2020-01-23 | NBB_2020_002Added · Updated
The National Bank of Belgium requires financial institutions supervised by the Bank to review and update their Overall Risk Assessments (ORA) following a horizontal control analysis of 2018 summary tables. Institutions must ensure their ORA processes are risk-based, consistently identify all significant activities and risk factors, and distinguish between inherent risk identification and residual risk management. Updated ORA summary tables and conclusions regarding any necessary reviews must be reported in the AMLCO’s annual activity report submitted by 30 June 2020.
NBB_2020_002 – 23 January 2020 Communication – Page 1/8 Boulevard de Berlaimont 14 – BE-1000 Brussels Phone +32 2 221 24 33 Company number: 0203.201.340 RPM (Trade Register) Brussels www.nbb.be Communication Brussels, 23 January 2020 Reference: NBB_2020_002 Contact person: Justien Boussauw tel. +32 2 221 38 33 justien.boussauw@nbb.be Horizontal control analysis examining a sample of summary tables of the overall assessment of the risks of money laundering and/or terrorist financing Scope All companies subject to the supervision of the National Bank of Belgium that fall within the scope of the Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash, including:
Communication – Page 2/8 NBB_2020_002 – 23 January 2020 Dear Sir, Dear Madam, Since the entry into force of the Law of 18 September 2017 on the prevention of money laundering and terrorist financing and on the restriction of the use of cash (hereinafter “the Law”), the financial institutions subject to the supervision of the National Bank of Belgium (hereinafter “the Bank”) are required to perform an overall assessment of the risks of money laundering and/or terrorist financing to which they are exposed (hereinafter “ORA”) and to update this assessment when it appears that the ORA is no longer adequate to describe the current risks of money laundering and terrorist financing (hereinafter “ML/FT”)1. This assessment is primarily useful for the financial institution itself, as it forms the main foundation for establishing adequate policies, procedures and internal control measures on the subject2. Moreover, each institution should be able to demonstrate that its policies, procedures and internal control measures allow for the proper management and reduction of the risks identified in the context of the ORA3. When a financial institution does not perform its ORA correctly, the impact could be considerable: the institution not only runs the risk of misallocating its resources, but also of being itself involved in money laundering or terrorist financing activities. Where appropriate, the financial institution may, in addition to the non-negligible impact on its reputation, be subject to coercive measures and/or administrative sanctions imposed by the Bank, and even to (criminal) legal proceedings. From this perspective and starting from its own risk classification, the Bank carried out a horizontal analysis and an assessment of a substantial number of ORA summary tables and the related questionnaires, which had been completed by the financial institutions under its supervision and were to be communicated to the Bank by 15 July 2018 at the latest4. Parallel to this analysis, the Bank took into account the responses to the periodic questionnaire relating to anti-money-laundering and counter-terroristfinancing (hereinafter “AML/CFT”), the content of the AMLCO’s annual report and any other relevant information (e.g. inspections or information from CTIF-CFI). As an extension of this control action and in cases where the Bank deemed this appropriate, it addressed specific and individualised oral or written feedback to the institutions. For other financial institutions, this feedback was incorporated in other (particularly event-driven) control actions or taken into account in the preparation of future inspections. On the basis of the analyses performed, the Bank also generated a number of more general findings which are detailed below. Several transversal expectations and recommendations were formulated in the process. However, the Bank emphasises that these findings, expectations and recommendations concerning the reporting of 15 July 2018 are in no way exhaustive and that each AMLCO should, with the support of his senior officer responsible for AML/CFT, review the ORA of his financial institution in light of this communication, identify any improvements and/or updates to be made and perform the improvements and/or updates required. The conclusions of this review should be reported to the Bank in the AMLCO’s next annual activity report on 2019 (to be submitted by 30 June 2020 through eCorporate). Where appropriate, the updated ORA summary table should also be submitted to the Bank (either also through eCorporate or by e-mail for financial institutions that do not have access to eCorporate). 1 For the full legislative and regulatory framework, please refer to the references included in the section “Comments and recommendations by the NBB” on the Bank’s website: See in particular Risk-based approach and overall risk assessment (https://www.nbb.be/en/financial-oversight/combating-money-laundering-and-financing-terrorism/riskbased-approach-and). 2 The ORA differs in this respect from the individual risk assessment required by Article 19 of the Law, which is intended to determine, on a case by case basis, which due diligence measures are appropriate to apply. 3 See Article 17, second paragraph of the Law. 4 Circular NBB_2018_02 of 24 January 2018 on the overall assessment of money laundering and terrorist financing risks, as well as its three annexes.
NBB_2020_002 – 23 January 2020 Communication – Page 3/8 Main findings of the horizontal analysis of the ORA summary tables I. General comments The entry into force of the Law represented a partial break with the past: the approach chosen by the Legislator is now explicitly and essentially risk-based and supported by a legal obligation for risk assessment. The first ORA, which had to be approved by each financial institution’s management committee or senior management5, therefore had the merit of raising financial institutions’ awareness of the importance of the ORA as foundation of their internal AML/CFT organisation. The results of the horizontal control action of the ORA summary tables, which were to be submitted to the Bank by 15 July 2018, were unsatisfactory on average and, therefore, provided ample room for improvement. The Bank found that certain financial institutions limited themselves to a purely formal approach without taking into account the purpose or importance of the ORA. That being said, very large differences were noted from one financial institution to the other regarding the quality of the ORA summary tables. Certain entities belonging to groups that already applied this ORA approach in the past (e.g. the “SIRA” process in the Netherlands), but also some stand-alone and/or smaller financial institutions were able to meet the prudential expectations (taking into account the principle of proportionality). Additionally, our analyses often revealed a lack of consistency between the information included in these ORA summary tables and the information reported to the Bank in the annual AML/CFT questionnaire, in the AMLCO’s annual activity report or by other means. II. The distinction between the ORA and the reporting of results to the Bank The Bank found that it would be useful to specify its expectations regarding the content of the ORA summary table, which was to be submitted by the financial institutions by 15 July 2018 and which will have to be resubmitted to the Bank in the future in case of future updates of the ORA:
Communication – Page 4/8 NBB_2020_002 – 23 January 2020 available to the Bank in its capacity as AML/CFT supervisory authority (that can always request this documentation when needed)7. III. The ORA process Often, the content of the questionnaire relating to the methodology followed to achieve the ORA8 was unsatisfactory and did not make it possible to understand how the financial institution was organised to perform the ORA in an organised and controlled (and controllable) manner. Conversely and as a matter of good practice, the Bank found that, in certain cases, the ORA was not performed in isolation by the AMLCO, who was responsible for the project, but that the AMLCO tried to approximate concrete reality as closely as possible by involving not only the specialists of the AML cell but also the persons who are in direct contact with customers or their transactions, the IT department, etc. Additionally, the Bank also found that certain financial institutions do not follow the different steps of the overall risk assessment in methodological order; the objective of the ORA is certainly not to justify the comprehensiveness of the existing risk management measures, but rather to verify whether these measures are sufficient and, if necessary, to supplement or amend them with additional measures. As a reminder, the following steps should be taken:
NBB_2020_002 – 23 January 2020 Communication – Page 5/8 This procedure, which should also be approved by the management committee or the senior management of the financial institution, makes it possible for the ORA process to be subject to internal control. It should systematically cover the different steps of the ORA and, given that the ORA process is a permanent exercise, the procedure should specify the modalities for reviewing the ORA. A review is required:
Communication – Page 6/8 NBB_2020_002 – 23 January 2020 Risk class – Subcategory Risks related to customers Customers or beneficial owners that are politically exposed persons (PEPs) or family members of PEPs or that are known to be closely associated with PEPs Customers or beneficial owners residing in a high-risk country Customers that are trusts or similar legal constructions Customers that are active in risk sectors Customers that are identified remotely Customers that cannot reasonably justify their inability to provide documentation supporting their claimed identity Risks related to products/services/transactions Products or services allowing for payments from third parties without knowing the identity of those third parties Products or services that are cash intensive (many payment services or certain current accounts) Very high-value transactions Incoming non-SEPA payment transactions Outgoing non-SEPA payment transactions Risk of a personal loan being used for the purpose of terrorist financing (e.g. loans without a precise purpose or whose purpose cannot be verified) Risks related to the countries or geographical areas concerned Funds are received from or sent to jurisdictions subject to financial sanctions, embargoes or restrictive measures in relation to terrorism, terrorist financing or the proliferation of weapons of mass destruction The respondent bank is established in a high-risk country (correspondent banking) Life insurance benefits payable to a beneficiary residing in a high-risk country Risks related to the distribution channel Relationship entered into through a third-party introducer (broker) Relationship entered into through the internet Relationship entered into through a call centre As a matter of good practice, the Bank also found that some ORA summary tables mentioned risks related to the non-integration of IT systems (hindering a complete view of the customers) or to the significant turnover of front-line staff (e.g. in the front office) or Compliance staff (that might not yet have received the necessary AML/CFT training in particular). b. Risk exposure Subsequently, the financial institution should assess the inherent risk by combining the probability of the risk occurring with the impact of any such materialisation of the risk, taking into account the activity effectively performed16. The Bank does not prescribe the values or units to be used by the financial institution, the main objective being that the financial institution (and the Bank) can obtain a coherent and comprehensible view of its risk exposure. This should enable the financial institution to then define risk management measures in accordance with the risk appetite determined by its board of directors. In all cases, the Bank would like it to be clear from the documentation on the ORA process how the probability of the risk occurring and the impact of any such materialisation of the risk are scored. With regard to the probability of risk occurrence, financial institutions should take care not to underestimate their risks. For example, a credit institution can have few PEP customers in its customer base in absolute terms, but this number can represent a substantial percentage of its total customer base. 16 The template provided by the Bank for drafting the ORA summary table does not include these two columns, but there is nothing to prevent the financial institutions from adding this information at their discretion.
NBB_2020_002 – 23 January 2020 Communication – Page 7/8 In the ORA summary table, and more specifically in the column “Risk exposure”, the Bank found examples of good practices consisting of scores ranging from “Low” to “High” or even “Very High” accompanied by a motivation or legend. Finally, the Bank stresses the fact that the risk management measures implemented should not be taken into account in the assessment of the risk exposure level at this stage (see point V below): for example, a financial institution that assessed an inherent ML/FT risk as “Low” because of the existence of various operational procedures within the institution, did not understand the ORA process correctly, as its purpose is to determine the intensity of the risk management measures on the basis of an assessment of the inherent risks, not the residual risks. V. Gap analysis (phase 2) a. Existing risk management measures The Bank notes that, in a second phase (the gap analysis phase), the financial institution should make an inventory of the risk management measures it already applies to manage or limit the various risks identified17. This inventory of the risk management measures should also include compliance with the legal framework laid down in AML/CFT regulations. b. Adequacy of risk management Subsequently, the financial institution should subject these internal procedures and controls to a critical examination, either to conclude that they are sufficient in view of the inherent risks detected or to identify the (potentially substantial) improvements to be made in order to effectively reduce the risks (mitigation and question of residual risk)18. The Bank found that the aim of the ORA was often to justify, a priori and without proper analysis, that the control procedures and measures in place were sufficient in view of the risks identified. Furthermore, in certain cases, instead of this assessment, some financial institutions limited themselves to referring to the legal provisions. This is inadequate: it is the internal procedures and not the legal provisions that should be analysed in order to determine whether they are, on the one hand, in accordance with the legal provisions and, on the other hand, sufficient to effectively manage and reduce the risks identified. In the ORA summary table, and more specifically in the column “Adequacy of risk management”, the Bank identified examples of good practices consisting of scores ranging from “Sufficient” to “Insufficient” accompanied by a motivation or legend. VI. Importance of an ambitious action plan (phase 3) The action plan should be sufficiently ambitious in providing timely and appropriate solutions for the weaknesses identified (regardless of whether this involves introducing a new procedure, reviewing the automated transaction monitoring system, etc.). When establishing this action plan, it may therefore be appropriate to prioritise actions based on the impact of the identified gaps on the overall efficiency of the AML/CFT mechanisms implemented, especially if the plan comprises a large number of new measures to be introduced. In the ORA summary table, and more specifically in the column “New/additional measures, if any”, some institutions merely and almost systematically included a vague and stereotypical formula such as “increase due diligence measures” or “adjust procedure” or “provide training”, which did not make it possible for the Bank to assess the adequacy of the ORA performed. Finally, the Bank notes that the financial institutions should ensure the overall coherence of the action plan: for instance, financial institutions will logically be required to provide for more (substantial) actions with regard to the activities or risk factors for which the residual risk was assessed as high during phase 2 (gap analysis) than for the activities or risk factors for which the residual risk was assessed as low.
17 This corresponds to the column “Existing risk management measures” of the ORA summary table. 18 This corresponds to the column “Adequacy of risk management” of the ORA summary table.
Communication – Page 8/8 NBB_2020_002 – 23 January 2020 The content of this communication supplements the comments and recommendations by the Bank published on its website. This communication, as well as an unofficial English translation, can also be found on the Bank’s website. A copy of this communication is being sent to the auditor(s)19 of your company or institution. Yours faithfully, Pierre Wunsch Governor 19 Where applicable.