2017-06-22 | 32/SEOJK.03/2017Added · Updated
OJK Circular No. 32/SEOJK.03/2017 requires banks to implement risk-based Anti-Money Laundering and Counter-Terrorism Financing (APU and PPT) programs, mandating the establishment of a Special Work Unit or designated responsible officials at headquarters and branches. Banks must adopt specific policies for customer identification and verification, including a Rp100,000,000 threshold for walk-in customers, and identify beneficial owners holding 25% or more equity. The regulation outlines risk assessment factors, tolerance levels, and mitigation strategies, requiring banks to align their existing procedures with POJK No. 12/POJK.01/2017 within six months of its enactment.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To the Board of Directors of Banks,
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 32 /SEOJK.03/2017
CONCERNING
IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS IN THE BANKING SECTOR
In connection with the Financial Services Authority Regulation Number 12/POJK.01/2017 concerning the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs in the Financial Services Sector (State Gazette of the Republic of Indonesia Year 2017 Number 57, Additional State Gazette of the Republic of Indonesia Number 6035), hereinafter referred to as POJK APU and PPT, it is necessary to further regulate the implementation of Anti-Money Laundering and Counter-Terrorism Financing (APU and PPT) programs in the banking sector through this Financial Services Authority Circular Letter as follows:
I. GENERAL PROVISIONS
a. Bank means Commercial Banks, Sharia Commercial Banks, Rural Banks (BPR), and Sharia Rural Financing Banks (BPRS);
b. Commercial Bank means a bank that conducts conventional business activities and provides payment circulation services in its activities;
c. Sharia Commercial Bank means a bank as referred to in Law Number 21 of 2008 concerning Sharia Banking, including branch offices of banks located abroad;
d. Sharia Business Unit, hereinafter referred to as UUS, is a working unit of the headquarters of a conventional Commercial Bank functioning as the parent office of offices or units conducting business activities based on Sharia principles, or a working unit in the branch office of a bank located abroad conducting conventional business activities functioning as the parent office of Sharia sub-branches and/or Sharia units;
e. Rural Bank, hereinafter abbreviated as BPR, is a bank that conducts conventional business activities and does not provide payment circulation services in its activities;
f. Sharia Rural Financing Bank, hereinafter abbreviated as BPRS, is a Sharia Rural Financing Bank as referred to in Law Number 21 of 2008 concerning Sharia Banking.
Banks providing diverse financial transaction services are highly vulnerable to being used as a means of Money Laundering and/or Terrorism Financing. In order to prevent Banks from being used as a means of Money Laundering and/or Terrorism Financing, Banks must implement APU and PPT programs.
With the increasing complexity of banking products and services, including their marketing (multichannel marketing), and the increasing use of information technology in the banking industry, there is a need to improve the quality of APU and PPT program implementation based on a risk-based approach in accordance with general principles applicable internationally and regulations in POJK APU and PPT and this Financial Services Authority Circular Letter.
Referring to Article 13 of POJK APU and PPT, Banks are required to have policies and procedures for the implementation of APU and PPT programs as part of the management and mitigation of Money Laundering and/or Terrorism Financing risks, adjusted to the risk level inherent in each Bank.
Based on Article 67 paragraph (1) of POJK APU and PPT, Banks that have established policies and procedures for the implementation of APU and PPT programs are required to adjust said policies and procedures in accordance with POJK APU and PPT, at the latest 6 (six) months since POJK APU and PPT was promulgated.
The adjustment of policies and procedures as referred to in item 5 refers to POJK APU and PPT and this Financial Services Authority Circular Letter.
II. ACTIVE SUPERVISION BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
a. Banks establish policies and procedures regarding the technical and strategic implementation of APU and PPT programs based on the Bank's risk assessment as referred to in Article 2 of POJK APU and PPT.
b. The establishment of policies and procedures regarding the technical implementation of APU and PPT programs is approved by the Board of Directors as referred to in Article 6 of POJK APU and PPT.
c. The establishment of policies and procedures regarding the strategic implementation of APU and PPT programs is proposed by the Board of Directors as referred to in Article 6 of POJK APU and PPT, and approved by the Board of Commissioners as referred to in Article 7 of POJK APU and PPT.
d. Policies and procedures regarding the technical implementation of APU and PPT programs as referred to in letter b include, among others, the determination of Customers categorized as Politically Exposed Persons (PEP) and the grouping of prospective Customers, Customers, and/or Walk In Customers (WIC) based on the risk level of Money Laundering and/or Terrorism Financing occurrence;
e. Policies and procedures regarding the strategic implementation of APU and PPT programs as referred to in letter c include, among others, changes in organizational structure related to the implementation of APU and PPT programs.
f. The Board of Directors must have adequate understanding of the Money Laundering and/or Terrorism Financing risks inherent in all operational activities of the Bank, so that the Board of Directors is able to manage and mitigate Money Laundering and/or Terrorism Financing risks arising in accordance with the Bank's risk profile.
a. Based on considerations of Money Laundering and/or Terrorism Financing risk levels, Banks must:
establish a Special Work Unit (UKK) and/or appoint responsible officials for the implementation of APU and PPT programs at the headquarters and branch offices.
For branch offices of banks located abroad, the establishment of UKK and/or appointment of responsible officials for the implementation of APU and PPT programs is carried out for the branch office and sub-branch offices.
have adequate working mechanisms. The aforementioned mechanism is implemented by each working unit and/or relevant employees, taking into account anti-tipping off provisions and information confidentiality.
b. The UKK and/or responsible officials for the implementation of APU and PPT programs report to and are responsible to the director overseeing the compliance function. In the event that BPRS does not yet have a director overseeing the compliance function, the UKK and/or responsible officials for the implementation of APU and PPT programs report to and are responsible to one of the members of the Board of Directors.
c. The UKK and/or responsible officials for the implementation of APU and PPT programs must at least have:
adequate knowledge and experience regarding APU and PPT programs and banking products and activities, including relevant regulatory provisions;
adequate experience in the banking field; and
adequate knowledge regarding risk assessment and mitigation of APU and PPT program implementation.
d. Responsible officials for the implementation of APU and PPT programs at:
headquarters must be at least at a level below the Director; and/or
branch offices must be at least at the supervisor level.
e. In determining the Money Laundering and/or Terrorism Financing risk level at branch offices, Banks consider the factors as referred to in the risk-based approach section of APU and PPT program implementation in item 3 of Part III of this Financial Services Authority Circular Letter.
f. For branch offices of Banks with Money Laundering and/or Terrorism Financing risk levels other than low, and where only working units or employees related to Customers are present, the responsible official for the implementation of APU and PPT programs may:
come from the headquarters or regional office with specific duties and responsibilities to supervise the implementation of APU and PPT programs in several specific branch offices; or
be held concurrently by an official from a working unit not related to Customers (non-operational) at other branch offices, such as the risk management working unit. Concurrent holding of positions is permitted considering that the working unit implementing APU and PPT program policies and procedures is separate from the working unit supervising their implementation.
g. For branch offices with low Money Laundering and/or Terrorism Financing risk levels, the official responsible for the implementation of APU and PPT programs may be held concurrently by an official from a working unit related to Customers (operational), provided that such operational duties do not affect the independence and professionalism of the official in carrying out their tasks. For BPR and BPRS, the official responsible for the implementation of APU and PPT programs may be held concurrently by the branch office head.
III. POLICIES AND PROCEDURES
a. Policies and procedures regarding the identification and verification of prospective Customers or WIC must at least include:
requests for information and supporting documents regarding prospective Customers or WIC as referred to in Article 20, Article 21, Article 22, Article 23, and Article 24 of POJK APU and PPT; and
the verification process for information and supporting documents of prospective Customers or WIC.
b. Identification and verification procedures for prospective Customers who will establish a business relationship with the Bank include, among others, at the time of account opening, credit card ownership, or safe deposit box rental. In the event that the account is a joint account, identification and verification procedures are carried out for all prospective Customers.
c. In the event that the Bank assesses there is a change in risk level from:
Customers; and/or
Receiving Banks or Successor Banks abroad that have previously established business relationships with Commercial Banks or Sharia Commercial Banks for Cross Border Correspondent Banking,
identification and re-verification are carried out in accordance with the risk-based approach, namely in the event:
| Individual Customers and Corporate Customers | Receiving Banks or Successor Banks |
|---|---|
| a. There is a significant increase in transaction value. | a. There is a significant or substantial change in the profile of the Receiving Bank and/or Successor Bank. |
| b. There is a fundamental change in documentation standards. | b. Information on the profile of the Receiving Bank and/or Successor Bank available is not yet complete with required information. |
| c. There is a significant change in Customer profile, including significant or substantial changes in transaction patterns. | |
| d. Information in the available Customer Identification File (CIF) is not yet complete with required documents. | |
| e. Using anonymous accounts or accounts using fictitious names. |
d. In the event that the Bank uses third parties to carry out identification procedures, the Bank must:
provide information regarding identification procedures to the third party;
ensure that the third party understands the basic principles of Customer Due Diligence (CDD), including basic procedures for verification; and
make an agreement or contract as the basis for cooperation between the Bank and the third party, one of the materials of which is requiring the third party to apply identification procedures in accordance with the Bank's procedures.
e. The Bank is responsible for the results of identification carried out by third parties.
f. Before conducting transactions with WIC, the Bank requests all information as referred to in letter a item 1) for WIC conducting transactions of at least Rp100,000,000 (one hundred million rupiah) or equivalent in value based on the following criteria:
transactions are conducted in one (1) single instance or multiple transactions in one (1) working day;
transactions are conducted at the same Bank office; and
the type of transaction conducted is the same type of transaction, including deposit transactions, withdrawal transactions, money transfer or remittance transactions, check cashing transactions, and is not a combination of several transactions of different types.
g. For corporate prospective Customers, the information as referred to in letter a item 1) must be supported by corporate identity documents at least in the form of:
deed of establishment and/or articles of association of the company; and
business license or other licenses from competent authorities.
Example:
Business license to conduct foreign currency exchange business activities and money transfer business activities from competent monetary authorities, or business license to conduct business activities in the timber or forestry sector from the Ministry of Environment and Forestry of the Republic of Indonesia.
h. For corporate prospective Customers established abroad, the identity documents referred to are other similar documents to the deed of establishment and/or articles of association in accordance with the regulations of the authority in the country where the company is located.
i. The identity verification process must be completed before establishing a business relationship with prospective Customers or before conducting transactions with WIC.
j. The identity verification process may be completed subsequently if conditions are met, such as the completeness of documents cannot be fulfilled at the time the business relationship is to be established, for example because identity documents are still being processed or the articles of association are still being approved.
k. The identity verification process as referred to in letter j must be completed immediately after the establishment of the business relationship.
a. In conducting identification of corporate prospective Customers, Banks must determine the Beneficial Owner. Examples of identification of Beneficial Owners of corporate prospective Customers include, among others:
individuals owning 25% (twenty-five percent) or more of shares;
individuals owning less than 25% (twenty-five percent) of shares but can prove that they exercise control; or
individuals in the company holding positions on the board of directors who play the most significant role in controlling the company.
b. The verification process for Beneficial Owners is completed in the same manner as the verification process for prospective Customers as referred to in item 1 letter i, letter j, and letter k.
In implementing risk-based APU and PPT programs, Banks must at least carry out activities of identifying inherent risks, determining risk tolerance, formulating risk mitigation and control steps, evaluating residual risks, applying the risk-based approach, and reviewing and evaluating the existing risk-based approach.
a. Identification of Inherent Risks
Banks must consider the vulnerability of the Bank as a means of Money Laundering and/or Terrorism Financing. As a first step, Banks understand the Bank's business activities as a whole from a broad perspective so that the Bank can predict possible risks.
Banks must consider factors that can increase Money Laundering and/or Terrorism Financing risks.
Factors as referred to in item 2) are as follows:
a) Customers
Banks must categorize Customers based on risk levels according to the characteristics of each Bank.
b) Countries or Geographic Areas
Banks must identify risk levels by considering, among others, the location of bank offices, the domicile of bank customers, the location where transactions occur, the transaction destination area, and the location of funds sources entering the customer's account.
c) Products, Services, or Transactions
Banks must identify risk levels related to the products and services offered, including transactions occurring with Customers or WIC, including products and services that are easily convertible to cash or cash equivalents, or whose funds are easily transferred from one area to another with the intent to obscure the origin of the funds.
d) Distribution Networks (Delivery Channels)
Distribution Networks (Delivery Channels) are means used by Customers to obtain a product or service, or to conduct a transaction. Some distribution networks can increase Money Laundering and/or Terrorism Financing risks because certain types of distribution networks can be used to obscure the true identity of Customers or Beneficial Owners.
a) Customers, including:
(1) Customers who establish business relationships or conduct financial transactions that are unnatural or inconsistent with the Customer's profile;
(2) Customers with unexplained frequency and movement of funds among Financial Service Providers (FSPs) in various regions;
(3) Corporate Customers with complex ownership structures making it difficult to identify Beneficial Owners, ultimate owners, or ultimate controllers of the Corporation;
(4) Customers seeking or receiving Bank products or services that do not match their needs or do not provide benefits to the Customer;
(5) Customers in the form of charitable organizations or other non-profit organizations not regulated and supervised by specific authorities;
(6) Customers with account ownership or contracts at the Bank where the business relationship with the Bank is represented by supporting professions such as accountants, advocates, or other professions;
(7) Customers included in the PEP category, including family members or close associates of PEPs;
(8) Customers whose verification process is not conducted through direct meetings (non face to face);
(9) Customers using unusual payment methods such as cash or cash equivalents including negotiable certificates of deposit or traveller’s cheques; and/or
(10) Customers providing very minimal information.
b) Countries or Geographic Areas, including:
funds received from or sent to high-risk countries or jurisdictions; and/or
Customers having significant relationships with high-risk countries or jurisdictions.
Example of countries or geographic areas with high risk levels as referred to in the Explanation of Article 30 paragraph (2) letter c of POJK APU and PPT.
c) Products, Services, or Transactions, including:
prime customer services;
credit cards;
custodian services;
safe deposit boxes;
foreign currency exchange business activities;
trust activities with management;
letters of credit (L/C); and/or
receipt of payments in significant amounts in cash, drafts, or cash checks.
d) Distribution Networks (Delivery Channels) including electronic banking services such as internet banking, mobile banking, Short Message Service (SMS) banking, Electronic Data Capture (EDC), and Automated Teller Machines (ATM).
a) typology trends, methods, techniques, and schemes of Money Laundering and/or Terrorism Financing as referred to in Appendix I which is an integral part of this Financial Services Authority Circular Letter; and
b) the Bank's business model, including business scale, number of branch offices, and number of employees as inherent risk factors internally within the Bank.
a) Banks conduct identification of each factor as referred to in item 4) and 5), considering the likelihood and impact of Money Laundering and/or Terrorism Financing risks occurring.
b) Banks must determine the level of Money Laundering and/or Terrorism Financing risk by considering the results of identification of each factor as referred to in letter a).
The aforementioned risk levels can be divided into 3 (three) categories: low, medium, and high.
c) Illustration of Money Laundering and/or Terrorism Financing risk assessment is as referred to in Appendix II which is an integral part of this Financial Services Authority Circular Letter.
b. Determination of Risk Tolerance
Risk tolerance is the maximum risk level established by the Bank in conducting business activities in accordance with the risk level to be taken (risk appetite). Risk tolerance is an important component of effective risk management.
In determining risk tolerance, Banks need to consider, among others, their ability to face threats related to Money Laundering and/or Terrorism Financing, such as limits on the number of high-risk customers and/or characteristics inherent in high-risk products, which can affect the Bank's overall risk as referred to in regulatory provisions governing risk management for Banks.
c. Formulation of Risk Mitigation and Control Steps
Risk mitigation is the application of risk controls to limit identified Money Laundering and/or Terrorism Financing risks in conducting risk assessments. Risk mitigation will help the Bank's business activities remain within the established risk tolerance.
Banks must develop written risk mitigation strategies (in the form of policies and procedures to mitigate risks) and apply them to areas or business relationships according to the risk level as a result of identification.
Mitigation and risk controls are based on risk tolerance and the risk level taken (risk appetite). Mitigation and risk controls must be commensurate with the risks identified by the Bank.
All business activities of the Bank must have risk control steps as mitigation steps for all identified risk factors and in accordance with the risk level in the area or business relationship, followed by adequate monitoring and documentation processes.
d. Evaluation of Residual Risks
Residual risk is the risk remaining after the application of risk controls and mitigation. Banks need to note that even though the Bank has applied risk mitigation and management strictly, the Bank will still have residual risks that must be managed well.
Residual risks must be in accordance with the established risk tolerance. Banks must ensure that residual risks are not greater than the established risk tolerance. In the event that residual risks are greater than risk tolerance, or in the event that risk controls and mitigation are inadequate, the Bank must return to carrying out risk mitigation and control steps as referred to in letter c and increase the level or quantity of established mitigation steps.
With the activity of evaluating residual risks, Banks must be able to adjust the risk level possessed to the tolerated risk.
e. Application of Risk-Based Approach
regarding the implementation of AML and CTF programs in the financial services sector.
Banks must document their risk-based approach. Policies and procedures related to the risk-based approach must be communicated, understood, and complied with by all employees, particularly those involved in identification and verification, data and customer information record-keeping, and reporting of financial transactions to the relevant authorities. The relevant employees must receive sufficient information to process and complete financial transactions, including identifying and documenting Customers in accordance with the provisions of legislation regarding the implementation of AML and CTF programs in the financial services sector.
With the implementation of the risk-based approach, Banks must be able to:
a) ensure that the risk assessments performed reflect the risk-based approach process, as well as the risk control measures implemented to reduce the level of risk according to the identification results;
b) update data, information, and supporting documents for Customers and Beneficial Owners;
c) monitor all business relationships held;
d) conduct more frequent monitoring of business relationships with high risk related to Money Laundering and/or Terrorism Financing;
e) apply adequate measures against high-risk Customers at least:
(1) conduct more frequent monitoring; and
(2) conduct more in-depth identification and/or update Customer data; and/or
f) involve senior officials in handling high-risk conditions, including granting approval to establish business relationships with PEPs.
f. Review and Evaluation of the Risk-Based Approach
a) policies and procedures;
b) risk assessments related to Money Laundering and/or Terrorism Financing; and
c) human resource training programs.
In the event of changes in business strategy related to business activities and/or the addition of new products and services, Banks must update policies and procedures for risk control.
Reviews of the risk-based approach can help evaluate the need for improvements to existing policies and procedures, or the formulation and implementation of new policies and procedures if necessary.
Banks document the results of the review, including improvement steps and necessary follow-up actions.
a. Enhanced Due Diligence (EDD) against Prospective Customers, Customers, WICs, and/or Beneficial Owners with High Risk
Banks must conduct more in-depth CDD activities or Enhanced Due Diligence (EDD) against criteria for Prospective Customers, Customers, WICs, and/or Beneficial Owners that meet high-risk criteria as referred to in Article 30 paragraph (2) of the OJK Regulation on AML and CTF.
Examples of EDD as referred to in item 1) include the following:
a) seeking additional information related to high-risk Prospective Customers, Customers, WICs, and/or Beneficial Owners regarding:
(1) occupation, wealth lists, or other information in databases accessible to the public or via the internet, and periodically updating the identity data of high-risk Customers and/or Beneficial Owners;
(2) reasons and purposes of business relationships or financial transactions, whether prospective or already conducted; and
(3) sources of funds or sources of wealth;
b) requesting approval from senior officials to initiate or continue business relationships with high-risk Prospective Customers, Customers, WICs, and/or Beneficial Owners; and/or
c) conducting stricter monitoring of high-risk Customers and/or Beneficial Owners, by increasing the frequency and duration of monitoring, and selecting transaction patterns that require further review.
In the event that based on the results of EDD conducted on high-risk Customers who conduct transactions inconsistent with the Customer's profile, but clear underlying reasons for the transactions are obtained, monitoring of such transactions is conducted in accordance with applicable procedures. In the event that EDD results do not yield clear underlying reasons or explanations, such transactions must be reported in the Suspicious Financial Transaction Report (LTKM) and subject to stricter monitoring.
The nature, quality, and quantity of Customer and/or Beneficial Owner information obtained from EDD results must provide an overview of the risk level arising from the business relationship.
The information obtained must be verifiable and provide assurance regarding the profile of the actual high-risk Customer and/or Beneficial Owner.
b. EDD for Member Get Member Programs
For Banks providing credit card products through member get member programs, the EDD process includes:
ensuring that supporting documents containing the identity of prospective Customers have been legalized by a competent institution; and
the first payment transaction is conducted directly by the credit card holder at the issuing credit card Bank located in Indonesia for the purpose of Customer identity verification.
c. EDD for Trust Services with Management
a) the settlor who entrusts the management of their assets; and
b) the beneficiary of the entrusted assets.
In the event that the settlor also acts as the beneficiary, the EDD conducted is only on the settlor or beneficiary, explaining that the settlor and beneficiary are the same party.
Commercial Banks and Sharia Commercial Banks request information from prospective settlors based on applicable provisions for prospective Customers.
Commercial Banks or Sharia Commercial Banks request information from beneficiaries at least including:
a) type of information;
b) beneficiary account number; and
c) name of the Commercial Bank or Sharia Commercial Bank receiving the transfer of funds from the settlor's account.
a. Banks reject or cancel transactions including against:
Customers who wish to conduct fund transfer transactions but are unwilling to complete the fund transfer application; and/or
Incoming transfers to Customer accounts, however, after the Receiving Bank conducts re-CDD and based on information from the Sending Bank, it is known that the receiving Customer's account is an account holding proceeds of criminal acts as referred to in the provisions of legislation regarding the prevention and eradication of Money Laundering criminal acts.
The Receiving Bank must cancel the incoming transfer transaction by returning the funds to the Sending Bank, provided the funds are still stored in the receiving Customer's account.
b. In the event of closure of business relationships related to fund transfer transactions, the closure procedure is conducted in accordance with the provisions of legislation regarding fund transfers.
c. Rejection or cancellation of transactions against receiving Customer accounts used to hold proceeds of criminal acts may be accompanied by the return of funds to the sending Customer if the following requirements are met:
there is a report from the sending Customer to the Sending Bank, accompanied by supporting documents such as a report to the Police;
the identity of the receiving Customer is known to be false and/or suspected of using false documents;
there is still remaining funds in the receiving Customer's account;
the transaction from the sending Customer's account was conducted via fund transfer;
the funds stored in the receiving Customer's account, whether partially or entirely, originate from the sending Customer's account;
the account or fund balance in the receiving Customer's account is not currently blocked or seized by a competent agency; and
there is a clause in the account opening agreement regarding the Bank's obligation to reject transactions, cancel transactions, and/or close business relationships with Customers.
d. The return of funds as referred to in letter c is conducted through the process of debiting funds from the receiving Customer's account to be credited back to the sending Customer's account.
e. The return of funds as referred to in letter d is conducted with the following provisions:
in the event that there is only 1 (one) sending Customer who applies for the return of funds, the funds returned to the sending Customer are equal to the funds belonging to the sending Customer that are still present in the receiving Customer's account; or
in the event that there is more than 1 (one) sending Customer who applies for the return of funds, if the funds present in the receiving Customer's account are believed by the Bank:
a) to originate from all sending Customers and the amount is sufficient for the return of funds to all sending Customers, the Bank may return the funds;
b) to originate only from some sending Customers and the amount is sufficient, the Bank will only return funds to those sending Customers whom the Bank believes are the source of the funds in the receiving Customer's account;
c) to originate from all sending Customers and the amount is not sufficient for the return of funds to all sending Customers, the return of funds is only conducted based on an agreement among the sending Customers. If no agreement is reached, the return of funds is conducted based on a final and binding court decision ordering the Bank to return the funds to the entitled party; or
d) to originate from some sending Customers and the amount is not sufficient for the return of funds to those sending Customers, the return of funds is only conducted to each sending Customer whom the Bank believes still has funds in the receiving Customer's account, based on an agreement among those sending Customers. If no agreement is reached, the return of funds is conducted based on a final and binding court decision ordering the Bank to return the funds to the entitled party.
Upon the occurrence of the return of funds to the sending Customer, the Sending Bank creates a minutes of fund return signed by the Sending Bank official and the sending Customer.
f. The process as referred to in letter e does not apply in the event that the names of the receiving Customer and/or sending Customer are listed in the List of Suspected Terrorists and Terrorist Organizations (DTTOT).
a. Monitoring
Banks conduct continuous monitoring activities to identify the consistency between Customer transactions and the Customer's profile and to record documents thereof, particularly regarding business relationships or transactions with Customers and/or banks from high-risk countries or jurisdictions.
Continuous transaction and Customer profile monitoring activities include:
a) ensuring the completeness of Customer information and supporting documents as referred to in item 1 letter a item 1);
b) examining the consistency between transaction patterns and the Customer's profile;
c) examining name similarities or matches with names listed in:
(1) terrorist database;
(2) DTTOT;
(3) names of suspects or defendants published in mass media or by competent authorities; and
(4) National Blacklist (DHN).
a) databases issued by competent parties such as the Center for Financial Transaction and Report Analysis (PPATK); or
b) mass media such as newspapers, magazines, television, and/or the internet.
Monitoring of transactions and Customer profiles must be conducted periodically using a risk-based approach.
In the event that based on monitoring results there are name similarities or matches as referred to in item 2 letter c), the Bank must conduct clarification to ensure the name similarity or match.
In the event that the Customer's name and identity match the terrorist database and/or match the names of suspects or defendants informed in mass media as referred to in item 2 letter c) item (1) and item (3), the Bank reports such Customer in the LTKM.
In the event that the Customer's name and identity match the DTTOT name as referred to in item 2 letter c) item (2), the Bank reports such Customer in the LTKM and conducts blocking after receiving a blocking request or order from a competent institution as referred to in the provisions of legislation regarding guidelines for immediate blocking of Customer funds in the financial services sector whose identity is listed in the DTTOT.
In the event that the Customer's name and identity match the name listed in the DHN as referred to in item 2 letter c) item (4), the Bank examines the rehabilitation process conducted by such Customer. In the event of irregularities in the rehabilitation process, the Bank reports such Customer in the LTKM.
All monitoring activities are documented systematically and in written form, either through formal documents such as memos, notes, or records, or through informal documents such as correspondence via electronic mail.
b. Data Updating as a Follow-up to Monitoring
Banks must apply CDD procedures for Customers to update data, considering materiality and risk level. Such CDD is conducted by considering the timing of the previous CDD and the adequacy of data obtained.
Banks must ensure that documents, data, or information collected in the CDD process are always updated and relevant by re-examining existing data, particularly those related to high-risk Customers.
Customer data updating is conducted using a risk-based approach that includes updating the Customer profile, including transaction patterns. In the event that the Bank's resources are limited, data updating activities are conducted on a priority scale.
In determining the priority scale as referred to in item 3), the Bank may prioritize several criteria, including:
a) Customers with a high risk level;
b) transactions with significant amounts and/or deviating from transaction profiles or Customer profiles (red flags) as referred to in Appendix III which is an integral part of this OJK Circular;
c) account balances with significant value; or
d) information in the CIF not in accordance with the OJK Regulation on AML and CTF.
Data updating is conducted periodically based on the risk level of Customers or transactions. For example, for high-risk Customers, data updating can be conducted every 6 (six) months, for medium-risk Customers every 1 (one) year, and for low-risk Customers every 2 (two) years.
Implementation of data updating for Customers listed in the data updating plan report can be conducted, among others, at the time of:
a) opening additional accounts;
b) loan facility renewal;
c) replacement of savings books, ATMs, or other banking product documents;
d) visits for safe deposit box purposes; and/or
e) loan repayment.
Example: A Customer fills in the income amount in the account opening form as Rp5,000,000.00 (five million rupiah) per month, however, based on monthly salary transfers conducted by the company where the Customer works, the income amount is known to be Rp15,000,000.00 (fifteen million rupiah). In this case, the Bank fills in the monthly income amount in the CIF as Rp15,000,000.00 (fifteen million rupiah) accompanied by a note, memo, or record explaining the reason or consideration for filling in that figure and the approval of the competent Bank official. Such note, memo, or record documents become an integral part of the Customer account opening agreement.
All data updating activities must be recorded.
In the data updating process, the Bank notifies the Customer in writing regarding the Bank's obligation to reject transactions, cancel transactions, and/or close business relationships if the Customer meets the criteria as referred to in Article 42 of the OJK Regulation on AML and CTF.
a. Cross Border Correspondent Banking Procedures
Before providing Cross Border Correspondent Banking services, Banks must conduct a CDD process against prospective respondent banks, whether acting as Receiving Banks or Issuing Banks. For L/C transactions, the Receiving Bank and/or Issuing Bank includes the issuing bank, advising bank, confirming bank, and/or negotiating bank.
The CDD process is conducted by requesting information regarding:
a) the profile of the prospective Receiving Bank and/or Issuing Bank, including among others the composition of the Board of Directors and Board of Commissioners, business activities, banking products owned, marketing targets, and purposes of account opening. Information sources to ensure such information are based on adequate public information issued and established by competent authorities, among others banker’s almanac;
b) the reputation of the Receiving Bank and/or Issuing Bank based on accountable information, including negative reputation, for example:
(1) sanctions previously imposed by authorities on the Receiving Bank and/or Issuing Bank related to violations of authority regulations and/or FATF Recommendations; or
(2) the Receiving Bank and/or Issuing Bank is in the process of investigation and/or supervision by competent authorities related to the prevention and eradication of Money Laundering and/or Terrorism Financing criminal acts.
b. Payable Through Account
The Sending Bank must ensure access to Payable Through Accounts (PTA) in cooperation between the Sending Bank and the Receiving Bank and/or Issuing Bank, which is embodied in a written cooperation agreement.
Examples of PTA transactions are as follows:
Bank A (established and under the supervision of the South Pacific Island Vanuatu authority) opens a PTA at American Express Bank International (AMEX) in Miami, United States. The purpose of opening the PTA is for Bank A in Vanuatu to provide virtual AMEX banking services to US citizen Customers residing in the Vanuatu territory but who are not AMEX Customers.
Customers are given checkbooks and applications allowing them to deposit or withdraw funds through Bank A's PTA. This PTA transaction allows for the misuse of accounts and transactions conducted by Customers, which ultimately poses reputational risk to AMEX.
a. Provisions applicable to the Sending Bank are as follows:
The Sending Bank must obtain information and conduct identification and verification against the sending Customer or WIC and/or the receiving Customer or WIC, at least as referred to in Article 51 of the OJK Regulation on AML and CTF.
In the event that the original sender is already a Customer of the Sending Bank, the Sending Bank must obtain information:
a) name of the sending Customer;
b) sending Customer's account number;
c) sending Customer's address;
d) identity document number, identification number, or place and date of birth of the sending Customer;
e) source of funds for the sending Customer;
f) name of the receiving Customer or WIC;
g) receiving Customer's account number or receiving WIC's address;
h) amount of money and currency type; and
i) transaction date.
In the event that fund transfer activities are conducted by multiple sending Customers or WICs from the same sender in the form of batch file transmission, the Sending Bank must obtain information regarding each sending Customer or WIC.
Information regarding sending Customers or WICs and/or receiving Customers or WICs in items 1) and 2) must be transmitted by the Sending Bank to the Issuing Bank or Receiving Bank.
All fund transfer activities must be documented.
b. Provisions applicable to the Issuing Bank are as follows:
Ensuring the completeness of information regarding sending Customers or WICs and receiving Customers or WICs as referred to in letter a item 1).
Forwarding the message and fund transfer order received from the Sending Bank.
All information received from the Sending Bank must be documented in accordance with the provisions of legislation regarding document record-keeping.
Ensuring the completeness of information regarding sending Customers or WICs and receiving Customers or WICs for fund transfer transactions to foreign countries with a straight-through processing pattern.
In the event that the Issuing Bank receives a transfer order from a Sending Bank outside the country that is not accompanied by information as referred to in letter a item 1), the Issuing Bank may:
a) execute the fund transfer;
b) refuse to execute the fund transfer; or
c) suspend the fund transfer transaction.
c. Provisions applicable to the Receiving Bank are as follows:
Ensuring the completeness of information regarding sending Customers or WICs and receiving Customers or WICs in fund transfer transactions from abroad, both at the time the transaction is conducted (real-time monitoring) and after the transaction is conducted (post-event monitoring).
All information received must be documented in accordance with the provisions of legislation regarding document record-keeping.
In the event that the Receiving Bank receives a transfer order from a Sending Bank located outside the country that is not accompanied by the information referred to in letter a number 1), the Receiving Bank may:
a) execute the fund transfer; b) refuse to execute the fund transfer; or c) suspend the fund transfer transaction.
The action to be taken by the Receiving Bank as per the action choices in number 3) must be accompanied by adequate follow-up measures, including more intensive monitoring, and/or reporting as a Reporting Entity.
In the event that the Receiving Bank receives a transfer order from a Sending Bank within the territory of Indonesia that is not accompanied by the information referred to in letter a number 1) but is only accompanied by the Sender Customer's account number or the Sender Customer's or Sender WIC's transaction reference number, the Receiving Bank may request the required information in writing from the Sending Bank.
a. In order to monitor the implementation of the AML and CTF program within the network of offices and subsidiaries abroad, the Bank must require the network of offices and subsidiaries to monitor and report periodically on the implementation results of the AML and CTF program, including statistics of Reporting Entities that have been reported to the local authorities.
b. In the event that provisions of Indonesian legislation regarding the implementation of the AML and CTF program result in violations of the legislation in the country where the network of offices and subsidiaries are located, the Bank must take adequate actions to mitigate Money Laundering and/or Terrorism Financing risks and submit a report to the Financial Services Authority.
c. In carrying out information exchange between the Bank with Indonesian legal entity status and all network offices and subsidiaries abroad, the Bank must pay attention to information security levels and legislative provisions.
d. In the event of differences in AML and CTF program standards between the Bank with Indonesian legal entity status and network offices and subsidiaries abroad, the determination of strict or lenient criteria for AML and CTF regulations at the location of the network offices and subsidiaries abroad must be supported by an analysis of each legislative provision.
a. The Bank must manage all data or transaction documents obtained through CDD procedures, both domestically and abroad, for a minimum period of 5 (five) years.
b. Supporting documents related to Customer or WIC identity must at least include copies or recordings of the Customer's or WIC's identity documents (examples: identity cards, driver's licenses, passports, or similar documents).
c. Other supporting documents that need to be managed include account files and business correspondence, including analysis results conducted (examples: investigations conducted to ensure the background and purpose of large, complex, and unusual transactions).
IV. INTERNAL CONTROL
To minimize potential risks faced by the Bank, the internal control system must be able to timely detect weaknesses and deviations occurring in the implementation of the AML and CTF program.
Internal control for the implementation of the AML and CTF program is carried out by the Internal Audit Work Unit (SKAI) or appointed officials with authority including:
a. conducting compliance testing of policies and procedures through sample testing of various services, products, and Customers using a risk-based approach to obtain an overview of the effectiveness of policy and procedure implementation;
b. developing risk-based audit programs and procedures with audit priorities on work units or branch offices classified as having high business complexity; and/or
c. assessing the adequacy of processes in place at the Bank to identify and report suspicious transactions, paying attention to anti-tipping-off provisions.
The Bank must implement clear separation of functions, duties, and responsibilities between operational work units and work units carrying out control functions.
The Bank must have an internal control system, both functional and embedded, that can ensure that the implementation of the AML and CTF program by relevant work units is in accordance with established policies and procedures by ensuring that work units have:
a. implemented internal supervision well, accurately, and effectively; and
b. provided adequate training for all employees in work units related to the implementation of AML and CTF.
V. MANAGEMENT INFORMATION SYSTEM
a. A management information system to identify suspicious financial transactions using parameters adjusted periodically and considering business complexity, transaction volume, and the Bank's risk profile.
b. The Bank must have and maintain an integrated Customer profile (single CIF).
c. Information contained in the single CIF includes all products and services used by the Customer at a Bank, including but not limited to savings, deposits, current accounts, credit or financing, safe deposit boxes, structured products, and/or trusts.
d. For joint accounts, a CIF is created for each party to the joint account, for example:
Joint account in the names of A and B, the CIFs created are 2 (two) CIFs, namely CIF in the name of A and CIF in the name of B, with information that both A and B have a joint account.
Joint account in the name of A or B, the CIFs created are 2 (two) CIFs, namely CIF in the name of A and CIF in the name of B, with information that both A and B have a joint account.
e. Commercial Banks that have Customers who are also recorded as Customers in the Sharia business unit of the same Commercial Bank may have 2 (two) different CIFs provided the Bank can identify that the 2 (two) CIFs belong to the same Customer. Both CIFs can be categorized as an integrated Customer profile.
The Bank must maintain the DTTOT database received from the Financial Services Authority, issued by the Chief of the Indonesian National Police based on a decision of the Central Jakarta District Court.
VI. HUMAN RESOURCES AND TRAINING
In order to prevent the Bank from being used as a means or objective for Money Laundering and/or Terrorism Financing, the Bank must conduct:
a. pre-employee screening procedures upon the hiring of new employees as part of the implementation of Know Your Employee (KYE), with the following provisions:
Screening methods are adjusted to needs, the Bank's business complexity, and the Bank's risk profile.
Screening methods must at least ensure that the candidate's profile has no criminal record, including:
a) requiring candidates to create a statement letter and/or submit a Police Record Certificate (SKCK);
b) verifying the identity and education obtained by the candidate;
c) ensuring the candidate's credit quality is not classified as non-performing;
d) ensuring the candidate's track record within a certain period, for example the last 5 (five) years; and/or
e) conducting research through other information media.
a) ensuring employees do not have non-performing loans;
b) conducting internet research;
c) verifying employees who have undergone significant lifestyle changes;
d) monitoring employee accounts;
e) ensuring that employees have understood and complied with the staff code of conduct; and/or
f) evaluating employees responsible for high-risk activities, including employees with access to Bank data, facing prospective Customers or Customers, and/or involved in the procurement of goods and services for the Bank.
b. Pre-employee screening, introduction, and monitoring of employee profiles are formulated in the KYE policy, which refers to regulations governing the implementation of anti-fraud strategies.
a. Training Participants
The Bank must provide training on the implementation of the AML and CTF program to all employees.
In determining training participants, the Bank prioritizes employees with daily tasks meeting the following criteria:
a) direct contact with Customers (front liners);
b) supervising the implementation of the AML and CTF program; and/or
c) related to the preparation of reports to PPATK and the Financial Services Authority.
b. Training Methods
Training can be conducted electronically (online-based) or face-to-face.
Electronic training (online-based) can use electronic learning (e-learning) media, whether provided by competent authorities such as PPATK and/or provided independently by the Bank.
Face-to-face training is conducted using approaches including:
a) interactive face-to-face (e.g., workshops) with training topics adjusted to participant needs. This approach is used for prioritized employees and conducted periodically, for example, every year.
b) one-way face-to-face (e.g., seminars) where the training topic is a general overview of the implementation of the AML and CTF program. This approach is given to non-prioritized employees and conducted when there are significant regulatory changes.
c. Training Topics and Evaluation
a) implementation of legislative provisions related to the implementation of the AML and CTF program;
b) techniques, methods, and typologies of Money Laundering and/or Terrorism Financing, including trends and developments in the risk profile of banking products; and
c) policies and procedures for implementing the AML and CTF program and the role and responsibilities of employees in preventing and combating Money Laundering and/or Terrorism Financing, including consequences if employees commit tipping off.
The depth of training topics is adjusted to employee needs and alignment with employee duties and responsibilities.
To determine employee understanding levels and training material suitability, the Bank must evaluate each training session conducted.
Evaluation can be conducted directly through interviews or indirectly through tests.
The Bank must take follow-up actions from training evaluation results through the refinement of training materials and methods.
VII. REPORTING
a. Reports on the data update plan and reports on the realization of data updates must be approved and submitted by the Director overseeing the compliance function for the Bank. In the event that a Sharia Rural Bank (BPRS) does not yet have a Director overseeing the compliance function, the reports on the data update plan and the realization of data updates must be approved and submitted by one of the Board of Directors members.
b. For Rural Banks (BPR) and Sharia Rural Banks (BPRS), the submission of the data update plan report for the first time must be submitted no later than the end of December 2017. Meanwhile, the submission of the data update realization report for the first time must be submitted no later than the end of December 2018.
c. Changes to the data update activity plan report can be made as long as changes occur outside the Bank's control and must be submitted to the Financial Services Authority no later than 7 (seven) working days since the change was made.
d. Reports on the data update plan and reports on the realization of data updates are made in accordance with the format referred to in Appendix IV, which is an integral part of this Financial Services Authority Circular.
Reporting of suspicious financial transactions, cash financial transactions, and fund transfers to and from abroad is made in accordance with reporting regulations and procedures referring to legislative provisions governing reporting to PPATK.
VIII. CLOSING
a) Bank Indonesia Circular Number 6/37/DPNP dated September 10, 2004 regarding Assessment and Imposition of Sanctions for the Implementation of Customer Identification Principles and Other Obligations related to the Law on Money Laundering Criminal Acts;
b) Bank Indonesia Circular Number 15/21/DPNP dated June 14, 2013 regarding the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs for Commercial Banks; and
c) Bank Indonesia Circular Number 13/14/DKBU dated May 12, 2011 regarding the Implementation of Anti-Money Laundering and Counter-Terrorism Financing Programs for Rural Banks and Sharia Financing Banks;
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Determined in Jakarta on June 22, 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
APPENDIX I
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 32 /SEOJK.03/2017
REGARDING
THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS IN THE BANKING SECTOR
MONEY LAUNDERING AND/OR TERRORISM FINANCING CRIME TYPOLOGIES
A. Money Laundering Crimes
Money laundering, internationally known as money laundering, is the act of placing, transferring, paying, spending, donating, entrusting, taking abroad, exchanging, or other acts over assets known or reasonably suspected to be proceeds of crime with the intent to hide or disguise the origin of the assets so that they appear to be legitimate assets.
Generally, the money laundering process can be grouped into 3 (three) stages of activities including:
a. Placement is the effort to place cash money originating from crimes into the financial system, or the effort to place giro money (checks, bank drafts, deposit certificates, etc.) back into the financial system, especially the banking system.
b. Layering is the effort to transfer assets originating from crimes (dirty money) that have been successfully placed in a Reporting Institution (PJK) (especially Banks) as a result of placement efforts to another Reporting Institution. An example is conducting multiple transactions or fund transfers.
c. Integration of assets is the effort to use assets originating from crimes that have successfully entered the financial system through placement or transfer so that they appear to be legitimate assets (clean money), for legal business activities or to finance criminal activities again. An example is purchasing assets and opening or conducting business activities.
a. Smurfing, which is the effort to avoid reporting by breaking down transactions conducted by many perpetrators.
b. Structuring, which is the effort to avoid reporting by breaking down transactions so that the transaction amount becomes smaller.
c. U Turn, which is the effort to obscure the origin of criminal proceeds by reversing transactions and then returning them to the original account.
d. Cuckoo Smurfing, which is the effort to obscure the source of funds by sending funds from criminal proceeds through a third-party account waiting for funds from abroad, unaware that the received funds are proceeds of crime.
e. Purchase of assets or luxury goods, which is hiding ownership status of assets or luxury goods, including asset transfers undetected by the financial system.
f. Barter, which is avoiding the use of cash or financial instruments so they cannot be detected by the financial system.
g. Underground banking or alternative remittance services, which are money transfer activities through informal channel mechanisms conducted based on trust.
h. Use of third parties, which are transactions conducted using third-party identities to avoid detection of the identity of the actual owner of the criminal proceeds.
i. Mingling, which is mixing criminal proceeds with funds from legal business activities to obscure the source of funds.
j. Use of false identities, which are transactions conducted using false identities to make it difficult to trace identities and detect the presence of money laundering perpetrators.
B. Terrorism Financing Crimes
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Unlike TPPU, whose purpose is to disguise the origin of assets, the purpose of Terrorism Financing Crimes (TPPT) is to assist terrorist activities, whether with assets that are proceeds of a crime or with assets obtained legitimately.
To prevent Banks from being used as a means for terrorism financing crimes, Banks need to implement AML and CTF Programs adequately.
Determined in Jakarta on June 22, 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
APPENDIX II
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 32 /SEOJK.03/2017
REGARDING
THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS IN THE BANKING SECTOR
ILLUSTRATION
MONEY LAUNDERING AND/OR TERRORISM FINANCING RISK ASSESSMENT
The risk level of each factor can be assessed using likelihood (probability of risk occurrence) and impact (loss impact experienced by the Bank if the risk occurs) parameters.
LIKELIHOOD X IMPACT = RISK LEVEL
The likelihood scale refers to the potential risk of Money Laundering and/or Terrorism Financing occurring for each specific risk assessed.
The impact scale refers to the severity or damage experienced if the risk likelihood occurs. The impact of Money Laundering and/or Terrorism Financing risks can be viewed from several perspectives, including the impact of loss amounts if the risk occurs on the Bank's business, such as suffering financial losses from crimes or through sanctions imposed by the OJK.
Consequence Impact on Money Laundering and Terrorism Financing Risks
Large impact has a large impact on Money Laundering and Terrorism Financing Risks Medium impact has a medium impact on Money Laundering and Terrorism Financing Risks Small impact has a small impact on Money Laundering and Terrorism Financing Risks
Frequency Likelihood of Money Laundering and/or Terrorism Financing Risks
Frequent occurs more than 1 time in 1 year
Quite frequent occurs 1 time in 1 year
Rare does not occur but does not mean it is impossible to occur
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
A risk matrix is a matrix used to combine the likelihood of risk occurrence and the impact of risk occurrence to obtain a risk value. Subsequently, the Bank can compile a risk value table that can be used to help decision-making and assist in determining actions taken to mitigate overall risk.
Determined in Jakarta on June 22, 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
Money Laundering and Terrorism Financing Risk Impact Level
High 3 Risk is likely to occur and/or causes serious impact Follow-up: transactions cannot be conducted until risk is reduced.
Medium 2 Risk may occur and/or has considerable impact on the Bank Follow-up: transactions can be conducted simultaneously with risk reduction.
Low 1 Small likelihood of risk occurrence and/or has minimum impact.
Follow-up: transactions can be conducted.
LIKELIHOOD
Frequent Medium 2 High 3 High 3
Quite frequent 1 Medium 2 High 3
Rare 1 1 Medium 2
Small Medium Large
IMPACT
APPENDIX IV
FINANCIAL SERVICES AUTHORITY CIRCULAR
NUMBER 32 /SEOJK.03/2017
REGARDING
THE IMPLEMENTATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS IN THE BANKING SECTOR
DATA UPDATE PLAN REPORT
(BANK NAME)
YEAR ...
No.
Customer Type and Risk Level
Number of CIFs
Information to be Updated
Method or Strategy
Percentage of Updated CIFs Fulfilled
CIFs to be Updated
% of Total CIFs
(a) (b) (c) (d) (e) (f) (g)
1 Individual Customers a. High Risk b. Medium Risk
c. Low Risk
2 Corporate Customers a. Non-micro and small enterprises
3 State Institutions, Government Agencies, International Institutions, and Foreign Diplomatic Missions a. High Risk b. Medium Risk
c. Low Risk
4 Cross Border Correspondent Banking a. High Risk b. Medium Risk
c. Low Risk
REALIZATION REPORT OF THE DATA UPDATE PLAN
(BANK NAME)
YEAR.....
No.
Customer Type and Risk Level
Development
Obstacles
Efforts to be taken
Target
Realization
Deviation (%)
(a) (b) (c) (d) (e) (f) (g)
1 Individual Customers a. High Risk b. Medium Risk
c. Low Risk
2 Corporate Customers a. Micro and Small Enterprises
No.
Customer Type and Risk Level
Development
Obstacles
Efforts to be taken
Target
Realization
Deviation (%)
(a) (b) (c) (d) (e) (f) (g)
2) Medium Risk
3) Low Risk
e. Other than companies and foundations (with legal entity status or without legal entity status)
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana
Established in Jakarta on 22 June 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
APPENDIX III
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY NUMBER 32 /SEOJK.03/2017 REGARDING THE APPLICATION OF ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING PROGRAMS IN THE BANKING SECTOR
EXAMPLES OF
UNUSUAL TRANSACTIONS, ACTIVITIES, AND BEHAVIORS (RED FLAGS)
This copy is consistent with the original
Legal Director 1
Legal Department signed
Yuliana b. Transaction patterns inconsistent with the Customer profile, which initially met the criteria for simplified CDD treatment when establishing a business relationship with the Bank.
c. Customer indicated to be involved in Terrorism Financing activities.
d. Customer indicated to be attempting bribery to influence officials or Bank employees. e. Customers intentionally providing false information as an attempt to obtain simplified CDD treatment.
14. Transactions Related to the Rehabilitation Process of Name Inclusion in the National Blacklist
In the rehabilitation process, Customers settle transactions previously rejected because they did not meet the requirements established in regulations governing the payment system. Settlement is conducted by making several cash transactions on the same day in significant amounts without clear underlying reasons.
Established in Jakarta on 22 June 2017
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY, signed
NELSON TAMPUBOLON
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works