2017-09-06 | 47/SEOJK.04/2017Added · Updated
This Circular establishes the implementation requirements for Anti-Money Laudding and Counter-Terrorism Financing (APU PPT) programs for Capital Market Financial Service Providers (PJK), including securities companies acting as underwriters or brokers, investment managers, and custodian banks. It mandates a risk-based approach requiring PJKs to identify, assess, and mitigate inherent and residual risks associated with customers, geographic areas, products, and distribution channels. The document defines money laundering and terrorism financing typologies, outlines the six-step risk-based approach cycle, and requires PJKs to align their internal controls and monitoring with national and sectoral risk assessments.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 47 /SEOJK.04/2017
REGARDING
IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS IN THE CAPITAL MARKET SECTOR
In order to implement the mandate of Article 68 of Financial Services Authority Regulation Number 12/POJK.01/2017 regarding the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2017 Number 57, Supplement to the State Gazette of the Republic of Indonesia Number 6035), it is necessary to regulate implementation provisions regarding the implementation of anti-money laundering and counter-terrorism financing programs in the capital market sector in this Financial Services Authority Circular Letter as follows:
I. GENERAL PROVISIONS
b. Money Laundering is money laundering as referred to in the Law regarding the prevention and eradication of Money Laundering criminal acts.
c. Terrorism Financing is terrorism financing as referred to in the Law regarding the prevention and eradication of Terrorism Financing criminal acts.
d. Anti-Money Laundering and Counter-Terrorism Financing, hereinafter abbreviated as APU PPT, are efforts to prevent and eradicate Money Laundering and Terrorism Financing criminal acts. e. The Board of Directors for Capital Market PJK is the Board of Directors as referred to in the Law regarding limited liability companies. f. The Board of Commissioners for Capital Market PJK is the Board of Commissioners as referred to in the Law regarding limited liability companies.
Capital Market PJK are highly vulnerable to the possibility of being used as a medium for Money Laundering and Terrorism Financing. Capital Market PJK are possible entry points for wealth that is the proceeds of criminal acts or represents the financing of terrorist activities into the financial system, which can subsequently be utilized for the benefit of criminals. For example, for Money Laundering perpetrators, such wealth can be withdrawn back as wealth that appears legitimate and can no longer be traced to its origin. Whereas for Terrorism Financing perpetrators, such wealth can be used to finance terrorist activities.
The increasing complexity of financial service products and services, including their marketing (multi-channel marketing), as well as the increasing use of information technology in the financial services industry, results in a higher risk of Capital Market PJK being used as a means for Money Laundering and/or Terrorism Financing.
In this regard, there is a need to improve the quality of the implementation of APU PPT programs based on a risk-based approach in accordance with general principles applicable internationally, as well as in line with national risk assessment (NRA) and sectoral risk assessment (SRA).
The implementation of a risk-based APU PPT program must at least include:
a. active supervision by the Board of Directors and Board of Commissioners; b. policies and procedures;
c. internal controls;
d. information management systems; and e. human resources and training.
Overview of Money Laundering Criminal Acts
a. Money Laundering Criminal Acts (TPPU) are acts of placing, transferring, paying, spending, donating, entrusting, taking abroad, exchanging, or other acts over wealth known or reasonably suspected to be the proceeds of criminal acts with the intent to hide or disguise the origin of the wealth so that it appears to be legitimate wealth. b. Generally, the Money Laundering process can be grouped into 3 (three) stages of activities, including:
II. RISK-BASED ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAM (RISK BASED APPROACH)
Obligations for the Implementation of Risk-Based APU PPT Programs
a. Capital Market PJK are obligated to implement risk-based APU PPT programs as referred to in Articles 2 to 5 of Financial Services Authority Regulation Number 12/POJK.01/2017 regarding the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector. b. In the implementation of risk-based APU PPT programs, Capital Market PJK must refer to and consider risks as stated in the NRA and SRA. The risks stated in the NRA and SRA may develop and change. Therefore, the implementation of APU PPT programs owned by Capital Market PJK must be responsive to changes in those risks.
Risk Concept
a. Definition of Risk
Risk can simply be viewed as a combination of the likelihood of occurrence and the level of damage or loss that may result from an event. In the context of Money Laundering and Terrorism Financing, risk is defined as:
b. Risk Management
Risk management is a process performed to assist in decision-making. In relation to Money Laundering and Terrorism Financing, the intended risk management includes understanding Money Laundering risk and Terrorism Financing risk, assessing both risks, and developing methods to manage and mitigate identified risks. In implementing risk management for Money Laundering and Terrorism Financing risks, Capital Market PJK can develop risk management methods in accordance with the characteristics of Capital Market PJK while still referring to legislation regulating APU PPT.
c. Inherent Risk and Residual Risk
In performing risk assessment, it is important to distinguish between inherent risk and residual risk. Inherent risk is the risk attached to an event or condition that exists prior to the implementation of control measures. This inherent risk is related to the business activities and customers of Capital Market PJK. On the other hand, residual risk is the level of risk remaining after the implementation of risk mitigation steps and controls.
d. Risk-Based Approach
In the context of Money Laundering and Terrorism Financing, the risk-based approach is a process that includes the following:
In performing inherent risk identification, Capital Market PJK must consider the vulnerability of Capital Market PJK to be used as a means for Money Laundering and Terrorism Financing. The initial step for Capital Market PJK in performing risk assessment is to understand the overall business activities of the Capital Market PJK from a broad perspective. This understanding will enable Capital Market PJK to consider where risks occur, whether risks occur in business activities, customers, or specific products.
Capital Market PJK must consider elements that trigger the emergence of risks from the customer side, geographic/country/jurisdiction, products, services, or transactions, and distribution channels. The actual amount of risks inventoried by Capital Market PJK will vary depending on the business activities of Capital Market PJK, and the products or services offered.
Customer Risk
Capital Market PJK must pay attention to risks that may arise from customers. Therefore, Capital Market PJK need to categorize customers based on risk levels. This categorization can refer to the risk classification established by Capital Market PJK, in accordance with legislation and applicable international standards. Some customer categories whose activities may indicate high risk include:
a) customers who conduct business relationships or transactions that are unnatural or inconsistent with the customer profile, such as:
(1) significant and unexplainable geographical distance between the customer's residence or business location and the location where the transaction is conducted; and (2) customers who conduct transactions with patterns and transaction values significantly different from those usually conducted; b) corporate customers whose ownership structure is complex and makes it difficult to identify the beneficial owner, ultimate owner, or ultimate controller of the corporation; c) customers who fall into the category of politically exposed persons (PEP), hereinafter abbreviated as PEP, including family members or close associates of PEP; d) customers whose beneficial owner is unknown; and e) customers who are unwilling to provide data and information in the identification process or customers who provide very minimal information or information that is reasonably suspected to be fictitious.
Country or Geographic Area Risk
Country risk or geographic area risk, together with other risk factors, provides very useful information for Money Laundering and Terrorism Financing risk assessment. In performing risk assessment, Capital Market PJK must identify high-risk elements related to geographical location, both the geographical location of Capital Market PJK and the geographical location of customers or the location where the business relationship occurs, and its impact on overall risk. The Money Laundering and Terrorism Financing risk in the business activities of Capital Market PJK increases when:
a) funds are received from or sent to high-risk countries/jurisdictions; or b) customers have significant relationships with high-risk countries/jurisdictions.
Risks related to domicile, citizenship, or transactions must be assessed as part of the inherent risk of Capital Market PJK customers.
Indicators determining that a country or geographic area is high-risk for Money Laundering and Terrorism Financing include:
a) jurisdictions that have been subject to mutual assessment by organizations conducting such assessments (such as: Financial Action Task Force on Money Laundering (FATF), Asia Pacific Group on Money Laundering (APG), Caribbean Financial Action Task Force (CFATF), Committee of Experts on the Evaluation of Anti-Money Laundering Measures and the Financing of Terrorism (MONEYVAL), Eastern and Southern Africa Anti-Money Laundering Group (ESAAMLG), The Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), The Grupo de Accion Financiera de Sudamerica (GAFISUD), Intergovernmental Anti-Money Laundering Group in Africa (GIABA) or Middle East & North Africa Financial Action Task Force (MENAFATF))
identified as jurisdictions that do not adequately implement FATF Recommendations; b) countries identified as non-cooperative or Tax Havens by the Organization for Economic Cooperation and Development (OECD); c) countries with low levels of governance as determined by the World Bank; d) countries with high levels of corruption as identified in the Transparency International Corruption Perception Index; e) countries widely known as places of production and trade of narcotics; f) countries subject to sanctions, embargoes, or similar measures, including by the United Nations; or g) countries or jurisdictions identified by trusted institutions as funding or supporting terrorist activities, or allowing terrorist organizations to operate in their country.
Product/Service/Transaction Risk
Overall risk assessment must also include the determination of potential risks arising from various products or services offered by Financial Service Institutions in the Capital Market Sector. The following factors can increase the risk profile of products or services:
a) Products or services that offer flexibility in withdrawals with certain costs, such as customer fund lending services that can be withdrawn at any time, or transactions for the purchase or sale of mutual fund units that are not limited and can be withdrawn at any time. b) Products or services with high cash value. c) Receipt of payments from unknown third parties or parties with no relationship, such as direct settlement of securities transactions to corporate accounts. d) Transactions using online trading. e) Receipt of payments using cash, such as cash deposits during margin calls.
Distribution Network Risk (delivery channels)
Distribution networks are media used to obtain a product or service, or media used to conduct a transaction. Distribution networks must be considered as transaction risk. Distribution networks that allow transactions without direct face-to-face meetings have inherently higher risks. Some distribution networks can be used without face-to-face meetings, such as the internet or telephone, and can be accessed 24 (twenty-four) hours a day, 7 (seven) days a week, from anywhere. This can be used to obscure the true identity of customers or beneficial owners, thereby posing higher risks. Although some distribution networks are commonly used, such as online trading, these must still be considered as part of the factors that can cause customer risk or product risk to be higher.
Some indicators that can cause high-risk distribution networks include:
a) transactions without face-to-face meetings; b) use of agents; and/or c) online purchase of products or services.
Financial Service Institutions in the Capital Market Sector need to consider the business model, business scale, number of branches, and number of employees owned by the respective Financial Service Institutions as inherent risk factors within the Financial Service Institutions in the Capital Market Sector.
Risk Assessment Scoring
a) After identifying and documenting inherent risks, Financial Service Institutions in the Capital Market Sector must assign a level to each risk. b) The risk scale must be formulated, adjusted to the business scale and type of business of Financial Service Institutions in the Capital Market Sector. c) Businesses with a small business scale conducting simple transactions may categorize risks into 2 (two) categories: low and high. d) For business activities with a larger business scale, it is expected that risks can be categorized into several levels, such as medium, medium-high, or high.
To assist Financial Service Institutions in the Capital Market Sector in conducting risk assessments, they may use the probability and impact matrix as contained in the Appendix, which is an integral part of this Financial Services Authority Circular.
In conducting the identification stage of inherent risks, Financial Service Institutions in the Capital Market Sector must be able to explain all risk assessments conducted by the Financial Service Institutions in the Capital Market Sector with reasons and considerations. Financial Service Institutions in the Capital Market Sector can provide documented information showing that they have considered high-risk indicators in their risk assessments.
b. Establishing Risk Tolerance
c. Formulating Risk Reduction and Control Steps
d. Conducting Evaluation of Residual Risks
e. Applying a Risk-Based Approach
After Financial Service Institutions in the Capital Market Sector conduct risk assessment, they must apply a risk-based approach to daily business activities. Even though a risk-based approach is used, existing obligations such as identification, verification, and monitoring must still be performed as minimum requirements.
The risk-based approach owned by Financial Service Institutions in the Capital Market Sector must be documented in the form of policies and procedures to demonstrate the compliance level of the Financial Service Institution in the Capital Market Sector.
Policies and procedures related to the risk-based approach must be communicated, understood, and complied with by all employees, especially employees conducting customer data and information identification and maintenance, and transaction reporting to relevant authorities.
Policies and procedures related to the risk-based approach must meet the following minimum requirements:
a) customer identification; b) risk assessment; c) special actions for high-risk areas; d) record keeping; and e) reporting.
Financial Service Institutions in the Capital Market Sector need to conduct periodic monitoring of all business relationships conducted, and of high-risk business relationships regarding Money Laundering and Terrorism Financing.
Financial Service Institutions in the Capital Market Sector apply stricter special steps for high-risk customers or business relationships.
Financial Service Institutions in the Capital Market Sector need to note that risk management and risk mitigation require leadership and involvement of senior officials.
Senior officials are responsible for decision-making regarding policies, procedures, and internal control processes and Money Laundering and Terrorism Financing risk mitigation in the business activities owned by Financial Service Institutions in the Capital Market Sector.
With the risk-based approach, it is expected that Financial Service Institutions in the Capital Market Sector can:
a) ensure that the risk assessment conducted reflects the risk-based approach process, the frequency of monitoring low-risk and high-risk customers, and also reflects the internal control steps implemented to reduce identified high risks; b) apply a risk-based approach; c) update data and information regarding customers and beneficial owners; d) monitor all business relationships owned; e) conduct more frequent monitoring of high-risk business relationships regarding Money Laundering and Terrorism Financing; f) take specific steps for high-risk customers; and/or g) involve senior officials in facing situations or high-risk areas (for example, for Politically Exposed Persons (PEPs), approval to conduct business relationships is given by senior officials).
f. Review and Evaluation of the Owned Risk-Based Approach
III. ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
Active supervision by the Board of Directors and Board of Commissioners as referred to in Article 6 and Article 7 of Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector is carried out as follows:
IV. POLICIES AND PROCEDURES
regarding customer profiles based on a risk-based approach to ensure consistency between customer profiles and transactions conducted. CDD can be conducted on all information or only on part of the information.
a) establishing a business relationship with a prospective customer, such as when opening a securities account.
b) there is a financial transaction in Indonesian Rupiah and/or foreign currency with a value of at least IDR 100,000,000.00 (one hundred million Rupiah).
Example:
A general customer (walk-in customer) who orders securities in the primary market with a value of at least IDR 100,000,000.00 (one hundred million Rupiah).
c) there are indications of suspicious financial transactions related to Money Laundering and/or Terrorism Financing, for example, transactions that meet one of the criteria for suspicious financial transactions but still require further investigation to ensure whether the transaction is classified as a suspicious financial transaction that must be reported to the Center for Reporting and Analysis of Financial Transactions (PPATK).
d) Capital Market PJK doubts the accuracy of information provided by customers, proxies, and/or beneficial owners.
Example: the proxy is an individual who has no affiliation or cooperative relationship with the beneficial owner. Capital Market PJK can conduct confirmation regarding the accuracy of the authority of the party representing or acting on behalf of the beneficial owner.
b. Policies and Procedures for Acceptance and Identification of Prospective Customers
Capital Market PJK must have policies regarding the acceptance and identification of prospective customers that include at least the following:
requests for information regarding prospective customers;
requests for copies or recordings of customer identity documents, namely Identity Cards (KTP) for customers who have KTP based on the Law on Population Administration, or other documents that can show the National Identity Number (NIK) for customers who do not yet have KTP;
investigation into the accuracy of supporting identity documents for prospective customers;
requests for more than one identity card issued by competent authorities, if there is doubt regarding the existing identity card;
if necessary, interviews can be conducted with prospective customers to obtain assurance regarding the accuracy of information, identity proof, and supporting documents for prospective customers;
prohibition on opening or maintaining anonymous accounts or accounts using fictitious names;
face-to-face meetings with prospective customers at the beginning of establishing a business relationship to ensure the accuracy of the prospective customer's identity;
vigilance regarding transactions or business relationships with prospective customers originating from or related to countries that are not adequate in implementing Financial Action Task Force (FATF) recommendations; and
the process of verifying the identity of prospective customers and beneficial owners must be completed before establishing a business relationship with prospective customers.
c. Policies and Procedures for Identification of Beneficial Owners
In the event that a prospective customer represents a beneficial owner to establish a business relationship or conduct transactions, Capital Market PJK must conduct CDD procedures on the beneficial owner that are equally strict as the CDD procedures for prospective customers.
In the event that the beneficial owner is classified as a Politically Exposed Person (PEP), the procedure applied is stricter CDD procedures or Enhanced Due Diligence (EDD).
In identifying corporate prospective customers, Capital Market PJK must determine the beneficial owner.
For beneficial owners that are government institutions, government agencies, or companies listed on the stock exchange, the obligation to submit documents and/or ultimate controlling party identities does not need to be performed. The definition of companies listed on the stock exchange includes:
a) customers who are companies that are subsidiaries of companies listed on the stock exchange, where the parent company's ownership is majority; and/or
b) customers who are companies not listed on the stock exchange but whose internal policies require public exposure that explains the company's performance to the public, as applies to companies listed on the stock exchange.
Exceptions to the obligation to submit documents and/or identities of ultimate controlling parties of beneficial owners must be documented.
In the event that Capital Market PJK doubts or cannot verify the identity of the beneficial owner, Capital Market PJK must refuse to establish a business relationship or conduct transactions with the prospective customer.
For prospective customers or beneficial owners whose business relationships or transactions are rejected, Capital Market PJK must obtain at least the name, identity number, address, and place and date of birth according to copies of identity documents obtained by Capital Market PJK for the purpose of reporting Suspicious Financial Transaction Reports (LTKM).
d. Verification of Prospective Customers, Customers, and Beneficial Owners.
Capital Market PJK must investigate the accuracy of information provided by prospective customers, customers, and beneficial owners by verifying supporting documents based on documents and/or other independent sources and ensuring the currency of such information.
In order to verify the accuracy of the identity of prospective customers, customers, and beneficial owners, verification is conducted by:
a) face-to-face meetings with prospective customers, customers, and beneficial owners at the beginning of establishing a business relationship;
b) conducting interviews with prospective customers, customers, and beneficial owners if necessary;
c) matching the consistency of profiles of prospective customers, customers, and beneficial owners with the self-photos contained in identity cards;
d) matching the consistency of signatures, thumbprints, or fingerprints with identity documents or other documents containing signatures, thumbprints, or fingerprints. Other documents include, among others, statements from prospective customers, customers, and beneficial owners, family cards, or credit cards;
e) requesting that prospective customers, customers, and beneficial owners provide more than one identity document issued by competent authorities if there is doubt regarding the existing identity card;
f) archiving copies of identity cards after matching with the original valid documents;
g) conducting cross-checks to ensure consistency of various information provided by prospective customers, customers, and beneficial owners. Cross-checks are conducted by, among others:
(1) contacting prospective customers, customers, and beneficial owners via telephone (home or office);
(2) contacting human resources officials at the workplace of prospective customers, customers, and beneficial owners if their employment is as employees of a company or agency;
(3) confirming the income of prospective customers, customers, and beneficial owners by requiring bank statements from other banks; or
(4) conducting geographic information analysis to view forest conditions through remote sensing technology for prospective customers, customers, and beneficial owners who are companies operating in the forestry sector;
h) ensuring that prospective customers, customers, and beneficial owners do not have negative tracks by verifying the identity of prospective customers, customers, and beneficial owners using other independent sources, including as follows:
(1) terrorist lists and/or suspected terrorist lists and terrorist organizations issued by the National Police of the Republic of Indonesia;
(2) National Blacklist (DHN); or
(3) other data owned by Capital Market PJK, employer identities of prospective customers, customers, and beneficial owners, telephone accounts, and electricity accounts; and/or
i) ensuring the possibility of unusual or suspicious matters.
a) what you have, namely identity documents owned by prospective customers, namely electronic Identity Cards (e-KTP); and
b) what you are, namely biometric data, including in the form of fingerprints of prospective customers, customers, and beneficial owners.
The identity verification process for prospective customers, customers, and beneficial owners must be completed before establishing a business relationship with prospective customers, customers, and beneficial owners.
Under certain conditions, the verification process can be completed after the business relationship has been established.
Certain conditions as referred to in item 5) are:
a) document completeness cannot be fulfilled at the time the business relationship is to be established, for example, because documents are still being processed. Therefore, prospective customers, customers, and beneficial owners can submit documents after establishing a business relationship, within the timeframe determined by Capital Market PJK; and/or
b) if the risk level of individual prospective customers, customers, and beneficial owners is classified as low.
e. Enhanced Due Diligence (EDD)
In the event that Capital Market PJK assesses a customer as high-risk, Capital Market PJK applies a higher level of CDD in the form of EDD to the relevant Customer.
EDD as referred to in item 1) is implemented by verifying information of prospective customers, customers, and beneficial owners, based on the accuracy of information, accuracy of information sources, and types of information involved.
Information verification in the implementation of EDD as referred to in item 2) can be conducted by, among others:
a) seeking additional information about the relevant customer and updating customer or beneficial owner identity data;
b) seeking additional information about the nature and purpose of the business relationship;
c) seeking additional information regarding the source of funds or wealth of the customer;
d) seeking additional information regarding the reasons for the transaction in question or conducted;
e) requesting approval from senior officials to initiate or continue the business relationship; and/or
f) conducting increasingly strict monitoring of the business relationship, namely by increasing the number and duration of supervision used, and having transaction patterns that require further examination.
f. In conducting business relationships with prospective customers, customers, and beneficial owners receiving EDD treatment, Capital Market PJK must appoint senior officials as responsible persons for the business relationships with such prospective customers, customers, and beneficial owners.
g. Simplified CDD
Capital Market PJK must document Customers receiving Simplified CDD treatment in a list containing information regarding the reasons for risk determination so that they are classified as low risk.
Customers who have received Simplified CDD treatment must be removed from the Simplified CDD customer list if they meet the following criteria:
a) indicated to be related to Money Laundering or Terrorism Financing; or
b) no longer meet the criteria as referred to in Article 40 of Financial Services Authority Regulation Number 12/POJK.01/2017 regarding the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector.
a) undergo CDD or EDD according to the customer's current risk level; and/or
b) be reported in the LTKM if transactions are indicated to be related to Money Laundering or Terrorism Financing.
h. CDD by Third Parties
Capital Market PJK may use the results of CDD conducted by third parties on prospective customers who have become customers of such third parties. The third parties referred to have established business relationships with customers that are independent of the business relationships conducted between customers and Capital Market PJK using the third-party CDD results, and such third parties apply their own CDD procedures.
Third parties as referred to in item 1) are as follows:
a) PJK in the banking sector and non-bank financial industry sector, for example, if a securities company receives customers who are bank customers, the securities company may use the CDD results conducted by the said bank as long as the securities company has signed a third-party CDD cooperation agreement with the bank and the securities company can obtain information and copies of supporting documents as soon as possible if the securities company needs them in the implementation of the APU and PPT program.
b) Financial institutions and providers of goods and/or services and specific professions that have CDD procedures and are subject to supervision by competent authorities according to statutory regulations. Examples of financial institutions include non-bank foreign exchange business operators (money changers) and money transfer business operators. Securities companies must still meet the requirements as referred to in letter a).
In the event that Capital Market PJK uses CDD results conducted by third parties, Capital Market PJK is obligated to implement the provisions as referred to in Article 41 paragraph (2) of Financial Services Authority Regulation Number 12/POJK.01/2017 regarding the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector, namely that the implementation of CDD by third parties is limited to the customer identification and verification stages, while the transaction monitoring stage and customer data updating remain the responsibility of Capital Market PJK.
The provisions as referred to in item 1), item 2), and item 3) do not apply to agency relationships. In the event that Capital Market PJK uses agents in implementing CDD procedures, the application of such CDD procedures is conducted by the agent on behalf of and for the account of the delegating Capital Market PJK. The CDD results conducted by the agents as referred to are handed over to the delegating Capital Market PJK.
As an example, in the event that an Investment Manager uses a mutual fund sales agent (APERD) in marketing mutual fund products, the application of CDD is conducted by the APERD on behalf of and for the account of the Investment Manager according to procedures established by the Investment Manager, and under the supervision of the Investment Manager.
a. Rejection of Business Relationships
a) prospective customers wish to conduct transactions but are unwilling to provide information and/or complete documents required by Capital Market PJK as referred to in Articles 21 to 24, and Article 28 of Financial Services Authority Regulation Number 12/POJK.01/2017 regarding the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector; and/or
b) prospective customers provide information and/or documents that are inconsistent or reasonably suspected to be forged documents or information whose accuracy is doubted.
b. Closure of Business Relationships
a) prospective customers or customers are unwilling to provide information and/or complete documents required by Capital Market PJK;
b) prospective customers or customers provide information and/or documents that are inconsistent or reasonably suspected to be forged documents or information whose accuracy is doubted;
c) the source of transaction funds owned by prospective customers or customers is known and/or reasonably suspected to originate from criminal proceeds; and
d) prospective customers or customers are listed in terrorist lists and/or suspected terrorist lists and terrorist organizations.
Capital Market PJK must notify customers in writing regarding the closure of the business relationship.
Written notification can be conducted by sending letters addressed to customers according to the address contained in the Capital Market PJK database or announced through print media, electronic media, or other media.
If after written notification, customers do not withdraw remaining funds stored in Capital Market PJK, the settlement of such remaining customer funds is conducted according to statutory regulations, including by handing over remaining funds to the Estate Management Office (Balai Harta Peninggalan). In the event that the closure of the business relationship is related to fund transfer transactions, the closure procedures are conducted according to statutory regulations governing fund transfers.
Capital Market PJK must document prospective customers or customers subject to closure of business relationships as referred to in item 1) in a separate list.
a. Monitoring
The level and nature of monitoring conducted by Capital Market PJK will depend on the company's business scale, the Money Laundering and Terrorism Financing risk level owned by Capital Market PJK, and the type of business activities.
Capital Market PJK must conduct monitoring activities that include at least:
a) continuous monitoring to identify consistency between customer transactions and customer profiles and to archive such documents, especially regarding business relationships or transactions with customers and/or Capital Market PJK from countries with inadequate APU and PPT programs;
b) analysis of all transactions that are inconsistent with customer profiles; and
c) if necessary, requesting information regarding the background and purpose of transactions that are inconsistent with customer profiles, while observing anti-tipping off provisions as referred to in the Law on the Prevention and Eradication of Money Laundering and Terrorism Financing.
a) ensuring the completeness of customer information and documents;
b) investigating consistency between transaction profiles and customer profiles; and
c) investigating name similarities or matches with names contained in:
(1) terrorist database;
(2) suspected terrorist lists and terrorist organizations;
(3) names of suspects or defendants published in mass media or by competent authorities; and
(4) National Blacklist (DHN).
a) databases issued by competent authorities such as PPATK; or
b) mass media, such as newspapers, magazines, television, and the internet.
Capital Market PJK must classify transactions and customers requiring special monitoring. Monitoring of customer accounts must be conducted more strictly if there are high-risk customers.
All monitoring activities must be well documented in written form, either through formal documents such as memos, notes, or records, or through informal documents such as correspondence via electronic mail (email).
b. Data Updating
Capital Market PJK must apply CDD procedures to its customers for the purpose of data updating, to update data materiality and risk. CDD can be conducted by considering the timing of previous CDD implementation and the adequacy of obtained data.
Capital Market PJK must update information and documents as referred to in the OJK Regulation regarding APU and PPT and archive them.
Capital Market PJK must ensure that documents, data, or information collected in the CDD process are always updated and relevant by re-examining existing data, especially those related to high-risk customers.
Capital Market PJK must update customer data so that the identification and monitoring of suspicious financial transactions can run effectively.
Customer data updating is conducted using a risk-based approach that includes updating customer profiles and transactions. In the event that Capital Market PJK has limited resources, data updating activities are conducted on a priority scale.
Parameters for determining priority scales as referred to in item 5) include, among others:
a) high customer risk level;
b) transactions with significant amounts and/or deviating from transaction profiles or customer profiles (red flag);
c) significant changes in balance values; and/or
d) information in the Customer Identification File (CIF) is not in accordance with the OJK Regulation regarding APU and PPT.
Data updating is conducted periodically according to the needs and complexity of Capital Market PJK and is based on customer or transaction risk levels.
Implementation of data updating for customers listed in the data updating plan report can be conducted, among others, at the time:
a) opening additional business relationships;
b) extending the use of Capital Market PJK products or services;
c) replacing customer data and identity documents; or
d) closing business relationships.
In the event that a customer whose data is to be updated was a customer before the implementation of Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorist Financing Programs in the Financial Services Sector, Capital Market Financial Institution Providers (PJK) must notify the aforementioned customer in writing regarding the obligation of Capital Market PJK to reject transactions, cancel transactions, and/or terminate the business relationship as stipulated in point IV number 2.
Maintenance of accurate data regarding transactions, management of the CDD process, and management of policies and procedures must at least meet the following requirements:
a. customer data documentation is classified according to the customer's risk level; b. documents managed must at least include:
1) copies or recordings of customer identity documents, namely the Identity Card (KTP) for customers who have a KTP based on laws regarding population administration, or other documents that can show the Population Identity Number (NIK) for customers who do not yet have a KTP;
2) files related to the CDD and EDD process, including the results of analysis conducted; and
3) transaction information which includes among others the type and amount of currency used, the date of the transaction order, the origin and destination of the transaction, and the account number related to the transaction;
c. the retention period for documents is as follows:
1) documents related to customer data with a retention period of at least 5 (five) years from:
a) the end of the business relationship with the customer; and/or b) the discovery of transaction inconsistencies with economic and/or business purposes;
2) documents related to customer financial transactions with a retention period as regulated in laws regarding corporate documents;
d. Capital Market PJK must ensure that all documents, both those related to customer data and those related to customer transactions, can be provided at all times for the needs of the competent authority.
Reporting to Senior Officials, the Board of Directors, and the Board of Commissioners regarding the Implementation of the AML and CFT Program
a. In the event that the CDD process reveals a prospective customer or customer categorized as high risk, the Capital Market PJK employee who conducts CDD must report to the senior official. The senior official is responsible for accepting and/or rejecting the business relationship with high-risk prospective customers and customers. b. In the event that the senior official approves the business relationship with a high-risk customer, the senior official is responsible for monitoring transactions of high-risk customers.
c. The senior official must report to the Board of Directors overseeing the AML and CFT program implementation regarding the number of high-risk prospective customers or customers, including the number of high-risk customers who were rejected, accepted, or had their business relationship terminated.
d. The Board of Directors must provide directives regarding the report submitted by the senior official and establish risk mitigation steps. e. The Board of Directors reports to the Board of Commissioners regarding the results of monitoring the overall implementation of the AML and CFT program as per the written policies and procedures established by the PJK. f. The Board of Directors may propose updates to policies and procedures in the event of risk developments that need to be mitigated by Capital Market PJK, which are not yet included in the written policies and procedures.
V. INTERNAL CONTROLS
The implementation of internal controls in the context of implementing the AML and CFT program is carried out by the compliance officer or the Internal Audit Unit (SKAI).
An effective internal control system as referred to in Article 57 paragraph (1) of Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorist Financing Programs in the Financial Services Sector must be capable of detecting weaknesses and deviations from the implementation of the AML and CFT program.
In order to implement effective internal controls as referred to in Article 57 paragraph (2) of Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorist Financing Programs in the Financial Services Sector, Capital Market PJK must have an internal control framework that includes:
a. the appointment of a Compliance Unit (UKK) and/or officials responsible for managing the implementation of the AML and CFT program; b. special monitoring of operational activities that have high-risk potential, whether from customers, products, or geographic areas, including matters deemed vulnerable and potentially related to suspicious transactions, and/or matters that, based on suggestions and information from industry associations or regulators and law enforcement, require special attention;
c. the submission of fast and accurate information in the event of indications and/or suspicions regarding Money Laundering (TPPU) and Terrorist Financing (TPPT), compliance initiatives, compliance deficiencies, corrective actions taken, and reports of suspicious activities;
d. the application of policies, procedures, and controls regarding customer due diligence (CDD); e. the provision of adequate controls for high-risk customers, transactions, and products, such as transaction limits or management approval; and f. testing the effectiveness of the implementation of the AML and CFT program by taking random samples and documenting the testing conducted.
VI. MANAGEMENT INFORMATION SYSTEMS
Information systems that can identify, analyze, monitor, and effectively provide reports regarding the characteristics of transactions conducted by Capital Market PJK customers as referred to in Article 59 paragraph (1) of Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorist Financing Programs in the Financial Services Sector must at least have the following criteria:
a. can store accurate, complete, and up-to-date customer data and information. The aforementioned data and information must be used as one of the parameters in monitoring customer transactions; b. can provide detailed information on individuals, business fields, and countries that meet the criteria for high-risk areas and must be updated regularly;
c. can identify suspicious financial transactions using parameters that are adjusted periodically and consider the complexity of business, transaction volume, and risks possessed by Capital Market PJK;
d. can effectively provide reports regarding the characteristics of transactions conducted by customers; and e. can enable Capital Market PJK to trace each transaction (individual transaction), both for internal and/or OJK purposes, as well as in relation to judicial cases.
Capital Market PJK is required to have and maintain a unified customer profile (single customer identification file). The aforementioned single customer identification file consists of a single investor identification number (SID) provided by the Depository and Clearing Institution.
Capital Market PJK is required to ensure that customer transaction monitoring using information systems is implemented effectively and continuously.
Capital Market PJK is required to ensure the security and reliability of information systems.
Capital Market PJK is required to have standard operating mechanisms or procedures regarding the use of information systems, including establishing access limits for each information system user.
Written policies and procedures owned by Capital Market PJK must consider information technology factors that have the potential to be abused by Money Laundering or Terrorist Financing perpetrators, such as: account opening via the internet, money orders or fund transfer orders via fax or telephone, and other electronic transactions.
VII. HUMAN RESOURCES AND TRAINING
Human Resources
In the context of preventing the use of Capital Market PJK as a medium or destination for Money Laundering and Terrorist Financing, Capital Market PJK must conduct:
a. screening procedures (pre-employee screening) upon the acceptance of new prospective employees as part of the implementation of know your employee (KYE), with the following provisions:
1) screening methods adjusted to the needs, business complexity, and risk profile of Capital Market PJK; and
2) screening methods as referred to in number 1), including among others:
a) requiring prospective employees to create a statement letter stating they have never committed disgraceful acts and/or submitting a Police Record Certificate (SKCK); b) verifying the identity and highest formal education obtained by prospective employees; c) ensuring the track record of prospective employees; and d) researching the profile of prospective employees through other media information; b. recognition and monitoring of employee profiles including among others employee behavior and lifestyle, including among others:
1) conducting monitoring verification and verification for employees who have undergone significant changes in lifestyle;
2) ensuring that employees have understood and complied with the employee code of conduct (staff code of conduct); and
3) evaluating employees responsible for activities classified as high risk, namely those who have access to Capital Market PJK data and interact with prospective customers or customers; and
c. screening procedures (pre-employee screening), recognition, and monitoring of employee profiles are formulated in the know your employee policy based on regulations governing the implementation of anti-fraud strategies.
Training
Capital Market PJK is required to conduct training regarding the implementation of the AML and CFT program continuously according to needs, business complexity, and risk assessment of Capital Market PJK in the following manner:
a. training participants:
1) Capital Market PJK must provide training on the implementation of the AML and CFT program to all employees.
2) In determining training participants, Capital Market PJK prioritizes employees whose daily tasks meet criteria including among others:
a) direct interaction with customers (customer service); b) supervising the implementation of the AML and CFT program; or c) related to the preparation of reports to PPATK and OJK.
3) Employees who supervise the implementation of the AML and CFT program must receive training periodically, while other employees must receive training at least 1 (one) time during their employment period. Employees who interact directly with customers (front liners) must receive training before placement.
b. Training Methods
1) Training can be conducted electronically (online based) or face-to-face.
2) Electronic training (online based) can use e-learning media, whether provided by competent authorities such as PPATK or provided independently by Capital Market PJK.
3) Face-to-face training is conducted interactively (e.g., workshops) or one-way face-to-face (e.g., seminars).
c. Training Topics
Training topics must at least cover:
1) implementation of legislation related to the AML and CFT program;
2) techniques, methods, and typologies of Money Laundering or Terrorist Financing, including trends and developments in the risk profile of Capital Market PJK products; and
3) policies and procedures for implementing the AML and CFT program, as well as the roles and responsibilities of employees in preventing and combating Money Laundering or Terrorist Financing, including consequences if employees engage in tipping off.
Training depth is adjusted to the needs of Capital Market PJK and relevance to employee duties and responsibilities. d. Training Evaluation
1) To determine employee understanding levels and training material relevance, Capital Market PJK must evaluate the training conducted.
2) Evaluation can be conducted directly through interviews or indirectly through tests.
3) Capital Market PJK must follow up on the results of training evaluations through the refinement of training materials and methods.
VIII. REPORTING
Reporting of data update plans and reports on the realization of data updates is conducted with the following provisions:
a. reports are addressed to:
1) Head of the Capital Market Supervision Department 2A, Financial Services Authority, for securities companies.
2) Head of the Capital Market Supervision Department 2B, Financial Services Authority, for custodian banks.
b. report content is submitted to the Financial Services Authority in printed document form and may also be prepared in digital format using digital media (compact disk).
c. reports must conform to the format as contained in the Appendix, which is an integral part of this Financial Services Authority Circular.
In the event that the Financial Services Authority has provided an electronic system, reporting as referred to in number 1 may be submitted through the aforementioned electronic system.
IX. CLOSING
This Financial Services Authority Circular takes effect on the date of establishment.
Established in Jakarta on September 6, 2017
EXECUTIVE HEAD
CAPITAL MARKET SUPERVISOR
FINANCIAL SERVICES AUTHORITY,
signed
HOESEN
APPENDIX
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 47 /SEOJK.04/2017
CONCERNING
THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORIST FINANCING PROGRAMS IN THE CAPITAL MARKET SECTOR
RISK BASED APPROACH CYCLE
Distribution Network Risk
Media used to obtain or offer goods and services, whether directly, through agents, and/or online.
SEPARATION OF RISKS RELATED TO THE BUSINESS ACTIVITIES OF CAPITAL MARKET FINANCIAL INSTITUTION PROVIDERS (PJK) A. The following table presents several examples of risk factors that may be faced by Capital Market PJK as part of risk assessment related to Capital Market PJK business activities. The table also outlines rational reasons that can help Capital Market PJK distinguish each risk level. B. Capital Market PJK can decide the risk scale to be used by Capital Market PJK. This guideline does not require Capital Market PJK to determine high, medium, and low risk scales. Capital Market PJK can use only high and low scales according to business activities, needs, and the complexity of Capital Market PJK.
C. It should be noted that the use of this table is not the application of the Risk Based Approach because the application of the Risk Based Approach must meet the Risk Based Approach cycle. This table helps Capital Market PJK in assessing risks regarding Capital Market PJK business activities, but does not consider customer risks.
D. This risk table presents examples of inherent risks that have not yet been mitigated.
E. Risk mitigation is required for risks categorized as high.
EXAMPLE RISK SEPARATION TABLE
| Factor | Low | Medium | High |
|---|---|---|---|
| Products or Services<br>Electronic transactions<br>example: online trading | Capital Market PJK does not provide electronic transaction services. | Capital Market PJK has several electronic transaction services. | Capital Market PJK offers diverse electronic transaction services.<br>example: online trading |
| Ownership Structure | Capital Market PJK is owned by a State-Owned Enterprise (BUMN). | Capital Market PJK is owned by private entities. | Capital Market PJK is owned by Foreign entities. |
| Geographic Area<br>based on TPPU and TPPT risk levels | Capital Market PJK is located in an area with low TPPU and TPPT risk levels. | The Headquarters or some branch offices or offices outside branch offices of Capital Market PJK are located in areas with medium or moderate TPPU and TPPT risk levels. | The Headquarters or some branch offices or offices outside branch offices are located in areas with high TPPU and TPPT risk levels. |
| High-Risk Country Geography | Capital Market PJK has no business relationships with high-risk countries. | Capital Market PJK has business relationships with high-risk countries with medium or moderate transaction volumes. | Capital Market PJK has business relationships with high-risk countries with high transaction volumes. |
Some indicators in the table above are vague or require further explanation, such as the use of words 'several' or 'significant'. Capital Market PJK can interpret these according to the scale of Capital Market PJK business activities.
LIKELIHOOD AND IMPACT MATRIX
A. In conducting risk identification, one of the tools that can be used by Capital Market PJK is the likelihood and impact matrix. The matrix helps Capital Market PJK determine the extent of efforts or monitoring that need to be conducted to identify inherent risk. It should be noted that the matrix is only an example. Capital Market PJK can use other tools or other forms of matrices that are appropriate to the business scale, needs, and complexity of Capital Market PJK so that it truly reflects the risks faced by Capital Market PJK.
B. The likelihood and impact matrix will help Capital Market PJK decide what needs to be done by considering the overall risk. As previously mentioned, the risk-based approach is a process that enables Capital Market PJK to apply steps proportional to the identified risks as part of the risk assessment. Each box in the matrix indicates the resources needed to perform:
C. How to read the priority matrix
DATA UPDATE PLAN REPORT
(Name of Capital Market PJK)
Position .....
| No | Type of Customer and Risk Level | Number of SID | Information to be Updated | Method/Strategy | Percentage of SID Updated | SID to be Updated | % of Total SID |
|---|---|---|---|---|---|---|---|
| (a) | (b) | (c) | (d) | (e) | (f) | (g) | |
| 1 | Individual Customers | ||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk | |||||||
| 2 | Corporate Customers | ||||||
| a. Non-Micro and Small Enterprises | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| b. Micro and Small Enterprises | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| c. Financial Service Providers | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| d. Foundations | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| e. Other than companies and foundations (with or without legal entity status) | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| 3 | State Institutions, Government Agencies, International Institutions, and Foreign State Representations | ||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk |
Notes:
(a) Filled with number
(b) According to Column
(c) Filled with the planned number of SID updates to be carried out for the next 1 (one) year (d) Filled in percentage (e) Information can be filled in more than one, such as updating home address or employment.
(f) Methods or strategies can be filled in more than one, such as correspondence via mail or electronic mail.
(g) Time targets are adjusted according to the capabilities and conditions of each PJK in the Capital Market Sector, for example, quarterly.
DATA UPDATE REALIZATION REPORT
(Name of PJK in the Capital Market Sector)
Position ......
| No | Customer Type and Risk Level | Development | Obstacles | Measures to be Taken | Target | Realization | Deviation (%) |
|---|---|---|---|---|---|---|---|
| (a) | (b) | (c) | (d) | (e) | (f) | (g) | |
| 1 | Individual Customers | ||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk | |||||||
| 2 | Corporate Customers | ||||||
| a. Micro and Small Enterprises | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| b. Non-Micro and Small Enterprises | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| c. Financial Service Providers | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| d. Foundations | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| e. Other than companies and foundations (with or without legal entity status) | |||||||
| 1) High Risk | |||||||
| 2) Medium Risk | |||||||
| 3) Low Risk | |||||||
| 3 | State Institutions, Government Agencies, International Institutions, and Foreign State Representations | ||||||
| a. High Risk | |||||||
| b. Medium Risk | |||||||
| c. Low Risk |
Notes:
(a) Filled with number
(b) According to Column
(c) Filled with the target number of SID updates (d) Filled with the realized number of SID updates (e) Filled with the percentage difference between the target number of SID updates (c) and the realized number of SID updates (d). (f) Obstacles can be filled in more than one. (g) Filled with measures to overcome obstacles and can be filled in more than one.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Determined in Jakarta on September 6, 2017
EXECUTIVE HEAD
CAPITAL MARKET SUPERVISOR, signed
HOESEN
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.