2021-01-29 | 6/SEOJK.05/2021Added
This circular mandates Information Technology-Based Lending Service Providers to implement Anti-Money Laundering and Counter-Terrorism Financing programs based on a risk-based approach, including customer due diligence and enhanced due diligence for high-risk clients. Providers are required to identify beneficial owners and politically exposed persons, report suspicious transactions to the Financial Transaction Reports and Analysis Centre, and maintain adequate internal controls to prevent the misuse of lending services for money laundering, terrorism financing, or weapons proliferation financing. The document defines specific roles for the Board of Directors and Board of Commissioners and outlines the vulnerabilities of lending platforms to financial crimes.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
The Board of Directors of Information Technology-Based Lending Service Providers, At your place.
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 6/SEOJK.05/2021 CONCERNING GUIDELINES FOR THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS FOR INFORMATION TECHNOLOGY-BASED LENDING SERVICE PROVIDERS
In relation to the mandate of Article 68 of the Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2017 Number 57, Supplement to the State Gazette of the Republic of Indonesia Number 6035) as amended by the Financial Services Authority Regulation Number 23/POJK.01/2019 concerning Amendments to the Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2019 Number 178, Supplement to the State Gazette of the Republic of Indonesia Number 6394), it is necessary to regulate further regarding the implementation of anti-money laundering and counter-terrorism financing programs for Information Technology-Based Lending Service Providers in the Financial Services Authority Circular Letter as follows:
I. GENERAL PROVISIONS
In this Financial Services Authority Circular Letter, the following terms are defined as:
a. Financial Services Provider of Information Technology-Based Lending Services is a provider of information technology-based lending services as referred to in the Financial Services Authority regulations regarding information technology-based lending services. b. Information Technology-Based Lending Service Provider, hereinafter referred to as the Provider, is an Indonesian legal entity that provides, manages, and operates information technology-based lending services.
c. Borrower is a person and/or legal entity that has debt arising from an information technology-based lending service agreement.
d. Lender is a person, legal entity, and/or business entity that has a claim arising from an information technology-based lending service agreement. e. Information Technology-Based Lending Service User, hereinafter referred to as User, is a Lender and Borrower who uses information technology-based lending services. f. Customer is the User as referred to in letter e. g. Prospective Customer is a prospective User who will use the Provider's services. h. Board of Directors:
Providers are highly vulnerable to the possibility of being used as a means of Money Laundering, Terrorism Financing, and/or financing the Proliferation of Weapons of Mass Destruction. Providers may become an entry point for wealth that is the result of MLCA or TFCA into the financial system, which can subsequently be utilized for the interests of criminals. For example, for Money Laundering perpetrators, such wealth can be withdrawn as wealth that appears legitimate and can no longer be traced to its origin. Whereas for Terrorism Financing or financing the Proliferation of Weapons of Mass Destruction perpetrators, such wealth can be used to finance terrorist activities or fund the development of weapons of mass destruction.
The increasing complexity of financial services products and services, including their marketing (multi-channel marketing), and the increasing use of Information Technology in the financial services industry, result in a higher risk of Providers being used as a means of Money Laundering, Terrorism Financing, and/or financing the Proliferation of Weapons of Mass Destruction.
In this regard, there is a need to improve the quality of the implementation of AML and CFT programs and the prevention of financing the Proliferation of Weapons of Mass Destruction based on a risk-based approach in accordance with general principles applicable internationally and in line with national risk assessment (NRA) and sectoral risk assessment (SRA).
General Overview of Money Laundering
a. On the basis, the process of Money Laundering can be grouped into 3 (three) stages of activities, including:
General Overview of Terrorism Financing
a. Every terrorist act carried out in Indonesia basically requires support, both in the form of armaments (firearms, sharp weapons, and explosives), housing, vehicles for mobilization, war facilities, funds, and provision of other needs to carry out terrorist acts. In terrorism criminal acts, money or funds are intended as a means to carry out actions and not as a target to be sought, so various methods will be used by perpetrators of terrorism criminal acts to obtain funds, whether legally such as selling goods and/or services, or through criminal acts such as robbery, fraud, up to hacking online investment websites. The accumulated funds are used to obtain armaments, purchase explosives, build networks or recruit members, train for war, mobilize members from or to a place for the implementation of terrorist actions. The Law Number 9 of 2013 concerning the Prevention and Eradication of Terrorism Financing Criminal Acts contains the definition of funds as all assets or movable or immovable objects, whether tangible or intangible, obtained in any way and in any form, including in digital or electronic format, evidence of ownership, or connection with all assets or objects thereof including but not limited to bank loans, traveler's checks, checks issued by banks, money transfer orders, shares, securities, bonds, bank drafts, and debt acknowledgments.
b. TFCA is the direct or indirect use of wealth for terrorist activities, terrorist organizations, or terrorists. Terrorism Financing is basically a type of criminal act different from MLCA, however, both contain similarities in using financial services as a means to commit a criminal act.
c. Unlike MLCA, whose purpose is to disguise the origin of wealth, the purpose of TFCA is to assist terrorist activities, whether with wealth that is the result of a criminal act or with wealth obtained legally. To prevent Providers from being used as a means of TFCA, Providers need to implement AML and CFT programs adequately.
d. Some Terrorism Financing modus operandi include:
1) robbery or theft, where TFCA perpetrators claim that it is halal to take the property of others or other parties. In this regard, TFCA perpetrators do:
a) theft of funds for Terrorism Financing by taking loans from Providers without any intention to repay such loans. In this case, perpetrators consider that funds from theft by borrowing from such Providers are funds that can be used for terrorist actions; and/or b) criminal acts such as robbery where funds from robbery crimes are combined with funds obtained by Borrowers through Providers to subsequently be used to finance the management of terrorist networks and terrorist activities;
2) perpetrators hack accounts of Customers registered with Providers to take out loans through Providers, the funds of which are used for terrorist activities;
3) misuse of foundations, where loan funds received by foundations as Borrowers through Providers are misused to finance the management of terrorist networks and terrorist activities;
4) disguise of business activities (goods/services) where Borrowers, when taking out loans through Providers, disguise their business activities such as trading or service businesses, but in practice, the loan funds mentioned are used to finance the management of terrorist networks and terrorist activities;
5) borrowing funds through several Providers intended to obtain maximum loan funds to be used to finance the management of terrorist networks and terrorist activities, and intended to break up transactions to avoid reporting;
6) funding from individuals or institutions, both domestic and foreign, given directly or indirectly to Lenders to be distributed to Borrowers affiliated with such individuals or institutions, where such funds are used to finance the management of terrorist networks and terrorist activities;
7) use of business addresses by Borrowers that have no connection with the work of Borrowers, intended so that loan funds can be approved and received by Borrowers in relatively large amounts, where the funds received by Borrowers are used to finance the management of terrorist networks and terrorist activities. Example: housewives as Borrowers with addresses in business areas receive relatively large loan funds through Providers to subsequently be used to finance the management of terrorist networks and terrorist activities; and
8) use of students/students who meet the requirements as Borrowers through Providers, among others for the schooling needs of Borrowers that
conducted regularly, where the funds received by the Student are used to fund the management of terrorist networks and terrorist activities.
II. IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS AND THE PREVENTION OF WEAPONS OF MASS DESTRUCTION PROLIFERATION FINANCING BASED ON RISK (RISK BASED APPROACH)
Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs and the Prevention of Weapons of Mass Destruction Proliferation Financing Based on Risk (Risk Based Approach) must include at least:
a. active supervision by the Board of Directors and Board of Commissioners; b. policies and procedures;
c. internal controls;
d. information management systems; and e. human resources and training.
Obligations for the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs and the Prevention of Weapons of Mass Destruction Proliferation Financing Based on Risk (Risk Based Approach)
a. Anti-Money Laundering and Counter-Terrorism Financing Programs and the prevention of Weapons of Mass Destruction Proliferation Financing are programs that must be implemented by Providers in conducting business relationships and transactions with Users. These programs include, among other things, requirements stipulated in the FATF Recommendations as efforts to protect Providers from being used as instruments or targets for money laundering, terrorism financing, and the prevention of financing for the proliferation of weapons of mass destruction.
The FATF Recommendations emphasize that Providers are obligated to identify, assess, and understand the risks of Money Laundering and Terrorism Financing, as well as the financing of the proliferation of weapons of mass destruction, related to Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels).
Providers conduct self-assessments and implement effective risk management framework processes. Providers must document and update risk assessments related to the implementation of Anti-Money Laundering and Counter-Terrorism Financing programs and the prevention of financing for the proliferation of weapons of mass destruction.
b. The implementation of Anti-Money Laundering and Counter-Terrorism Financing programs and the prevention of financing for the proliferation of weapons of mass destruction based on risk (risk based approach) supports Providers in implementing prevention and risk mitigation measures commensurate with the identified Money Laundering and Terrorism Financing (TPPU) and Terrorism Financing (TPPT) risks, as well as the financing of the proliferation of weapons of mass destruction. Providers can subsequently allocate their resources according to their risk profile, manage internal controls, internal structures, and implement policies and procedures to prevent and detect Money Laundering and Terrorism Financing, as well as the financing of the proliferation of weapons of mass destruction.
c. In the implementation of Anti-Money Laundering and Counter-Terrorism Financing programs and the prevention of financing for the proliferation of weapons of mass destruction based on risk (risk based approach), Providers must refer to the risks listed in the NRA (National Risk Assessment) and SRA (Sectoral Risk Assessment). The risks listed in the NRA and SRA may develop and change; therefore, Providers must be responsive to changes in these risks.
a. Definition of Risk
Risk can be defined as the likelihood (likelihood) of an event and its impact. Simply put, risk can be seen as a combination of the probability of occurrence and the level of damage or loss that may result from an event. In the context of Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction, risk is interpreted as:
at the national level, as a threat and vulnerability caused by Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction that endanger the national financial system as well as national safety and security; and
at the Provider level, as a threat and vulnerability that places the Provider at risk of being used as an instrument for Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction.
Threats can be parties or objects that can cause loss. In the context of Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction, threats can include criminal actors, facilitators (parties assisting in the execution of criminal acts), funds of criminal perpetrators, or even terrorist groups.
Vulnerability is a business activity element that can be exploited by identified threats. In the context of TPPU, TPPT, and the financing of the proliferation of weapons of mass destruction, vulnerability can be interpreted as weak internal controls by the Provider or the offering of high-risk products/services/transactions.
Impact refers to the level of serious damage and loss arising if TPPU, TPPT, and the financing of the proliferation of weapons of mass destruction occur.
b. Risk Management
Risk management is a process widely used in the public and private sectors to assist in decision-making. In relation to Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction, the process includes understanding the risks of Money Laundering and Terrorism Financing, as well as the financing of the proliferation of weapons of mass destruction, assessing these risks, and developing methods to manage and mitigate identified risks.
In implementing risk management regarding Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction, Providers can develop risk management methods according to the characteristics of the Provider, while still referring to regulations regarding Anti-Money Laundering and Counter-Terrorism Financing (APU PPT) and the prevention of financing for the proliferation of weapons of mass destruction.
c. Inherent Risk and Residual Risk
In conducting risk assessments, it is important to distinguish between inherent risk and residual risk.
Inherent risk is the risk attached to an event or condition that exists prior to the implementation of control measures. This inherent risk is related to the Provider's business activities and Customers. On the other hand, residual risk is the level of risk remaining after the implementation of risk mitigation steps and controls.
d. Risk Based Approach
In the context of Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction, the risk based approach is a process that includes the following:
risk assessment covering 4 (four) risk factors, namely:
a) Customers; b) countries/geographic areas/jurisdictions; c) products/services/transactions; and d) distribution networks (delivery channels);
Providers must consider all relevant risk factors, including the risk of using Information Technology;
Providers must manage and mitigate risks through the implementation of internal controls and taking steps appropriate to the identified risks, as well as monitoring transactions and business relationships according to the assessed risk level;
in identifying, assessing, managing, and mitigating Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction risks, Providers must understand that these activities are not static. Identified risks may change over time in line with the development of new products or new threats entering the Provider's business activities;
Providers must periodically update risk assessments according to the Provider's needs; and
Providers must update Information Technology and Electronic Systems used in accordance with regulations governing electronic information and transactions (ITE). Updates to Information Technology and Electronic Systems include minimum system standards for Information Technology, information technology risk management, information technology security, resilience against system disruptions and failures, and system outsourcing, for example, the application of ISO 27001 in updating IT and electronic systems.
a. In conducting a risk based approach (Risk based Approach), Providers must perform 6 (six) activity steps as follows:
b. The flow of the risk based approach (risk based approach) cycle is as stated in the Appendix, which is an integral part of this Financial Services Authority Circular.
a. Identifying Inherent Risk (Inherent Risk)
In identifying inherent risk (inherent risk), Providers must consider the Provider's vulnerability to being used as an instrument for Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction. The initial step in conducting a risk assessment is to understand the Provider's overall business activities from a broad perspective. This understanding will enable Providers to consider potential risks, whether they occur in business activities, Customers, or specific products.
The actual amount of risk inventoried by Providers will vary depending on the products/services/transactions offered.
Providers must consider elements that trigger the emergence of risks for Providers from the perspective of Customers, countries/geographic areas/jurisdictions, products/services/transactions, or distribution networks (delivery channels). Providers must understand what elements constitute inherent risk and residual risk.
Customer Risk
Providers must pay attention to Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction risks related to the profile of Prospective Customers or Customers. Providers need to categorize Customers based on the level of Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction risks. This categorization can refer to the risk classification established by the Provider, in accordance with regulations and international standards.
a) personal data collection up to Customer transactions is conducted electronically; b) funds provided by Lenders (lender) have very large nominal values; c) the intensity of loan borrowing by Borrowers (borrower) exceeds reasonable limits, including those outside normal/reasonable policies or outside normal repayment schedules; d) the intensity of fund provision by Lenders (lender) exceeds reasonable limits, including those outside normal/reasonable policies or outside normal repayment schedules; e) receipt of funds from Lenders (lender) acting for Beneficial Owners; f) loan borrowing by Borrowers (borrower) acting for Beneficial Owners; g) Customers seeking or receiving Products/services/transactions from Providers that are not suitable for or not beneficial to those Customers; h) Customers or Beneficial Owners are unwilling to provide data and information in the identification process; i) Customers or Beneficial Owners provide very minimal information or information that is suspected to be fictitious; j) Customers or Beneficial Owners obscure or do not disclose their actual identities; k) gatekeepers such as accountants, lawyers, or other professions acting on behalf of Customers in relation to accounts/contracts with Providers; l) Customers included in the category of PEPs (Politically Exposed Persons), including family members or related parties (close associates) of PEPs; m) Lenders or Borrowers are corporations with complex ownership structures that make it difficult to identify the Beneficial Owner, ultimate owner, or ultimate controller of the corporation; n) Customers are charitable organizations or other unregulated and unregulated non-profit organizations; o) institutional lenders are financial service institutions supervised by other regulatory/oversight authorities such as cooperatives or legal entities outside financial service institutions that do not effectively implement Anti-Money Laundering and Counter-Terrorism Financing (APU PPT) programs and the prevention of financing for the proliferation of weapons of mass destruction; p) institutional lenders originating from non-financial service institutions whose management consists of high-risk Customers, PEPs, or parties affiliated with PEPs; and/or q) risks of using false identities, in the form of identity forgery, namely impersonation identities (impersonating identities) and synthetic identities (combining real and false identities). Impersonation is done by someone stealing another person's identity. Meanwhile, synthetic identities use identity forgery by combining real identities with false identities to generate new identities that appear to be real.
In conducting risk assessments, Providers must identify high-risk elements related to geographic locations, whether the Provider's geographic location, the Customer's geographic location, or the location where business relationships occur, and their impact on overall risk.
Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction risks related to countries/geographic areas/jurisdictions increase when:
a) Lender (lender) funds are received from high-risk countries or jurisdictions; b) Lenders (lender) have affiliation relationships with individuals and/or corporations from high-risk countries or jurisdictions; c) Borrowers (borrower) have affiliation relationships with individuals and/or corporations from high-risk countries or jurisdictions; d) Lender (lender) funds are received from areas with high crime rates; e) Borrowers (borrower) reside in areas with high crime rates; f) Lender (lender) funds are received from border areas between countries; g) Borrowers (borrower) reside in border areas between countries; and/or h) Borrowers (borrower) and/or Lenders (lender) do not have known original residence areas (using fake IP addresses).
Risks related to domicile, citizenship, or transactions must be assessed as part of the inherent risk (inherent risk) of the Provider's Customers.
Indicators determining that a country/geographic area/jurisdiction is high-risk for Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction include, among others:
a) jurisdictions identified by organizations conducting mutual assessments of countries (such as: Financial Action Task Force on Money Laundering (FATF), Asia Pacific Group on Money Laundering (APG), Caribbean Financial Action Task Force (CFATF), Committee of Experts on the Evaluation of Anti-Money Laundering Measures and the Financing of Terrorism (MONEYVAL), Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), The Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), The Grupo de Accion Financiera de Sudamerica (GAFISUD), Intergovernmental Anti-Money Laundering Group in Africa (GIABA), or Middle East & North Africa Financial Action Task Force (MENAFATF)) as not adequately implementing FATF Recommendations; b) countries identified as non-cooperative or tax havens by the Organization for Economic Cooperation and Development (OECD); c) countries with low governance levels as determined by the World Bank; d) countries with high corruption risk levels as identified in the Transparency International Corruption Perception Index; e) countries widely known as drug production and trade centers; f) countries subject to sanctions, embargoes, or similar measures by, for example, the United Nations (UN); and g) countries or jurisdictions identified by trusted institutions as funders or supporters of terrorist activities and the financing of the proliferation of weapons of mass destruction, or that allow the activities of terrorist organizations and the proliferation of weapons of mass destruction in their countries.
Overall risk assessments must include determining risks that may occur for various products/services/transactions offered. Providers must pay attention to risks associated with specific products/services/transactions that are not specifically offered by the Provider but utilize the infrastructure owned by the Provider in providing products/services/transactions.
Matters that can increase product/service/transaction risks include, among others:
a) multi-purpose loan products that do not require Customers to attach/submit proof of purchase of goods and services; b) loan products for productive business financing where, in the financing process, Lenders can freely choose which loans to finance. This relates to the potential for affiliation relationships between Lenders and Borrowers to conduct Money Laundering through Providers; and c) loan products where payments can be made by persons who are not Customers, where Providers cannot detect the identity of the account making the payment.
Distribution networks (delivery channels) are media used to obtain products/services/transactions, or media used to conduct transactions. Distribution networks (delivery channels) must be considered as transaction risks.
One of the distinctive features of Providers' business is the distribution network (delivery channels) process conducted without direct meetings (non face to face), for example, the use of applications on mobile phones (mobile apps) and websites, which can be accessed 24 (twenty-four) hours a day, 7 (seven) days a week, and from anywhere.
With these distinctive features, Providers are very likely to be used to obscure the actual identities of Customers or Beneficial Owners (Beneficial Owner), thereby carrying higher risks. Although some distribution networks (delivery channels) using mobile phone applications or internet websites are common, these must still be considered as part of the factors that can cause Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction risks to be higher.
Several indicators that can cause distribution networks (delivery channels) to be high-risk include, among others:
a) online applications used in distribution networks are not certified to obtain information technology system outsourcing; and b) the use of third parties in distributing and/or paying loans, for example, the use of field agents.
Other relevant factors that can impact Money Laundering, Terrorism Financing, and the financing of the proliferation of weapons of mass destruction risks include, among others:
a) the development of typology trends, methods, techniques, and schemes for Money Laundering and Terrorism Financing; b) business models, business scale, number of branches, and number of employees as inherent risk (inherent risk) factors for Providers; c) high total values and intensities of transactions, requiring adequate risk mitigation; d) the use of Information Technology in all stages of Providers' business processes; e) data security from cyberattack risks, where Providers heavily rely on the use of open communication networks (internet), thereby posing significant risks of cyberattacks during internet usage; f) personal data protection, including protection against the acquisition, collection, processing, analysis, storage, presentation, disclosure, transmission, dissemination, and destruction of personal data in accordance with regulations. The greatest risk for Providers is related to poor personal data protection management; g) audit trails, where Providers are required to provide audit trails for all their activities within Providers' Electronic Systems. Audit trails are very important as they are used for supervision, law enforcement, dispute resolution, verification, testing, and other examinations; and h) data centers (data center) and disaster recovery centers (disaster recovery center), where the existence of data centers and disaster recovery centers is intended to facilitate the process of protecting personal data and to restore data or information and important functions of Electronic Systems that are disrupted or damaged due to natural and/or human-caused disasters.
Through data centers (data center) and disaster recovery centers (disaster recovery center), Providers maintain backup data (back up data), so as not to repeat the data collection process.
Providers need to consider that the risk factors as referred to in numbers 4) through 9) above may be interrelated between 1 (one) risk factor and other risk factors.
Risk-increasing indicators are not limited to the indicators referred to in numbers 4) through 9). Risk-increasing indicators may develop according to the complexity of the Provider.
Determination of Risk Scale
a) After identifying and documenting inherent risk (inherent risk), Providers need to assign a scale to each risk.
b) Risk scales are formulated by considering the characteristics and complexity of business activities.
c) For business activities with low business characteristics and complexity, the Provider may categorize risks into 2 (two) categories, namely low and high.
d) For business activities with high business characteristics and complexity, the Provider may categorize risks into several levels, for example, low, medium, and high.
To assist the Provider in conducting risk assessment evaluations, the Provider may use a likelihood and impact matrix as contained in the Appendix, which is an integral part of this Financial Services Authority Circular.
In carrying out the inherent risk identification stage, the Provider must be able to explain all risk identification processes conducted by the Provider and the reasons or considerations behind them.
Every risk element identified as high risk must be mitigated and documented. The Provider must be able to explain to the Financial Services Authority the mitigation steps for high-risk elements, for example, steps in policies and procedures or training programs.
The Provider must also be able to demonstrate to the Financial Services Authority that these risk mitigation steps have been implemented effectively, for example, demonstrated through internal audit or independent audit results.
The Provider must provide documented information showing that the Provider has specifically paid attention to high-risk indicators in its risk assessment.
In order to identify Money Laundering, Terrorism Financing, and/or Mass Weapon Proliferation Financing risks and establish risk ranking for Prospective Customers at the time of opening a relationship or Customers at the time of conducting transactions, the Provider may use regulatory technology such as big data analytics, machine learning, and/or robo advisors.
b. Establishing Risk Tolerance
Meanwhile, risk appetite is the risk that the Provider wishes to take, either in the form of risk taker or non-risk taker.
Risk tolerance is an important component of effective risk management.
The Provider must establish risk tolerance before considering risk mitigation.
When considering threats, the concept of risk tolerance will enable the Provider to determine the level of risk threat that can be tolerated by the Provider.
In establishing risk tolerance, the Provider needs to consider the following risk categories that may affect the Provider, including:
a) compliance risk; b) reputational risk; c) legal risk; d) operational risk; and e) fraud risk.
c. Risk Reduction and Control Steps
Risk mitigation is the application of internal controls to limit Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing that have been identified in conducting risk assessments. Risk mitigation will help ensure that the Provider's business activities remain within the established risk tolerance limits. In the event that the risk assessment results show that the Provider has a high risk level, the Provider must develop written risk mitigation strategies (consisting of policies and procedures to mitigate high risks) and implement them in high-risk areas or business relationships as identified.
Risk mitigation is carried out in the application of 5 (five) pillars of effective and adequate implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention, at least including:
a) active supervision by the Board of Directors and Board of Commissioners; b) policies and procedures; c) internal controls; d) management information systems; and e) human resources and training.
The Provider must demonstrate to the Financial Services Authority that such risk mitigation has been implemented effectively, for example, demonstrated by evidence of licenses/certifications as providers of Electronic Systems obtained from the Ministry in charge of communication and information affairs.
Internal controls and risk mitigation in high-risk areas or business relationships are based on risk appetite and risk tolerance.
In all situations, the Provider's business activities must consider internal controls that will influence the mitigation of all identified risks.
In risk assessments, all identified high-risk areas as part of the risk assessment must be mitigated with internal controls and well-documented.
For all Customers and business relationships, the Provider must:
a) conduct monitoring of all business relationships; and b) document related information and steps taken.
a) conduct more frequent monitoring of such business relationships; and b) take stricter steps in conducting identification and data updating.
a) update and maintain Customer and Beneficial Owner information; b) establish and conduct continuous monitoring activities at every level of the Provider's business relationships (for low-risk Customers conducted periodically and for high-risk Customers conducted more frequently than low-risk Customers); c) implement mitigation in high-risk areas. This risk mitigation strategy must be stated in policies and procedures; and d) consistently apply internal control procedures.
d. Evaluation of Residual Risk
Residual risk is the risk remaining after the application of internal controls and risk mitigation. The Provider needs to note that no matter how tight the risk mitigation and risk management are, the Provider will still have residual risk that must be managed well.
Residual risk must align with the established risk tolerance. The Provider must ensure that residual risk is not greater than the established risk tolerance. In the event that residual risk is still greater than the risk tolerance, or in the event that internal controls and mitigation for high-risk areas are inadequate, the Provider must return to risk reduction and control steps, and increase the level or quantity of established mitigation steps.
Characteristics of residual risk are:
a) risk has been tolerated/accepted:
In this risk, the risk remains beyond the tolerated limit. Acceptance of tolerated risk means that the efforts made by the Provider to reduce the risk do not have an effect in reducing the risk. However, the tolerated risk can increase over time. For example, when there are new threats of Money Laundering and Terrorism Financing;
b) risk has been mitigated:
In this risk, the risk remains even though it has been mitigated. This risk has been reduced, but cannot be eliminated. In practice, established internal controls may not be applicable (for example, monitoring systems or transaction monitoring processes fail, causing some transactions not to be reported).
a) evaluate the residual risk held; and b) adjust the level of risk held to the tolerated/accepted risk.
e. Implementation of Risk-Based Approach
The Provider implements a risk-based approach based on the results of risk assessments of daily business activities/operations, including identification, verification, and monitoring, which still need to be done as minimum requirements.
The risk-based approach held by the Provider must be documented to demonstrate the Provider's compliance. Policies and procedures related to the risk-based approach must be communicated, understood, and complied with by all employees, especially employees conducting identification and maintenance of Customer data and information and reporting transactions to relevant authorities. The Provider must provide sufficient information to process and complete transactions, in accordance with the identification and maintenance of Customer data and information as required.
Procedures and policies of the risk-based approach must meet the following minimum requirements:
a) Customer identification; b) risk assessment; c) special actions for high-risk areas; d) record keeping; and e) reporting.
Policies and procedures in the risk-based approach also cover matters related to the detection of suspicious transactions and the determination of monitoring types adjusted to the Customer's risk level or business relationship, as well as monitoring aspects from the side of frequency, implementation methods, and evaluation of monitoring results.
The Provider needs to conduct periodic monitoring of all business relationships conducted, and of high-risk business relationships regarding Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing. The Provider applies stricter special steps for high-risk Customers or business relationships.
The Provider needs to note that risk management and risk mitigation require leadership and involvement of senior officials. Senior officials are responsible for decision-making regarding policies, procedures, internal control processes, and mitigation of Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing in the business activities/operations held by the Provider.
With the risk-based approach, the Provider can:
a) ensure that the risk assessment conducted describes the risk-based approach process, the frequency of monitoring low-risk and high-risk Customers, and also describes the internal control steps applied to reduce identified high risks; b) apply the risk-based approach; c) update data and information for Customers and Beneficial Owners; d) monitor all business relationships held; e) conduct more frequent monitoring of high-risk business relationships; f) take specific steps for high-risk Customers; and/or g) involve senior officials in facing high-risk situations or areas (for example, for PEPs, approval to conduct business relationships is given by senior officials).
f. Review and Evaluation of Risk-Based Approach
a) risk assessment related to Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing; b) active supervision by the Board of Directors and Board of Commissioners; c) policies and procedures; d) human resource needs possessing knowledge and capabilities in Information Technology and the Provider's business processes; e) human resource training programs for employees, senior officials, and the Board of Directors and Board of Commissioners regarding the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention; and f) employee profiles including identity data profiling and employee competencies.
In the event of changes in business structure and the introduction of new products and services, updates to the risk assessment must be conducted for policies and procedures, mitigation steps, and internal controls.
The review of risk assessments related to Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing must cover all elements including policies and procedures regarding risk assessment, risk mitigation, and more intensive continuous monitoring. The review can help the Provider in evaluating the improvement of existing policies and procedures, or for the formation of new policies and procedures. Identified risks may change or develop along with the development of new products or the emergence of new threats to business activities. Ultimately, the review procedure will affect the effectiveness of the implementation of the risk-based approach.
With the review of the risk-based approach, the Provider can:
a) conduct reviews according to the Provider's needs; b) produce reviews covering compliance with policies and procedures, assessment of Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing risks, and training programs to test the effectiveness of the risk-based approach; c) document the review process and report to senior officials; and d) document review results along with the establishment of corrective steps to be followed up.
III. ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
Active supervision by the Board of Directors at least includes:
a. ensuring the Provider has policies and procedures for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention; b. proposing written policies and procedures regarding the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention to the Board of Commissioners, including mitigation of Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing risks, containing at least:
c. forming a special working unit and/or appointing an official responsible for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention;
d. providing clear directions regarding policies, supervision, and procedures for the management and mitigation of ML, TF, and Mass Weapon Proliferation Financing risks; e. ensuring the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention in accordance with established written policies and procedures;
f. supervising the compliance of working units in implementing the AML and CFT program and Mass Weapon Proliferation Financing prevention, including monitoring the implementation of duties of the UKK and/or officials responsible for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention; g. actively supervising and mitigating risks, especially those related to Customer risk, area/geographical/legal risk, product/service/transaction risk, and distribution network risk; h. ensuring that written policies and procedures regarding the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention align with changes and the development of products, services, and technology in the financial services sector and in accordance with the development of Money Laundering and/or Terrorism Financing and Mass Weapon Proliferation Financing modus operandi;
i. ensuring that all employees have participated in training related to the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention on a regular basis;
j. providing technical approval regarding policies, supervision, and procedures for the management and mitigation of ML, TF, and Mass Weapon Proliferation Financing risks related to the technical implementation of the Board of Directors' duties; and k. providing technical approval regarding policies, procedures, business plans, and/or changes to Electronic Systems by considering ML, TF, and Mass Weapon Proliferation Financing risks; and
l. ensuring information security aimed at maintaining the confidentiality of managed information.
Active supervision by the Board of Commissioners at least includes:
a. providing approval for written policies and procedures regarding the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention proposed by the Board of Directors, including mitigation of ML, TF, and Mass Weapon Proliferation Financing risks; b. supervising the implementation of the Board of Directors' duties and responsibilities regarding the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention;
c. ensuring there is discussion regarding Money Laundering, Terrorism Financing, and/or Mass Weapon Proliferation Financing in Board of Directors and Board of Commissioners meetings; and
d. Board of Directors and Board of Commissioners meeting discussions regarding Money Laundering, Terrorism Financing, and/or Mass Weapon Proliferation Financing must consider the following:
a) mitigation of Money Laundering and Terrorism Financing and Mass Weapon Proliferation Financing risks present in the Provider; b) handling of problems and/or obstacles faced by the Provider in implementing the AML and CFT program and Mass Weapon Proliferation Financing prevention; c) updates of regulatory provisions and typologies or modus operandi related to AML and CFT; d) effectiveness of the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention; and e) results of discussion meetings must be recorded in meeting minutes signed by the Board of Directors and Board of Commissioners attending the discussion meeting.
a. have adequate understanding of Money Laundering, Terrorism Financing, and Mass Weapon Proliferation Financing risks inherent in all operational activities of the Provider so that the Board of Directors and Board of Commissioners are able to manage and mitigate such risks adequately in accordance with regulatory provisions; b. have understanding regarding Money Laundering, Terrorism Financing, and Mass Weapon Proliferation Financing risks, especially Customer risk, country/geographical/jurisdictional risk, product/service/transaction risk, distribution network (delivery channels) risk, and other relevant risks;
c. ensure an adequate organizational structure for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention; and
d. be responsible for policies, procedures, implementation, and supervision of the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention, including the management and mitigation of ML, TF, and Mass Weapon Proliferation Financing risks in all operational activities of the Provider.
a. The Provider must have a responsible person for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention. b. The responsible person for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention must be within the Provider's organizational structure.
c. The determination and existence of the responsible person for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention is based on the Provider's needs and business complexity, meaning the Provider can have a UKK and responsible official, or only have a UKK, or only have a responsible official.
d. In the event that the responsible person for the implementation of the AML and CFT program and Mass Weapon Proliferation Financing prevention...
Massal consisting of an Anti-Money Laundering and Counter-Terrorism Financing Unit (UKK) must meet the following requirements:
e. In the event that the person responsible for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing is an official, the responsible official may only hold concurrent functions of compliance and risk management.
f. The UKK and/or the responsible official for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing must report to and be responsible to the Board of Directors, which has the task of overseeing the implementation of the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing.
g. The person responsible for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing may be carried out by one of the members of the Board of Directors. In the event that a member of the Board of Directors is designated as the person responsible for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing, that member of the Board of Directors may not perform other functions and may only perform compliance and risk management functions.
h. In the event that the Provider has branch offices, the Provider must have a person responsible for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing at the head office and branch offices. The person responsible for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing at the branch office may hold concurrent functions with the person responsible for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing at the head office, provided that the implementation of the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing is within the control range of the responsible person at the head office.
i. The UKK and/or the responsible official for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing must:
IV. POLICIES AND PROCEDURES
Policies and procedures for implementing the Anti-Money Laundering and Counter-Terrorism Financing Program and the prevention of Mass Destruction Weapons Proliferation Financing based on a risk-based approach must include at least:
a. identification and verification of Prospective Customers or Customers; b. identification and verification of Beneficial Owners;
c. termination of business relationships or refusal of transactions;
d. management of Money Laundering, Terrorism Financing, and Mass Destruction Weapons Proliferation Financing risks that are continuous regarding Customers, geographic areas/jurisdictions, products/services/transactions, or distribution networks; e. maintenance of accurate data regarding transactions, management of the Customer Due Diligence (CDD) process, and management of policies and procedures; f. updating and monitoring; g. reporting to senior officials, the Board of Directors, and the Board of Commissioners; and h. reporting to the Financial Intelligence Unit (PPATK).
The policies and procedures as referred to in number 1 must take into account the Know Your Customer (KYC) Principles.
KYC, consisting of Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD), is conducted not only for Prospective Customers at the time of registration as Users, but also for Customers through monitoring of Customer transactions.
CDD includes activities of identification, verification, and monitoring conducted by the Provider, with the aim of ensuring that business relationships or transactions are consistent with the profile, characteristics, and/or transaction patterns of Prospective Customers and Customers. Meanwhile, EDD is a more in-depth CDD action conducted by the Provider against Prospective Customers or Customers with high risk, including Politically Exposed Persons (PEP) and/or in high-risk areas.
Through CDD or EDD:
a. The Provider can obtain detailed information regarding Prospective Customers, get to know Customers, and understand the transactions conducted by Customers, identify abnormal or suspicious transactions by Customers, protect the reputation and integrity of the Provider, facilitate compliance with regulations, and protect the Provider from external threats, namely being used as a means of Money Laundering, Terrorism Financing, and/or Mass Destruction Weapons Proliferation Financing; and b. The Provider must always be careful in accepting Prospective Customers and continue to monitor transactions by Customers using the Provider's services. If transactions conducted are not consistent with the profile, characteristics, or habitual transaction patterns of the respective Customers, the Provider is required to submit a Suspicious Transaction Report (TKM) to the PPATK.
CDD is conducted by the Provider at the time:
a. establishing a business relationship with Prospective Customers or conducting transactions with Customers; b. there are financial transactions in Indonesian Rupiah and/or foreign currency with a value of at least equivalent to IDR 100,000,000.00 (one hundred million Rupiah);
c. there are indications of suspicious financial transactions related to Money Laundering, Terrorism Financing, and/or Mass Destruction Weapons Proliferation Financing; or
d. the Provider doubts the truthfulness of information provided by Prospective Customers, Customers, authorized representatives, and/or Beneficial Owners.
Re-CDD can be conducted by the Provider if the Provider assesses that there is a change in risk level caused by, among others:
a. a significant increase in transaction value; b. significant changes in Customer profiles; and
c. information in the Customer Identification File (CIF) is not yet complete with documents for verification.
Identification of Prospective Customers or Customers
a. The Provider is required to identify and classify Prospective Customers or Customers into groups of natural persons, corporations, and other legal arrangements. b. The Provider must have policies regarding the acceptance and identification of Prospective Customers or Customers.
c. The acceptance and identification policies for Prospective Customers as referred to in letter b must include at least the following:
d. The Provider can conduct acceptance and identification of Prospective Customers or Customers electronically, provided that the Provider's Electronic System is capable of identifying the identity of Prospective Customers or Customers.
e. In the implementation of acceptance and identification of Prospective Customers or Customers electronically, the Provider must still pay attention to the guidelines for acceptance and identification of Prospective Customers or Customers as referred to in letter a, letter b, and letter c.
f. In the event that acceptance and identification of Prospective Customers is conducted electronically, implementation can be done, among others, by filling out electronic forms and submitting copies of documents as referred to in Article 20, Article 21, Article 22, Article 23, and Article 24 of the OJK Regulation on Anti-Money Laundering and Counter-Terrorism Financing in softcopy format through the Provider's website or application.
g. In addition to copies of documents as referred to in letter f, the Provider may request additional data, documents, and information needed to identify and verify Prospective Customers or Customers, submitted through the website or application of the Provider. The examples of such additional data, documents, and information are as follows:
meant in letter a); and
4) for Prospective Customers in the form of state institutions, government agencies, international institutions, and foreign state representations, including name, email, phone number, face photo (selfie), and identity documents of the party authorized to act on behalf of the state institution, government agency, international institution, and foreign state representation in conducting business relations with the Provider if that individual is high-risk or a PEP.
the Provider must pay attention to the provisions as referred to in number 9 letter g.
b) in the event no majority share ownership is found (shareholders have the same ownership percentage), then identification of the shareholder who most controls the company is carried out through other forms, for example, individuals who have the ability in determining or appointing members of the Board of Directors; and c) in the event no shareholder who most controls the company is found because, for example, decisions are taken collectively by all shareholders of the company, then identification of Beneficial Owners is based on members of the Board of Commissioners or Board of Directors who most control the limited liability company concerned. The steps of information tracing in the context of identifying Beneficial Owners as referred to in letters a to c above are not optional alternative steps, but are sequential steps that will each be used if the previous step has been applied by the Provider, but the Provider has not yet been able to identify Beneficial Owners through that step.
7) For Beneficial Owners in the form of state institutions or government agencies, companies with majority state-owned shares, or public companies or issuers, Prospective Customers are not required to submit documents and/or identity of the ultimate controller. Nevertheless, the Provider still carries out identification and verification of Beneficial Owners using data and information available in the public domain. Exceptions to the requirement to submit documents and/or identity of the ultimate controller of Beneficial Owners must be documented by the Provider.
b) matching the consistency of thumbprints, fingerprints, or face photos (selfies) with identity documents or other documents that include signatures, thumbprints, fingerprints, or face photos (selfies) of Beneficial Owners; c) requesting to provide more than one identity document of Beneficial Owners issued by competent authorities if there is doubt about the existing identity documents; d) conducting cross-checks (if necessary) to ensure the consistency of various information submitted. Cross-checks are carried out by ways, among others:
(1) contacting Prospective Customers via telephone (home or office); (2) contacting human resources officials at the place where Prospective Customers work if the occupation of Prospective Customers is an employee of a company or agency; (3) confirming the income of Prospective Customers by requiring bank statements from banks or other financial service providers; and (4) conducting geographical information analysis to see forest conditions through remote sensing technology against Prospective Customers who are companies operating in the forestry sector; e) ensuring that Prospective Customers do not have a negative track record by verifying the identity of Prospective Customers using other independent sources including:
(1) lists of suspected terrorists and terrorist organizations issued by the Indonesian National Police; (2) lists of financing for the proliferation of weapons of mass destruction; and (3) other data such as employer identities of Prospective Customers, telephone accounts, and electricity accounts.
b. In the event the Provider implements simplified CDD, the Provider must:
ensure that information and supporting documents for simplified CDD contain at least identity, source of funds, and purpose of transactions;
establish criteria for Customers with simple profiles and characteristics who receive simplified CDD treatment and are equipped with clear reasons or bases for establishment that are consistent with the risk assessments conducted by the Provider, for example, High-Risk Customers or PEPs are not included as Prospective Customers or Customers with simplified CDD treatment;
ensure that simplified CDD requirements are able to manage and mitigate the level of threats from ML, TF, and WMD proliferation financing;
ensure that simplified CDD requirements do not include Customers who are categorized as High-Risk Customers or PEPs based on legislation;
notify the Financial Services Authority (OJK) of the plan to implement simplified CDD procedures including criteria for Customers with simple profiles and characteristics who receive simplified CDD treatment and the time when the simplified CDD procedures will start. Example: After conducting a risk analysis of its Customers, the Provider decides to apply simplified CDD to certain groups of Customers by changing its AML and CTF and WMD proliferation prevention policies and procedures. Based on changes to AML and CTF and WMD proliferation prevention policies and procedures, simplified CDD will be enforced starting March 30, then the Provider can submit notification to the Financial Services Authority of the plan to implement simplified CDD on March 20;
document Customers who receive simplified CDD treatment in a list that also contains information regarding the reasons for establishing Customer risk so that they are classified as low-risk Customers and receive simplified CDD treatment;
request information from prospective Customers with reference to applicable regulations; and
ensure information security is aimed at keeping managed information confidential.
c. Customers who have received simplified CDD treatment must be removed from the list of simplified CDD Customers if they meet the criteria:
identified in connection with suspected Money Laundering and Terrorism Financing and WMD proliferation financing;
have an increasing risk level; and/or
do not match the initial purpose at the time of registration as users.
d. The Provider can carry out identification and verification of Prospective Customers or Customers in the context of simplified CDD electronically as long as the Provider's Electronic System is capable of identifying the official identity of Prospective Customers or Low-Risk Customers and meeting the criteria for Prospective Customers or Customers with simple profiles and characteristics and is capable of verifying the truthfulness of the official identity of the Prospective Customers or Customers concerned. e. In the event the Provider carries out identification and verification of Prospective Customers or Customers in the context of simplified CDD electronically, then the implementation must pay attention to the provisions as referred to in number 8 letters d to g, and number 9 letter g.
b. Given that one of the requirements for using the Provider's services is that prospective Lenders and Borrowers must have become Bank Customers, the Provider may use the results of CDD that have been carried out by Banks against Prospective Customers who have become Bank Customers.
c. In the event the Provider uses the results of Third-Party CDD (including Bank CDD results):
unwillingness to provide information and/or complete documents required by the Provider;
the Provider cannot believe the truthfulness of identity and document completeness;
incoming transfers to customer accounts, but after the Provider receives and conducts re-CDD and based on the sender it is known that the receiving Customer's account is an account for concealing criminal proceeds as referred to in legislation regarding the prevention and eradication of ML and TF.
providing information and/or documents that are inconsistent or reasonably suspected to be fake documents or information whose truthfulness is doubted;
the source of transaction funds owned is known and/or reasonably suspected to originate from criminal proceeds;
recorded in lists of suspected terrorists and terrorist organizations; and/or
recorded in lists of financing for the proliferation of weapons of mass destruction.
c. Providers are required to notify Customers in writing regarding the closure of business relations.
d. Written notifications can be carried out by sending letters addressed to Customers according to addresses listed in the Provider's database or announced through print media, electronic media, or other media. e. In the event the Provider refuses business relations with Prospective Customers or refuses transactions or closes/terminates business relations with Customers, then the Provider is required to report this to PPATK regarding the refusal of business relations or transactions or closure/termination of business relations as suspicious financial transactions. f. In the event written notification has been carried out and Customers do not take the remaining funds stored with the Provider, then the settlement of the remaining Customer funds is carried out in accordance with applicable legislation, among others by handing over remaining funds to the Estate Office. g. Providers must document Prospective Customers or Customers subject to transaction refusal or business relation closure as referred to in letter b in a separate list.
b. Policies and procedures to manage Money Laundering and/or Terrorism Financing risks and WMD proliferation financing continuously include:
Massal, as well as investigations and inquiries into funds indicated to originate from crime, so that documents stored by the Provider must be sufficient to be used as evidence (if necessary) by law enforcement agencies.
b. The Provider must account for or document Customer data, including data obtained from the identification and verification process of Prospective Customers or transaction monitoring of Customers, including those with high risk or Politically Exposed Persons (PEP) in the context of Enhanced Due Diligence (EDD), Beneficial Owners, or those classified as low risk and meeting the criteria for Prospective Customers or Customers with simple profiles and characteristics in the context of Simplified Due Diligence (CDD).
c. The Provider must have policies and procedures regarding the retention period of documents covering:
d. Documents as mentioned in letters b and c may be stored through data formats or electronic documents in the Provider's database while still paying attention to data security systems or electronic documents.
e. In the event that documents as mentioned in letters b and c are stored through data formats or electronic documents in the Provider's database, the Provider must ensure the ability to display the data or electronic documents completely in accordance with statutory regulations, when requested by the Financial Services Authority (OJK) and/or other competent authorities such as PPATK and/or law enforcement agencies.
b. The obligation to update Customer data by the Provider as referred to in letter a includes:
c. Activities to update data, information, and/or supporting Customer documents are based on the level of Money Laundering and Terrorism Financing risks and weapons of mass destruction proliferation financing of said Customer and are focused on higher-risk Customers first.
d. Customer risk levels are obtained from the results of Customer risk assessments articulated in the classification of Customers based on risk levels, which can be divided into:
e. In updating data, information, and/or supporting Customer documents (Customer data updating), the Provider must document the Customer updating efforts in the form of worksheets containing the Customer name, date of Customer update, method of Customer update (e.g., via email, telephone, mail, news in mass media and electronic media including the internet or other trusted sources), results of Customer data updates, and follow-up actions on the results, particularly regarding Customer data that failed to be updated.
f. In the event that the Provider has limited resources, Customer updating activities are carried out on a priority scale, among others based on:
g. Criteria for high-risk Customers can be seen from:
h. Implementation of Customer data updates listed in the data update plan report can be carried out, among others, at:
i. The Provider must ensure that documents, data, or information gathered in the CDD process are always updated and relevant by re-examining existing data, particularly those related to high-risk Customers or PEPs.
j. Regarding the updating of lists of suspected terrorists and terrorist organizations and lists of financing for the proliferation of weapons of mass destruction, the Provider must:
k. The Provider may perform Customer data updates electronically. In the event that the Provider performs data updating processes electronically, then:
l. The Provider must account for and document the Customer data updating process.
m. Accounting and documentation of Customer data updates can be done manually in written form through formal documents such as memos, notes, or records, which can also be stored through data formats or electronic documents in the Provider's database.
b. Monitoring conducted by the Provider as referred to in letter a must pay attention to the following matters:
c. Activities to monitor Customer profiles and transactions are conducted continuously, including activities:
d. Information sources that can be used to monitor Customers designated as suspects or defendants can be obtained, among others, through:
e. The Provider must classify transactions and Customers requiring special monitoring. Monitoring of Customer transactions must be stricter if there are high-risk Customers.
f. In the event that the Provider monitors Customer profiles and transactions electronically, the Provider must ensure that the Electronic System used can:
g. The Provider may monitor profiles and transactions electronically using regulatory technology, among others by utilizing algorithms, specific parameters, artificial intelligence, and machine learning.
h. The Provider must account for and document the process of monitoring Customer profiles and transactions.
i. Accounting and documentation of monitoring Customer profiles and transactions can be done manually in written form through formal documents such as memos, notes, or records, or through data formats or electronic documents in the Provider's database.
b. The audit trail is used for supervision, law enforcement, dispute resolution, verification, testing, and other examinations.
c. Implementation of the audit trail at least covers:
d. The audit trail process can be conducted electronically, among others by:
b. Reports on the progress of approval and supervision of these special conditions are reported hierarchically from senior officials, the Board of Directors, and the Board of Commissioners.
c. Policies and procedures for reporting to senior officials, the Board of Directors, and the Board of Commissioners cover:
b. The Provider must submit other reports related to the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing in the event of information requests from PPATK.
V. INTERNAL CONTROL
A. INTERNAL CONTROL
An effective risk-based approach to the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing must be implemented in internal control and internalized in the Provider's business processes.
The Provider must have an internal control system to ensure the Provider's compliance in effectively implementing the AML/CFT program and prevention of weapons of mass destruction proliferation financing and to minimize the Money Laundering and Terrorism Financing and weapons of mass destruction proliferation financing risks faced by the Provider.
In internal control, the Provider must pay attention to the following matters:
a. the scale and complexity of the Provider; b. the diversity of business or operational activities of the Provider, including the diversity of countries/geographical areas/jurisdictions, Customer profiles, products or services, and the Provider's overall transaction activities;
c. distribution channels used;
d. volume and scale of transactions; e. the level of risk assessment for each business activity of the Provider; and/or f. business relationships between the Provider and Customers, either directly or through agents, third parties, correspondents, or non-face-to-face communication.
The Provider must have an effective internal control framework in the implementation of the risk-based AML/CFT program and prevention of weapons of mass destruction proliferation financing, which covers at least:
a. adequate policies, procedures, and internal monitoring capable of timely detecting weaknesses and deviations occurring in the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing; b. limits of authority and responsibility of work units related to the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing, where the Provider must ensure clear separation of duties, authority, and responsibilities between the special control unit, functions, or officials appointed to carry out internal control functions and the Provider's business units;
c. appointment of UKK and/or officials responsible for managing the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing;
d. updating standards for compliance with the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing; e. policies, procedures, and monitoring related to employee screening/recruitment of the Provider, to ensure that Provider employees are not used as a means for money laundering and/or terrorism financing and weapons of mass destruction proliferation financing through the Provider's business processes; f. monitoring of Customers, Customer transactions, and/or the use of Information Technology in the Provider's business processes, particularly those with high risks related to Money Laundering and Terrorism Financing and weapons of mass destruction proliferation financing, including monitoring of specific matters that require special attention based on, among others, suggestions and information from industry associations, regulators, or law enforcement agencies; g. provision of systems capable of accurately identifying, monitoring, and reporting suspicious financial transactions; h. provision of routine reviews of risk assessments and management processes;
i. adequate supervision before offering new products or services or using new technologies or offering modified products or services that have the potential to increase Money Laundering and Terrorism Financing and weapons of mass destruction proliferation financing risks;
j. rapid and accurate dissemination of information in the event of indications and/or suspicions related to Money Laundering and Terrorism Financing and weapons of mass destruction proliferation financing risks, corrective measures taken, results of weakness identification regarding owned regulations, action plans for improvement, and reports submitted to competent parties; k. compliance with statutory regulations, reporting requirements, and recommendations related to compliance with the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing, and updating changes in statutory regulations;
l. implementation of policies, procedures, and controls over Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD);
m. adequate supervision regarding high-risk Customers, transactions, and products, such as transaction limits or management approval; n. adequate supervision of Provider employees who complete reports, receive grants, monitor suspicious activities, or engage in other activities that are part of the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing; o. integration of compliance with the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing into job descriptions and appropriate performance evaluations; p. training related to the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing that is appropriate and relevant for all employees; q. testing of the effectiveness of the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing by taking random samples and documenting the tests conducted; and r. independent internal audits to test compliance and effectiveness of the implementation of the AML/CFT program and prevention of weapons of mass destruction proliferation financing, implemented in accordance with the needs and complexity of the Provider's business.
In conducting internal control, the Provider may use regulatory technology such as algorithms, utilization of artificial intelligence technology, or machine learning.
In the event that the Provider conducts internal control using regulatory technology as referred to in item 5, the Provider must ensure that the regulatory technology used in the internal control system:
a. is based on risk assessment results, which include how the Provider manages and mitigates risks over the Information Technology used; b. is guaranteed reliability and has been certified by the Ministry managing government affairs in the field of communications and informatics; and
c. uses security measures, including the use of security tools such as encryption technology, antivirus usage, and firewalls.
The person responsible for internal control regarding the implementation of the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction based on risk, as referred to in item 5, has authority at least covering:
a. formulating risk-based audit programs and procedures with audit priorities on work units or branch offices that have high business complexity; b. assessing the adequacy of processes applied by the Provider in identifying and reporting suspicious financial transactions, taking into account anti-tipping-off regulations;
c. assisting the Board of Directors and Board of Commissioners of the Provider in conducting supervision by detailing the operational aspects of planning, implementation, and monitoring of audit results;
d. making analyses and assessments in the fields of finance, accounting, operations, and other activities through audits; e. identifying all possibilities to improve and increase the efficiency of resource and fund utilization; and f. providing improvement suggestions and objective information about the activities examined at all levels of the Provider's management.
The person responsible for internal control must:
a. ensure that internal control in the implementation of the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction is applied well, correctly, and effectively in accordance with established policies and procedures, and covers the internal control framework as referred to in item 4; b. create a risk management and compliance culture; and
c. ensure that employees comply with established policies and procedures.
The Provider may have a system for reporting suspected violations (whistleblowing system/WBS) intended to maintain professional integrity, and the accountability of the Provider, where the system allows internal company parties (employees) or external parties such as Prospective Customers, Customers, or the general public, to report suspected violations of ethics, behavior, work procedures, and/or applicable laws and regulations committed by human resources (including Directors and Board of Commissioners) of the Provider.
The system for reporting suspected violations (WBS) must at least cover:
a. an independent, free, and confidential reporting system; b. protection of the reporter's identity confidentiality;
c. protection for the reporter from pressure, dismissal, legal lawsuits, up to physical actions. Protection is not only for the reporter but can also be extended to the reporter's family members; and
d. information on the implementation of follow-up actions, including when, how, and to which institution the follow-up is submitted.
An independent work unit managing the system for reporting suspected violations (WBS) may be held concurrently by officials appointed as the person responsible for internal control.
B. INTERNAL CONTROL OVER THE USE OF INFORMATION TECHNOLOGY IN THE PROVIDER'S BUSINESS PROCESS
The Provider must ensure that internal control over the use of Information Technology in the Provider's business process is sufficiently adequate and effective in implementing the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction, and is capable of anticipating the possibility that the Information Technology used by the Provider is not utilized as a means of Money Laundering, Terrorism Financing, and/or financing for the Proliferation of Weapons of Mass Destruction.
In implementing the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction, the Provider must have and effectively apply an internal control system for all aspects of Information Technology used in implementing the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction, which includes at least:
a. having and applying policies, standards, and procedures for the use of Information Technology used in implementing the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction consistently and continuously, intended to reduce the risk of errors or failures in the information systems used, at least covering aspects:
The internal control system effectively covering all aspects of Information Technology use as referred to in item 2 is part of the Provider's internal control system.
The Provider must ensure the continuity and stability of Information Technology operations and mitigate risks that could potentially disrupt the Provider's operational activities.
The Provider must ensure that information security is implemented effectively, taking into account at least:
a. information security aimed at ensuring that managed information maintains confidentiality, integrity, and availability effectively and efficiently, taking into account compliance with regulations; and b. information security conducted on technological aspects, human resources, and processes in the use of Information Technology.
In the event that the Provider uses Information Technology service providers used in implementing the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction, the Provider must ensure that such Information Technology service providers have implemented Information Technology usage risk management. As an example, the service provider has obtained certification from official institutions.
In the event that the Provider uses Information Technology service providers, the Provider must take certain actions as a form of risk mitigation in the event of conditions such as:
a. worsening performance of Information Technology services by the Information Technology service provider, which can significantly impact the Provider's business activities; b. the Information Technology service provider becoming insolvent, in the process of liquidation, or declared bankrupt by the court;
c. violations by the Information Technology service provider regarding the Provider's confidentiality obligations and the obligation to keep Customer personal data confidential; and/or
d. conditions causing the Provider to be unable to provide data required for supervision by the Financial Services Authority (OJK).
VI. MANAGEMENT INFORMATION SYSTEM
The management information system is intended to identify, analyze, monitor, and provide reports effectively regarding the characteristics of transactions conducted by Customers using parameters adjusted periodically and considering business complexity, transaction volume, and risks held by the Provider, including among others:
a. financial transactions that deviate from the profile, characteristics, or habitual transaction patterns of the respective Customer; b. financial transactions by Customers who are suspected of being conducted with the intention of avoiding reporting of the relevant transactions as required by reporting parties in accordance with applicable laws and regulations;
c. financial transactions conducted or cancelled using assets suspected to originate from criminal acts;
d. financial transactions requested by PPATK to be reported by reporting parties because they involve assets suspected to originate from criminal acts; e. Customer transactions that do not meet CDD requirements; and f. Customer transactions whose information truthfulness is doubted by the Provider.
The Provider must ensure that the Information Technology used in the management information system is guaranteed reliability, and has been based on risk assessment results which include how the Provider manages and mitigates risks over the Information Technology used.
Written policies and procedures owned by the Provider must consider Information Technology factors that have the potential to be abused by Money Laundering and Terrorism Financing actors and financing for the Proliferation of Weapons of Mass Destruction, such as account opening via the internet, or fund transfer orders via facsimile or telephone, and other electronic transactions.
The Provider must have a management information system that allows tracing of every transaction (individual transaction) and responding fully, quickly, and accurately to information, data, and document requests for both internal and/or Financial Services Authority (OJK) purposes, as well as in relation to law enforcement efforts and judicial interests.
The Provider must maintain databases of Politically Exposed Persons (PEP), suspected terrorists and terrorist organizations, and the Proliferation of Weapons of Mass Destruction list.
To facilitate monitoring in the context of analyzing suspicious financial transactions, the Provider is required to have and maintain a unified Customer profile (single CIF).
Information contained in the single CIF covers all products or services used by the Customer at a Provider.
For joint accounts (if any), the CIF is created for each respective party owning the joint account. For example, a joint account in the names of A and B, the CIF created is 2 (two) CIFs, namely CIF in the name of A and B, informing that both A and B have a joint account.
For the purpose of maintaining the single CIF, the Provider must establish a policy that for every additional account and/or product or service by an existing Customer, the Provider must link the additional account, product, or service with the Customer Information Number of the respective Customer.
To ensure the management information system continues to run well and effectively, the Provider must mitigate risks including against:
a. data security from cyberattacks and the use of digital identity, which can be done by:
VII. HUMAN RESOURCES AND TRAINING
A. HUMAN RESOURCES
To prevent the Provider from being used as a medium or destination for Money Laundering, Terrorism Financing, and/or financing for the Proliferation of Weapons of Mass Destruction involving internal parties, the Provider is required to conduct:
a. screening procedures for new employee recruitment (pre-employee screening) as part of the implementation of know your employee (KYE); and b. Introduction and monitoring of employee profiles.
Screening procedures for new employee recruitment (pre-employee screening) are conducted in the form of:
a. screening methods intended to ensure that the prospective employee's profile has no criminal records, including requiring prospective employees to make a statement letter and/or submit a police record certificate (SKCK); b. verifying identity and education obtained by prospective employees, including through face-to-face or virtual interviews, intended to further ensure the truthfulness of information and data from prospective employees;
c. researching through media or other information regarding the background of prospective employees, including work history, and/or work experience of prospective employees;
d. ensuring a good track record of prospective employees, including by requesting recommendation letters from previous companies where the prospective employee previously worked; and e. ensuring the prospective employee's credit quality is not classified as non-performing loans.
Introduction and monitoring of employee profiles, including employee behavior and lifestyle, including among others:
Screening procedures (pre-employee screening), introduction, and monitoring of employee profiles are documented in the Provider's written KYE policies and procedures, guided by regulations governing the implementation of anti-fraud strategies.
B. TRAINING
The Provider is required to conduct continuous training regarding policies and procedures for implementing the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction, as well as the role and responsibilities of employees in preventing and combating Money Laundering, Terrorism Financing, and/or financing for the Proliferation of Weapons of Mass Destruction, to all employees.
In conducting continuous training as referred to in item 1, the Provider may:
a. cooperate with other parties such as Provider associations, PPATK, and/or relevant competent authorities; and/or b. involve employees in training conducted by Provider associations, PPATK, Financial Services Authority (OJK), and/or other competent authorities.
In determining training participants, the Provider prioritizes employees whose daily tasks meet the following criteria:
a. conducting supervision of the implementation of the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction; and/or b. related to the preparation of reports to PPATK and the Financial Services Authority (OJK).
Employees whose daily tasks are as referred to in item 3 must receive continuous training.
Other employees besides those referred to in item 3 must receive training at least 1 (one) time during their employment period, where such training must have been conducted at the latest 1 (one) year since the employee first worked as a Provider employee.
Training methods
a. Training can be conducted virtually or online or face-to-face. b. Virtual or online training as referred to in letter a can use e-learning media, whether provided by competent authorities such as PPATK, Financial Services Authority (OJK), or provided independently by the Provider.
c. Face-to-face training as referred to in letter a is conducted using approaches including:
Training Materials and Evaluation
a. The Provider can develop training materials regarding the implementation of the AML and CFT program and the prevention of financing for the Proliferation of Weapons of Mass Destruction according to needs. Some topics that can become training materials include among others:
VIII. REPORTING
Updating customer data no later than December 31, 2021.
Submission of the realization report as referred to in item 4) is submitted to the Financial Services Authority (Otoritas Jasa Keuangan) every year no later than 1 (one) month after the reporting period ends.
For example, for customer data updates conducted during the period from January to the end of December 2021, the Provider must submit the realization report no later than January 31, 2022.
Submission of the customer data update plan report as referred to in item 3) for the first time must be submitted no later than the end of December 2022. Meanwhile, submission of the realization report as referred to in item 4) for the first time must be submitted no later than the end of January 2023.
In the event of changes to the data update activity plan report previously submitted to the Financial Services Authority (OJK), the Provider is required to submit such changes no later than 7 (seven) working days since the change was made.
The cover letter for submitting the customer data update plan report as referred to in item 3) and the realization report as referred to in item 4), signed by the Board of Directors, and the content of the customer data update plan report and realization report, are submitted online through the Financial Services Authority's data communication network system.
In the event that the Financial Services Authority's data communication network system as referred to in item 9) is not yet available, the cover letter for submitting the report and the content of the report are submitted via electronic mail (email); and
In the event that the Financial Services Authority's data communication network system as referred to in item 9) and electronic mail (email) as referred to in item 10) experience technical disturbances or problems, the cover letter for submitting the report and the content of the report may be submitted offline in the form of a hardcopy and/or electronic storage media.
Reports as referred to in items 3) and 4) are submitted by the Provider to:
Executive Head of Non
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works