: Investors break up transactions with funds derived from criminal funds through several accounts with the Provider.
smurfing, which is the effort to break transactions with funds derived from criminal proceeds through several accounts under different individual names, whether affiliated or not, for the benefit of one person or a specific Beneficial Owner.
As an example: Investors purchase Securities through Crowdfunding Services where the funds used are derived from criminal proceeds. The purchase of Securities is conducted through several Investor accounts with different names and identities to avoid suspicious Securities purchase transactions, compared to if conducted through only 1 (one) Investor account.
mingling (mixing criminal proceeds with legal business), which is a technique of mixing or combining criminal proceeds with legal business proceeds with the aim of obscuring the source of criminal funds.
As an example:
a) Investors combine their criminal funds with legal funds to subsequently be invested through Crowdfunding Services by purchasing Issuer Securities that conduct legitimate business activities; or b) Issuers combine their criminal funds with legal funds received from Investors through Crowdfunding Services, which are subsequently used to conduct legitimate business activities;
use of professional services such as legal consultants, notaries, financial planners, and accountants including public accountants, with the aim of obscuring the identity of beneficiaries and the source of criminal funds.
As an example: Investors or Issuers cooperate with legal consultants, notaries, financial planners, or accountants including public accountants in the form of transaction engineering or manipulation to disguise criminal funds in legal audits and legal opinions, corporate articles of association and bylaws, financial planning proposals, and/or Issuer financial reports;
use of other people's names (nominees), family members, or third parties, intended to obscure the identity of those controlling criminal funds by using the legitimate identity of other parties, both on Investors and Issuers;
forgery of face photos (selfies) during non-face-to-face verification for CDD purposes;
Investors changing account numbers indicating a change in account ownership when Investors are about to receive financing returns;
use of companies in tax haven countries that have no real business (paper companies) as classified by competent international organizations, including countries categorized as High-risk and other Monitored Jurisdictions by the Financial Action Task Force on Money Laundering (FATF), where criminal funds are transferred to such companies, and the company becomes the source of funds for Investors;
use of fake identities on the internet (utilization of internet encryption and access to identity) by hacking (unauthorized access to other people's devices and/or accounts) of e-mails, websites, and/or creating websites that appear genuine but are fake (phishing) with the aim of obscuring identity and/or creating fake identities for Money Laundering purposes. The use of fake identities can be done by stealing other people's identities or combining real identities with fake identities to generate new identities that appear genuine;
Investors and Issuers are parties with an affiliation relationship, where the funds used to conduct Securities purchase transactions through Crowdfunding Services from Investors to such Issuers are funds derived from criminal proceeds; and/or
depositing funds for Securities purchase transactions through Crowdfunding Services by Investors is done by parties other than the intended Investors, where the deposited funds are criminal funds.
a. Every terrorist act carried out in Indonesia essentially requires support, both in the form of weaponry (firearms, sharp weapons, and explosives), accommodation, vehicles for mobilization, war facilities, funds, and the provision of other needs. Based on the Law concerning the prevention and eradication of the criminal act of terrorism financing, funds are all assets or movable or immovable objects, whether tangible or intangible, obtained in any manner and in any form, including in digital or electronic format, proof of ownership, or connection with all such assets or objects including but not limited to bank credits, traveler's checks, checks issued by banks, money transfer orders, shares, bonds, bank drafts, and debt acknowledgment instruments. In terrorist criminal acts, money or funds are intended as a means to carry out terrorist acts and not as a target to be sought, so various methods will be employed by perpetrators of terrorism criminal acts to obtain funds, either legally such as selling goods and/or services or through criminal acts such as robbery, fraud, up to hacking online investment sites. The accumulated funds are used to obtain weaponry, buy explosives, build networks or recruit members, war training, and mobilize members from or to a place for the implementation of terrorist acts.
b. TFCA is the direct or indirect use of wealth for terrorist activities, terrorist organizations, or terrorists. Terrorism Financing is essentially a type of criminal act different from MLCA. However, both have similarities, namely using financial services as a means to commit a criminal act.
c. Unlike MLCA, whose purpose is to disguise the origin of wealth, the purpose of TFCA is to assist terrorist activities, whether with wealth that is the result of a criminal act or with wealth obtained legally. To prevent Providers from being used as a means of TFCA, Providers need to implement AML and CFT programs adequately.
d. Some terrorism financing modus operandi and typologies, including:
robbery or theft by Issuers who claim that taking the property of others is halal. In this regard:
a) Issuers offer Securities through Crowdfunding Services with the aim of obtaining funds that can be used to finance terrorist network management and terrorist activities, without the intention to return investment funds, including investment results in the form of dividends or returns to Investors; or b) criminals hack Issuer accounts and use funds from Issuer Securities offerings whose accounts have been hacked to finance terrorist network management and terrorist activities;
use of funds by Issuers that do not match the intended use of funds from Securities offerings through Crowdfunding Services.
As an example: funds from Securities offerings were initially intended for the development of Issuer business activities, but after receiving the funds, those funds are used to finance terrorist network management and terrorist activities;
criminals acting as Issuers who have an affiliation relationship with:
a) Investors located domestically or abroad; and/or b) individuals or institutions located domestically or abroad and conducting investments by providing funds directly or indirectly to Investors, where the funds obtained are used to finance terrorist network management and terrorist activities;
disguise of business activities by Issuers by submitting documents and/or information to the Provider indicating that their business activities are legal goods and/or services trading. However, after funds from Securities offerings are collected, they are used to finance terrorist network management and terrorist activities;
Issuers change account numbers indicating a change in account ownership when Issuers are about to receive financing where the funds received are used to finance terrorist network management and terrorist activities; and/or
use of nominees as controllers on Issuers offering Securities through Crowdfunding Services, where subsequently those funds are used to finance terrorist network management and terrorist activities.
II. IMPLEMENTATION OF RISK-BASED AML AND CFT PROGRAM (RISK BASED APPROACH)
The implementation of risk-based AML and CFT programs (risk based approach) covers at least:
a. active oversight by the Board of Directors and Board of Commissioners; b. policies and procedures;
c. internal controls;
d. information management systems; and e. human resources and training.
Providers are obligated to implement Risk-Based AML and CFT Programs (Risk Based Approach) in conducting business relationships and transactions with Users. This program includes, among others, what is mandated in FATF Recommendations as an effort to protect Providers from being used as a means of Money Laundering and/or Terrorism Financing.
In FATF Recommendations, it is stated that Providers are obligated to identify, assess, and understand Money Laundering and Terrorism Financing risks related to Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels).
Providers must conduct self-assessments regarding MLCA and/or TFCA risks, and implement an effective risk management framework process. In addition, Providers must document and update risk assessments related to the implementation of such AML and CFT programs.
The implementation of risk-based AML and CFT programs (risk based approach) supports Providers in implementing prevention and risk mitigation measures commensurate with the identified MLCA and/or TFCA risks. Providers can subsequently allocate their resources according to their risk profile, manage internal controls, internal structure, and implement policies and procedures to prevent and detect Money Laundering and/or Terrorism Financing.
In the implementation of risk-based AML and CFT programs (risk based approach), Providers must refer to the risks listed in the NRA and SRA. The risks listed in the NRA and SRA may develop and change, so Providers must be responsive and consider such risk changes.
a. Risk Definition
Risk is defined as the likelihood of an event and its impact. Simply put, risk is seen as a combination of the probability of occurrence and the level of damage or loss that may result from an event.
In the context of Money Laundering and Terrorism Financing, risk is interpreted as:
where the Service Provider is used as a means for Money Laundering and/or Terrorism Financing. Threats can be parties or objects that can cause losses. In the context of Money Laundering and Terrorism Financing, threats can include criminal actors, facilitators (parties assisting in the execution of criminal acts), funds of criminal perpetrators, or even terrorist groups.
Vulnerability is an element of business activities that can be exploited by identified threats. In the context of AML/CFT, vulnerability is defined as weak internal controls of the Service Provider or the offering of high-risk products/services/transactions.
Impact refers to the level of serious damage and losses that arise if AML/CFT occurs.
b. Risk Management
Risk management is a process widely used in the public and private sectors to assist in decision-making. In relation to Money Laundering and Terrorism Financing, the aforementioned process includes understanding Money Laundering and/or Terrorism Financing risks, assessing these two risks, and developing methods to manage and mitigate identified risks.
In implementing risk management for Money Laundering and/or Terrorism Financing risks, Service Providers can develop risk management methods in accordance with the characteristics of the Service Provider while still referring to laws and regulations governing AML and CFT.
c. Inherent Risk and Residual Risk
In conducting risk assessments, it is important to distinguish between inherent risk and residual risk. Inherent risk is the risk attached to an event or condition that exists prior to the application of control measures. This inherent risk is related to the Money Laundering and/or Terrorism Financing risk profile of Prospective Customers or Customers, which includes at least 4 (four) risk factors, namely: Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution channels. On the other hand, residual risk is the level of risk remaining after the implementation of risk mitigation steps and controls.
d. Risk-Based Approach
In the context of Money Laundering and/or Terrorism Financing, the risk-based approach is a process that includes the following:
Risk assessment covering at least 4 (four) risk factors, namely:
a) Customers; b) Countries/geographic areas/jurisdictions; c) Products/services/transactions; and d) Distribution channels.
Service Providers must consider all relevant risk factors, including the risk of using Information Technology.
Service Providers must manage and mitigate Money Laundering and/or Terrorism Financing risks through the implementation of internal controls and by taking steps appropriate to the identified risks, as well as monitoring transactions in accordance with the assessed level of Money Laundering and/or Terrorism Financing risk.
In identifying, assessing, managing, and mitigating Money Laundering and/or Terrorism Financing risks, Service Providers must understand that these activities are not static. Identified risks can change over time in line with the development of new products or new threats entering the Service Provider's business activities.
Service Providers must periodically update their Money Laundering and/or Terrorism Financing risk assessments according to the Service Provider's needs.
Service Providers must update Information Technology and Electronic Systems used in accordance with laws and regulations governing electronic information and transactions (ITE). Updates to Information Technology and Electronic Systems include minimum IT system standards, IT risk management, IT security, resilience against system disruptions and failures, and IT system governance, for example, the implementation of ISO 27001 in updating Information Technology and Electronic Systems.
a. In implementing the risk-based approach, Service Providers must carry out 6 (six) activity steps as follows:
b. The flow of the risk-based approach cycle as stated in the Appendix, which is an integral part of this Financial Services Authority Circular.
a. Identification of Inherent Risk
In identifying inherent risks, Service Providers must consider the Service Provider's vulnerability to being used as a means for Money Laundering and/or Terrorism Financing. The initial step in risk assessment is understanding the Service Provider's business activities comprehensively from a broad perspective. This understanding enables Service Providers to consider potential Money Laundering and/or Terrorism Financing risks, whether they occur on the side of Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution channels.
Service Providers must consider elements that trigger risks for the Service Provider, from the side of Customers, countries/geographic areas/jurisdictions, products/services/transactions, and/or distribution channels. Service Providers must understand which elements constitute inherent risks and residual risks.
Customer Risk
Service Providers must pay attention to Money Laundering and Terrorism Financing risks related to the profile of Prospective Customers or Customers. Service Providers need to categorize Customers based on the level of Money Laundering and/or Terrorism Financing risk, referring to the risk classification established by the Service Provider.
Customer risks related to the specific business processes of the Service Provider increase if:
a) Customers are PEPs (Politically Exposed Persons), including family members or close associates of PEPs; b) Customers are detected using virtual private networks intended to mask IP addresses when accessing the Service Provider's application; c) The investment value of Investors has a nominal value that does not match the profile of the said Investor (exceeding reasonableness limits); d) The intensity of investment by Investors exceeds reasonableness limits, including those outside normal/reasonable policies or habits; e) Investors or Issuers act for Beneficial Owners; f) Investors seek or choose Issuer offerings through the Service Provider that do not match the Investor's needs or are not beneficial to the Investor; g) Customers or Beneficial Owners provide very minimal information or information that is suspected to be fictitious; h) Customers or Beneficial Owners obscure or do not disclose their true identity; i) Gatekeepers, such as supporting professions in the capital market, including accountants, legal consultants, appraisers, notaries, or other professions acting on behalf of Customers in relation to accounts at the Service Provider; j) Investors in corporate form have complex ownership structures or make it difficult to identify the Beneficial Owner, ultimate owner, or ultimate controller of the corporation; k) Customers are charitable organizations or other non-profit organizations that are not regulated and supervised by competent institutions or authorities; l) Investors are institutions supervised by other regulatory/supervisory authorities that have not effectively implemented AML and CFT programs; m) Investors or Issuers change the account numbers recorded at the Service Provider; and/or n) The risk of using false identities in the form of identity forgery, namely impersonation identities (impersonating identities) and synthetic identities (combining real and false identities). Impersonation identities are done by stealing another person's identity, while synthetic identities use identity forgery by combining real identities with false identities to generate a new identity that appears real.
Country/Geographic Area/Jurisdiction Risk
In conducting risk assessments, Service Providers must identify risks related to geographic locations, both the Service Provider's geographic location and the Customer's geographic location, or the location where the business relationship occurs, and its impact on overall risk.
Money Laundering and/or Terrorism Financing risks related to countries/geographic areas/jurisdictions increase if:
a) Investors or Issuers have affiliations with individuals and/or corporations from high-risk countries or jurisdictions; b) Investors or Issuers reside in high-risk areas; c) Investors or Issuers are detected accessing the Service Provider's application while in high-risk areas; d) Investors or Issuers are detected accessing the Service Provider's application while in cross-border areas; e) Investors reside in cross-border areas; and/or f) The original residence area of Investors or Issuers is unknown (using fake IP addresses).
Indicators determining that a country/geographic area/jurisdiction is high-risk for Money Laundering and Terrorism Financing include:
a) Jurisdictions identified by organizations conducting mutual assessments of a country (such as: Financial Action Task Force (FATF) on Money Laundering, Asia Pacific Group on Money Laundering (APG), Caribbean Financial Action Task Force (CFATF), Committee of Experts on the Evaluation of Anti-Money Laundering Measures and the Financing of Terrorism (MONEYVAL), Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), The Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), Grupo de Accion Financiera de Sudamerica (GAFISUD), Inter-Governmental Action Group Against Money Laundering in West Africa (GIABA), or Middle East & North Africa Financial Action Task Force (MENAFATF)) as not adequately implementing FATF Recommendations; b) Countries identified as non-cooperative or tax havens by the Organization for Economic Cooperation and Development (OECD); c) Countries with low levels of good governance as determined by the World Bank; d) Countries with high corruption risk levels as identified in the Transparency International Corruption Perception Index; e) Countries widely known as places of production and trade centers for narcotics; f) Countries subject to sanctions, embargoes, or similar measures by, for example, the United Nations (UN); or g) Countries or jurisdictions identified by trusted institutions as funding or supporting terrorist activities, or allowing terrorist organization activities in their country.
Overall risk assessment must include determining risks that can occur over various products/services/transactions offered.
Factors that can increase product/service/transaction risks include:
a) Equity-type securities such as stocks related to high-risk business financing like property financing, consumer credit financing (motor vehicle loans), and export/import activity financing; or b) Debt-type securities and/or sukuk in the form of high-risk project financing.
Distribution channels are media used to obtain a product/service/transaction, or media used to conduct a transaction.
One of the distinctive features of the Service Provider's business is the distribution channel process conducted without direct meetings (non-face-to-face). For example, the use of mobile apps and websites, which can be accessed 24 (twenty-four) hours a day, 7 (seven) days a week, and from anywhere. Additionally, Service Providers must also pay attention to borderless risks as part of what can increase distribution channel risks, where media used for borderless transactions have higher risks compared to non-borderless transactions.
With these distinctive features, it is very possible for the Service Provider to be used to obscure the true identity of Customers or Beneficial Owners, thus having higher risks.
Although the use of mobile phone applications or internet websites is common, this must still be considered as part of factors that can cause Money Laundering and/or Terrorism Financing risks to increase.
Some indicators causing distribution channels to be high-risk include online applications that have not been tested for reliability and security, especially regarding Customer data confidentiality.
Other relevant factors that can impact Money Laundering and/or Terrorism Financing risks include:
a) Development of Money Laundering and/or Terrorism Financing modus operandi and typologies; b) Business model, business scale, and number of employees as inherent risk factors of the Service Provider; c) High total value and intensity of transactions requiring adequate risk mitigation; d) Use of Information Technology throughout the Service Provider's entire business process chain; e) Data security from cyberattack risks, where Service Providers heavily rely on the use of open communication networks (internet), thus posing significant risks of cyberattacks during internet usage; f) Personal data protection, including protection against the acquisition, collection, processing, analysis, storage, presentation, disclosure, transmission, dissemination, and destruction of personal data in accordance with laws and regulations. The greatest risk for Service Providers is related to poor personal data protection management; g) Audit trails, where Service Providers are required to provide audit trails for all their activities within the Service Provider's Electronic System. Audit trails are very important as they are used for supervision, law enforcement, dispute resolution, verification, testing, and other examinations; and/or h) Data centers and disaster recovery centers, where the existence of data centers and disaster recovery centers is intended to facilitate personal data protection processes and to restore data or information and important Electronic System functions disrupted or damaged by natural and/or human-caused disasters.
Through data centers and disaster recovery centers, Service Providers retain backup data so as not to repeat the data collection process.
Service Providers need to consider that the risk factors referred to in items 3) to 8) above may be interrelated between one risk factor and other risk factors.
Indicators that can increase risk are not limited to those referred to in items 3) to 8). Risk-increasing indicators can develop according to the complexity of the Service Provider's business activities.
After identifying and documenting inherent risks, Service Providers need to provide assessments regarding the level of each risk for Prospective Customers, for example, low, medium, and high.
To assist Service Providers in evaluating risk assessments, Service Providers can use likelihood and consequence matrices as stated in the Appendix, which is an integral part of this Financial Services Authority Circular.
In the identification stage of inherent risks, Service Providers must be able to explain the entire risk identification process conducted by the Service Provider and the reasons or considerations behind it.
Each risk element identified as high-risk must be mitigated and documented. Service Providers must be able to explain to the Financial Services Authority the mitigation steps for high-risk elements, for example, steps in policies and procedures or training programs.
Service Providers must also be able to show the Financial Services Authority that these risk mitigation steps have been implemented effectively, for example, demonstrated through internal audit results or independent audit results.
Service Providers must provide documented information showing that the Service Provider has specifically paid attention to high-risk indicators in their risk assessments.
In order to identify AML/CFT risks and set risk scales for Prospective Customers at the opening of business relationships or Customers during transactions, Service Providers can use regulatory technology such as big data analytics, artificial intelligence, machine learning, and/or robo advisors.
The utilization of regulatory technology in the implementation of AML/CFT programs by Service Providers can also be conducted by Service Providers during electronic verification, transaction monitoring, and the determination of red flag alerts, while paying attention to Customer data and information security.
b. Setting Risk Tolerance
Risk tolerance is a breakdown of the level of risk to be taken (risk appetite).
Meanwhile, risk appetite is the risk that the Service Provider wants to take, either in the form of risk taker or non-risk taker.
Service Providers must set risk tolerance before considering risk mitigation.
When considering threats, the concept of risk tolerance will give Service Providers the ability to determine the level of threat risk that can be tolerated by the Service Provider.
In setting risk tolerance, Service Providers need to consider risk categories that can affect the Service Provider, including:
a) Compliance risk; b) Reputational risk; c) Legal risk; d) Operational risk; and e) Fraud risk.
c. Implementation of Risk-Based Approach
Service Providers are obligated to implement AML and CFT programs with a risk-based approach based on the results of Money Laundering and/or Terrorism Financing risk assessments.
The risk-based approach owned by Service Providers must be documented to demonstrate the Service Provider's compliance level.
Policies and procedures related to the risk-based approach must be communicated, understood, and adhered to by all employees, particularly employees who conduct identification and record-keeping of Customer data and information and report transactions to relevant authorities.
Procedures and policies of the risk-based approach must meet the following minimum requirements:
a) Customer identification; b) Risk assessment; c) Special actions for high-risk areas; d) Record-keeping; and e) Reporting.
Policies and procedures in the risk-based approach also cover matters related to the detection of suspicious transactions and the determination of monitoring types adjusted to the level of Customer risk or business relationship, as well as monitoring aspects from the side of frequency, implementation methods, and evaluation of monitoring results.
Service Providers need to conduct periodic monitoring of all business relationships conducted, and of business relationships with high Money Laundering and/or Terrorism Financing risks. Service Providers must apply stricter special steps for Customers or business relationships with high risks.
Service Providers need to pay attention that risk management and risk mitigation require leadership and involvement of senior officials. Senior officials are responsible for decision-making regarding policies, procedures, internal control processes, and mitigation of Money Laundering and/or Terrorism Financing risks in the business activities owned by the Service Provider.
With the risk-based approach, Service Providers can:
a) Ensure that the risk assessments conducted reflect the risk-based approach process, frequency...
monitoring of low-risk and high-risk Customers, and also describes the internal control measures implemented to reduce identified high risks; b) applying a risk-based approach; c) updating data and information regarding Customers and Beneficial Owners; d) monitoring all business relationships held; e) conducting more frequent monitoring of business relationships with high risk related to Money Laundering and/or Terrorism Financing; f) taking specific measures against High-Risk Customers; and/or g) involving senior officials in facing high-risk situations or areas (for example, approval to establish a business relationship is given by senior officials).
d. Risk Mitigation and Control Measures
e. Evaluation of Residual Risk
f. Review and Evaluation of the Risk-Based Approach
The Money Laundering and/or Terrorism Financing risk assessment held by the Provider must be evaluated based on the need to test the effectiveness of the APU and PPT program implementation compliance, which includes:
a) active supervision by the Board of Directors and Board of Commissioners; b) policies and procedures; c) information management systems; d) internal controls; e) human resource needs possessing knowledge and skills in Information Technology and the business processes of P2P Lending Services; f) human resource training programs for employees, senior officials, and the Board of Directors and Board of Commissioners regarding the application of the APU and PPT program; and/or g) employee profiles including identity data profiling and employee competencies.
In the event of changes in business activity structures, the offering of new products and services, and new technologies, updates to the risk assessment must be carried out for policies and procedures, mitigation steps, and internal controls.
The review of the Money Laundering and/or Terrorism Financing risk assessment must include all elements including policies and procedures regarding risk assessment, risk mitigation, and more intensive continuous monitoring. The review of the risk assessment can help the Provider in evaluating the refinement of existing policies and procedures or the formation of new policies and procedures. Identified risks can change or develop along with the development of new products or the emergence of new threats to the Provider's business activities. Ultimately, the review procedures for the risk assessment will affect the effectiveness of implementing the risk-based approach in applying the APU and PPT program.
With the review of the risk-based approach, the Provider can:
a) conduct reviews according to the Provider's needs; b) generate reviews that cover compliance with policies and procedures, risk assessments for Money Laundering and/or Terrorism Financing, and training programs to test the effectiveness of the risk-based approach; c) document the review process and report to senior officials; and d) document the review results along with the establishment of corrective measures to be followed up.
III. ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
In supporting the effectiveness of the application of the APU and PPT program, the Board of Directors and Board of Commissioners must:
a. have adequate understanding of the Money Laundering and/or Terrorism Financing risks inherent in all operational activities of the Provider so that the Board of Directors and Board of Commissioners are able to manage and mitigate such risks adequately in accordance with regulatory provisions; b. have understanding regarding inherent risks, including Customer risk, country/geographical area/jurisdiction risk, product/service/transaction risk, distribution network (delivery channels) risk, and other relevant risks;
c. ensure an adequate organizational structure for the application of the APU and PPT program, including ensuring that the APU and PPT responsible person is within the organizational structure; and
d. be responsible for policies and procedures, application, and supervision of the application of the APU and PPT program, including the management and mitigation of Money Laundering and/or Terrorism Financing risks in all operational activities of the Provider.
Responsible Person for the Application of the APU and PPT Program
a. The Provider must have a responsible person for the application of the APU and PPT program. b. The responsible person for the application of the APU and PPT program must be within the Provider's organizational structure.
c. The determination and existence of the responsible person for the application of the APU and PPT program is based on the needs and complexity of the Provider's business, meaning the Provider can have a UKK and responsible official, or only have a UKK, or only have a responsible official.
d. In the event that the responsible person for the application of the APU and PPT program is a UKK, it must meet the following provisions:
IV. POLICIES AND PROCEDURES
Policies and procedures for the application of the APU and PPT program based on the risk-based approach contain at least:
a. identification and verification of Prospective Customers or Customers; b. identification and verification of Beneficial Owners;
c. termination of business relationships or rejection of transactions;
d. continuous management of Money Laundering and Terrorism Financing risks related to Customers, countries/geographical areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels); e. maintenance of accurate data related to transactions, documentation of the CDD process, and documentation of policies and procedures; f. updating and monitoring; g. reporting to senior officials, the Board of Directors, and the Board of Commissioners; and h. reporting to PPATK.
The policies and procedures referred to in item 1 must consider the Principle of Knowing the Service User (PMPJ/Know Your Customer (KYC)).
PMPJ/KYC consisting of CDD and EDD is carried out not only to Prospective Customers at the time of registration as Users, but also to Customers through monitoring of Customer transactions at the Provider.
Through CDD or EDD:
a. The Provider can obtain detailed information regarding Prospective Customers, Customers, Customer transactions, including suspicious transactions. b. The Provider can protect the Provider's reputation and integrity, facilitate compliance with regulations, and protect the Provider from external threats, namely being used as a means of Money Laundering and/or Terrorism Financing; and
c. The Provider must always be careful in accepting Prospective Customers and continue to monitor transactions of Customers using the Provider's services. If transactions carried out do not match the profile, characteristics, or habitual transaction patterns of the relevant Customer, the Provider is obligated to submit a Suspicious Transaction Report (TKM) to PPATK.
CDD is carried out by the Provider at the time:
a. establishing a business relationship with a Prospective Customer or transacting with a Customer; b. there are financial transactions in Rupiah and/or foreign currency with a value of at least equivalent to IDR 100,000,000.00 (one hundred million Rupiah);
c. there are indications of Suspicious Transactions (TKM) related to Money Laundering and/or Terrorism Financing; or
d. the Provider doubts the truthfulness of information provided by Prospective Customers, Customers, authorized representatives, and/or Beneficial Owners.
Re-CDD can be carried out by the Provider if the Provider assesses that there is a change in risk level caused by among others:
a. significant increase in transaction value; b. significant changes in Customer profile; and/or
c. information in the Customer profile available in the single investor identification number has not been completed with supporting documents for verification purposes.
Identification of Prospective Customers or Customers
a. The Provider is obligated to identify and classify Prospective Customers or Customers into groups of natural persons, legal persons, and other legal arrangements. b. The Provider must have policies regarding the acceptance and identification of Prospective Customers or Customers.
c. The acceptance and identification policies for Prospective Customers as referred to in letter b must at least cover the following matters:
conduct business relations with the Provider; and b) other obligations in forms other than trust, namely data, information related to names, email addresses, phone numbers, face photos (selfies), and identity documents of individuals who hold positions equivalent to the parties in the trust as referred to in letter a).
direct meeting (face to face) with the Prospective Customer at the beginning of establishing business relations;
matching the consistency of the Prospective Customer's profile, face photo (selfie), and Customer's identity photo;
matching the consistency of fingerprint identity documents, and/or face photos (selfies) with identity documents or other documents containing signatures, fingerprints, and/or face photos (selfies);
requesting the Prospective Customer to provide more than one identity document issued by competent authorities if there is doubt regarding the existing identity documents;
If necessary, conducting cross-checks to ensure consistency of various information provided. Cross-checks are conducted by methods, including:
a) contacting the Prospective Customer via landline or office phone; b) contacting the human resources official at the workplace of the Prospective Customer if the Prospective Customer is an employee of a company or agency; c) confirming the Prospective Customer's income by requiring bank statements from banks or other financial service providers; or d) conducting geographic information analysis to view forest conditions through remote sensing technology for Prospective Customers who are companies operating in the forestry sector; and/or
ensuring that the Prospective Customer has no negative track record by verifying the identity of the Prospective Customer using other independent sources, including:
a) lists of suspected terrorists and terrorist organizations issued by the Indonesian National Police; b) lists of funding for the proliferation of weapons of mass destruction; or c) other data such as the Prospective Customer's employer identity, phone accounts, and electricity accounts.
c. The completion of the identity verification process for Prospective Customers or Customers must be done before opening business relations with the Prospective Customer or transactions with the Customer.
d. In certain conditions, the verification process may be completed after the business relationship or transaction has been established.
Example: identity documents required are still being processed and cannot be fulfilled at the time of establishing business relations with the Provider. e. In the event that the verification process is completed after the business relationship or transaction has been established as referred to in letter d, then the Provider must conduct adequate risk mitigation, for example by doing the following:
requesting documents that can prove that the completeness of the required documents is still being processed;
Example:
a) for corporate Customers and other obligations, in the form of documents proving the processing of business permits issued by competent agencies, and/or documents proving the processing of tax identification numbers from competent government agencies that handle tax affairs; or b) for individual Customers, in the form of documents proving that inheritance deeds or sale and purchase deeds as source of funds documents are being processed by a notary/land deed official;
imposing service and/or transaction restrictions provided by the Provider; and/or
the Provider requests the Prospective Customer to complete the required documents within a certain period.
f. The Provider may conduct the verification process for Prospective Customers or Customers electronically, provided that the Electronic System used by the Provider is capable of verifying the truthfulness of the identity of the Prospective Customer or Customer. g. In the event that the Provider carries out the verification process electronically, then the Provider must pay attention to the following:
The Provider may conduct electronic verification via direct face-to-face meeting (electronic face-to-face verification) with the following provisions:
a) electronic face-to-face verification can be conducted through electronic facilities owned by the Provider or by third parties; b) in the event that electronic face-to-face verification is conducted through electronic facilities owned by the Provider, then its implementation uses software owned by the Provider with hardware owned by the Provider or hardware owned by the Customer or Prospective Customer; c) in the event that electronic face-to-face verification is conducted using electronic facilities owned by third parties, then the third party is required to obtain approval from the Financial Services Authority in accordance with the Financial Services Authority Regulation regarding the implementation of the AML and CFT program in the financial services sector; d) electronic face-to-face verification through electronic facilities owned by the Provider is conducted in the form of electronic facilities equivalent to real-time and online video banking, electronically connecting the Provider's employees/officials with the Prospective Customer or Customer. Example: Video call features in the application owned by the Provider that are connected directly in real-time and online with the Provider's employees/officials via smartphones, computers, and/or tablets owned by the Prospective Customer or Customer; e) electronic face-to-face verification through electronic facilities owned by third parties is conducted in the form of video banking or equivalent to real-time and online video banking, electronically connecting the Provider's employees/officials with the Prospective Customer or Customer; f) electronic face-to-face verification owned by the Provider or third parties must not be conducted using providers that generally provide electronic facilities, such as WhatsApp calls, Line calls, and Skype; g) to provide additional assurance for the Provider in carrying out the electronic face-to-face verification process through electronic facilities owned by the Provider or third parties, the Provider may add the use of motion detection mechanisms and/or technology to ensure that the Prospective Customer or Customer is a living subject and there is no identity fraud attempt. Example: Motion detection mechanisms in the electronic face-to-face verification process include, for example, the Provider's officials/employees requesting the Prospective Customer or Customer to move randomly in various directions (e.g., moving the face 45 degrees or 90 degrees to the left or right), requesting the Prospective Customer or Customer to show the surrounding area of the Prospective Customer or Customer during verification, and/or asking questions that confirm the truthfulness of information or identity to the Prospective Customer or Customer.
The face-to-face verification process may be exempted from the non-face-to-face verification process (non-face-to-face verification) with the following provisions:
a) non-face-to-face verification is conducted using software owned by the Provider with hardware owned by the Provider or hardware owned by the Customer or Prospective Customer.
Example: Software owned by the Provider and hardware owned by the Customer or Prospective Customer used for non-face-to-face verification include, for example:
(1) applications owned by the Provider that can be accessed via mobile devices (mobile devices) including smartphones and/or computer tablets; and/or (2) the Provider's website that can be accessed via electronic devices of the Prospective Customer or Customer including computers and/or laptops. The Provider must ensure that the hardware owned by the Prospective Customer or Customer is equipped with supporting verification features such as cameras, scanners, recorders, and/or location trackers; b) non-face-to-face verification is required to utilize population data that meets 2 (two) authentication factors covering:
(1) what you have, namely identity documents owned by the Prospective Customer, namely Electronic Identity Cards (KTP Elektronik); and (2) what you are, namely biometric data including in the form of fingerprints, iris data of the Prospective Customer, and/or facial recognition technology. Access to population data can be obtained by referring to legislation governing the granting of access rights and utilization of population data, which can be accessed via web services, web portals, and card readers. Access to population data via web services and web portals, for example, is through a joint platform where the joint platform acts as an intermediary that does not have access rights to population data and does not store personal data. Other examples of population data access are through parties that utilize population administrative data meeting 2 (two) authentication factors as referred to in item (1) and item (2), where such parties obtain certification from the Ministry that handles government affairs in the field of communications and information; c) to provide additional assurance for the Provider in the non-face-to-face verification process as referred to in letter b), the Provider may:
(1) add other authentication factors, namely what you know, which may include personal identification numbers (PIN), passwords, one-time passwords (OTP), verification emails, and/or challenge-response; and/or (2) add the use of motion detection technology to ensure that the Prospective Customer or Customer is a living subject and there is no identity fraud attempt.
To provide additional assurance for the Provider, verification conducted electronically by the Provider may utilize artificial intelligence technology or other algorithms matched with the Provider's database.
Identification of High-Risk Prospective Customers or Customers or PEPs
a. In the event that the Provider assesses that a Prospective Customer or Customer is High-Risk or a PEP, then the Provider is obligated to apply Enhanced Due Diligence (EDD). b. The Provider must have policies and procedures for the identification of High-Risk Prospective Customers or Customers or PEPs.
c. The policies and procedures for the identification of High-Risk Prospective Customers or Customers or PEPs as referred to in letter b must at least include the provisions as referred to in the identification provisions for Prospective Customers or Customers as referred to in item 7.
d. The identification of High-Risk Prospective Customers or Customers or PEPs can be conducted electronically, provided that the Provider's Electronic System is capable of identifying the official identity of the High-Risk Prospective Customer or Customer or PEP. e. In the event that the identification of High-Risk Prospective Customers or Customers or PEPs is conducted electronically, its implementation can be done, for example, by filling out electronic forms and submitting copies of documents as referred to in Article 20, Article 21, Article 22, Article 23, and Article 24 of the Financial Services Authority Regulation regarding the implementation of the AML and CFT program in the financial services sector electronically (softcopy) through the Provider's website or application. f. In addition to the document copies as referred to in letter e, the Provider may request additional data, documents, and information needed to identify and verify Prospective Customers electronically, the submission of which is conducted through the Provider's website or application. Examples of such additional data, documents, and information include, for example, data and information as referred to in item 7 letter g regarding the identification of Prospective Customers or Customers.
Verification of High-Risk Prospective Customers or Customers or PEPs
a. Verification of High-Risk Prospective Customers or Customers or PEPs is implemented by paying attention to the provisions as referred to in item 8 letter a, letter b, letter c, letter d, and letter e. b. In addition to paying attention to the provisions as referred to in letter a, the Provider may conduct verification of High-Risk Prospective Customers or Customers or PEPs in the implementation of EDD by methods including:
The Provider must ensure whether business relations with Prospective Customers or transactions with Customers are conducted for the benefit of:
a) the Prospective Customer or Customer; or b) other parties or Beneficial Owners.
If the Prospective Customer represents a Beneficial Owner to open business relations or conduct transactions, the Provider must conduct CDD procedures against the Beneficial Owner that are equally strict as the CDD procedures for the Prospective Customer.
In the event that the Beneficial Owner is classified as a High-Risk Customer or PEP, then the procedure applied is stricter CDD procedures or Enhanced Due Diligence (EDD).
The Provider must examine the truthfulness of information submitted by the Prospective Customer by verifying supporting documents based on documents and/or other independent sources and ensuring the currency of such information.
In identifying corporate Prospective Customers, the Provider must determine the Beneficial Owner based on data and/or information submitted by the Prospective Customer.
Identification of Beneficial Owners from corporations in the form of limited liability companies can be conducted, for example, through information tracing as follows:
a) individuals who have a majority share ownership percentage. Majority share ownership depends on the ownership structure of the limited liability company, which can be based on a threshold, for example, parties who own shares with a percentage of more than 25% (twenty-five percent). b) in the event that no majority share ownership is found (shareholders have equal ownership percentages), then the identification of the shareholder who most controls the corporation is conducted through other forms, for example, individuals who have the ability to determine or appoint members of the Board of Directors. c) in the event that no shareholder who most controls the corporation is found, for example, decisions are taken collectively by all shareholders of the corporation, then the identification of the Beneficial Owner is based on members of the Board of Commissioners or Board of Directors who most control the aforementioned limited liability company. The steps of information tracing in the context of identifying Beneficial Owners as referred to in letters a), b), and c) above are not optional alternative steps, but are sequential steps that will each be used if the previous steps have been applied by the Provider. However, if the Provider has not yet been able to identify the Beneficial Owner through these steps.
For Beneficial Owners in the form of state institutions or government agencies, companies with majority state-owned shares, or public companies or issuers, Prospective Customers are not required to submit documents and/or identity documents of ultimate controllers. Nevertheless, the Provider still conducts identification and verification of the Beneficial Owner using data and information available in the public domain. Exceptions to the requirement to submit documents and/or identity documents of the ultimate controller of the Beneficial Owner must be documented by the Provider.
If the Provider doubts or cannot be convinced of the identity of the Beneficial Owner, the Provider is obligated to refuse to conduct business relations with the Prospective Customer or transactions with the Customer.
For Prospective Customers or Beneficial Owners whose business relations are rejected, the Provider must obtain at least information on name, identity number, address, and place and date of birth in accordance with copies of identity documents obtained by the Provider for the purpose of STR reporting.
Identification of Beneficial Owners can be conducted electronically, provided that the Provider's Electronic System is capable of identifying the official identity of the Beneficial Owner.
To determine whether the Prospective Customer or Customer acts for the benefit of a Beneficial Owner, implementation can be done, for example, by adding questions as to whether the Prospective Customer or Customer acts for the benefit of a Beneficial Owner when filling out electronic forms filled in via the Provider's website or application.
In the event that the identification of Beneficial Owners is conducted electronically, implementation can be done, for example, by filling out electronic forms and uploading copies of identity documents in accordance with the provisions regarding the obligation to conduct identification and verification of the identity of Beneficial Owners as referred to in the Financial Services Authority Regulation regarding the implementation of the AML and CFT program in the financial services sector, electronically (softcopy) through the Provider's website or application.
b. Verification of Beneficial Owners
In order to ensure the truthfulness of the identity of the Beneficial Owner, verification can be conducted by:
a) conducting interviews via telephone or video conference with the Beneficial Owner if necessary; b) matching the consistency of thumbprints, fingerprints, or face photos (selfies) with identity documents or other documents containing signatures, thumbprints, fingerprints, or face photos (selfies) of the Beneficial Owner; c) requesting the provision of more than one identity document of the Beneficial Owner issued by competent authorities if there is doubt regarding the existing identity documents; d) If necessary, conducting cross-checks to ensure consistency of various information provided. Cross-checks are conducted by methods, including:
(1) contacting the Prospective Customer via landline or office phone; (2) contacting the human resources official at the workplace of the Prospective Customer if the Prospective Customer is an employee of a company or agency; (3) confirming the Prospective Customer's income by requiring bank statements from banks or other financial service providers; or (4) conducting geographic information analysis to view forest conditions through remote sensing technology for Prospective Customers who are companies operating in the forestry sector; and/or e) ensuring that the Prospective Customer has no negative track record by verifying the identity of the Prospective Customer using other independent sources, including:
(1) lists of suspected terrorists and terrorist organizations issued by the Indonesian National Police; (2) lists of funding for the proliferation of weapons of mass destruction; or (3) other data such as the Prospective Customer's employer identity, phone accounts, and electricity accounts.
The completion of the identity verification process for Beneficial Owners is done before opening business relations with Prospective Customers or transactions with Customers who act on behalf of the benefit of Beneficial Owners.
In certain conditions, the verification process may be completed after the business relationship or transaction has been established. Certain conditions include conditions where:
a) document completeness cannot be fulfilled at the time of establishing business relations or transactions, for example, because documents are still being processed. Therefore, Beneficial Owners can submit documents after establishing business relations, within the timeframe established by the Provider, followed by adequate risk mitigation, and/or b) the risk level of individual Beneficial Owners is classified as low.
Verification of Beneficial Owners can be conducted electronically, provided that the Provider's Electronic System is capable of verifying the truthfulness of the official identity of the Beneficial Owner.
In the event that the Provider conducts electronic verification of Beneficial Owners, then the Provider must pay attention to the provisions as referred to in item 8 letter g.
ensure that information and supporting documents for Simplified CDD contain at least identity, source of funds, and purpose of transaction;
establish criteria for Customers with simple profiles and characteristics who receive Simplified CDD treatment, accompanied by clear reasons or bases for the establishment that are consistent with the risk assessment conducted by the Provider, for example, High-Risk Customers or PEPs are not included as Prospective Customers or Customers with Simplified CDD treatment;
ensure that Simplified CDD requirements are capable of managing and mitigating the level of threats of money laundering and/or terrorism financing;
ensuring that simplified CDD requirements do not cover Customers who, based on legislation, are categorized as high-risk Customers or PEPs;
notifying the Financial Services Authority (OJK) of the plan to implement simplified CDD procedures, including criteria for Customers with simple profiles and characteristics who receive simplified CDD treatment, and the time when the simplified CDD procedures will begin.
Example:
After conducting a risk analysis of its Customers, the Provider decides to implement simplified CDD on a specific group of Customers by amending its existing AML and CTF policies and procedures. Based on the amendment to the AML and CTF policies and procedures, if simplified CDD will be implemented starting from March 30, the Provider may submit a notification to the Financial Services Authority regarding the plan to implement simplified CDD before March 30;
c. Customers who have received simplified CDD treatment must be removed from the simplified CDD Customer list if they meet the following criteria:
d. The Provider may perform identification and verification of Prospective Customers or Customers for the purpose of simplified CDD electronically, provided the Provider's Electronic System is capable of identifying the official identity of the Prospective Customer or low-risk Customer, meets the criteria for Prospective Customers or Customers with simple profiles and characteristics, and is capable of verifying the authenticity of the official identity of the Prospective Customer or Customer in question.
e. In the event that the Provider performs identification and verification of Prospective Customers or Customers for the purpose of simplified CDD electronically, the implementation must take into account the provisions as referred to in number 7 letters d, e, f, and g, and number 8 letter g.
b. Third-party CDD does not apply to agency relationships or outsourcing. This is because in agency relationships or outsourcing, CDD is conducted for the benefit of the Provider in accordance with the Provider's procedures and subject to the control of the Provider who delegates the implementation of such procedures.
c. In the event that CDD results performed by a bank are available against a Prospective Customer, the Provider may use the CDD results performed by that bank against the Prospective Customer.
d. In the event that the Provider uses the results of Third-Party CDD (including bank CDD results):
CDD responsibility remains with the Provider.
The Provider must understand the purpose and intent of the business relationship and identify and verify the Customer and Beneficial Owner.
The Provider must obtain the necessary information related to CDD procedures as soon as possible.
The Provider must have cooperation with the third party in the form of a written agreement, wherein it must be ensured that the written agreement contains clauses confirming that the Provider has the right to obtain information, data, or copies of supporting Customer documents from the third party that has performed CDD on such Customer, provided that such information, data, or copies of supporting Customer documents are needed solely for the implementation of the AML and CTF program and not for other interests such as marketing.
Example: the interest in implementing the AML and CTF program is the fulfillment of requests for information, data, and copies of supporting Customer documents from the Financial Services Authority, PPATK, or law enforcement officials;
The Provider must take adequate steps to ensure that the third party is willing to fulfill requests for information and copies of supporting documents immediately at the first opportunity when needed by the Provider in the implementation of the AML and CTF program.
The Provider must ensure that the third party is a financial institution and/or a provider of goods and/or services and specific professions that have CDD procedures and are subject to supervision by the competent authority in accordance with applicable regulations.
As an example, the Provider may use CDD results performed by:
a) financial service providers in the banking, capital market, and/or non-bank financial industry, where the financial service provider has CDD procedures established by the competent supervisory authority, namely the Financial Services Authority; or b) commodity futures brokerage companies where the commodity futures brokerage company has CDD procedures established by the competent supervisory authority, namely the Commodity Futures Trading Regulatory Agency (BAPPEBTI).
The Provider must pay attention to information regarding the country risk where the third party originates.
In the event that the Provider intends to use third-party CDD results from a third party located in a high-risk country, this may be done if:
a) the third party is in the same financial group as the Provider; b) the financial group has effectively implemented CDD, document management, and the AML and CTF program in accordance with FATF Recommendations; c) adequate risk mitigation has been carried out by the AML and CTF unit against the high-risk country based on the AML and CTF program policy at the financial group level; and d) the financial group is supervised by a competent authority.
The Provider ensures that the third party is in a country that complies with FATF standards.
b. The Provider must reject the business relationship or transaction or close/terminate the business relationship with a Prospective Customer or Customer in the event that:
c. The Provider is obligated to notify the Customer in writing regarding the closure of the business relationship.
d. Written notification may be carried out by delivering a letter addressed to the Customer according to the address recorded in the Provider's database or announced through print media, electronic media, or other media.
e. In the event that the Provider rejects the business relationship with a Prospective Customer or rejects a transaction or closes/terminates the business relationship with a Customer, the Provider is obligated to report such rejection of business relationship or transaction or closure/termination of business relationship to PPATK as a Suspicious Transaction Report (TKM).
f. In the event that written notification has been carried out and the Customer does not withdraw the remaining funds stored with the Provider, the settlement of the remaining Customer funds is carried out in accordance with applicable legislation, including by handing over the remaining funds to the Estate Management Office (Balai Harta Peninggalan).
g. The Provider must document Prospective Customers or Customers subject to transaction rejection or business relationship closure as referred to in letter b in a separate list.
b. Policies and procedures for managing Money Laundering and/or Terrorism Financing risks on an ongoing basis include:
Risk Identification
In conducting risk identification, the Provider must assess the Money Laundering and/or Terrorism Financing risks inherent in its business by considering inherent risks such as Customer risk, country/geographical area/jurisdiction risk, product/service/transaction risk, and distribution network (delivery channels) risk.
Risk Control and Mitigation
Risk control and mitigation that can be applied include:
a) identifying and verifying Prospective Customers and monitoring Customer transactions; b) increasing the frequency of supervision and conducting continuous review of business relationships; c) upgrading CDD to Enhanced Due Diligence (EDD) conducted by the Provider against increased Money Laundering and/or Terrorism Financing risks present in the Customer, the source of funds used to purchase products/services/transactions, and the Customer's transaction patterns in purchasing products and services; and
d) escalation or hierarchical approval for opening business relationships or transactions through senior official approval.
b. The Provider must manage or document Customer data, including data obtained from the identification and verification process of Prospective Customers or monitoring of Customer transactions, including those that are high-risk or PEPs in the context of EDD, Beneficial Owners, or those classified as low-risk and meeting the criteria for Prospective Customers or Customers with simple profiles and characteristics in the context of Simplified CDD.
c. The Provider must have policies and procedures for document retention periods covering:
documents related to Customer data must be retained for a period of at least 5 (five) years from:
a) the end of the business relationship with the Customer; and/or b) the discovery of transaction inconsistencies with economic purposes and/or business purposes.
documents related to Customer financial transactions with a period as regulated in laws regarding corporate documents;
documents retained must include at least:
a) Customer identity and supporting documents;
b) transaction information conducted; c) results of analysis that have been conducted; d) correspondence with Customers; and e) other documents related to TKM reporting.
d. Documents as mentioned in letters b and c may be stored via data format or electronic documents in the Provider's database while still paying attention to data or electronic document security systems.
e. In the event that documents as mentioned in letters b and c are stored via data format or electronic documents in the Provider's database, the Provider must be able to display the data or electronic documents in full in accordance with legislation, when requested by the Financial Services Authority and/or other competent authorities such as PPATK and/or law enforcement officials.
b. The obligation to update data regarding Customer information and documents as referred to in Financial Services Authority Regulations regarding the implementation of AML and CTF programs in the financial services sector.
c. Data, information, and/or supporting document updating activities are based on the Money Laundering and/or Terrorism Financing risk level of the Customer and are focused on higher-risk Customers first.
d. Customer risk levels are obtained from the results of Customer risk assessments formulated in Customer classification based on risk levels, which can be divided into:
e. In conducting data, information, and/or supporting document updating (Customer data updating), the Provider must document Customer updating efforts in the form of worksheets containing the Customer's name, date of Customer update, method of Customer update (e.g., via e-mail, telephone, letter, news in mass media and electronic media including the internet or other trusted sources), results of Customer data updates, and follow-up on update results, particularly for Customer data that could not be updated.
f. In the event that the Provider's resources are limited, Customer updating activities are conducted on a priority scale, including based on:
g. High-Risk Customer criteria can be seen from:
background or profile of High-Risk Customers;
financial services sector products that are high-risk for use as a means of Money Laundering and/or Terrorism Financing;
transactions with parties from high-risk countries or Customers having significant relationships with high-risk countries;
transactions inconsistent with profile;
included in the PEP category;
business field included in high-risk business;
country or territory of origin, domicile, or place of transaction included in high-risk countries;
listed in the list of suspected terrorists and terrorist organizations;
listed in the list of Proliferation Financing for Weapons of Mass Destruction; and/or
transactions suspected to be related to proceeds of Money Laundering and/or Terrorism Financing.
h. Implementation of Customer data updates listed in the data update plan report can be conducted, among others, at:
i. The Provider must ensure that documents, data, or information collected in the CDD process are always updated and remain relevant by re-examining existing data, particularly those related to High-Risk Customers or PEPs.
j. Regarding the updating of the list of suspected terrorists and terrorist organizations and the list of Proliferation Financing for Weapons of Mass Destruction, the Provider:
must maintain the list of suspected terrorists and terrorist organizations and the list of Proliferation Financing for Weapons of Mass Destruction;
must match the consistency of Customer names and information held by the Provider with names and information in the list of suspected terrorists and terrorist organizations and the list of Proliferation Financing for Weapons of Mass Destruction provided by the Financial Services Authority;
must match the consistency of Prospective Customer names and information to become the Provider's Customers with names and information in the list of suspected terrorists and terrorist organizations and the list of Proliferation Financing for Weapons of Mass Destruction received by the Provider; and
may use the updated list of suspected terrorists and terrorist organizations and the list of Proliferation Financing for Weapons of Mass Destruction as a screening tool when establishing business relationships with Prospective Customers.
k. The Provider may update Customer data electronically. In the event that the Provider conducts the data updating process electronically, then:
l. The Provider must manage and document the Customer data updating process.
m. Management and documentation of Customer data updates can be conducted manually in written form through formal documents such as memos, notes, or records, which can also be stored via data format or electronic documents in the Provider's database.
b. Monitoring conducted by the Provider as referred to in letter a must take into account the following matters:
monitoring is conducted continuously to identify consistency between Customer transactions and Customer risk profiles;
monitoring includes analysis of all transactions that do not match the Customer's risk profile; and
if necessary, the Provider may request information regarding the background and purpose of transactions for transactions that do not match the Customer profile, while paying attention to anti-tipping-off provisions.
Anti-tipping-off provisions are provisions that prohibit the Provider from informing Customers or any other party, whether directly or indirectly, in any manner, regarding TKM reports that are being prepared or have been submitted to PPATK.
c. Monitoring of Customer profiles and transactions is conducted continuously and includes activities:
d. Information sources that can be used to monitor Customers designated as suspects or defendants can be obtained, among others, from:
e. The Provider must classify transactions and Customers requiring special monitoring. Monitoring of Customer transactions must be stricter if there are High-Risk Customers.
f. In the event that the Service Provider conducts electronic monitoring of Customer profiles and transactions, the Service Provider must ensure that the Electronic System used can:
Policies and Procedures for Reporting to PPATK
a. The Service Provider must have policies and procedures for reporting obligations to PPATK in accordance with the provisions and reporting procedures as referred to in legislation governing the prevention and eradication of Money Laundering and legislation governing the prevention and eradication of Terrorism Financing, including implementing regulations such as the PPATK Head Regulation. b. The policies and procedures for reporting obligations as referred to in letter a cover at least policies and procedures for reporting STRs, reports related to the Weapons of Mass Destruction Proliferation Financing list, and other reports related to the implementation of the AML/CFT program in the event of information requests from PPATK.
Policies and Procedures for Reporting to the National Police of the Republic of Indonesia
The Service Provider must have policies and procedures for reporting obligations to the National Police of the Republic of Indonesia regarding reports related to suspected terrorist lists and terrorist organization lists, and other reports related to the implementation of the AML/CFT program in the event of information requests from the National Police of the Republic of Indonesia.
V. INTERNAL CONTROL
A. GENERAL PROVISIONS ON INTERNAL CONTROL
An effective risk-based AML/CFT program must be implemented in internal control and internalized in the Service Provider's business processes.
The Service Provider must have an internal control system to ensure the Service Provider's compliance in effectively implementing the AML/CFT program and to minimize the Money Laundering and/or Terrorism Financing risks faced by the Service Provider.
In internal control, the Service Provider must pay attention to the following:
a. the scale and complexity of the Service Provider; b. the business or operational activities of the Service Provider, including geographical/country aspects, Customer profiles, products or services, and the Service Provider's overall transaction activities;
c. the distribution channels used;
d. the volume and intensity of transactions; e. the level of risk assessment for each business activity of the Service Provider; and/or f. the business relationship between the Service Provider and Customers, whether directly or through agents, third parties, correspondents, or non-face-to-face communication.
The Service Provider must have an effective internal control framework in the implementation of the risk-based AML/CFT program, which covers at least:
a. adequate policies, procedures, and internal monitoring capable of timely detecting weaknesses and deviations occurring in the implementation of the AML/CFT program; b. limits on authority and responsibility of work units related to the implementation of the AML/CFT program, where the Service Provider must ensure a clear separation of duties, authority, and responsibilities between the special internal control unit, functions, or officials designated to perform internal control functions and other business units of the Service Provider;
c. the appointment of the UKK and/or officials responsible for the implementation of the AML/CFT program;
d. updating the compliance standards for the implementation of the AML/CFT program; e. policies, procedures, and monitoring related to the screening/recruitment of Service Provider employees, to ensure that Service Provider employees are not used as a means of ML/TF through the Service Provider's business processes; f. monitoring of Customers, Customer transactions, and/or the use of Information Technology in the Service Provider's business processes, particularly those with high Money Laundering and/or Terrorism Financing risks, including monitoring of specific matters that require special attention based on suggestions and information from industry associations, regulators, or law enforcement agencies; g. the provision of systems capable of accurately identifying, monitoring, and reporting STRs; h. the provision of regular reviews of risk assessments and process management;
i. adequate supervision before the offering of new products or services, the use of new technology, or the offering of modified products/services that have the potential to increase Money Laundering and/or Terrorism Financing risks;
j. the prompt and accurate dissemination of information in the event of indications and/or suspicions related to Money Laundering and/or Terrorism Financing risks, corrective steps taken, results of weakness identification regarding owned regulations, follow-up plans for improvements, and reports submitted to competent authorities; k. compliance with applicable legislation, reporting requirements, and recommendations related to compliance in the implementation of the AML/CFT program, and updating changes in applicable legislation;
l. the implementation of policies, procedures, and controls over Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD);
m. adequate supervision regarding High-Risk Customers, transactions, and products, such as transaction limits or management approval; n. adequate supervision of Service Provider employees who complete reports, receive tips, monitor suspicious activities, or are involved in other activities that are part of the implementation of the AML/CFT program; o. the integration of compliance with the implementation of the AML/CFT program into job descriptions and appropriate performance evaluations; p. training related to the implementation of the AML/CFT program that is appropriate and relevant for all employees; q. testing of the effectiveness of the implementation of the AML/CFT program by taking random samples and documenting the tests conducted; and r. independent internal audits to test compliance and the effectiveness of AML/CFT implementation, carried out in accordance with the needs and complexity of the Service Provider's business.
In conducting internal control, the Service Provider may use regulatory technology such as algorithms, the use of artificial intelligence technology, and/or machine learning.
In the event that the Service Provider conducts internal control using regulatory technology as referred to in number 5, the Service Provider must ensure that the regulatory technology used in the internal control system:
a. is based on the results of risk assessments, which include how the Service Provider manages and mitigates risks over the Information Technology used; b. is guaranteed to be reliable and has been certified by the Ministry responsible for communication and information technology affairs; and
c. guarantees data and information security, including the use of security tools such as encryption technology, antivirus, and firewalls.
The person responsible for internal control related to the implementation of the risk-based AML/CFT program as referred to in number 5 has authority covering at least:
a. formulating risk-based audit programs with audit priorities on work units classified as having high business complexity; b. assessing the adequacy of existing processes at the Service Provider in identifying and reporting STRs, taking into account anti-tipping off regulations;
c. assisting the Service Provider's Board of Directors and Board of Commissioners in conducting supervision by detailing the operational aspects of planning, implementation, and monitoring of audit results;
d. creating analyses and assessments in the fields of finance, accounting, operations, and other activities through audits; e. identifying all possibilities to improve and increase the efficiency of resource and fund usage; and f. providing objective improvement suggestions and information regarding audited activities at all levels of the Service Provider's management.
The person responsible for internal control must:
a. ensure that internal control in the implementation of the AML/CFT program is applied well, correctly, and effectively in accordance with established policies and procedures, and covers the internal control framework as referred to in number 4; b. create a culture of risk management and compliance; and
c. ensure that employees comply with established policies and procedures.
The Service Provider may have a suspected violation reporting system (whistleblowing system/WBS) intended to maintain professional integrity and the accountability of the Service Provider. The system allows internal company parties (employees) or external parties such as Prospective Customers, Customers, or the general public to report suspected violations of ethics, behavior, work procedures, and/or applicable legislation committed by human resources (including Directors and the Board of Commissioners) of the Service Provider.
The suspected violation reporting system (WBS) covers at least:
a. an independent, free, and confidential reporting system; b. protection of the reporter's identity confidentiality;
c. protection of the reporter from pressure, dismissal, legal lawsuits, up to physical actions. Protection is not only for the reporter but can also be extended to the reporter's family members; and
d. information on the implementation of follow-up, including when, how, and to which institution the WBS follow-up is conducted.
The independent work unit managing the suspected violation reporting system (WBS) may be held concurrently by the official designated as the person responsible for internal control.
B. INTERNAL CONTROL OVER THE USE OF INFORMATION TECHNOLOGY IN THE SERVICE PROVIDER'S BUSINESS PROCESS.
The effective internal control system for all aspects of Information Technology usage as referred to in number 2 is part of the Service Provider's overall internal control system.
The Service Provider must ensure the continuity and stability of Information Technology operations and conduct risk mitigation that has the potential to disrupt the Service Provider's operational activities.
The Service Provider must ensure that information security is implemented effectively, paying attention to at least:
a. information security intended to maintain the confidentiality, integrity, and availability of managed information effectively and efficiently, taking into account compliance with regulations; and b. information security conducted on technological aspects, human resources, and processes in the use of Information Technology.
In the event that the Service Provider uses third-party Information Technology service providers used in the implementation of the AML/CFT program, the Service Provider must ensure that the third-party Information Technology service provider has implemented Information Technology usage risk management. For example, the service provider has certification from an official institution.
In the event that the Service Provider uses Information Technology service providers, the Service Provider must take specific actions as a form of risk mitigation in the event of conditions including:
a. deterioration in the performance of Information Technology services by the Information Technology service provider, which can have a significant impact on the Service Provider's business activities; b. the third-party Information Technology service provider becomes insolvent, in the process of liquidation, or is declared bankrupt by a court;
c. violations by the third-party Information Technology service provider regarding regulations governing the obligation to keep Customer personal data confidential; and/or
d. conditions that cause the Service Provider to be unable to provide data required for supervision by the Financial Services Authority and/or information needs from other competent authorities such as PPATK and/or law enforcement agencies.
VI. MANAGEMENT INFORMATION SYSTEM
viruses and firewalls, including their updates, with reference to regulations issued by the Ministry or Agency responsible for cyber and state cryptography affairs;
6) increasing human resource awareness in their environment to provide personal data protection in the Information Technology they manage;
7) conducting training on preventing failures in personal data protection in the Information Technology they manage;
8) conducting periodic IT audits and/or as needed according to the needs of the Provider, intended to ensure the reliability of the Information Technology used and to ensure that their Information Technology is not used/exploited by Money Laundering and/or Terrorism Financing perpetrators;
and/or
9) providing education to Customers regarding personal data security and prevention of cyberattacks.
b. personal data protection, which can be done as follows:
c. data centers and disaster recovery centers used by the Provider in carrying out Crowdfunding Services in accordance with applicable legislation.
VII. HUMAN RESOURCES AND TRAINING
A. HUMAN RESOURCES
To prevent the Provider from being used as a medium or destination for Money Laundering and/or Terrorism Financing involving internal parties, the Provider is obligated to conduct:
a. screening procedures for the acceptance of new employees (pre-employee screening) as part of the implementation of know your employee; and b. identification and monitoring of employee profiles.
Screening procedures for the acceptance of new employees (pre-employee screening) are conducted in the form of:
a. screening methods intended to ensure that the profile of prospective employees has no criminal records, including requiring prospective employees to create a statement letter and/or submit a police record certificate; b. verifying the identity and education obtained by prospective employees, including through face-to-face or virtual interview processes intended to further ensure the truthfulness of information and data from prospective employees;
c. conducting research through media or other information regarding the background of prospective employees, including work history and/or work experience of prospective employees;
d. ensuring a good track record of prospective employees, including by requesting recommendation letters from previous companies where the prospective employee has worked; and e. ensuring that the credit quality of prospective employees is not classified as non-performing loans.
Identification and monitoring of employee profiles, including employee behavior and lifestyle, include:
a. verifying employees who have experienced significant changes in lifestyle; b. ensuring that employees understand and comply with the employee code of conduct; and
c. evaluating employees responsible for activities classified as high-risk, including those with access to Provider data and/or those interacting with Prospective Customers or Customers.
Screening procedures (pre-employee screening), identification, and monitoring of employee profiles are documented in the Provider's written policies and procedures for know your employee, guided by regulations governing the implementation of anti-fraud strategies.
B. TRAINING
VIII. REPORTING
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
IX. OTHER PROVISIONS
Provisions regarding the prevention of Weapons of Mass Destruction Proliferation Financing in this Financial Services Authority Circular are advisory until the implementation of the prevention of Weapons of Mass Destruction Proliferation Financing is mandated for Providers based on Financial Services Authority Regulations regarding the implementation of anti-money laundering and counter-terrorism financing programs in the financial services sector.
X. CLOSING
This Financial Services Authority Circular takes effect on the date of establishment.
Established in Jakarta on September 20, 2022
CHIEF EXECUTIVE
OF THE CAPITAL MARKET SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
INARNO DJAJADI
APPENDIX
FINANCIAL SERVICES AUTHORITY CIRCULAR
REPUBLIC OF INDONESIA
NUMBER 17 /SEOJK.04/2022
REGARDING
GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS FOR INFORMATION TECHNOLOGY-BASED CROWDFUNDING SERVICE PROVIDERS
A. RISK-BASED APPROACH CYCLE (RISK BASED APPROACH) STEP 1: IDENTIFY INHERENT RISK Types of Risks Customer Risk Country/Geographic/Jurisdiction Risk Product/Service/Transaction Risk Distribution Network Risk Customers in Crowdfunding Services use digital identity systems and non face-to-face services based on inherent risk identification. In the Provider's business activities, there are specifics, namely the collection of personal data and customer verification using electronic systems. Country risk, geographic area risk, or jurisdiction risk, along with other risk factors, provide useful information for assessing money laundering and terrorism financing risks. Products, services, or transactions that may be exposed to higher risks related to Money Laundering and Terrorism Financing. Additionally, there are factors that can increase the risk profile of products, services, or transactions. One of the distinctive features of the Crowdfunding Service Provider's business is the distribution network (delivery channels) process conducted without direct meetings (non face-to-face). Other relevant risks, especially those related to the use of electronic systems.
STEP 2: SET RISK TOLERANCE
Setting the level and type of risk that can be tolerated by the Provider
STEP 3: RISK-BASED APPROACH
Implementing mitigation and control strategies for high-risk areas regarding money laundering and terrorism financing risks
STEP 6: REVIEW OF RISK-BASED APPROACH (RISK BASED APPROACH) Conducting periodic evaluations of the risk-based approach (Risk Based Approach/RBA) to assess the effectiveness of implementing the AML and CFT program
STEP 5: RESIDUAL RISK EVALUATION
Ensuring residual risk is in accordance with the established risk tolerance. (Residual risk is the risk remaining after the implementation of internal controls and risk mitigation)
STEP 4: RISK REDUCTION AND CONTROL
Implementing internal controls to limit identified money laundering and terrorism financing risks during risk assessment, and developing and compiling mitigation strategy documents for high-risk areas
B. LIKELIHOOD AND CONSEQUENCE MATRIX
b. Consequence
Consequence in this context refers to the level of seriousness or consequences of damage or loss that occurs if a risk materializes.
The emergence of consequences depends on the Provider's internal conditions. Consequences arising from Money Laundering and Terrorism Financing risks can be viewed from various perspectives, including:
Likelihood and Consequence Matrix
Each box in the matrix indicates the resources needed to perform:
Box 5 requires effort and monitoring to prevent an increase in risk (not changing to Box 4 or Box 3).
c. Box 4
The condition in Box 4 indicates a moderate likelihood and impact of Money Laundering and Terrorism Financing risks. In this condition, the Service Provider needs to take actions, efforts, or monitoring. Adequate actions, efforts, or monitoring will reduce the likelihood and impact (consequence) of Money Laundering and/or Terrorism Financing risks. Conversely, if actions, efforts, or monitoring are inadequate, the risk will increase to high risk.
d. Box 3
The condition in Box 3 indicates that the Service Provider needs to allocate resources to carry out actions, efforts, and monitoring. There is a likelihood of Money Laundering and/or Terrorism Financing risks with a consequence that can be categorized as moderate. Therefore, the Service Provider needs to pay attention to all existing business activities and business relationships so as not to cause an increase in risk (not changing to Box 2 or Box 1).
e. Box 2
The condition in Box 2 indicates that the likelihood of Money Laundering and/or Terrorism Financing risks is high. In this condition, the Service Provider needs to pay attention to all business activities and business relationships and deploy resources to suppress the likelihood and consequence of risks. The Service Provider needs to apply stricter mitigation steps to prevent the risk from increasing to very high, or becoming a condition in Box 1.
f. Box 1
The condition in Box 1 indicates that the likelihood of Money Laundering and/or Terrorism Financing risks is very high, including the magnitude of the consequence of such risks. In such conditions, more resources, special actions, special efforts, and periodic monitoring are needed to minimize such risks.
C. EXAMPLES OF SUSPICIOUS FINANCIAL TRANSACTIONS RELATED TO MONEY LAUNDERING IN THE PROVISION OF INFORMATION TECHNOLOGY-BASED CROWDFUNDING SERVICES
Users are suspected of acting on behalf of third parties but do not inform the Service Provider.
The Service Provider realizes that the User is a perpetrator suspected of committing Money Laundering and/or Terrorism Financing.
The Service Provider finds inconsistencies between the User's profile and the value of transactions conducted.
Example: A student as an Investor makes an investment through the Service Provider with a value of hundreds of millions or billions of Rupiah.
The Service Provider suspects involvement between the Investor and the Issuer or has an affiliation relationship in relation to Money Laundering and/or Terrorism Financing.
The Service Provider receives information from reliable sources (PPATK, supervisory and regulatory bodies, including the Financial Services Authority, law enforcement agencies, mass media, or other sources) that the User is suspected of being involved in illegal activities and/or has a criminal background.
The User changes or cancels the transaction after the Service Provider requests the User's identity documents.
Registration as a User in the name of a business entity, foundation, organization, and/or individual involved, suspected of being involved, or related to terrorist activities.
User transactions related to business using personal accounts.
Users/managers or owners of Users are suspected of using proceeds of crime.
Example: Proceeds of crime are used by the Investor to buy securities issued by the Issuer or proceeds of crime are used by the Issuer to pay dividends to the Investor through the Service Provider.
Managers or owners of Users are suspected of committing a crime.
Transactions involve fictitious companies or paper companies.
Financial transactions requested by PPATK because the User has been designated as a suspect/defendant in a criminal case.
Example: The Investor has been designated as a suspect/defendant.
Financial transactions requested by PPATK due to their connection with other transactions currently under analysis or examination by PPATK.
Financial transactions requested by PPATK based on investigations or inquiries currently being conducted by law enforcement agencies.
Users/candidate Users provide incorrect information regarding matters related to identity, income sources, or their business.
Example: The Issuer does not provide correct information regarding income, office address, business activities, and others.
Users/candidate Users use identity documents whose authenticity is doubted or suspected to be fake, such as different signatures or different photos.
Users/candidate Users are reluctant or refuse to provide information/documents requested by Service Provider officers without a clear reason.
Users are unwilling to provide correct information or immediately decide to terminate business relationships/close accounts when Service Provider officers request information regarding transactions conducted.
Users are reluctant to provide complete information on the source of funds and the purpose of transactions to the Service Provider.
Users use different names (different spellings) from one transaction to another.
Transactions involve fictitious companies with indications of the use of fake documents.
Users attempt to convince Service Provider employees not to complete any documentation required to conduct transactions.
Inconsistencies in identification or verification are found that cannot be explained (e.g., differences in previous country of residence, differences in the country that issued previous passports, differences in countries visited according to the passport, or differences in documents related to name, address, and date of birth).
Users provide information that is doubted or unclear.
Users refuse to provide personal identity documents.
All presented identities cannot be verified for authenticity due to certain reasons.
Users present different identity documents each time a transaction is conducted.
There are facts regarding the history of Investors and Issuers listed in collectibility category 2 or above through data from the Financial Information Services System (SLIK).
There are facts regarding the history of Investors and Issuers listed as issuers of empty checks and/or empty giro orders through data from the National Blacklist (DHN).
Users use Post Office Box (PO BOX) addresses and originate from high-risk countries.
D. EXAMPLE FORMAT OF CUSTOMER DATA UPDATE PLAN REPORT CUSTOMER DATA UPDATE PLAN REPORT (SERVICE PROVIDER NAME) YEAR ……
| No. | Customer Type and Risk Level | Total Single Investor Identification | Information to be Updated | Method or Strategy | Target Percentage of Single Investor Identification Fulfillment to be Updated in a Certain Period | Single Investor Identification to be Updated | % against Total Single Investor Identification |
|---|---|---|---|---|---|---|---|
| (a) | (b) | (c) | (d) | (e) | (f) | (g) | |
| 1 | Individual Customers | ||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk | |||||||
| 2 | Corporate Customers | ||||||
| a. Non-micro and small business | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| b. Micro and small business | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| c. Financial Service Institutions (PJK) | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| d. Foundations | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| e. Other than companies and foundations (with legal entity status or without legal entity status) | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| 3 | Other Legal Arrangement Customers | ||||||
| a. Trust | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| b. Other than Trust | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| 4. State Institutions, Government Agencies, International Institutions, and Foreign State Representations | |||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk |
E. EXAMPLE FORMAT OF CUSTOMER DATA UPDATE REALIZATION REPORT CUSTOMER DATA UPDATE REALIZATION REPORT (SERVICE PROVIDER NAME) YEAR ……
| No. | Customer Type and Risk Level | Development | Obstacles | Efforts to be Taken | Target | Realization | Deviation (%) |
|---|---|---|---|---|---|---|---|
| (a) | (b) | (c) | (d) | (e) | (f) | (g) | |
| 1 | Individual Customers | ||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk | |||||||
| 2 | Corporate Customers | ||||||
| a. Non-micro and small business | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| b. Micro and small business | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| c. Financial Service Institutions (PJK) | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| d. Foundations | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| e. Other than companies and foundations (with legal entity status or without legal entity status) | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| 3 | Other Legal Arrangement Customers | ||||||
| a. Trust | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| b. Other than Trust | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| 4. State Institutions, Government Agencies, International Institutions, and Foreign State Representations | |||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk |
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
(b). As per the column.
(c). Filled with the target number of Single Investor Identifications to be updated.
(d). Filled with the realized number of Single Investor Identifications to be updated.
(e). Filled with the percentage difference between the target Single Investor Identification to be updated (c) and (d) the realized number of Single Investor Identifications to be updated.
(f). Obstacles can be filled with more than one.
(g). Filled with efforts to overcome obstacles and can be more than one.
2. The number of risk levels can be adjusted according to policies established by the Service Provider.
Determined in Jakarta on date 20 September 2022 EXECUTIVE HEAD CAPITAL MARKET SUPERVISOR FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, signed INARNO DJAJADI
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.