2023-09-05
Added · Updated
This instruction establishes application measures for credit institutions and financial companies in the Democratic Republic of Congo to manage money laundering, terrorist financing, and proliferation financing risks through a risk-based approach. It mandates comprehensive customer identification and verification procedures, including specific thresholds for occasional transactions and enhanced due diligence for politically exposed persons. The document requires entities to implement internal controls, risk mapping, and prior approval processes for new products or technologies by compliance and risk management officers.
BANQUE CENTRALE DU CONGO
THE GOVERNOR
INSTRUCTION NO. 15 TO CREDIT INSTITUTIONS AND FINANCIAL COMPANIES CARRYING STANDARDS RELATING TO THE COMBAT AGAINST MONEY LAUNDERING AND THE FINANCING OF TERRORISM AND THE PROLIFERATION OF MASS DESTRUCTION WEAPONS
(Modification No. 3)
The Central Bank of Congo,
Having regard to the Organic Law No. 18/027 of December 13, 2018, on the organization and functioning of the Central Bank of Congo, particularly Articles 10 and 43;
Having regard to Law No. 22/068 of December 27, 2022, on the fight against money laundering and the financing of terrorism and the proliferation of weapons of mass destruction, particularly Title III;
Having regard to Law No. 22/069 of December 27, 2022, on the activity and supervision of Credit Institutions;
Having regard to Ordinance-Law No. 23/010 of March 13, 2023, on the Digital Code, particularly Articles 171 to 182.
Decrees the following provisions in matters of combating money laundering and the financing of terrorism and proliferation:
TITLE I: GENERAL PROVISIONS
CHAPTER 1: OBJECT
Article 1:
The purpose of this Instruction is to specify the implementation measures in the field of combating money laundering and the financing of terrorism and the proliferation of weapons of mass destruction for the establishments subject to Article 3 below.
Article 2:
The provisions of this Instruction are based on a risk-based approach, allowing subject entities to ensure that measures aimed at preventing or mitigating the risk of money laundering and the financing of terrorism and the proliferation of weapons of mass destruction are proportionate to the identified risks and lead to decisions on how to efficiently and effectively allocate their own resources.
MCM
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 2
CHAPTER 2: SCOPE OF APPLICATION
Article 3:
This Instruction applies to the credit institutions and financial companies listed below, hereinafter referred to as "subject establishments" or "subject entities":
(i) credit institutions:
(ii) financial companies:
Article 4:
In addition to the credit institutions and financial companies mentioned in Article 3, all other structures authorized by the Central Bank of Congo, whose nature of activities requires the implementation of measures to combat money laundering and the financing of terrorism and the proliferation of weapons of mass destruction, are also subject to this Instruction.
CHAPTER 3: DEFINITIONS
Article 5:
For the purposes of this Instruction, the following terms are understood as:
MCM
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 3
the conversion, transfer, or manipulation of assets by any person who knows that these assets originate from criminal activity or participation in criminal activity, with the aim of concealing or disguising the illicit origin of said assets or helping any person involved in the commission of the offense to escape the legal consequences of their acts;
the concealment or disguise of the nature, origin, location, disposition, movement, or true ownership of assets or rights related thereto, by any person who knows that these assets originate from criminal activity or participation in criminal activity;
the acquisition, possession, or use of assets by a person who knows, suspects, or should have known that said assets originate from criminal activity or participation in criminal activity;
conspiracy or participation in an association to commit an act constituting money laundering, association to commit said act, attempts to perpetrate it, aid, incitement, or advice to a natural or legal person, with a view to executing or facilitating its execution.
terrorist act:
MCM
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 4
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 5
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 6
k) General Officer or Senior Officer commanding the Armed Forces or the Congolese National Police;
l) Member of an administration, management, or supervisory body of a public or parastatal enterprise;
m) Public agents of the State holding the rank of Director.
For the Foreign Politically Exposed Person:
For the Politically Exposed Person of an international organization:
For family members of a Politically Exposed Person who are assimilated:
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 7
virtual asset service provider: any natural or legal person not covered elsewhere in this Instruction and who, for commercial activity, provides one or more of the following services, for themselves or on behalf of another natural or legal person:
business relationship: an engagement of a professional or commercial relationship that is presumed, at the time the contact is established, to be of a certain duration. The business relationship may be provided for by a contract according to which several successive operations will be carried out between the contracting parties or which creates continuing obligations on their part. A business relationship is also established when, in the absence of such a contract, a client regularly benefits from the intervention of a person subject to this Instruction for the realization of several or a continuous operation.
TITLE II: RISK ASSESSMENT
Article 6:
Subject entities are required to take appropriate and proportionate measures to their nature, size, and volume of activities, to manage their exposure to money laundering, terrorist financing, and proliferation of weapons of mass destruction risks in their respective sectors of activity.
They put in place processes to identify, assess, monitor, manage, and mitigate money laundering and terrorist financing and proliferation risks. They take enhanced measures to manage and mitigate these risks when they prove to be higher. Conversely, when risks are lower, they are authorized to implement simplified measures, except in cases of suspicion of money laundering or terrorist financing.
In this framework, subject entities develop their money laundering, terrorist financing, and proliferation risk maps according to a risk-based approach and taking into account the principle of proportionality.
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 8
Article 7:
Subject entities put in place a device to assess the risks resulting from the implementation of new products and new commercial practices, including new distribution mechanisms and the use of new technologies related to new products or those pre-existing.
These assessments intervene before:
Article 8:
The Heads of compliance and risk management functions put in place in accordance with the relevant provisions of Instructions 18 and 53 in force of the Central Bank of Congo relating to the conditions for the approval of Credit Institutions and Financial Companies, their managers, and Auditors as well as the modification of their statutory situations, are required to give their prior opinions before the implementation of any process mentioned in Article 7 of this Instruction.
TITLE III: DUE DILIGENCE AND SUPERVISION OBLIGATIONS
Article 9:
Subject entities are required to put in place a due diligence device on financial operations carried out by their clients. This due diligence requires:
Subject entities are required, for the entire duration of the business relationship, to collect, analyze, and update information elements that allow maintaining appropriate and updated knowledge of their clients.
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 9
CHAPTER 1: CUSTOMER IDENTIFICATION
Article 10:
Subject entities put in place an effective due diligence procedure to identify completely and verify the identity of the client before entering into a business relationship.
This procedure is carried out for the purpose of ensuring the identity, address, and, where applicable, the beneficial owners of legal persons or legal structures in the following cases:
Article 11:
Subject entities are required to verify that client representatives are legally authorized to act on behalf and for the account of the clients.
They are required to identify and verify also the identification elements of client legal and natural persons or other legal entities with reliable and independent information sources.
563, Colonel Tshatshi Boulevard - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
BANQUE CENTRALE DU CONGO CONTINUATION, PAGE 10
Article 12:
When it comes to the identification of a client or an intermediary natural person, they will be required to present the national identity card or any other officially admitted document in force in the Democratic Republic of Congo.
The verification of the identity of a natural person or their legal representative requires the possession of an original official document in force and issued by the competent authority and bearing a photograph of which a copy is taken, as well as, where applicable, the power of representation.
The verification of their address is carried out by presenting a document capable of proving it.
Article 13:
The document provided for client identification must contain legible information and a clear photograph showing the last name, middle name, and first name, date and place of birth, as well as the address of their home or residence, the dates and places of issue of the documents as well as the names and capacity of the Authority or person who issued the document and, if applicable, the authenticator.
When the natural person exercises a professional activity, they must additionally provide all documents attesting that they are authorized to practice in the relevant sector.
Article 14:
Without prejudice to the Interministerial Decree of the Ministers having respectively the Interior and Justice in their attributions, which determines the documents that can serve for this identification, in accordance with Article 31 paragraph 5 of the law, the identification and verification of the identity of natural persons are carried out by means of one of the following valid probative documents:
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 11
Article 15:
The regulated entities are required to verify the information obtained during identification with reliable and independent information sources before entering into a business relationship with the client.
By derogation from the previous paragraph, when the risk of money laundering, terrorism financing, and proliferation is assessed as low, the verification of the client's identity and, if applicable, the beneficial owner's identity may be carried out after entering into the business relationship.
Article 16:
The regulated entities are required to ensure that client representatives are legally authorized to act on behalf of and for the account of the clients.
They identify and verify the identity elements of these representatives under the same conditions as the clients and verify these elements with reliable and independent information sources.
Article 17:
The regulated entities identify and verify the identity of the client, legal person, using the following information:
a) the statutes and any document establishing that it has been legally constituted and has a real existence at the time of identification, any official act or register recording its name, its legal form. b) the powers that govern and bind the legal person (statutes), the powers of persons acting on its behalf, the determination of the source of funds and the identification of their beneficiaries as well as the persons who control these funds; c) the address of the registered office or that of one of the main activity centers, if it is different from the address of the registered office.
This obligation also applies to companies whose capital consists of bearer shares or held by proxies.
The regulated entities are required to identify and verify the identity of clients who are or act on behalf of a legal person or a legal structure.
The regulated entities are required to implement effective verification mechanisms to collect and obtain all necessary information on the business relationship with its client.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 12
They must also understand the nature of the activity of legal persons or legal structures as well as their ownership and control structures. To this end, they proceed to the verification of persons exercising management functions within legal persons or legal structures.
Article 18:
The regulated entities are required to identify the beneficial owner on each operation carried out and on the business relationship.
Without prejudice to the identification of the beneficial owner with reliable and independent information sources that can guarantee the regulated entity to know their identity, the latter verifies the identity elements of the beneficial owner upon presentation of any probative written document.
In case of doubt regarding the identity of the beneficial owner or as soon as no natural person exercises control through a participation, the regulated entities identify the natural persons, if they exist, who exercise control over the legal person or the legal structure by other means.
When no natural person is identified after the implementation of the measures in the paragraphs above, the regulated entities identify the relevant natural person who holds the position of senior managing official.
The regulated entities identify the beneficial owners of legal structures and take reasonable measures to verify the identity of these persons, using the following information:
a) for trusts: the identity of the trust settlor, the trustee(s), if applicable, the protector, the beneficiaries or the category of beneficiaries and any other natural person exercising ultimate effective control over the trust including through a control/ownership chain;
b) for other types of legal structures: the identity of persons occupying equivalent or similar positions.
Article 19:
The opening by regulated entities of anonymous accounts or under false names or pseudonyms is prohibited. They are also forbidden from holding or maintaining anonymous accounts or accounts under manifestly fictitious names. They are required to close without delay any account on which clients demanding anonymity or presenting themselves under a false name appear.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 13
Article 20:
In the event that the client is a professional bound by secrecy and acting as an intermediary, they cannot invoke professional secrecy to refuse to communicate the identity of the beneficial owner.
When the regulated entities consider that the identity of their clients and the identification elements previously obtained are incomplete or not accurate, they proceed to update the file with new information on the client.
Article 21:
The regulated entities are required, for clients who are legal persons, to identify and take reasonable measures to verify the identity of the beneficial owners using the following information:
Article 22:
The regulated entities are required, for clients who are legal structures, to identify the beneficial owners and take reasonable measures to verify the identity of these persons using the following information:
Article 23:
The regulated entities are required, in accordance with the legislation in force on digital matters in the Democratic Republic of Congo, to set up an electronic identification device consisting of using data from the identity of a natural or legal person by electronic processes that uniquely represent the natural or legal person requesting the entry into a business relationship.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 14
Article 24:
The regulated entities are required to inquire by all means about the identity of the persons on whose behalf they act.
When doubts persist regarding the identity of the beneficial owner after having carried out the verification, the regulated entities are required to trigger the suspicious transaction reporting procedure in accordance with Article 92 of Law No. 22/068 of December 27, 2022 on the fight against money laundering and terrorism financing and the proliferation of weapons of mass destruction.
Article 25:
For any account opening operation or remote operation, the regulated entities must ensure that they put in place adapted measures to guarantee the identification of the clientele.
These measures may notably provide for the authentication of identification documents presented, the request for additional documents, the possibility of an independent verification of the client's situation by a third party of confirmed reputation, the requirement of a first payment through an account opened in the client's name with a bank subject to international standards on the fight against money laundering and terrorism financing and proliferation or a letter with acknowledgment of receipt at the client's address.
Article 26:
The regulated entities may resort to third parties to ensure the identification of some of their clients. In all cases, they retain responsibility for the identification of their clientele. To this end, the regulated entities must:
Article 27:
In order to maintain complete knowledge of their client, the regulated entities, depending on the identified risks and the mitigation measures applied to manage these risks, collect and proceed to a periodic review of the data related
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 15
to the identification of the clientele during the entire duration of a business relationship and the confidentiality preservation measures for clients and their transactions must not prevent them from submitting these clients and their transactions to an examination and surveillance as rigorous as those usually implemented.
The regulated entities apply due diligence measures towards existing clients and implement due diligence measures related to these existing relationships in a timely manner, taking into account the existence of previous due diligence measures.
Article 28:
The regulated entities are required to profile the money laundering and terrorism financing and proliferation risk of their clients based on the information obtained during identification. This profiling is subject to a semi-annual evaluation.
Article 29:
The regulated entities are required to make copies of all the above documents that served in the client identification process, both for legal persons and natural persons.
CHAPTER II: ON THE CONSTANT AND PARTICULAR SURVEILLANCE OF OPERATIONS
Article 30:
The regulated entities exercise constant vigilance in the treatment of transactions and regarding the business relationship, notably by:
i. exercising permanent vigilance regarding any business relationship and carefully examining the operations carried out to ensure that they are consistent with what they know about their clients, their commercial activities, their risk profile and, if applicable, the source of their funds; ii. collecting, updating and analyzing, during the entire duration of the business relationship, the information elements, among those listed for this purpose by the Central Bank of the Congo, which allow maintaining appropriate knowledge of their client. The collection and conservation of these information must be carried out in accordance with the objectives of assessing the risk of money laundering and terrorism financing and proliferation, and surveillance adapted to this risk.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 16
To this end, they must ensure that the operations and assets entrusted to them by the persons with whom they maintain a business relationship are related to their economic activities and their assets.
The vigilance that the regulated entities must exercise on the activities of their clients requires from the latter a good understanding and mastery of the movements carried out on the different accounts of each client in order to identify atypical transactions.
Article 31:
The regulated entities put in place a system allowing to detect on all accounts, atypical transactions based on criteria that take into account the risks incurred.
The surveillance device must be adapted to the level of risk incurred. The regulated entities are required to implement risk management systems and enhanced due diligence measures if the risks of money laundering, terrorism financing, and proliferation are higher.
Article 32:
The regulated entities define clear policies and procedures for the acceptance of new clients including notably the description of the different types of clients likely to represent for them a risk higher than average.
These different types of clients must be distinguished taking into account the nature and importance of the risk incurred of money laundering and terrorism financing and the proliferation of weapons of mass destruction.
Article 33:
The regulated entities may exploit factors such as the clients' antecedents, countries of origin or residence, origin of their funds, links between accounts, types of transactions they carry out on their bank accounts or their professional activities.
The admission of any new client requires approval at the appropriate hierarchical level depending on the risk incurred of money laundering and terrorism financing and the proliferation of weapons of mass destruction.
Article 34:
The regulated entities specify in writing to their employees, the appropriate criteria allowing them to determine the operations requiring particular attention, the diligence to be carried out regarding these last ones as well as the procedure required in order to transmit, within regulated deadlines, the
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 17
written reports to the Head of the prevention of money laundering, terrorism financing and the proliferation of weapons of mass destruction.
In case of urgency, an oral declaration may precede the transmission of the aforementioned written report.
Article 35:
The policies and procedures in force in a regulated establishment must effectively protect its employees against any threat or sanction that would follow the written or oral transmission of information stating suspicion of money laundering and terrorism financing and the proliferation of weapons of mass destruction.
The examination of operations notably includes that of their economic justification and their apparent legitimacy.
Article 36:
The surveillance system must:
Article 37:
When a regulated entity cannot fulfill its due diligence obligation towards a counterparty, it cannot establish or maintain a business relationship with the latter.
Regarding the elements not allowing the regulated entity to carry out the diligence related to its due diligence obligation, the latter can proceed to a suspicious transaction declaration to CENAREF in accordance with the legislation in force on the fight against money laundering and terrorism financing and the proliferation of weapons of mass destruction.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 18
Article 38:
The due diligence that the regulated entities must observe by virtue of this Instruction also applies to financial operations carried out for the account of their natural or legal person clients. These clients are notably notaries, lawyers, accountants, companies that carry out as a habitual profession the intermediation, advice and assistance in matters of wealth management.
Article 39:
The regulated entities must exercise enhanced vigilance regarding operations executed by persons whose mail is domiciled with a third party, in a post office box, at the counters of a credit establishment or who change address frequently.
Article 40:
In the event that the regulated entities suspect that an operation relates to money laundering or terrorism financing and consider that by fulfilling their due diligence obligation, they would alert the concerned client, they can choose not to pursue the process of implementing due diligence measures and to address without delay a suspicious operation declaration to CENAREF.
Article 41:
The regulated entities must be equipped with adequate risk management systems to determine if a potential client, a client or a beneficial owner is a politically exposed person upon entry into the business relationship or during the business relationship and implement specific measures. They inquire to identify the origin of the wealth and the origin of the funds of clients and beneficial owners who are politically exposed persons.
Due diligence measures must be reinforced vis-à-vis politically exposed persons, particularly those holding prominent public functions at the national level.
Article 42:
All regulated entities must be equipped with risk management systems allowing to identify all operations carried out by their group with a client.
The regulated entities are required, if the regulation requires it, to freeze all assets held by the same person in their books.
Article 43:
The regulated entities are required, prior to any operation with a correspondent bank located abroad, to take adequate measures to gather
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF THE CONGO CONTINUATION, PAGE 19
sufficient information about this correspondent bank to well understand the nature of its activities and to evaluate, based on publicly available information, the reputation of the institution and the quality of the supervision, including verifying if the concerned institution has been the subject of an investigation or intervention by the supervisory authority regarding money laundering, terrorism financing and the proliferation of weapons of mass destruction.
They also evaluate the controls put in place by the correspondent bank on the plan of the fight against money laundering and terrorism financing and the proliferation of weapons of mass destruction and specify in writing the respective responsibilities of each institution.
Article 44:
The approval of the Compliance Officer and that of the Head of the fight against money laundering and terrorism financing and the proliferation of weapons of mass destruction is required before establishing new correspondent banking relationships.
The regulated entities must not establish or pursue correspondent banking relationships with so-called fictitious banks that are constituted and approved in countries and territories where they are not subject to any effective supervision on a consolidated basis regarding money laundering, terrorism financing and the proliferation of weapons of mass destruction.
Article 45:
The regulated entities obtain and conserve the information relating to the ordering client, client in their books, of an electronic transfer and verify the accuracy of all this information in the message or payment form accompanying an electronic transfer.
Article 46:
Subject entities, constituted as parent companies at the level of the Democratic Republic of Congo, must put in place policies and procedures ensuring that their subsidiaries and branches are effectively protected against the risks of operations used for the purposes of money laundering, terrorist financing, and the proliferation of weapons of mass destruction.
These policies and procedures are specific to each entity according to the country of establishment, the nature of activities carried out, etc.... They include provisions allowing communication to the headquarters of the information necessary for the effective prevention of money laundering, terrorist financing, and the proliferation of weapons of mass destruction throughout the group.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd
CENTRAL BANK OF CONGO CONTINUED, PAGE 20
Article 47:
Subject entities having subsidiaries or branches established in offshore zones or in countries that do not have regulations on the prevention of money laundering, terrorist financing, and the proliferation of weapons of mass destruction at least equivalent to that applicable in the Democratic Republic of Congo or whose regulations are not effectively implemented, must ensure that these entities are equipped with a vigilance device at least as strict as that provided for by this Instruction.
Branches and subsidiaries established abroad communicate to their registered office the provisions of the host country that oppose the implementation of all or part of the recommendations formulated by the headquarters. The latter informs CENAREF and the competent supervisory authority.
TITLE IV: ON THE PRESERVATION AND COMMUNICATION OF PIECES AND DOCUMENTS
Article 48:
Without prejudice to provisions prescribing more stringent obligations, subject entities to this Instruction are required to retain for a period of ten (10) years from the closing of their accounts or the cessation of their relations with their usual or occasional clients, their beneficial owners or their economic beneficiaries:
They also retain all pieces and documents relating to the operations they have carried out and the report on the examination of enhanced due diligence referred to in Title V of this Instruction for 10 years, after the execution of the operation. The same applies to the keeping of necessary registers on transactions both national and international.
Article 49:
When the transfer is carried out electronically, the subject entity is required to retain for a period of at least five (5) years, the information of the financial institution of the ordering party or the other intermediate financial establishment to the extent that certain technical restrictions prevent the information required on the ordering party or the beneficiary accompanying a cross-border transfer from remaining attached during a corresponding national electronic transfer.
563, Boulevard Colonel Tshatshi - Kinshasa – Gombe Email: sgouverneur@bcc.cd - Website: http://www.bcc.cd