2009-03-31 | Texto Completo y Refundido de la Norma PLD/FT y sus ReformasAdded · Updated
This document establishes the regulatory framework for the prevention of money laundering, asset laundering, and terrorist financing (PLD/FT) for banks, financial institutions, insurance companies, securities market participants, and general warehouse operators in Nicaragua. It mandates the implementation of a Comprehensive Prevention and Risk Management System (SIPAR LD/FT), including specific policies for customer due diligence, employee knowledge, and correspondent relationships. The regulation defines risk assessment matrices, monitoring procedures, suspicious transaction reporting obligations, and the administrative structure for compliance, including the appointment of a Prevention Administrator and independent audit requirements.
Get SIBOIF alerts — same-day email on every new publication.
April, 2009
Managua, Nicaragua
RESOLUTION NO. CD-SIBOIF-524-1-MAR5-2008............................................................................................7
CONSIDERING..................................................................................................................................................7
TITLE I ................................................................................................................................................................9
GENERAL PROVISIONS............................................................................................................................9
SINGLE CHAPTER...............................................................................................................9
SCOPE, OBJECTIVE AND CONCEPTS ................................................................................9
Art. 1.- Scope ..................................................................................................................9
Art. 2.- Objective ..............................................................................................................9
Art. 3.- General Concepts ............................................................................................10
TITLE II .............................................................................................................................................................10
PROVISIONS APPLICABLE TO BANKS AND FINANCIAL INSTITUTIONS................................................................10
CHAPTER I........................................................................................................................10
PREVENTION PROGRAM AND RESPONSIBILITY.............................................10
Art. 4.- Prevention Program or Comprehensive System of Prevention and Administration of Risks of Money Laundering, Assets or Goods; and Terrorist Financing
(SIPAR LD/FT)................................................................................................................10
Art. 5.- Institutional Responsibility..............................................................................12
Art. 6.- Responsibility of the Board of Directors.................................................................12
Art. 7.- Integration of the SIPAR LD/FT.............................................................................15
CHAPTER II.......................................................................................................................17
POLICY OF "DUE DILIGENCE FOR CUSTOMER KNOWLEDGE"
(CDD)...................................................................................................................................17
Art. 8.- CDD Policy........................................................................................................17
Art. 9.- Identification .......................................................................................................19
Art. 10.- Required Documents....................................................................................20
Art. 11.- Verification .......................................................................................................23
Art. 12.- Customer Comprehensive Profile (CCP).........................................................................26
Art. 13.- Customer File.......................................................................................30
Art. 14.- Standard CDD....................................................................................................31
Art. 15.- Enhanced CDD .............................................................................................31
Art. 16.- Measures of Enhanced CDD..........................................................................35
Art. 17.- Simplified CDD .............................................................................................37
CHAPTER III .....................................................................................................................38
COMPLEMENTARY KNOWLEDGE POLICIES...........................................38
Art. 19.- Policy "Know Your Employee"...................................................................38
Art. 20.- Policy "Know Your Correspondent Relationships" ....................................38
Art. 21.- Policy "Know Your Electronic Fund Transfers"......................39
Art. 22.- Policy "Know Your Buyers of Consignment Instruments".....40
Art. 23.- Policy "Know Your Suppliers" .............................................................41
CHAPTER IV .....................................................................................................................41
MATRICES FOR PLD/FT RISK ASSESSMENT...............................................41
Art. 24.- PLD/FT Risk Matrices...............................................................................41
Art. 25.- New Technologies, Products and Services......................................................42
CHAPTER V ......................................................................................................................42
MONITORING AND REPORTS .............................................................................................42
Art. 26.- Monitoring, Detection and Security ....................................................................42
Art. 27.- Alert Signals and Indicators .......................................................................43
Art. 28.- Determination of suspicion and obligation to present Suspicious Transaction Report
(STR)............................................................................................................44
Art. 29.- Special measures for the secure and confidential structuring, handling and
presentation of an STR ...................................................................................................45
Art. 30.- Monitoring and Detection of Cash Transactions above the determined
threshold ......................................................................................................................46
Art. 31.- Obligation to Report Cash Transactions above the determined
threshold (CTR)...........................................................................................................47
Art. 32.- CTR Exceptions.........................................................................................47
Art. 33.- Cash Transaction that also qualifies for an STR ............................48
CHAPTER VI .....................................................................................................................48
ARCHIVING AND PRESERVATION OF INFORMATION ....................................................48
Art. 34.- Custody of Information and Supporting Documents........................................48
Art. 35.- Availability of information and supporting documentation ..........................49
Art. 36.- Updating and extraction of information .......................................................49
CHAPTER VII....................................................................................................................50
IMPLEMENTATION AND CONTROL OF THE SIPAR LD/FT .................................................50
Art. 37.- Implementation and control function ...............................................................50
Art. 38.- PLD/FT Prevention Committee............................................................................50
Art. 39.- Integration of the PLD/FT Prevention Committee...................................................50
Art. 40.- Functions of the PLD/FT Prevention Committee ..........................................................51
Art. 41.- PLD/FT Risk Prevention Administrator ........................................55
Art. 42.- Appointment ...................................................................................................55
Art. 43.- Characteristics of the position ....................................................................................56
Art. 44.- Financial Group Case .................................................................................56
Art. 45.- Objection.............................................................................................................57
Art. 46.- Support Administrative Structure .................................................................57
Art. 47.- Professional Profile of the PLD/FT Prevention Administrator .............................57
Art. 48.- Incompatibilities.............................................................................................57
Art. 49.- Temporary or interim substitution..........................................................................58
Art. 50.- Removal...........................................................................................................58
Art. 51.- Functions of the PLD/FT Prevention Administrator.........................................59
CHAPTER VIII ..................................................................................................................62
PLD/FT PREVENTION TRAINING ...................................................................62
Art. 52.- PLD/FT Training Program ..............................................................62
Art. 53.- Minimum Elements of the Program.....................................................................62
Art. 54.- Statistics and Records on Training......................................................64
CHAPTER IX .....................................................................................................................64
INSTITUTIONAL CODE OF CONDUCT .................................................................64
Art. 55.- Incorporation of the SIPAR LD/FT topic..............................................................64
Art. 56.- Minimum PLD/FT Aspects of the Code of Conduct .........................................65
CHAPTER X ......................................................................................................................65
INDEPENDENT AUDIT ON THE SIPAR LD/FT ...........................................65
Art. 57.- Independent Audit ....................................................................................65
Art. 58.- Minimum Audit Functions.......................................................................65
TITLE III............................................................................................................................................................69
PARTICULAR AND EXCEPTION PROVISIONS..................................................................................69
CHAPTER I........................................................................................................................69
FINANCIAL GROUPS AND CONSOLIDATED PLD/FT RISK MANAGEMENT .............69
Art. 59.- PLD/FT Risk Management.................................................................................69
Art. 60.- Internal Audit of the Controlling Company .................................................70
Art. 61.- Consolidated External Audit of the Financial Group .........................................70
CHAPTER II.......................................................................................................................70
INSURANCE MARKET ................................................................................................70
Art. 62.- Applicability of the PLD/FT Norm in the Insurance Market........................70
Art. 63.- Exceptions and Particularities .........................................................................71
Art. 64.- Subsequent Identification and Verification..............................................................72
Art. 65.- Enhanced CDD .............................................................................................73
Art. 66.- Simplified CDD .............................................................................................73
Art. 67.- Relationship of the Insurance and/or Reinsurance Company with Insurance
intermediaries. .......................................................................................................................73
CHAPTER III .....................................................................................................................74
SECURITIES MARKET ................................................................................................74
Art. 68.- Applicability of the PLD/FT Norm in the Securities Market ........................74
Art. 69.- Exceptions and Particularities .........................................................................75
Art. 70.- Operation Control .....................................................................................76
CHAPTER IV .....................................................................................................................76
GENERAL WAREHOUSE MARKET .......................................76
Art. 71.- Applicability of the PLD/FT Norm in the General Warehouse Market....................................76
Art. 72.- Exceptions and Particularities .........................................................................76
CHAPTER V ......................................................................................................................77
REPRESENTATIVE OFFICES AND "SECOND-TIER" BANKS....................77
Art. 73.- Applicability of the Norm to Representative Offices............................77
Art. 74.- Application of the SIPAR LD/FT regarding its jurisdiction of origin..................78
Art. 75.- Enhanced CDD .............................................................................................78
Art. 76.- Exceptions and Particularities .........................................................................78
Art. 77. – "Second-Tier" Banks..............................................................................78
CHAPTER VI .....................................................................................................................79
SPECIAL REGIME FINANCIAL COMPANIES.................................................79
Art. 78.- Companies under Consolidated Supervision..............................................................79
Art. 79.- Exceptions .......................................................................................................79
TITLE IV............................................................................................................................................................79
TRANSITORY AND FINAL PROVISIONS...............................................................................................79
SINGLE CHAPTER.............................................................................................................79
Art. 80.- Modification and/or Inclusion of Annexes..............................................................79
Art. 81.- Graduality for the application of some particular provisions of the
present Norm.................................................................................................................80
Art. 82.- Repeals .....................................................................................................80
Art. 83.- Validity.............................................................................................................81
ANNEXES...............................................................................................................................................................82
ANNEX 1: GENERAL CONCEPTS FOR THE APPLICATION OF THE PLD/FT NORM ..................83
ANNEX 2: FORMATS FOR THE CUSTOMER COMPREHENSIVE PROFILE (CCP) .........................................87
i.- Banking and Financial Market............................................................................87
ii.- Insurance Market .................................................................................................99
iii.- Securities Market................................................................................................103
iv.- General Warehouse Market .....................................................108
ANNEX 3: ALERT SIGNALS AND INDICATORS..............................................................................113
I.- Common to all Supervised Entities................................................................113
II.- Specific to the Banking and Financial Market ..................................................120
III.- Specific to the Insurance Market ......................................................................133
IV.- Specific to the Securities Market ......................................................................136
V.- Specific to the General Warehouse Market Market.............................138
ANNEX 4: INSTRUCTIONS AND FORMAT FOR THE PRESENTATION OF THE
SUSPICIOUS TRANSACTION REPORT (STR)..........................................................................................................140
I.- Instructions for the presentation and submission of the Suspicious Transaction Report
(STR): ................................................................................................................................140
II.- Format for the presentation of the Suspicious Transaction Report (STR)..........142
ANNEX 5: MANUAL AND FORMAT FOR THE AUTOMATED PRESENTATION OF CASH TRANSACTION REPORTS
(CTR) ........................................................................................................................145
i.- Conceptual aspects (Data Flow).........................................................................145
ii.- Types of submissions .............................................................................................................146
ii.1 Submissions from Financial Institutions to the SIBOIF ...............................................146
ii.2 Format of the files ...........................................................................................146
ii.3 Submissions from the SIBOIF to Supervised Entities .................................................147
iii.- File formats according to submission type...................................................................148
iii.1: General Money Laundering Prevention Data (PLdD_Datos) .......................148
iii.2: Persons (PLdD_Persona) .....................................................................................149
iii.3: Data versus Persons Relationship (PLdD_Datos_Persona) .....................................150
iv.- SIBOIF response files ..........................................................................151
iv.1: Incidents..............................................................................................................151
iv.2: Statistics.............................................................................................................152
v.- Annex catalogs...........................................................................................................152
v.1: General catalogs.................................................................................................152
Id_ reporting_entity.................................................................................................159
v.2: Validation Catalog........................................................................................160
vi- User Manual for the upload of the Cash Transaction Report (CTR)....160
vi.1 Introduction.............................................................................................................160
vi.2 General Description of the System ............................................................................160
vi.2.1 System Structuring ...................................................................................161
vii.- Formats with their Instructions.....................................................................................169
vii.1: Exchange of GNUPG public keys ..........................................................169
vii.2 Request for additions, deletions and changes of access accounts.......................................174
viii.- GNUPG Manual...................................................................................................178
viii.1 Introduction ..........................................................................................................178
viii.2 Generation of keys .......................................................................................179
viii.3 Encrypt files .......................................................................................................181
viii.4 Decrypt files..................................................................................................181
viii.5 Generate the public key ........................................................................................182
viii.6 Importing a public key to your keyring ............................................................182
RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 of date March 5, 2008 STANDARD FOR THE MANAGEMENT OF PREVENTION OF THE RISKS OF MONEY LAUNDERING, GOODS OR ASSETS; AND OF TERRORIST FINANCING
The Board of Directors of the Superintendence of Banks and Other Financial Institutions decides to approve and issue the Standard for the Management of Prevention of the Risks of Money Laundering, Goods or Assets; and of Terrorist Financing, in accordance with the following considerations, legal basis, and content:
CONSIDERING
I
That the Political Constitution of the Republic of Nicaragua, in its articles 24 and 99, establishes as one of its guarantee pillars the just requirements of the common good above particular or individual interests, which, translated into economic-financial management, translates into the promotion of a responsible and healthy development of the Financial System as an activity qualified as being of public interest in the Laws governing it by mandate of the Constitution itself, and from whose legal basis emanated the Standard for the Prevention of Money Laundering and Other Assets in 2002 and the Standard on Compliance Officers in 2006, approved by this Board of Directors in the exercise of its inalienable power to issue standards expressly attributed to it by article 10 of Law No. 316: “Law of the Superintendence of Banks and Other Financial Institutions” and for the specific topic in articles 28 (second paragraph) and 36 (second paragraph) of Law No. 285: “Law of Narcotics, Psychotropics and Other Controlled Substances; Money Laundering and Assets Proceeding from Illicit Activities.”
II
That it is necessary to issue a new and updated Standard that integrates the previous ones and that, with a risk-based approach, seeks to adjust to legislative developments and trends, to the conventions and agreements that Nicaragua is a signatory to, to experiences and alert indicators, to guidelines, principles, recommendations, standards, and international best practices, and adapted to the local reality of the different sectors that make up our supervised Financial System; promoting greater effectiveness in the prevention and detection of cross-border risks of Money Laundering, Goods or Assets; and of Terrorist Financing, and consequently also on the legal, operational, and reputational risks that these entail.
III
That by its very nature, the Financial System faces various risks of internal and external origin, and in this context each Supervised Entity, considering that regardless of its size and its particular business specificity, will always be exposed to being used for Money Laundering, Goods or Assets and/or for Terrorist Financing; must, therefore, strengthen its permanent prevention and administration of these transnational risks through permanent review and improvement of its programs, measures, procedures, policies, and internal controls.
IV
That it is necessary to highlight that the mechanisms for the administration of Money Laundering, Goods or Assets; and Terrorist Financing risks, are specially directed to control and mitigate them, and respond to the need to prevent, detect, and report them timely, efficiently, and effectively; and this is only possible if the Supervised Entity truly knows the usual and reasonable financial activities of its clients. Therefore, this special prevention task differs substantially from the mechanisms for the administration of other typical financial risks and/or general compliance with laws and regulations applicable to the particular activity within the industry in which the Supervised Entity operates, which are differently directed to be assumed by it wholly or partially based on its profile and profitability versus risk ratio, and covering them through capital contributions in correspondence with the intent or willingness of its partners to assume higher levels of risk.
V
That the measures established in this Standard do not constitute disincentives or obstacles for Supervised Entities in carrying out their financial activity with clients and legitimate capital, but, on the contrary, are technical tools for the safe promotion of business, of an eminently preventive nature and of self-interest, with minimum requirements to be followed; from which it corresponds to each Entity to adjust and strengthen them according to the changing activities of its industry and as part of its corporate responsibility, in order to achieve a sound, prudent, adequate, and efficient management of the prevention of Money Laundering, Goods or Assets; and Terrorist Financing risks, and in this way prevent funds originating from criminal activities or attempting to finance them from being channeled through the Financial System.
THEREFORE
In accordance with the considerations, and in application of the provisions contained in article 36, second paragraph, of Law No. 285: “Law of Narcotics, Psychotropics and Other Controlled Substances; Money Laundering and Assets Proceeding from Illicit Activities” published in La Gaceta, Official Journal, No. 69 of April 15, 1999; in articles 10 (items 1, 3, and 5) and 19 (item 18) of Law No. 316: “Law of the Superintendence of Banks and Other Financial Institutions” published in La Gaceta, Official Journal, No. 16 of October 14, 1999 (reformed by Laws No. 552, 564, and 576); in articles 4 (item 6, literals “c” and “g” and item 7, literal “a”), 113 (item 1), and 164 (second part) of Law No. 561: “General Law of Banks, Non-Banking Financial Institutions, and Financial Groups”, published in La Gaceta, Official Journal, No. 232 of November 30, 2005; and in article 212 of Law No. 587, “Capital Market Law”, published in La Gaceta, Official Journal, No. 222 of November 15, 2006; the Board of Directors of the Superintendence of Banks and Other Financial Institutions, in the exercise of its powers,
RESOLVES:
APPROVE THE FOLLOWING
STANDARD FOR THE MANAGEMENT OF PREVENTION
OF THE RISKS OF MONEY LAUNDERING, GOODS OR ASSETS; AND OF TERRORIST FINANCING
RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008
TITLE I
GENERAL PROVISIONS
SINGLE CHAPTER
SCOPE, OBJECT, AND CONCEPTS
Art. 1.- Scope
The Standard for the Management of Prevention of the Risks of Money Laundering, Goods or Assets; and of Terrorist Financing, hereinafter referred to as the AML/CTF Prevention Standard or simply the AML/CTF Standard; is applicable, with the exceptions and particularities that it expressly establishes; to all Entities that are under the authorization, regulation, supervision, surveillance, and audit of the Superintendence of Banks and Other Financial Institutions, hereinafter Superintendence, and that operate, among others, in the sectors of Banks, Financial Institutions, Insurance, Securities, and General Deposit Warehouses as credit auxiliaries, individually or as members of a Financial Group; all referred to as Supervised Entity (ies) for the purposes of this Standard.
Art. 2.- Object a) This Standard aims to establish the requirements, guidelines, and basic and minimum aspects regarding the measures that Supervised Entities integrating the Nicaraguan Financial System must adopt, implement, update, and improve, under their own initiative and responsibility, in accordance with the nature of the industry and market in which each of them operates and according to the level of risk of their respective structures, clients, businesses, products, services, distribution channels, and jurisdictions in which they operate; to manage, prevent, and mitigate the risk of being used, consciously or unconsciously, locally or cross-border, for Money Laundering, Goods or Assets; and for Terrorist Financing, hereinafter AML/CTF. b) AML/CTF risk is the inherent risk that Supervised Entities have and face permanently by the nature of their business; of being used, consciously or unconsciously, for Money Laundering, Goods or Assets; and for Terrorist Financing; and consequently, they are obligated to develop a sound and prudent management of prevention of said risk.
c) It is the responsibility of each Supervised Entity to make adjustments as necessary, in attention to the nature of their business and the weighting of their own AML/CTF risks as high, medium, or low; or, when legal and/or regulatory changes occur in the matter; in order to develop an adequate, efficient, and effective management of prevention thereof.
Art. 3.- General Concepts
For the purposes of this Standard, a list of general concepts is established in Annex 1, which is an integral part of it.
TITLE II
PROVISIONS APPLICABLE TO BANKS AND FINANCIAL INSTITUTIONS
CHAPTER I
PREVENTION PROGRAM AND RESPONSIBILITY
Art. 4.- Prevention Program or Integral System of Prevention and Administration of Money Laundering, Goods or Assets; and Terrorist Financing Risks (SIPAR AML/CTF) a) Every Supervised Entity, in attention to the industry in which it operates, its own specificity within it, the nature and complexity of its business, financial products, and services, the volume of operations, its geographic presence, the technology used for the provision of its services, in weighting its risks, and in compliance with the specific legal provisions of the matter and general provisions contemplated by this Standard; must formulate, adopt, implement, and develop effectively and efficiently, a Prevention Program or Integral System of Prevention and Administration of Money Laundering, Goods or Assets; and Terrorist Financing Risk, which may also be referred to briefly as SIPAR AML/CTF. b) The SIPAR AML/CTF must include: policies, procedures, and internal controls expressed in their respective Manual of Prevention of Money Laundering, Goods or Assets; and Terrorist Financing Risk, hereinafter AML/CTF Manual; periodically updated risk matrices; monitoring system; and operational plans; all of which must comply and adjust, insofar as applicable, to the national legal framework, including international conventions on the matter of which Nicaragua is a party; as well as, resolutions, instructions, and guidelines of the SIBOIF; codes of conduct, guides, corporate mandates, audit recommendations, evaluations, and periodic self-assessments, among others; that are related to the prevention of Money Laundering, Goods or Assets; and Terrorist Financing risks in the Financial System. International best practices and standards constitute guidelines and references that must be taken into account to strengthen the SIPAR AML/CTF. c) The policies, procedures, internal controls, weightings, criteria, and variables for determining AML/CTF risk levels and its rating matrix must be duly documented.
d) The intensity of the policies, procedures, internal controls, tasks, and measures that each Supervised Entity decides to establish in its SIPAR AML/CTF will be subject to its AML/CTF risk level classified as high, medium, or low in all areas of its business and activities, its clients, and the size of the entity; and are mandatory and strictly complied with by them. The SIPAR AML/CTF of each Supervised Entity is considered an extension of this Standard, and non-compliance will be subject to the same regime of administrative measures provided for in the respective Standards. e) The SIPAR AML/CTF must have an integrative and comprehensive approach, allowing the Supervised Entity to prevent, detect, and report possible suspicious activities of AML/CTF in any of its three stages known internationally: placement, stratification, and integration; based on the four basic administrative tasks of an effective SIPAR AML/CTF:
i.- Prevention: of the risk that resources originating from activities related to AML/CTF are introduced or placed in the Financial System; through policies, procedures, and internal controls for adequate client knowledge, complemented by robust training and staff training at all levels of the entity. ii.- Detection: of activities intended to be carried out or that have been carried out, to stratify, integrate, or give the appearance of legality to operations related to AML/CTF; through the implementation of adequate, timely, and effective monitoring controls and tools. iii.- Reporting: timely, efficient, and effective reporting to the competent authority designated by law, of detected operations intended to be carried out or that have been carried out and that are suspected of being related to AML/CTF. iv.- Retention: for the legal period, of all files, transaction records, and documentation, both physical and electronic, derived from the preceding tasks. f) The Supervised Entity will keep all its directors, officials, and employees generally informed and trained regarding its respective SIPAR AML/CTF; and in a special and focused manner towards those who belong to areas or are in charge of products that according to their profile, need, linkage, and impact are more exposed to these risks. This information and training, general or special as appropriate, must apply to all levels of the Entity. g) The SIPAR AML/CTF must be subject to review and update in accordance with legislative, regulatory, and normative changes in the matter, or due to new and better practices of AML/CTF risk management; as well as in response to new schemes, indicators, signals, and patterns of AML/CTF detected by the Entity itself, or communicated by the SIBOIF or by any other competent authority, or accessible through other recognized national and international sources on the topic. h) When appropriate, Supervised Entities must implement the SIPAR AML/CTF at the level of the Financial Group constituted in Nicaragua, including all its branches, subsidiaries, and representative offices abroad. In this case, if the legal, regulatory, normative, and AML/CTF prevention practices of other countries where any member of the Financial Group operates differ from those established in Nicaragua, the member of said Group must apply the measures that result in the strictest among the different jurisdictions according to international standards; and equally, when in another country the application of the SIPAR AML/CTF is prohibited or prevented, such situation must be communicated without delay to the head office and the Superintendence, and adjusted to local Law.
Art. 5.- Institutional Responsibility a) It is the responsibility of the General Assembly of Partners or Shareholders, Board of Directors, officials, and employees of each Supervised Entity to protect its integrity against AML/CTF risks, in its own interest and that of the Financial System; and to comply with the laws, regulations, and standards on the matter. b) According to the law, Supervised Entities must not have as shareholders, partners, other investors, and representatives, including the beneficiaries of such investments, persons:
i.- Who cannot demonstrate the legitimate origin of the funds to acquire shares, share rights, or equity participations within the Supervised Entity. ii.- Who have been judicially proven to participate in activities related to drug trafficking and related crimes, and to AML/CTF.
Art. 6.- Board of Directors Responsibility
Without prejudice to the institutional responsibilities that the respective laws and standards assign and delimit to the Boards of Directors of Supervised Entities regarding risk management and internal control in general; all members of a Board of Directors must have a vigilant and proactive participation in the implementation and permanent monitoring of the effectiveness and efficiency of the SIPAR AML/CTF. Each Board of Directors is responsible for:
a) Promoting at all levels of the organization and as a component of good Corporate Governance, a culture of compliance with legal and normative requirements in AML/CTF prevention. b) Approve the SIPAR AML/CTF with its respective AML/CTF Manual, which must be autonomous, integral, complete, updated, and identify the legal, normative, and best practice provisions on which it is based; and its Annual AML/CTF Operational Plan, hereinafter referred to as AML/CTF POA; as well as instruct and monitor compliance therewith. c) Keep informed about the progress of the SIPAR AML/CTF, through the respective reports received; and act accordingly. The report recorded in the Board of Directors Minutes must contain at least the following:
i.- What type of report or information was presented.
ii. Position and name of the official presenting it.
iii. What analysis or deliberation was carried out.
iv. What agreements, resolutions, and actions were derived and adopted from its analysis.
v. What follow-up will be given to the decisions, its frequency, and by what means.
vi. A copy of the report must be part of the annexes of the Minutes.
d) If the provision in the previous letter cannot be evidenced through Board of Directors Minutes, the internal and external control bodies must highlight this weakness in the functioning of a essential part of Corporate Governance. e) Approve and verify the implementation, through reports, of control and audit mechanisms to ensure compliance with legal requirements and with the policies and procedures established in the SIPAR AML/CTF; including the adoption of measures to overcome gaps, weaknesses, and infringements detected by internal control bodies, external audit, or the supervisory entity. f) Assign, in a specific and identifiable manner, the budget that guarantees the necessary human, financial, and technological resources, adequate and in accordance with the nature, size, and magnitude of the operations offered by the Supervised Entity, for the efficient and effective implementation of the SIPAR AML/CTF; and for the functioning of the respective Administrative Support Structure provided for in article 46 of this Standard as applicable. g) Establish, by resolution recorded in Minutes, a Money Laundering, Goods or Assets; and Terrorist Financing Prevention Committee, hereinafter AML/CTF Prevention Committee, as an instance that assists but does not relieve the Board of Directors or the highest local authority in the country of foreign financial entity branches, of its direct responsibility in the approval, orientation, and monitoring of compliance with the SIPAR AML/CTF. h) Appoint, by resolution recorded in Minutes, the Money Laundering, Goods or Assets; and Terrorist Financing Prevention Administrator, hereinafter AML/CTF Prevention Administrator, as the main director, administration, and execution official of the SIPAR AML/CTF. i) Ensure that only named accounts are maintained in the Supervised Entity, and anonymous accounts or transactions, or those appearing under fictitious or inaccurate names, coded or encrypted, or whose high-risk clients do not present all the required information to obtain full certainty about the identity and origin of the funds, are rejected. j) Define and establish, within its AML/CTF Manual, an explicit and written policy for client and/or market segment acceptance. k) Establish and verify the implementation of risk-based CDD based on client knowledge and activities, including procedures and controls for the approval of new clients that must consider the inherent risk level that the client or transaction may present. The greater the risk the client represents, the higher the hierarchy of the Supervised Entity official who must approve or authorize their linkage and/or transaction, and/or the product or service derived from the linkage. l) Determine through duly approved policies and procedures according to their respective AML/CTF risk matrices, the exceptional cases in which to not interrupt the course of business and the development of its commercial activity; the Supervised Entity may conclude the client
identity verification after the establishment of a new commercial relationship. These policies must be established in the AML/CTF Manual clearly and specifically, and where procedures must be foreseen that contemplate, at a minimum, the following aspects:
i.- The manner in which risk management and mitigation will be carried out in relation to the conditions under which it is contemplated to perform verification subsequently.
ii. Determination of the maximum term within a short and reasonable time period to perform the subsequent verification.
iii. Criteria that allow identifying the absence of suspicion of AML/CTF or the way to reasonably ensure that there is no such suspicion.
iv. The conditions under which the client may use the commercial relationship before verification, including measures to limit the number, types, and/or amounts of operations.
m) Ensure that policies and procedures are formulated and implemented within the AML/CTF Manual aimed at evaluating AML/CTF risks in:
i. New products, services, or distribution channels, which must be applied prior to approval and launch to the market, in their design, development, and testing phases, in order that, once these products are launched to the market or new distribution channels are used, the risk profile of target clients and the pertinent policies, procedures, controls, and transaction monitoring and AML/CTF risk mitigation measures are already available.
ii. The development of new products and services in which, upon operationalizing them, the use of new or developing technologies is required, and in which by these anonymity is favored and/or where physical contact (face-to-face) with end-beneficiary clients is not required or minimized, including services to beneficiary clients using agents or intermediaries such as law firms, tax experts, accounting firms, or other forms of representation.
n) REPEALED.
ñ) Establish specific policies and procedures to administer and control the process of sharing client information with other Supervised Entities members of its Financial Group, and determine the type of information to be shared, when so agreed within the normal administrative process for the approval of operations, all of which must be recorded in the Board of Directors Minutes Book.
o) Establish specific policies and procedures with a focus on ML/TF prevention to know their external service providers.
p) Provide adequate specialized monitoring systems for the early detection of unusual and/or suspicious operations, which are consistent with the technology used to provide their services.
q) Ensure that all policies, procedures, and internal controls comprising the SIPAR ML/TF are contained, clearly defined, and updated in their respective AML/CFT Manual, as well as properly communicated to relevant personnel.
r) Establish policies and internal controls that discourage the use of unsafe practices in the management and administration of banking and financial activities, which, if they occur, lead to an increase in the ML/TF risk level of the Supervised Entity.
s) Ensure that the Supervised Entity provides all cooperation required by the Superintendency and other competent authorities, in all matters related to ML/TF prevention as provided by law.
t) Present a report to the General Assembly of Partners or Shareholders on the compliance with the SIPAR ML/TF, a topic that must be included and treated as an agenda item in the Annual Session of said Assembly, leaving a record of this in the respective Minutes Book. This report must refer at minimum to the most relevant aspects of the fundamental pillars that make up the SIPAR ML/TF, including the work environment in which the ML/TF Prevention Administrator operates, sanctions imposed on the entity for non-compliance with the SIPAR ML/TF, number of STRs submitted to the competent authority; number of employees trained on the subject, summary of relevant findings detected by the Supervisor, Internal Audit, and External Audit regarding weaknesses in their SIPAR ML/TF, as well as the results of their own self-assessment.
Art. 7.- Integration of the SIPAR ML/TF
The SIPAR ML/TF is integrated by the following five fundamental pillars:
a) Policies, procedures, and internal controls for due diligence with a risk-based approach, which must be contained in the respective AML/CFT Manual, in which, at minimum, the following aspects must be foreseen:
i.- Policy of “Due Diligence for Customer Knowledge” (CDD), which includes at minimum:
i.a.- Identification and verification of the customer, and creation of their Profile.
i.b.- Identification and verification of the ultimate beneficiary of the transaction or commercial relationship.
i.c.- Identification and verification of the nature and purpose of the transaction or commercial relationship.
i.d.- Update of the Customer Comprehensive Profile (CCP) based on the validity or documentary, transactional, and/or economic activity changes of the customer.
ii.- Complementary Knowledge Policies:
ii.a.- REPEALED.
ii.b.- Policy “Know Your Employee”.
ii.c.- Policy “Know Your Correspondent Relationships”
ii.d.- Policy “Know Your Electronic Fund Transfers”
ii.e.- Policy “Know Your Buyers of Consignment Instruments”
ii.f.- Policy “Know Your Providers”
iii.- Policy for Matrices for the Periodic Evaluation of ML/TF Risks, including those specific to new products.
iv.- Policy for permanent monitoring of the commercial relationship in attention to ML/TF risk.
v.- Policy for Early Detection of Unusual Operations.
vi.- Policy for Reporting Suspicious Operations in accordance with the laws and regulations on the subject.
vii.- Policy for Detection and Reporting of Cash Transactions for specific amounts in accordance with the laws and regulations on the subject.
viii.- Policy for the retention, conservation, and archiving of physical and/or electronic information, available to the competent authority.
ix.- Policy for the consolidated management of ML/TF risk at the Financial Group level, as applicable.
b) Implementation and Control Function of the SIPAR ML/TF, in charge of the following structures:
i.- Committee for the Prevention of Money Laundering, Goods or Assets; and of Terrorist Financing (ML/TF Prevention Committee).
ii.- Administrator for the Prevention of Money Laundering, Goods or Assets; and of Terrorist Financing Risks (ML/TF Prevention Administrator).
c) Institutional Program of permanent and specialized training on the subject of ML/TF Prevention.
d) Institutional Code of Conduct that includes the minimum aspects of ML/TF Prevention.
e) Independent Audit to verify the efficiency, effectiveness, compliance, and results obtained by the Supervised Entity in the implementation of the SIPAR ML/TF, through:
i.- Permanent Internal Audit.
ii.- Annual External Audit.
CHAPTER II
POLICY OF “DUE DILIGENCE FOR CUSTOMER KNOWLEDGE” (CDD)
Art. 8.- CDD Policy
a) The Supervised Entity, based on its specificity and risk profile within the industry in which it operates, must implement its own procedures, measures, and internal controls to develop adequate and continuous “Due Diligence for Customer Knowledge” (CDD) Policy in accordance with the minimum provisions indicated in this chapter.
b) The CDD Policy will be applied differently according to the ML/TF risk sensitivity and level determined by each Supervised Entity according to its own qualification matrix and in consideration of risk circumstances and factors. A high risk level corresponds to intensified CDD, a medium or normal risk level corresponds to standard CDD, and a low risk level corresponds to simplified CDD.
c) It is the inalienable responsibility of each Supervised Entity, in the development of its CDD, to identify, verify, know, and adequately monitor all its regular customers, including co-owners, representatives, signatories, and ultimate beneficiaries thereof; whether natural or legal persons, national or foreign; as well as to leave evidence in customer files on the verification of the information obtained. Regarding merely occasional customers who are non-recurring, non-permanent, and of low ML/TF risk, or other persons who intervene such as brokers, the Supervised Entity must at least identify them, noting the name, number, and type of identity document, and having the respective legal, official, valid, reliable, and indisputable documents in view in accordance with the laws on the subject.
d) The Supervised Entity, upon opening an account or initiating a commercial relationship with the customer, must obtain adequate information to know about:
i.- The unequivocal identity of the customer and/or ultimate beneficiary.
ii.- The origin of the funds and assets to be managed.
iii.- The purpose and nature of the relationship.
iv.- The volume of expected monthly activity.
e) The Supervised Entity must not initiate, establish, accept, maintain, execute, or develop:
i.- Anonymous accounts and/or business relationships, or those appearing under fictitious, inaccurate, coded, fantasy, or encoded names; or that in any way are not in the name of the customer-owner thereof. Every account or business relationship must be in the name of an identified and identifiable customer, whether a natural person or a legal person. When it comes to temporary or participatory associations recognized by law but without granting them legal personality, or when it comes to clearly specified projects financed by specialized funds or organisms recognized for those purposes; the accounts and/or business relationships may be named after said association or with references to said project, but in addition, it must be accompanied by the name of the natural or legal person who is its main link and/or manager and/or executor and/or responsible, which is the latter, for all effects, the person considered the customer of the Supervised Entity.
ii.- Accounts of a person (natural or legal) used to serve as a nest or bridge with the purpose of depositing, managing, or facilitating the transfer of funds originating from businesses and/or income belonging to another person (natural or legal) or company, own or not of the account holder, and with which the supervised entity has no contractual relationship.
iii.- Any commercial relationship or transaction with high-risk clients who, even applying what is provided in article 6, letter “l” and 11, letter “g” of this Norm; do not present the complete information required to obtain full certainty about their identity, the purpose of said relationship, and the specific justification of the origin of the funds or assets managed or to be used.
f) The CDD on commercial relationships with customers and the transactions they carry out, including monitoring, must be developed in a continuous and permanent manner, and will include the maintenance and periodic update of information.
g) The Supervised Entity, to ensure that customer records remain updated, must carry out regular and periodic reviews of them according to the deadlines indicated in article 12, letter “e” of this Norm, mainly when a significant or important transaction is carried out; when a relevant change occurs in the way the account and/or commercial relationship and/or expected activity operates; or when the documentation standards of a customer vary. The periodicity and depth of this diligence may be lower, in attention to the importance of commercial relationships and ML/TF risk levels according to the policies of the Entity itself.
h) Each Supervised Entity will determine the scope of CDD procedures for existing customers, according to the importance and ML/TF risk level according to the results of its risk qualification matrix, which it must previously elaborate and document, giving special attention to relationships and accounts where the identity of the customer or the ultimate beneficiary is not duly established, verified, or is not transparent.
i) To update the Customer Comprehensive Profile (CCP) with respect to new requirements for all existing customers as of the effective date of this Norm, CDD must be carried out based on the results of the ML/TF risk qualification matrix.
j) Procedures for the approval of new customers must consider the inherent ML/TF risk levels that they and/or their transactions may present. The higher the risk, the higher the hierarchy of the Supervised Entity official who approves their incorporation and/or transaction must be, which must be different from that which manages it.
Art. 9.- Identification
a) CDD must include requirements, procedures, and forms for the identification of customers, representatives, brokers, and ultimate beneficiaries, using legal, official, valid, reliable, and indisputable sources and documents in accordance with the laws on the subject.
b) The Supervised Entity, upon initiating a contractual relationship with regular customers in active, passive, or trust operations or any other service; must carry out the identification of the customer, including their representatives or brokers thereof, and their ultimate beneficiaries, as applicable; requiring the original of the legal, official, valid, reliable, and indisputable identity document in accordance with the laws on the subject; and other documents provided for in the next article according to each case; keeping a legible and clear photocopy thereof. For the case of merely occasional customers or operations that are non-recurring, non-permanent, and of low ML/TF risk, it will not be necessary to keep a physical photocopy of said documents, but the type and number of said documents must be verified and recorded in the respective forms.
c) When the customer is a legal person, the Supervised Entity must obtain updated documentation and evidence on its legal constitution and registration in the competent registry according to the activity to which it is dedicated, its domicile, the names of its owners or majority or significant partners, directors, trustees (when applicable), or other persons who exercise control over the customer; as well as the identification of persons authorized to represent, sign, or act on behalf of the customer, or bind it with the Supervised Entity, which must understand the ownership and control structure of the customer. Depending on the nature of these documents, they must be reviewed by the respective legal area of the Supervised Entity.
d) The identification requirement is exempted for those persons who make payments for public services such as water, electricity, and telephone through the respective bank accounts of the companies providing them, and official payments to State entity accounts, provided that the amounts paid are less than the threshold established in the Law on the subject to be reported. This exception does not exempt the Supervised Entity from the obligation to submit reports to the competent authority, as applicable, in accordance with the law on the subject.
e) For the purposes of the customer identification process, the Supervised Entity must have forms, physical or electronic, which contain and collect at minimum, the following requirements:
i.- Full name of the customer, the type and number of the legal, official, valid, reliable, and indisputable identity document in accordance with the laws on the subject, the customer's signature, address, and phone number of the customer or the person who physically carries out the transaction or business relationship.
ii.- Full name (and when possible, the type and number of the legal, official, valid, reliable, and indisputable identity document in accordance with the laws on the subject), address, and phone number of the person in whose name the transaction is carried out.
iii.- Full name (and when possible, the type and number of the legal, official, valid, reliable, and indisputable identity document in accordance with the laws on the subject), address, and phone number of the beneficiary or recipient of the transaction.
iv.- The identity of the affected accounts (numbers and holders) and type of transaction in question, such as deposits, withdrawal of funds, currency exchange, collection of checks, purchase of certified checks, manager's checks, purchase of drafts, payment orders, or other payments or transfers made through the Supervised Entity.
f) The Supervised Entity may not carry out customer identification each time the customer personally carries out a transaction, provided that when attending to them, their identity already registered, documented, and previously verified can be confirmed by internal and reasonable means.
Art. 10.- Required Documents
The Supervised Entity, upon initiating a business relationship with a customer and without prejudice to other Norms of the Superintendency and of Internal Regulations and Policies of each Entity, in the application of the CDD policy in the matter of ML/TF Prevention must require the following documents, as applicable in each case:
a) Legal, official, valid, reliable, and indisputable Identification Document for natural persons, in accordance with the laws on the subject:
i.- Identity Card for Nicaraguans residing in the country.
ii.- Identity Card or Residence Card and/or Passport for Nicaraguans not residing in the country.
iii.- Residence Card for foreigners residing in the country.
iv.- Passport with valid entry stamp for foreigners not residing in the country.
v.- Passport or Identity Card for foreigners not residing in Nicaragua and coming from a member country of the CA-4.
vi.- Badge or Official Document issued by the competent national authority, for foreigners who are members of representations or organizations with diplomatic rank; and/or the Passport issued by their respective country.
b) Official certification of registration in the competent Registry for the different legal persons, with which they accredit their respective legal standing in accordance with the laws on the subject, among others the following:
i.- Certification of registration as a Non-Profit Civil Association, or Foundation or Non-Governmental Organization.
ii.- Certification of registration as a Cooperative.
iii.- Certification of registration as a Commercial Company.
iv.- Certification of registration as a Union, Federation, Confederation, or Central Union.
v.- Certification of registration as a Political Party.
c) Photocopy of the Official Journal in which the creation of the legal person is published, as applicable.
d) Constitutive Deed and Bylaws duly registered in the competent Registry, in which the purpose or corporate object of the legal person is appreciated.
e) Document accrediting the power, mandate, or authority of representation that a person has with respect to another, natural or legal, to open and manage accounts, have a drawer signature, contract, or carry out the requested operation before the Supervised Entity.
f) Certification of the Board of Directors Meeting Minutes in which the authority granted to represent a society or entity is demonstrated.
g) Official Certification of the Minutes, Agreement, or Decree of appointment and/or taking office of the public official responsible for a State entity and/or copy of its publication in the State Official Journal.
h) Certificates and/or Licenses and/or Permits, or equivalent documents, valid and issued by the competent public registries, according to the activity to which the customer is dedicated.
i) RUC Document or Card (Unique Taxpayer Registry) for legal persons or equivalent document from the corresponding country for persons not domiciled in Nicaragua.
j) Certification of the Minutes where the members of the current Board of Directors of the legal person are recorded, at the time of carrying out the operation with the Supervised Entity. In this case, the identification, with official, legal, and indisputable document, of the natural person accredited as representative and the certification of the Minutes by which that authority is granted will also be required.
k) Updated Financial Statements for high-risk customers that constitute legal persons.
l) Letters of bank, commercial, or personal references in favor of the customer and of the persons designated by them before the Supervised Entity as their representatives, attorneys, and/or signatories. The number of references will be defined in the internal policies of each Supervised Entity according to the level of CDD they apply. The following exceptions or differentiated treatment regarding this requirement are established:
i.- For accounts in the name of government entities, it will not be necessary to demand references.
ii.- When it comes to deposit accounts for payment and withdrawal of salaries or wages of the customer, only the reference letter from the employer, which in turn is a client of the supervised entity with an account for payroll or roster, will be required. This exception only applies when the account is used by the titular customer for the exclusive purpose of crediting and debiting their salaries or wages. Otherwise, the Supervised Entity must apply the corresponding CDD.
iii.- Only one reference letter will be required, for the opening and/or management of Deposit Accounts to persons residing in Nicaragua, (natural or legal persons, national or foreign) that individually or added all accounts of the same person, the amount of their initial deposits or their final monthly balances in the same entity, do not exceed in national currency or in any other currency the equivalent of US$500.00 (five hundred United States dollars); or the sum of their debits or credits that individually or added all accounts of the same person do not exceed in one month in national currency or any other currency the equivalent of US$2,000.00 (two thousand United States dollars).
iv.- For the case of the preceding numeral, the Supervised Entity must implement adequate and timely control and monitoring systems to ensure that in such accounts or added the operations of all accounts, they cannot receive deposits or make withdrawals that added in the month are greater than the limits indicated, without written authorization of the manager of the office that manages or oversees the account, prior support of the reasons that justify the variations or excesses.
v.- If the contractual relationship is limited to loan operations, it will be sufficient for the Supervised Entity to require the customer's references, through the loan application forms, which must be verified by acceptable means, such as telephone, fax, email, mandatory consultation to the Risk Central of the Superintendency, and Private Risk or Credit Information Centers when the latter have established this in their policies, and additionally, leave written evidence of the way in which such verification was executed. This exception also applies to the case of loans in which the customer must open a deposit account for the exclusive purpose of crediting the
disbursement thereof, make deposits for its payment and/or deposit funds resulting from their economic activity in accordance with the declared Profile. m) All documents required that have been issued abroad and/or in a foreign language must be duly:
i.- Translated into Spanish, as appropriate. ii.- When they are documents of a legal or official nature, they must also be authenticated by the corresponding authorities in accordance with the laws and conventions on the matter. n) In the acceptance of the required documents, the Supervised Entity will adopt reasonable measures to:
i.- Prevent or avoid that obviously altered or doubtful identification documents are presented to or received by it; for which, in accordance with its own policies, it may use technological tools or require additional documents to corroborate the true identity of its clients, representatives, and managers, as necessary. ii.- Ensure that Certifications, and/or Certificates, and/or Licenses and/or Permits issued by competent public registries are valid at the time of initiating the commercial relationship with the client. iii.- Conduct a legal review of the presented legal documentation, where appropriate, mainly in the case of corporate clients. ñ) For new accounts and/or new business relationships with an existing client, the Supervised Entity will not require the documents indicated in this article, provided that they have been previously obtained, reviewed, and verified in accordance with the requirements of this Norm, and are archived and available for any review by the competent authority. This provision does not apply when compliance with Article 12, letter “e”, numeral “i” of this Norm is required, in which case updated documents and supporting evidence as necessary will be required.
Art. 11.- Verification
The DDC (Due Diligence) must include policies, procedures, and requirements to verify, before or during the course of establishing the usual commercial relationship, by means of legal, reliable, and indisputable documents and other pertinent and trustworthy information and sources; the real existence, identity, representation, domicile, legal capacity, corporate purpose, purpose of the operation, and origin of funds to be used. For occasional clients who are non-recurring, non-permanent, and low risk ML/TF, or other persons involved such as managers, the Supervised Entity must at least verify their identity. In the verification process, the Supervised Entity must at least:
a) Obtain, verify, and conserve the required and necessary information to determine the true existence and identity of clients and all persons in whose benefit an account is opened and/or the services offered by the Entity are used; as well as the owners or majority or significant partners of the corporate client, their representatives, and persons who have authorized signatures on said accounts and/or to authorize and/or carry out the transaction. b) Verify that the document identifying the client is not obviously altered or doubtful, being able to require additional documents to corroborate the true identity, as necessary. c) Review, the names of clients, beneficiaries, partners, guarantors, representatives, and/or signatories, against internal and/or external databases and/or publicly available risk lists provided by competent authority or international organizations regarding persons (natural or legal) designated or known as money launderers, terrorists, or terrorism financiers, or linked to organized crime; and against updated lists with public or private information from the Entity itself regarding unacceptable clients in accordance with its own policies. This review must be done at the start of the relationship, and periodically with the frequency defined in its internal policies. d) Conduct in-situ verification on the real existence of corporate clients. e) Implement measures to verify the identity of beneficial owners or real beneficiaries of accounts or transactions in all cases where the client acts, or where there are reasons to believe that they act on behalf of others as a representative, attorney, agent, or fiduciary. The measures must include procedures to investigate whether the client is acting or not on behalf of another person, and on the legal capacity under which the client is acting. f) Banks and financial institutions must implement policies and procedures to verify the information of the new endorsee client in the following cases:
i.- Certificates of Time Deposits that, in accordance with the relevant law and respective internal regulations, are issued as a Negotiable Instrument with a nominative character. ii.- Payment of checks that present more than one endorsement. g) Only in the exceptional cases expressly provided for in the policies and procedures approved by its Board of Directors in accordance with Article 6, letter “l”, of this Norm; the Supervised Entity may conclude the verification of the client's identity after the establishment of a new commercial relationship. It is up to each entity to determine which cases it will consider as exceptional according to its respective ML/TF risk level matrices. h) Verify the purpose or reason for opening operations, accounts, and any other contractual or business relationship with a client in accordance with the products and services for which the Supervised Entity is authorized.
i) Verify, within the legal framework and in accordance with the ML/TF risk level, the origin of the funds, assets, or goods deposited by the client, or that intervene in the transaction or that are used to pay for its operations with the Entity. j) Control and monitor, effectively and timely, all accounts and services received by the same client. k) Determine the existing relationships between the accounts, business or commercial operations of the same client, or group of clients linked to each other, managed within the Supervised Entity; in order to detect if there are interrelations without apparent reason or that do not correspond to the normal economic and transactional profile expected of them. l) Verify that accounts opened by state institutions in the Supervised Entity are in correspondence with the technical standards applicable to them for the handling of accounts, issuer signatures, check disbursement, and electronic transfer of funds. m) Obtain adequate references on clients, verifying that these must be independent to avoid cross-references between the same persons. n) Establish an adequate segregation of functions of the Supervised Entity's personnel: those who promote business, those who obtain information about the client, those who verify it, and those who approve the contractual or commercial relationship with the client. ñ) The Supervised Entity, in accordance with the complexity of its business and the weighting of its ML/TF risks, must have the necessary specialized tools for adequate and reasonable management of technological risk in the monitoring and prevention of ML/TF risks. These tools must allow, at minimum:
i.- Online consultation of the Comprehensive Customer Profile (PIC). ii.- Automatic and periodic comparison of the entire client portfolio against internal and/or external databases of publicly available risk lists. iii.- Facilitate queries on relationships between linked clients and accounts. iv.- Detect transactions by clients, risk levels, structuring, types of payment. v.- Flexibilize the parametrization and implementation of alerts on unusual and/or suspicious behavior in client operations. vi.- Document the workflow of follow-ups on clients generated by alerts, as well as for the management of the history of how many times a client has been the subject of alerts, what type of alerts and reports. vii.- Expedite the generation of reports. viii.- Follow up on Audit trails.
o) Based on all the documentation and information obtained, the Supervised Entity must develop an initial risk profile of the client, and when it indicates a higher than normal risk level or qualifies as high risk, it must develop additional verification measures in accordance with the Enhanced Due Diligence policy provided for in Articles 15 and 16 of this Norm. p) When the Supervised Entity cannot comply with the legal, regulatory, and its own policies requirements for the identification and verification of existing clients, or potential clients, as the case may be, nor can it obtain the necessary information about the purpose and nature of the commercial relationship; even applying what is provided for in Article 6, letter “l” and 11, letter “g”, of this Norm; it must terminate such relationship or not initiate it in accordance with Article 8, letter “e”, also of this Norm. In these cases, it must also consider, under its own decision, issuing a Suspicious Transaction Report (STR). What is executed in compliance with the provision contained in this letter must be duly documented.
Art. 12.- Comprehensive Customer Profile (PIC) The Supervised Entity must structure, adopt, and keep updated a “Comprehensive Customer Profile” (PIC) that it will fill out for its usual clients (natural or legal persons, national or foreign) with whom it establishes contractual business relationships; including their co-owners, representatives, and signatories. Each supervised industry, at the guild level, may structure its own PIC Format, taking as reference those proposed in Annex 2 of this Norm, and in which at minimum the information provided by the client itself, indicated in the following letters “a” and “b”, must be included. a) Data on the client - natural person:
i.- Names and surnames in accordance with the official, valid, and indisputable identification document; number, date of issue, expiration date, and issuing country of the identity document; sex, marital status, date of birth, country of birth, nationality. ii.- Name by which, socially and/or publicly, they are known. iii.- Home or mobile address and phone, contact phone, personal electronic address, profession and current occupation, as applicable. Name and address of their workplace, job title, and monthly salary, as applicable. Income range in which they qualify. iv.- Repealed. v.- Data on certificates and/or licenses and/or permits, or equivalent documents, as applicable by the client's activity; including the entity that issues it, date of issue, and expiration. vi.- Account numbers and/or contractual business relationships maintained between the client and the Entity, including types, dates of linkage, currency, initial deposit, and forms of payment as applicable.
vii.- Annual income and/or approximate sales volume obtained or generated by the client. viii.- The origin of the funds and assets to be managed, purpose, and nature of the relationship. ix.- Volume of normal and/or expected activity and/or transactions of the client monthly in each of their accounts and/or contractual relationships with the Entity, including number of transactions, amounts in debits, credits, transfers, and average balances, among other criteria, that allow their monitoring and comparison in an agile and timely manner with the client's real activity. x.- General data on accounts and/or business relationships with other financial institutions, national or foreign. xi.- The ML/TF risk level of the client in accordance with its own risk rating system. xii.- Data on the reference letter(s) in favor of the client, including the name of the grantor, number of their identification document, address, contact phone, workplace, time of knowing the referred client, and brief description of the result of the verification of the references indicating the employee who verifies it, date, time, name, and signature of the verifier. xiii.- The names of its largest clients and suppliers, as applicable. xiv.- The set of information established in Articles 8 to 11, inclusive, of this Norm, as applicable. b) Data on the client - legal person:
i.- Trade or Corporate Name (complete and abbreviated), commercial name, country in which it was constituted, date of constitution, date of registration in the competent Registry, RUC No. ii.- Number and date of the State Official Gazette in which the creation of the legal person is published, as applicable. iii.- Address of the headquarters or main office or parent company, phone, fax, PBX, post office box, page or website, electronic address. iv.- Corporate purpose, main economic or social activity to which the client is dedicated, indicating the type of operations, the profile of operations either retail or wholesale, identification of the geographic regions in which it operates, identity and domicile of its largest clients and suppliers. In the case of foreign legal persons, additionally, describe the profile of operations outside the country and to be carried out in Nicaragua. v.- Data on certificates and/or licenses and/or permits, or equivalent documents, as applicable by the client's activity; including the entity that issues it, date of issue, and expiration.
vi.- Identification of directors and administrators. vii.- Account numbers and/or contractual business relationships maintained between the client and the Entity, including types, dates of linkage, currency, initial deposit, and forms of payment as applicable. viii.- Annual income and/or approximate sales volume obtained or generated by the client. ix.- The origin of the funds and assets to be managed, purpose, and nature of the relationship. x.- Volume of normal and/or expected activity and/or transactions of the client monthly in each of their accounts and/or contractual relationships with the Entity, including number of transactions, amounts in debits, credits, transfers, and average balances, among other criteria, that allow their monitoring and comparison in an agile and timely manner with the client's real activity. xi.- General data on accounts and/or business relationships with other financial institutions, national or foreign. xii.- The ML/TF risk level of the client in accordance with its own risk rating system. xiii.- Data on the references in favor of the client, including the name of the grantor, number of their identification document, address, phone, workplace, time of knowing the referred client, and brief description of the result of the verification of the references indicating the employee who verifies it, date, time, name, and signature of the verifier. xiv.- The names of its largest clients and suppliers, as applicable. xv.- Additionally, the set of information established in Articles 8 to 11, inclusive, of this Norm, as applicable in accordance with the type of legal person. c) The information contained in the PIC and its supports must allow identifying the client and obtaining a reasonable knowledge of them, their main activity, the purpose of the relationship with the Entity, and the origin of the funds. d) In addition to the PIC in physical form, the Supervised Entity, according to the complexity of business, number of clients, volume of operations, technology used for service provision, and the weighting of its ML/TF risks, must maintain the PIC in an automated manner to facilitate monitoring and comparison between the expected activity declared by the client and their real monthly activity. Banks and financial institutions will keep the PIC both physically and electronically, always ensuring congruence of information between both supports.
e) The Supervised Entity must not create, update, and modify the PIC ex officio. The creation and update of the PIC must be based on information given by the client and verified by the Supervised Entity. The update of the PIC will be done in the following cases, requiring the client to provide the explanations and necessary supports that justify it:
i.- At most every four years when it comes to low-risk clients; at most every three years when it comes to medium-risk clients and at most annually when it comes to high-risk clients. These periods will be counted from the date of opening of the relationship and creation of the initial PIC, and then from each update. This periodicity may be shorter in view of the importance of the commercial relationships and the ML/TF risk levels in accordance with the Entity's own policies. ii.- When their economic activities in terms of markets, sales, and/or annual income, experience atypical or significant changes, variations, or increases in relation to their original PIC. It is the responsibility of each Supervised Entity to define in its ML/TF Prevention policies from what percentage or reasonable parameter it will consider a significant variation.
iii.- When there are reflected changes, variations, or atypical or significant increases in the real activity with respect to the originally declared expected monthly transactional activity. It is the responsibility of each Supervised Entity to define in its ML/TF Prevention policies from what percentage or reasonable parameter it will consider a significant variation. iv.- When new accounts are opened and/or new business relationships are established with the client. f) The initial PIC and its updates must also comply with the following guidelines:
i.- Be signed by the client, by the official who fills it out and reviews it, and by the official who authorizes it. ii.- Before the client's signature, there must be a note saying: “I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile”. iii.- In the updates of the PIC of natural person clients, their signature will not be mandatory when updating the data referred to in numeral “iii”, letter “a” of this article, unless it concerns salaries or income, or change of workplace, in which case the signature must be required. iv.- When the update of information about the client is carried out through online banking and/or electronic service, the Supervised Entity must take the necessary measures to give security and reliability to the entered information, in correspondence with Article 25 of this Norm.
g) Exceptionally, it will not be necessary for the Supervised Entity to complete a PIC in cases where the contractual relationship with the client is limited solely and exclusively to loan operations; provided that the Entity maintains internal forms where it collects the set of minimum information required in Articles 8 to 11, inclusive, of this Norm, as applicable. This exception does not apply in the case of loans on the occasion of which the client must also open a deposit account in accordance with the Entity's policies. h) When the client uses the services of more than one Supervised Entity belonging to the same supervised Financial Group operating in Nicaragua, and the main contractual relationship includes operations with a banking entity of said Group and that it complies at least with the minimum requirements established by this Norm; the Board of Directors of the respective banking entity, assuming its own risks, may authorize that the other members of the Group can obtain from the bank the pertinent and updated information about the client. The foregoing will be permissible, under the following conditions:
i.- That the Supervised Entity that obtains the information is not relieved of its responsibility to directly request from its client the data and information particular to its own business, necessary for the reasonable knowledge and verification of the client and elaboration of its Profile. ii.- That the banking entity that shares the information with the other members of its Financial Group, has the prior written authorization of the client and the information is necessary as part of the normal administrative process for the approval of operations with him.
iii. That the Financial Group to which the Entity requesting information belongs, has implemented a centralized and consolidated process of ML/TF risk management at the Group level and in a manner consistent with the requirements established in this Norm.
iv. That the Financial Group has adequate, secure, and periodically audited mechanisms for the exchange of information about clients among its members.
v. That there are internal and external audit programs for the periodic and integral evaluation of the application of ML/TF risk-based DDC controls, which include the review of the efficiency and effectiveness of the exchange of information among the members within the Financial Group.
Art. 13.- Client File
The Supervised Entity must form and conserve, in good condition and updated, a physical file for each client, in which a copy of the PIC and its duly signed updates, the supports for the application of DDC according to the risk level, as well as all the information and documents indicated in Articles 8 to 11, inclusive, of this Norm, as applicable, must be archived.
Art. 14.- Standard CDD a) The Supervised Entity must apply a standard or ordinary CDD to clients and operations that, according to its ML/TF risk level classification matrix, are classified as medium or normal risk clients; applying the measures provided for in Articles 8 to 13, inclusive, of this Norm, as applicable. b) The Supervised Entity must apply differentiated or stepped CDD, either intensifying or simplifying it with respect to standard CDD, depending on changes in the risk levels of clients or the commercial relationship according to updates in its matrix; considering the changes that occur, among others, in the following circumstances:
i.- The client's legal structure and background. ii.- The client's geographic location, jurisdiction, or country of origin. iii.- The economic sector in which the client operates and its activity within that sector. iv.- The client's work and professional environment, including determining whether they hold a significant public or private position. v.- The characteristics, complexity, and changes in transactions, products, or services required by the client. vi.- Significant changes in the expected monthly activity declared by the client compared to their actual activity. vii.- The channels and means of delivery or distribution of services and products, including the use of intermediaries, agents, brokers, managers, or electronic banking. viii.- The use of complex and low-transparency legal or fiduciary structures and the use of bearer instruments or bearer shares. ix.- The payment methods used. x.- The use of intermediaries and third parties. xi.- The linking of accounts, or business with relatives, representatives, or with the Supervised Entity or an affiliated group thereof. xii.- Any other indicator that each Supervised Entity deems pertinent according to its own business and risk level, or according to any guidelines or other mechanisms issued by the Superintendency or competent authority.
Art. 15.- Enhanced CDD a) Enhanced, reinforced, improved, expanded, or deeper CDD is the set of internal control policies, procedures, and differentiated measures that are reasonably more rigorous, deep, demanding, and exhaustive than standard CDD, which the Supervised Entity must design and apply to clients classified as high risk, based on the analysis of ML/TF risk factors and/or according to the results of the ML/TF risk level classification matrix. Risk factors are all those circumstances and characteristics of the client and operations that generate a higher probability of ML/TF risk, warranting special attention and enhanced CDD. b) Without prejudice to those that may additionally be included and classified in these categories according to the ML/TF risk classification matrices of each Supervised Entity, or as instructed by another authority with competence in the matter, or according to international best practices for ML/TF prevention; among the risk factors are considered the following: High-Risk Clients; Products, and/or Services, and/or High-Risk Accounts; High-Risk Distribution Channels; High-Risk Countries, Jurisdictions, and/or Geographic Areas. i.- High-Risk Clients:
i.a.- Persons engaged in the following business lines or activities: Currency Exchange Houses; Companies dedicated to the Transfer or Sending of Funds or Remittances; Casinos or Gambling; Savings and Credit Cooperatives; Lenders; Unregulated Microfinance Institutions; Unregulated Financial Activities; Pawnshops; Non-Profit Civil Associations; Foundations or Non-Governmental Organizations (NGOs); Investors and Real Estate Agencies; Commercializers and Lessors of Motor Vehicles; Commercializers and Lessors of Vessels and Aircraft; Free Trade Zones; Commercializers under Multi-Level or Pyramid Sales Systems (network marketing); Dealers of antiques, jewelry, metals and precious stones, coins, art objects, and postage stamps; Dealers of weapons, explosives, and ammunition. i.b.- Natural persons who individually or jointly maintain balances at the end of each month in the Supervised Entity in national currency or any other, equal to or greater than One Hundred Thousand United States Dollars (US$ 100,000.00), in their accounts under any business modality, including passive, active, or trust operations, or who in any way intervene in monthly accumulated movements of said amount, whether in debits or withdrawals, or in credits or deposits. i.c.- Persons with accounts showing high activity in cash and/or transfers. i.d.- Politically Exposed Persons (PEPs), including close family members, associates, and close collaborators of such persons. i.e.- Persons providing professional services such as Lawyers, Notaries, and Public Accountants; provided that their services are related to the following activities: sale and purchase of real estate and commercial, industrial, or financial entities; administration of money, accounts, securities, and other assets; and creation, organization, operation, or administration of partnerships, companies, legal entities, or legal structures. i.f.- Commercial Companies or Companies with bearer shares or convertible bearer shares. i.g.- Trusts or legal structures, especially when they function as Shareholder Holders (holding) abroad for the administration of assets and goods, or as providers of fiduciary services. i.h.- Legal entities constituted and established in Tax Havens (Off Shore). i.i.- Notoriously Public Persons (NPP). i.j.- Persons domiciled abroad. i.k.- Persons with financial activity in countries or jurisdictions that are considered by specialized international bodies as non-cooperators in the fight against ML/TF; and/or as tax havens and/or with high banking secrecy; and/or with low, poor, weak, or non-existent legislation on ML/TF prevention. i.l.- Clients who have been the subject of a Suspicious Transaction Report (STR). Without prejudice to the functions and powers of the competent authority to analyze STRs, information about these clients is solely for the exclusive consideration and internal handling of the reporting Supervised Entity, which must not disclose the names of its clients being analyzed or
considered for a possible STR or when such Report has been filed, in correspondence with what is provided in Article 29, letter "e", of this Norm and in the banking law. ii.- Products, and/or Services, and/or High-Risk Accounts:
ii.a.- Private Banking. ii.b.- Correspondent Banking and/or Correspondent Relationships. ii.c.- Electronic, Internet, or Telephone Banking, and/or businesses or transactions that are not "face-to-face", or that do not imply the physical presence of the parties, or that facilitate anonymity. ii.d.- Electronic or cable transfers of funds. ii.e.- Monetary instruments. ii.f.- Safety Deposit Boxes. ii.g.- Exchange Desk or Foreign Currency Buy/Sell. ii.h.- Loans guaranteed with liquid collateral (cash previously deposited in accounts, commercial securities, Time Deposit Certificates, Government Bonds, etc.). ii.i.- Trusts and asset administration services. ii.j.- Payable Through Account Services. ii.k.- Accounts managed by Representative Offices. ii.l.- Brokerage accounts, intermediaries, or investment agent accounts acting on behalf of third parties. iii.- High-Risk Distribution Channels:
iii.a.- Electronic Banking, Internet, or Online Branches. iii.b.- Telephone Banking. iii.c.- Automated Teller Machines (ATMs). iii.d.- Businesses or transactions that are not "face-to-face", or that do not require the physical presence of the parties, or that facilitate anonymity. iii.e.- Businesses or transactions through agents or intermediaries. iv.- High-Risk Countries, Jurisdictions, and/or Geographic Areas:
iv.a.- Those considered by specialized bodies such as FATF as non-cooperative or whose ML/TF risk prevention systems are considered non-existent or, if existing, are not applied effectively. iv.b.- Those considered by international bodies, such as the UN, as collaborators of international terrorism. iv.c.- Those considered of special attention due to their high incidence in the production, and/or trafficking, and/or consumption of illicit drugs. iv.d.- Those considered by international bodies working in the fight against ML/TF and/or in favor of international transparency; as offshore financial centers, tax havens, with high banking and fiscal secrecy, or with a high level of perceived public corruption. iv.e.- Those that have been subject to sanctions by international bodies or included in special attention lists due to the high ML/TF risk they represent. iv.f.- National or internal geographic areas of the country itself, when there is public information from official entities that these are being frequently used for the transit or trafficking of illicit drugs, illegal immigrants, or any other form of human trafficking, smuggling of goods, or illegal smuggling or trafficking of cash. iv.g.- Those identified by the Supervised Entity itself as deserving special attention based on its experience with them, by the history of monitored transactions originating from them, by the presence of high indicators of public corruption, among others.
Art. 16.- Enhanced CDD Measures
For clients, products, distribution channels, and geographic areas classified as high ML/TF risk, the Supervised Entity must apply more exhaustive or rigorous procedures and controls with respect to standard CDD. In addition to the measures provided for in Articles 8 to 13, inclusive, of this Norm, as applicable; the following must be applied at a minimum:
a) Establish and execute more rigorous verification procedures on all information supplied by the client. b) Obtain, evaluate, and archive relevant and complete information about the client regarding their activity or function, their authorization to operate, their current certification of registration in the competent registry according to the activity they are dedicated to, their appointment as applicable, their internal client knowledge policies as applicable, and the quality of supervision when subject to it. c) Conduct on-site inspections to verify the real existence and establishment of the client, in order to corroborate the congruence of the infrastructure and physical appearance of the business with the level of economic activity, annual sales, and transactional profile declared by the client. d) Require updated Financial Statements from high-risk clients that are legal entities. e) Execute necessary mechanisms to justify, evidence, and document the origin of funds, assets, or merchandise deposited by the client, or that intervene in the transaction or that they use to pay for their operations with the Entity. f) The contractual relationship, transaction, or link with the client must be approved by a senior management official or Board of Directors member. g) Exercise permanent, intensified, and more exhaustive surveillance and monitoring over accounts, transactions, and commercial relationships. h) Adopt measures to prevent the misuse of technological advances that could increase ML/TF risk in the provision of those services offered by the Supervised Entity and that facilitate anonymity due to lack of physical contact or not being "face-to-face" with the person or persons who actually carry out such operations, transactions, or other business relationships. i) Require the ML/TF prevention program applied by their high-risk clients, as they are obliged by the relevant law, complemented with the most recent certification of the audit conducted on said program. This requirement will not be demanded when the client is a Supervised Entity supervised by the Superintendency. j) Know, reasonably, who the owners and majority or significant partners are that make up a legal entity that is in turn a partner of the legal entity client of the Entity, as well as the true beneficiaries and/or owners of the funds managed; and particularly in the case of Commercial Companies, it is also necessary to identify:
i.- Persons who exercise real control over their operations, assets, properties, and businesses in general. ii.- Main shareholders/partners, authorized signatories, or other persons who exercise significant control over the company. iii.- Partners and other persons who exercise ownership control in the case of General and Limited Partnerships. iv.- Controlling persons, when other companies or trusts exercise control over the company. k) The Supervised Entity must also apply enhanced CDD to clients and transactions that, originally considered normal risk, present any of the following circumstances:
i.- There are doubts about the validity or sufficiency of information about the client derived from the identification and verification process. ii.- The client is included in lists of persons convicted, prosecuted, or under investigation for ML/TF matters by competent national authorities; or appear in national, foreign, international, or specialized body lists regarding persons linked to these risks; or by any other information of which the Entity itself has knowledge. iii.- There are sudden and unjustified changes in the client's expected activity. iv.- It concerns transactions and commercial relationships with clients operating from countries, jurisdictions, and geographic areas of high risk that do not comply with or sufficiently implement international standards in the matter of ML/TF prevention. v.- The Entity itself has suspicion or reasons to suspect that there is ML/TF risk, regardless of the amount of the operation or the type of client; or, when said client has been the subject of a Suspicious Transaction Report (STR) and the Entity decides to continue with the contractual relationship. l) When the Supervised Entity considers that carrying out the enhanced CDD process could directly or indirectly alert or warn the client, or potential client, of a potential Suspicious Transaction Report (STR) as it should or could be derived from said process; it must then execute the following measures:
i.- Do not continue with the enhanced CDD process. ii.- Consider the possibility of issuing, immediately, a Suspicious Transaction Report (STR). m) In cases where the Supervised Entity, according to its business, applies what is provided in the preceding letters "k" and "l", it is up to it to decide whether or not to continue with said contractual or business relationship. The compliance with this provision must be duly documented. n) Any other measure that the Superintendency or any other competent authority may eventually establish through guidelines, guides, circulars, instructions, or other mechanisms. ñ) Enhanced CDD measures for high-risk clients will be applied as follows:
i.- For new clients after the effective date of this Norm, immediately. ii.- For existing clients on the effective date of this Norm, within the timeframe provided in Article 81 of this Norm.
Art. 17.- Simplified CDD a) For clients and operations classified as low ML/TF risk, the Supervised Entity may apply simplified, reduced, lesser, or attenuated procedures and controls with respect to standard CDD. b) The Supervised Entity may only simplify CDD when, applying adequate matrices and mechanisms to establish the ML/TF risk level, it has determined the existence of low risk, without prejudice to what is provided in letter "d" of this Article. c) In simplified CDD, the identification of the client by indisputable document, the accreditation of representatives, the creation of the Client Profile (PIC) and the respective client file must not be overlooked; in addition to any other requirement that the Entity itself establishes according to its own policies on the occasion of the product or service offered and contracted. d) In correspondence with the preceding letters, the Supervised Entity may apply simplified CDD, among others, to the following types of clients:
i.- Entities Supervised by the Superintendency. ii.- Anonymous Companies that trade on the Stock Exchange and that by law must comply with disclosure requirements. iii.- State and municipal entities of Nicaragua. iv.- Occasional, non-recurrent, and low-risk clients. v.- Clients whose active operations in the Financial System are classified as "Microcredit" according to the respective Norm on the matter, and without prejudice to the own measures applicable due to passive and trust operations that may additionally exist with the client.
CHAPTER III
COMPLEMENTARY KNOWLEDGE POLICIES
Art. 18.- REPEALED.
Art. 19.- "Know Your Employee" Policy
The Supervised Entity, including the Human Resources and Security Area, must formulate and implement a "Know Your Employee" policy that forms part of the recruitment and selection program for new, permanent, and temporary staff, ensuring a high level of integrity, professionalism, and capability of the personnel. In this policy, the following aspects must be included at a minimum:
a) Requirements for personal and professional background checks, and abstaining from hiring employees who do not meet them. b) Specifically incorporate into the "Job Descriptions and Functions" that must form part of the Supervised Entity's Organizational Manual, the functions for the Prevention of ML/TF risks, according to the nature of each position. c) Create an Employee Profile and update it periodically, particularly when the employee assumes different responsibilities and with a higher ML/TF risk level within the Entity. d) Measures to detect possible changes in an employee's lifestyle, at any level, that allow deducing conduct not in line with their personal economic situation or family environment or with their professional profile; in consideration, in addition, of the Alert Signals and Indicators provided in Annex 3 of this Norm.
Art. 20.- "Know Your Correspondent Relationships" Policy a) Each Supervised Entity, according to its nature and business line, will develop a "Know Your Correspondent Relationships" policy, including Accounts, Investments, Deposits, and Reinsurance abroad. b) When the Supervised Entity provides or receives services in correspondent relationships, it must:
i.- Verify that the client financial institution maintains physical presence in the country where it is constituted, authorized, administered, and regulated. ii.- Abstain from establishing or continuing correspondent relationships with fictitious financial institutions or those constituted and authorized in a jurisdiction where they do not have physical presence or, having it, are not under an effective supervision regime; and also with financial institutions that in turn provide correspondent relationships to other fictitious financial institutions or those lacking such physical presence and supervision. iii.- Obtain, evaluate, and archive complete information about the client financial institution regarding its commercial activity, its authorization to operate, the quality of official supervision to which it is subject, its reputation, evaluate the sufficiency and effectiveness of its ML/TF prevention programs, the history of legal and/or regulatory actions to which they have been subjected in relation to the ML/TF topic, and the respective responsibilities for ML/TF risk control that each client financial institution has adopted. iv.- Determine if the client financial institution offers its correspondent services to other financial entities, identifying them and ensuring they have physical presence, authorization to operate, and ML/TF prevention programs.
Art. 21.- "Know Your Electronic Fund Transfers" Policy a) In the case of national or international Electronic Fund Transfers and Remittances or Money Sending, whether habitual or occasional; the Supervised Entity when acting as the ordering party, intermediary, or beneficiary, must:
i.- Include in the electronic fund transfer forms and related messages connected through the payment chain, the exact, precise, and valid information about the sender (name, type and number of identification, address, phone, and account number). This requirement must be complied with at least at the first and last link of the chain, as applicable. ii.- Ensure that the aforementioned information is maintained with the transfer and messages throughout the entire payment cycle. iii.- Examine more thoroughly fund transfers that do not contain complete information about the sender, or abstain from receiving them. b) The Supervised Entity must maintain an automated system for extracting data related to all transactions involving fund transfers or internal and external payment orders; that facilitates their monitoring. The Supervised Entity must not execute transfers without prior registration. The information to be registered in each transaction carried out and transmitted by the Originating or Beneficiary financial institution as applicable, will be at a minimum the following:
i.- Name and address of the person originating the payment order or transfer. ii.- The identification means (with legal and undeniable document) of the person managing the transaction. iii.- Account number, if the funds are debited from an account in the financial institution. iv.- Amount of the payment order or transfer. v.- The date on which the payment order or transfer was effected. vi.- Instructions included in the payment order or transfer received from the originating person. vii.- Identity of the beneficiary financial institution; and viii.- Name, address, and account number of the beneficiary person. ix.- If the funds, instead of being deposited into the beneficiary's account, are disbursed in cash, cashier's check, manager's check, or through another monetary instrument, the beneficiary financial institution must identify the form of payment effected. x.- If the beneficiary person is not an established client of the beneficiary financial institution, the latter must register the name, address, and identification (with legal and undeniable document) of the beneficiary. c) The requirements foreseen in the preceding literals “a” and “b” may be simplified when dealing with transfers and settlements from one financial institution to another financial institution, provided that both are acting on their own behalf.
Art. 22.- “Know Your Buyers of Consignment Instruments” Policy a) The Supervised Entity must maintain an automated system for the extraction of data regarding all its transactions involving the sale of Consignment Instruments, such as manager's checks, cashier's checks, traveler's checks, bank drafts, and others similar; which facilitates their monitoring. b) The information to be registered in each transaction involving the sale of Consignment Instruments shall be, at minimum, the following:
i.- Name, address, and telephone number of the person managing the transaction and of any other person on whose behalf or for whose benefit the same is carried out. ii.- Type and number of the identification means (with legal and undeniable document) of the person managing the transaction. iii.- Account number, if carried out by an established client. iv.- Form of payment, amount, and type of currency used for payment. v.- Description and identification of the instrument sold.
Art. 23.- “Know Your Providers” Policy
The Supervised Entity is obligated to develop “Know Your Providers” policies that include Anti-Money Laundering/Countering the Financing of Terrorism (AML/CFT) procedures for the knowledge of Providers of Goods and External Services of the Supervised Entity, and the management of individually documented files containing the contracted services, modalities and forms of payment, frequency of service provision, and delivery of goods; all in attention to the materiality of the contracting and risk qualification of the provider.
CHAPTER IV
MATRICES FOR AML/CFT RISK ASSESSMENT
Art. 24.- AML/CFT Risk Matrices
Each Supervised Entity must develop matrix or matrices with their respective procedures and systems, for the periodic evaluation of their AML/CFT risks, which include all areas of operation, clients, products, and services offered. a) The results of this evaluation will serve as elements for:
i.- The classification of the AML/CFT risk level of clients. ii.- The type of Enhanced Due Diligence (EDD) to be applied according to the AML/CFT risk classification levels. iii.- The development of controls for AML/CFT risk management. iv.- The intensity of monitoring procedures and systems for the detection of unusual and/or suspicious operations. b) In the AML/CFT risk evaluation, Supervised Entities must take into account the guidelines, typologies, and other standards issued by competent and specialized authorities and organizations on the subject, as well as their own experience in the markets where they operate. International standards must be taken into consideration. c) The periodicity of this evaluation must take into account the AML/CFT risk level of their clients, and be established in the respective policies. d) Each Supervised Entity must conduct an annual institutional self-assessment of its level of compliance with the AML/CFT SIPAR; and of the legislation and regulations in this matter applicable to them, developing the respective policies and procedures. The results of this process must be part of the report foreseen in article 6, literal “t” of this Norm.
Art. 25.- New Technologies, Products, and Services a) Each Supervised Entity must develop policies, procedures, and systems for the evaluation of AML/CFT risks, including the definition of the applicable matrix or matrices for the evaluation of new products and services, the technologies used, and distribution channels, to be applied prior to their launch in the design, development, testing, approval, and implementation phases. In this process, entities must pay special attention to the following:
i.- Products and services that use technologies that give rise to relationships that are not “face-to-face”, which favor anonymity and/or do not require or minimize physical contact with beneficiary clients. ii.- Services to beneficiary clients using agents, intermediaries, or other similar distribution channels. b) The technological systems and tools for classifying the AML/CFT risk level in new or sophisticated financial products and/or those that facilitate anonymity, for the monitoring of these and for the early detection of unusual and/or suspicious AML/CFT operations; must correspond to the technology that the Supervised Entity is using in the provision of the same.
CHAPTER V
MONITORING AND REPORTS
Art. 26.- Monitoring, Detection, and Security a) The Supervised Entity must detect and pay special attention to all activities, transactions, or operations that are unusually complex, unusual, significant, atypical, unusual, incongruent, disproportionate, or inconsistent, or that do not have an evident legal or commercial basis, or that do not maintain consistency with the economic and transactional profile declared by the client. This obligation applies to both transactions carried out and those merely attempted, whether or not they are suspected of AML/CFT, as well as to individual transactions, periodic transactions, and patterns of multiple transactions that meet one or more of the characteristics mentioned here or fall into and/or combine with the Signals and Alert Indicators of Annex 3 of this Norm. b) When the Supervised Entity detects or in any way has knowledge of activities, transactions, or operations according to the preceding literal, it must conduct its examination, scrutiny, or analysis documented within a maximum period of 45 days counted from the date of detection or the moment it has knowledge, to rule out or confirm the need to report it as a suspicious operation to the competent authority. Written evidence of this process and its conclusions must be left and archived for the legal period.
c) Suspicious operations are those activities and/or transactions of civil, commercial, or financial nature, whether effected or not, in cash or other types of assets and regardless of their amount; that have an unusual, atypical, incongruent, or inconsistent magnitude, periodicity, geographic origin or destination, or speed of rotation, that does not relate to the economic and transactional activity declared by the client in their profile and which does not offer appropriate, logical, and documented explanations and justifications for the case; or that the conditions of unusual, unusual, disproportionate, or significant complexity manifested in them exceed the parameters of normality regarding the transactions normally expected of the client according to their profile and the market in which they operate; or that for any reason do not have an economic basis or apparent lawful justification or purpose of legality; whereby the Supervised Entity has or should have knowledge, presumes, or has objective reasons to suspect, after having carried out the scrutiny and review of the case, that such activity or operation proceeds, and/or is linked and/or is destined to illicit activities, or to AML/CFT; or in any way attempts to evade the laws and regulations of this matter. d) It corresponds to each Supervised Entity to establish its own policies, procedures, monitoring systems, determination, and parametrization of alerts, in attention to the risk level, for the detection of unusual and/or suspicious activities, transactions, or operations. e) The procedures and systems for the monitoring referred to in the preceding literal must also be applied at the Financial Group level when applicable. Such procedures must provide for adequate monitoring that groups the accounts and activities of each client or group of related clients in a consolidated manner through the Supervised Entity or Financial Group. f) The systems and tools for monitoring and detecting unusual and/or suspicious AML/CFT operations must correspond to the technology used by the Supervised Entity in the provision of the services it offers; which must allow their effective, early, and timely detection in relation to the Customer Identification Program (CIP). g) The Supervised Entity must implement secure internal procedures that guarantee the strictest confidentiality in the handling, processing, analysis, reporting, and recording of operations, transactions, or activities referred to in literal “a” of this article. In these cases, the AML/CFT Prevention Administrator must be informed for the timely and without delay analysis of all relevant information regarding the operation, transaction, activity, or client, to determine if there is or is not a reasonable legal, financial, economic, or commercial explanation. The conclusions of said analysis must be sufficiently documented, archived, and retained for the period established by the law of this matter.
Art. 27.- Alert Signals and Indicators a) To fulfill the obligation to monitor and detect operations, transactions, or activities referred to in literal “a” of article 26 of this Norm; the Supervised Entity must take into account Annex 3 on Alert Signals and Indicators, as well as any other guide or instruction issued by competent authorities or recognized international organizations specialized in the subject of AML/CFT prevention that contain examples and indicators of unusual and/or suspicious transactions.
b) The Supervised Entity must detect and pay special attention to clients, operations, and/or behaviors foreseen in Annex 3 on Alert Signals and Indicators, according to their financial sector and business line, with the object of being analyzed in combination with other indicators, factors, criteria, and available information, and determine if the same constitute suspicious operations linked to AML/CFT risks. c) The Alert Signals and Indicators, considered individually, must not be considered suspicious, but rather as reference elements or “red flags” that allow the early determination of the possible presence of suspicious AML/CFT activities.
Art. 28.- Determination of Suspicion and Obligation to Submit Suspicious Operation Report (SOSR) a) When, in the process of examination, scrutiny, or analysis of transactions, operations, or activities initially detected as unusual and/or suspicious; a reasonable and documented explanation is obtained that justifies them or dispels the reason why they were subject to such scrutiny; it will not be necessary to report them as suspicious operations. The information of this process must be archived and retained for the period established by the law of this matter. b) When the conclusions obtained by the Supervised Entity from the examination, scrutiny, or documented analysis of transactions, operations, or activities detected with similar characteristics or falling within those referred to in literal “a” of article 26 and/or those foreseen in Annex 3 on Alert Signals and Indicators of this Norm, and the client does not document a legal, financial, economic, or commercial basis, explanation, and justification evident and reasonable regarding the same; or that even presenting the foregoing, the Entity in any way presumes, suspects, has reasons to suspect, has indications, knows, or should know, that the funds originate or are destined to an illicit activity or to AML/CFT, regardless that they do not fall into any Signal or Alert Indicator; the Supervised Entity must proceed to:
i.- Determine and qualify such activity as a suspicious operation. ii.- Immediately submit a Suspicious Operation Report (SOSR) to the competent authority according to the law of this matter, without invoking any secrecy, confidentiality, or reserve.
c) The SOSR must also be submitted:
i.- When the Supervised Entity cannot fulfill the Enhanced Due Diligence (EDD). ii.- When, in the scrutiny process, request for information to the client for the justification and analysis of transactions, operations, or activities detected based on the implementation of monitoring procedures and systems; the Supervised Entity might thereby directly or indirectly alert said client that they are being subject to analysis for a possible SOSR. In this case, the scrutiny process and request for information to the client must also be discontinued. d) The Supervised Entity will submit the SOSR regardless of the amount, nature, or type of client involved. The sending of an SOSR to the competent authority does not constitute a criminal complaint, but only basic information for subsequent financial analyses and investigations by the competent authority designated in the law of this matter, as applicable. e) The SOSR will be prepared and submitted by the AML/CFT Prevention Administrator in accordance with what is established in the applicable legislation, in this Norm, and in Annex 4 thereof, without prejudice to the instructions and guidelines that the competent authority of its analysis may issue regarding this matter. f) All suspicious operations must be reported, including attempted transactions that were not concretized. g) The SOSR must clearly indicate if the transaction was carried out, attempted, or rejected, and also if it was decided to terminate or continue the relationship with the client. h) According to what is established by the legislation of this matter, SOSRs prepared and submitted in good faith by a Supervised Entity in compliance with the same and with this Norm, do not constitute a violation of restrictions on the disclosure of information existing by contractual means or by legal or regulatory provision for the Supervised Entity, its directors, officials, and employees, nor will they imply any type of responsibility for them. i) The termination or continuation of the commercial relationship with the client upon the sending of an SOSR depends on the free decision of each Supervised Entity.
Art. 29.- Special Measures for the Secure and Confidential Structuring, Handling, and Presentation of an SOSR a) The SOSR will be sent and presented to the competent authority in physical form, according to the format and instructions foreseen in Annex 4 of this Norm, which may eventually be modified by the authority authorized for its analysis. b) The SOSR may also be sent electronically or magnetically using the automated security mechanisms that the Superintendent may eventually authorize through an Annex to this Norm; or as determined or instructed by the authority authorized for its analysis.
c) It is the responsibility of each reporting Supervised Entity to ensure that each SOSR contains relevant and complete information, and additionally a clear analysis and explanation regarding the background and reasons why the operation is considered suspicious. d) The SOSR that is presented without meeting these requirements will be returned by the competent authority to the Supervised Entity with notification to the Superintendency, all through channels of strict confidentiality. e) The procedures and handling of all SOSRs and related information are restricted access and must guarantee the strictest confidentiality and high security. No Supervised Entity, director, executive, official, employee, or agent linked to it may notify, disclose, or inform in any way, directly or indirectly, persons not authorized by the law of this matter, regarding the detection, scrutiny, or analysis of unusual and/or suspicious operations, or regarding the structuring, handling, issuance, presentation, and content of an SOSR. The law prohibits officials of the Supervised Entity from disclosing, informing, or alerting the client that their transaction is being analyzed or considered for a possible SOSR, or that said Report has been presented. f) The Supervised Entity, regarding the SOSRs, must supply the competent authority with any additional information requested by it in strict adherence to legal provisions, and comply with any instruction or order issued by them for the fulfillment of their functions. g) The SOSRs and the information supporting them must be kept in a special file, individual per client and centralized under the strict custody and confidentiality of the AML/CFT Prevention Administrator. The same treatment will be given to information regarding the operations, transactions, or activities referred to in literal “a” of article 26 that have been subject to examination, scrutiny, or analysis and did not warrant the issuance of an SOSR.
Art. 30.- Monitoring and Detection of Cash Transactions Above the Determined Threshold a) It corresponds to each Supervised Entity to establish its own procedures and monitoring systems for the detection and grouping of Cash Transactions that, for habitual or occasional clients, linked to the same client or beneficiary; in concept of deposits, withdrawals, credits, currency exchange, purchase and sale of securities, electronic transfers through or to said Entity, or other operations; and that in one day, individually or singly, multiple or fractional, from or to an account, or using totally or partially an account; whether in national or foreign currency; involve the exchange of currency in cash reaching an amount equal to or greater than the amount or threshold determined in the Law of this matter. These transactions by themselves do not constitute suspicious operations. b) The adopted monitoring mechanisms must include adequate computer systems that orderly collect the data indicated in Annex 5 of this Norm. In addition, these monitoring systems must allow the comparison of transactions, accounts, and activities of each client with their respective Profile established according to this Norm.
Art. 31.- Obligation to Report Cash Transactions Above the Determined Threshold (RTE) a) The Supervised Entities, without invoking any secrecy, confidentiality, or reserve, must inform and report to the competent authority according to the law of this matter, those Cash Transactions foreseen in the previous article. b) This information is called Cash Transaction Report (RTE) and must be presented with the data indicated in Annex 5 of this Norm, within the first ten (10) days of the following month corresponding to the report, that is, the Cash Transactions carried out during a calendar month will be reported to the competent authority within the first ten (10) calendar days of the following month. c) To fulfill this obligation, the Supervised Entity must include in the RTE those multiple or fractional transactions linked to the same client or beneficiary that in 1 working day reach an amount lower than the threshold established in the law of this matter, but that when added are equal to or greater than said amount, in national or foreign currency. d) The RTE will be presented electronically or magnetically, always complying with the procedures and instructions to ensure quality, security, and strict confidentiality according to this Norm and its Annex 5, which may eventually be modified by the competent authority receiving and analyzing the RTEs according to the law of this matter.
Art. 32.- Exceptions to the RTE a) The Supervised Entity, according to policies approved by its Board of Directors, may exempt certain clients from the RTE, provided that the following conditions concur:
i. That the client is not included in the list of High-Risk Clients foreseen in article 15, literal “b”, numeral “i”, of this Norm.
ii. That the client has maintained an account and commercial relationship with the Supervised Entity for a period greater than twelve (12) consecutive months.
iii. That the client carries out cash transactions with some frequency each month, which exceed the amount or threshold that establishes the law of this matter for its report, for a period greater than twelve (12) consecutive months. Such activity must be congruent with the Customer Identification Program (CIP), compatible with the business line to which they are dedicated, and consistent with the activity in the economic and geographic sectors in which they operate.
iv. That the client has domicile and operates in and from Nicaragua,
v.- That the Supervised Entity has conducted on-site verifications at the client's commercial or industrial establishment, upon authorizing and/or renewing such exception. The results of this verification must be documented. b) In the relationship with its clients exempt from STRs, the Supervised Entity must apply the procedures established in Annex 5, and subject them to monitoring. c) In the preparation of the register of clients exempt from STRs, the following procedures must be applied:
i.- Design an appropriate form or computerized register that allows documenting the authorization and review process of the criteria considered for granting and/or renewing the exception, maintaining a centralized file. ii.- Individually evaluate the exposure and risk of exempt clients, taking into account the purposes described in this Norm, and leave evidence thereof in the aforementioned form or register. The Money Laundering/Counter-Terrorist Financing (ML/CTF) Prevention Administrator must review the assessments performed. iii.- The authorization must include at least two favorable and independent opinions, one of which must correspond to the official who has direct contact with the client. iv.- Supervised Entities must permanently evaluate and monitor the exposure and risk of exempt clients, and at least semi-annually, conduct a formal review of the register of exempt clients to verify if they continue to meet the criteria that allowed their exemption, leaving evidence and comments thereof in the corresponding form or register. v.- The authorization of the renewals of the exceptions, individually considered, must be documented. Art. 33.- Cash Transaction that also qualifies for an STR If a reportable cash transaction also meets characteristics to be reported as an STR, both reports must be submitted separately.
CHAPTER VI
ARCHIVING AND PRESERVATION OF INFORMATION
Art. 34. - Storage of Information and Supporting Documents a) Every Supervised Entity must adopt measures to properly archive, preserve, and safeguard, physically and/or magnetically, all information and documentation derived from the application of its policies, procedures, and internal controls for ML/CTF Prevention; for the period established by the relevant law, counted from the date of finalization or closure of relationships, transactions, and/or accounts with the client.
b) The information and documentation that the Supervised Entity must conserve, retain, and archive physically or electronically, as applicable, must be adequate and sufficient to reconstruct transactional links or individual accounts, and to potentially serve as elements or clues in analyses, investigations, or judicial proceedings regarding ML/CTF. For these purposes, as a minimum, the information to be retained by the Entity must include the following elements:
i.- The Client File and Comprehensive Profile, and all documents and information leading to the true identity of the person with whom the Supervised Entity conducts operations habitually, and the client's history.
ii. Identification data of the client, representative, manager, and beneficiary, including name and address.
iii. Account files and commercial correspondence.
iv. Date, type, and account number used in transactions.
v. Type and currency amount used in transactions.
vi. As applicable, reports and statistics on STRs, including related analysis.
vii. As applicable, reports and statistics on STRs (Cash Transactions Reports).
viii. Statistics on investigations or inquiries related to ML/CTF.
Art. 35. - Availability of information and supporting documentation At the request of the Superintendence or any other competent authority, the Supervised Entity shall have available all information and documentation referred to in this Norm, which must be delivered without delay and without claiming any secrecy, within a reasonable time depending on the complexity and volume of the information required. Art. 36. - Updating and extraction of information a) The Supervised Entity must perform updates of the records and files of the various transactions of its clients. b) The Supervised Entity must maintain a manual and/or computerized system or by any other means, that enables and facilitates the effective extraction of data related to all operations, transactions, accounts, contracts, or services involving the commercialization, transfer, or intermediation of funds or monetary instruments via internal and/or external (electronic, telephone, fax, or other means) channels carried out by the Entity on behalf of or at the request of the client. For banks and financial institutions, this data extraction system must be electronic, without prejudice to other forms in which they may simultaneously develop them.
CHAPTER VII
IMPLEMENTATION AND CONTROL OF THE ML/CTF SIPAR Art. 37. - Implementation and control function Each Supervised Entity, and when applicable, each Financial Group, must effectively develop an Implementation and Control Function directly of the ML/CTF SIPAR, which is developed by the following structure and position:
a) A Money Laundering, Goods or Assets, and Terrorism Financing Prevention Committee, hereinafter ML/CTF Prevention Committee. b) A Money Laundering/Counter-Terrorist Financing (ML/CTF) Risk Prevention Administrator, hereinafter ML/CTF Prevention Administrator. Art. 38. - ML/CTF Prevention Committee Without prejudice to the responsibilities and functions of the Board of Directors, the ML/CTF Prevention Administrator, Management, and Audits on the subject of ML/CTF Prevention, the Supervised Entity must constitute a Money Laundering, Goods or Assets, and Terrorism Financing Prevention Committee (ML/CTF Prevention Committee). Art. 39. - Integration of the ML/CTF Prevention Committee The Board of Directors of the Supervised Entity shall establish the ML/CTF Prevention Committee, by resolution recorded in the Minutes, which shall be integrated and function according to the following conditions:
a) With at least three members of the Board of Directors. b) The following may not be members or act as secretary of the ML/CTF Prevention Committee:
i.- The ML/CTF Prevention Administrator and their Substitute, who report to said Committee. ii.- The Executive Director, General Manager, or principal Executive of the Supervised Entity, nor any other official who holds the status of titular or substitute member of the Board of Directors and who simultaneously exercises executive or managerial positions, roles, or functions in said Entity, who may be summoned to participate as guests regarding the topics to be addressed. c) In its sessions, the ML/CTF Prevention Committee may involve any official of the Supervised Entity, as a guest. d) It must adopt necessary measures to:
i.- Ensure that at least one of the directors comprising it has a broad base of legal, regulatory knowledge, and best practices and international standards for the prevention of ML/CTF risks, as well as knowledge of the operations and businesses of the industry and institution to which it belongs. ii.- Implement a rotation that allows all directors to become familiar with the operations of their institution and become aware of the importance of proactively managing the prevention of ML/CTF risks. e) When any member of the Committee has a personal interest or conflict of interest regarding any matter addressed within the Committee, they must abstain from considering the case, not be present during the discussion, nor influence the related topic, which must be recorded in the Minutes. f) In the case of branches of foreign financial entities, two first-level officials designated by the head office shall be incorporated into said Committee in place of the Board of Directors members. Art. 40. - Functions of the ML/CTF Prevention Committee The functions established below in no way signify that the ML/CTF Prevention Committee will replace the Board of Directors, the ML/CTF Prevention Administrator, Management, or Internal and External Auditors, in the execution of the work performed by each in the subject of ML/CTF Risk Prevention. The Prevention Committee shall have, among others, the following minimum functions:
a) General Functions:
i.- To be a support instance that assists in the execution of the ML/CTF SIPAR. ii.- To plan, coordinate, and ensure effective compliance with the policies approved by the Board of Directors of the Supervised Entity or the highest authority in the country for branches of foreign financial entities.
iii.- To establish its regulations regarding its operation, which shall be approved by the Board of Directors, which as a minimum, regulate its internal organization, operation, frequency of sessions, method of documenting meetings, and communication and follow-up of its agreements. iv.- To meet ordinarily at least once a month, without prejudice to extraordinary meetings that must be held to address matters requiring prompt attention. The ML/CTF Prevention Committee, exceptionally and without prejudice to the following paragraph, may hold sessions without the physical meeting of its members, through communication between them by email, telephone, fax, or any other means of communication that evidences the participation, identification, and decision of the participants. v.- To keep a Minute Book with numbered pages, where known and resolved matters are recorded. These Minutes must be signed by each of the members of the Committee.
vi.- To ensure the execution and compliance with the Institutional ML/CTF Action Plan and Annual Training Plan for the prevention of ML/CTF risks, prepared by the ML/CTF Prevention Administrator and duly approved by the Board of Directors. vii.- To report to the full Board of Directors, quarterly and in writing, the results of its activities so that each and every director is informed of the efficiency and effectiveness of the results obtained or the problems found in the implementation of the ML/CTF SIPAR. This report must contain, as a minimum, the following information:
vii.a.- Statistics of internal sanctions imposed by the Supervised Entity itself for non-compliance with the ML/CTF SIPAR and according to the respective Institutional Code of Conduct, indicating whether they concern employees, officials, or executives. vii.b.- Statistics of sanctions and reprimands imposed by the supervisory authority on the Supervised Entity, for non-compliance related to the ML/CTF SIPAR. vii.c.- Statistics on Suspicious Operations Reports (STR) submitted to the competent authority, by branch, by type of clients, and by type of products and/or services involved.
vii.d.- Statistics on Cash Transaction Reports (STR) submitted to the competent authority, by branch, by type of clients, and by type of products and/or services where cash was most used. vii.e.- Statistics of employees and officials, by type of administrative area, trained on the ML/CTF subject. vii.f.- Summary of findings detected by supervisory authorities, Internal Audit, and/or specific External Audit regarding their ML/CTF SIPAR and the status thereof. vii.g.- Limitations, obstacles, deficiencies, resource needs, and recommendations indicated by the ML/CTF Risk Prevention Administrator. vii.h.- Results of self-assessment, action plan derived therefrom, and resources necessary for its execution. vii.i.- Conclusions. viii.- Coordinate the performance of the self-assessment provided for in article 24, literal d), of this Norm.
ix.- Recommend to the Board of Directors the removal of the ML/CTF Prevention Administrator when their performance does not comply with what is established in this Norm or as a consequence of weaknesses and/or non-compliance resulting from Inspection Reports of the supervisory authorities authorized by law, or in Internal or External Audit reports. x.- The ML/CTF Prevention Committee shall serve as a communication channel between the Board of Directors and the ML/CTF Prevention Administrator of the Supervised Entity, for which said Committee must:
x.a.- Review the monthly reports of the ML/CTF Prevention Administrator on the results and problems or limitations in the implementation of the ML/CTF SIPAR. x.b.- Review the effectiveness and quality of the results of the implementation of the existing system for monitoring accounts and transactions for the detection and timely reporting of suspicious operations. x.c.- Promote the investigation and adoption of international best practices for the prevention of these risks, as well as adapt them to the specific characteristics of the Supervised Entity in accordance with the industry in which it operates. x.d.- Conduct at least one annual technical review of the policies, procedures, and controls for the prevention of these risks, in order to adapt them to its needs and institutional risk profile. x.e.- Review any other new matter related to the ML/CTF SIPAR ordered by the Board of Directors. b) Functions regarding Resolutions, Circulars, and Reports on the subject of ML/CTF Prevention by regulatory and supervisory entities:
i.- Evaluate how the most important problems or weaknesses in its ML/CTF SIPAR found by the Superintendence or other competent authorities have been or are being resolved by the Management of the Supervised Entity. ii.- Review in detail and integrally the results of all final inspection reports issued by the Superintendence regarding its ML/CTF SIPAR, and give special attention by following up on the compliance with all instructions and/or recommendations. iii.- Require the Management of the Supervised Entity to present the action plans adopted by it to attend to and comply with the instructions and/or recommendations of the Superintendence, and evaluate their viability. iv.- Verify that the tasks and deadlines established by the Superintendence for the implementation and compliance with the instructions derived from its Inspection Reports or established through Resolutions, Circulars, and/or Instructions regarding its ML/CTF SIPAR are fulfilled.
c) Functions regarding Audit Reports related to ML/CTF Prevention:
i.- Analyze the content and quality of the recommendations of audit reports on the ML/CTF SIPAR, evaluating any difference between the scope of the work planned by internal auditors or contracted with external auditors, respectively, in relation to that finally carried out, and which had not previously been reported by said auditors or the respective Audit Committee. ii.- Evaluate how the most important problems or weaknesses regarding ML/CTF Risk Prevention, found by Internal and/or External Audit during the course of their respective reviews, and which Internal and/or External Audit was or has been informing Management about, have been or are being resolved by Management, and not wait for them to be reported in a Final Report before addressing them. iii.- Review in detail the content of specific final reports or those referring to other risks but which also contain aspects directly related to the management of ML/CTF risks, issued by Internal and External Audit. iv.- Verify that internal and external auditors formulate and propose suggestions and/or recommendations of quality and technical basis on the subject of ML/CTF Risk Prevention, to improve those areas presenting weaknesses or deficiencies and/or to strengthen the policies, procedures, monitoring, and internal control that constitute the ML/CTF SIPAR, or because they are not being complied with, or are outdated relative to the Entity's own risk profile or regarding legal and/or regulatory requirements.
v.- Evaluate the recommendations to overcome the weaknesses found or to strengthen the ML/CTF Risk Prevention System presented in their respective reports by Internal and External Audit.
vi.- Evaluate the written comments on ML/CTF Prevention by internal or external auditors regarding matters, operations, or transactions of an irregular, unusual, or suspicious nature that they may have noted during the examination of business operations, files, and/or client transactions that warrant reporting to the authority designated in accordance with the relevant Law.
vii.- Evaluate the viewpoints or opinions of internal and/or external auditors regarding the technical competence of the ML/CTF Prevention Administrator and/or their performance in the position.
viii.- Require the Management of the Entity to present the action plans adopted by it to attend to and comply with the suggestions and/or recommendations on ML/CTF Prevention by the auditors, and evaluate their viability.
ix.- Review, through the ML/CTF Prevention Administrator, monthly the compliance with the action plans that Management adopts to remedy and resolve legal and regulatory non-compliance, internal policies and procedures, or weaknesses in the ML/CTF SIPAR. d) Functions regarding Senior Management or Executive Management Levels:
The ML/CTF Prevention Committee may summon or invite Senior Management or Executive Management levels to Committee sessions, whenever it deems necessary, to:
i.- Address and discuss at the appropriate level, particularly with those involved in decision-making, business, processes, and technology, matters concerning the concept of the Entity's policies and procedures related to the ML/CTF SIPAR, as well as compliance with laws and norms issued on the subject by the Superintendence or other competent state institutions. ii.- Obtain Management's viewpoints regarding the recommendations of internal and external auditors on the subject of ML/CTF Prevention internal control policies, and the cost/benefit analysis in the execution of those recommendations. iii.- Directly learn from Management reports on their action plans and the results of their execution to address the instructions of the Superintendence and recommendations of audits on the subject of ML/CTF Prevention. Art. 41. - Money Laundering, Goods or Assets, and Terrorism Financing Risk Prevention Administrator Without prejudice to the specific functions and responsibilities assigned by this Norm to the Board of Directors, the ML/CTF Prevention Committee (as applicable), and Audit; each Supervised Entity must have a Money Laundering, Goods or Assets, and Terrorism Financing Risk Prevention Administrator (ML/CTF Prevention Administrator or ML/CTF Administrator), as the principal executive official for the coordination, administration, and execution of the ML/CTF SIPAR. Art. 42. - Appointment The appointment of the ML/CTF Prevention Administrator must meet the following conditions:
a) Made directly by the Board of Directors of each Supervised Entity, before whose body this official must report and from which it will depend functionally, organizationally, and administratively. b) By Board of Directors Agreement, duly recorded in the Minutes of the corresponding Session.
c) Hired under a permanent labor regime; and with first-level managerial authority. d) With administrative treatment equivalent, in all aspects, to that granted to other first-level managerial bodies that make up the administrative structure of the Supervised Entity. e) Giving notice to the Superintendent, presenting the following documents: Certification of the appointment minutes, resume, notarized declaration by the ML/CTF Prevention Administrator confirming that they are not subject to any of the incompatibilities for the position established in this Norm, notarized reasoned photocopy of the official identity document, notarized reasoned photocopy of the respective academic degree, and photocopy of the supports accrediting training in ML/CTF prevention matters. Art. 43. - Characteristics of the position The position of ML/CTF Prevention Administrator must have the following characteristics:
a) To be exercised ethically, diligently, efficiently, and specialized. b) Invested with administrative, functional, and technical authority and independence necessary to guarantee adequate and effective management and implementation of the ML/CTF SIPAR, in coordination with those in charge of the different strategic business units or technical and operational support. All areas of the Supervised Entity must provide the ML/CTF Prevention Administrator with immediate and effective support and collaboration for the exercise of their functions. c) Exclusive for administering the ML/CTF SIPAR. Exceptionally, the Supervised Entity may also assign its ML/CTF Administrator other functions known as "Compliance" with specific work plans, budget, and resources for this other responsibility. Art. 44. - Case of Financial Group For the case of a Financial Group, the following conditions shall be attended to:
a) Each Supervised Entity that is part of a Financial Group must have its own ML/CTF Prevention Administrator, who may not hold the same position or develop the functions thereof for more than one Entity within the same Group. b) One of the ML/CTF Prevention Administrators within each Financial Group shall be designated as the ML/CTF Prevention Coordinator for the effective global implementation of the ML/CTF SIPAR in all Supervised Entities that are part of the Group and with a view to consolidated supervision. In general, the Prevention Coordinator must be an official of the head office in Nicaragua or of the most significant Supervised Entity in the Group, and in case of uncertainty, of the banking entity if it exists.
c) The Money Laundering/Financing Terrorism (ML/FT) Prevention Coordinator of a Financial Group shall be appointed in the same manner by the Board of Directors of the parent company or the corresponding Supervised Entity.
Art. 45.- Objection
The Superintendent may at any time object to and invalidate, through a reasoned resolution, the appointment of the ML/FT Prevention Administrator, the Substitute, and the ML/FT Prevention Coordinator within the Financial Group.
Art. 46.- Administrative Support Structure
Banks and Financial Institutions must establish and provide an Administrative Support Structure for the work carried out by the ML/FT Prevention Administrator and their Substitute, equipped with the necessary personnel and resources for the adequate implementation of the ML/FT Prevention System (SIPAR ML/FT), including conditions that allow an environment of privacy and confidentiality for the handling of information.
Art. 47.- Professional Profile of the ML/FT Prevention Administrator The person holding the position of ML/FT Prevention Administrator must have, at a minimum, the following requirements:
a) Be a Professional, duly accredited with a Bachelor’s University Degree in Business Administration, Economics, Finance, Public Accounting, Auditing, Law, or Computer Science. It is desirable to possess postgraduate degrees or specializations in these sciences, particularly if they relate to Banking Management, Financial Intermediation, or the Financial, Insurance, Securities, or General Warehouses of Deposit Markets. b) Have at least 3 years of relevant work experience and/or specialized training, duly accredited, within the industry in which the Supervised Entity that appoints them operates, as well as extensive knowledge of the operations and products of the Financial Markets as applicable: Banking Market, Insurance Market, Securities Market, and General Warehouses of Deposit Market, or in areas related to the business of the entity that appoints them.
Art. 48.- Incompatibilities
The following persons may not be appointed as ML/FT Prevention Administrator or ML/FT Prevention Coordinator in the case of a Financial Group:
a) Shareholders, partners, directors, general manager, highest-ranking executive, and related parties to the Supervised Entity, according to banking law. b) The internal and external auditor of the Supervised Entity. c) Those with criminal records for intentional crimes, and those who have been administratively or judicially convicted by a final resolution for serious violations of laws and regulations of a financial nature or related to ML/FT, within or outside Nicaragua. d) Those who have been directors, managers, assistant managers, or high-level officials of a Supervised Entity subject to intervention and/or forced liquidation processes; or when a judicial or administrative resolution by the Superintendent has established or establishes responsibilities, presumptions, or indications linking them to the aforementioned situations.
Art. 49.- Temporary or Interim Substitution a) The Supervised Entity must have officials with the necessary capacity to temporarily substitute the ML/FT Prevention Administrator in case of temporary absence, in accordance with their administrative succession plans. b) The Board of Directors of the Supervised Entity must appoint the Substitute for the ML/FT Prevention Administrator and inform the Superintendent thereof. c) When the substitute is to assume the position of ML/FT Prevention Administrator on an interim basis for more than 45 days, they must inform the Superintendent. The position of ML/FT Prevention Administrator, in the absence of the titular holder, cannot be performed on an interim basis by their substitute for more than 90 days without appointing a new titular holder. d) The Substitute must meet the same qualifications as the ML/FT Prevention Administrator and exercise the same functions in their absence. e) The Substitute for the ML/FT Prevention Administrator of Banks and Financial Institutions must necessarily belong to the staff of the Administrative Support Structure that the ML/FT Prevention Administrator must have.
Art. 50.- Removal a) Any removal, separation, or assignment to another position of the ML/FT Prevention Administrator, their Substitute, or the Coordinator in the case of a Financial Group, must be approved by the Board of Directors of the Supervised Entity through a resolution, and communicated to the Superintendent with an explanation of the reasons motivating the measure. The Superintendent will express their consent or objection to such removal within a period not exceeding 15 business days counted from the presentation of the communication. In the event of resignation of the ML/FT Prevention Administrator or their Substitute, the Supervised Entity will immediately inform the Superintendent. b) The Superintendent, pursuant to the power granted by law, in the exercise of their supervisory function and through a founded resolution, may instruct the Board of Directors of the entity to remove the ML/FT Prevention Administrator, the Substitute, and the ML/FT Prevention Coordinator in the case of a Financial Group.
Art. 51.- Functions of the ML/FT Prevention Administrator The ML/FT Prevention Administrator is the main executive official in charge of the coordination, administration, and execution of the ML/FT Prevention System (SIPAR ML/FT). The ML/FT Prevention Coordinator at the Financial Group level shall have equal responsibility, as applicable. Among others, the ML/FT Prevention Administrator must execute the following functions:
a) General Functions:
i.- Execute the policies, procedures, and internal controls for prevention that integrate the SIPAR ML/FT. ii.- Coordinate the elaboration, implementation, and updating, jointly with the relevant areas of the Supervised Entity, of the ML/FT Manual and the ML/FT Annual Action Plan (POA ML/FT). iii.- Participate in the periodic risk assessment of ML/FT faced by the Supervised Entity and in the development of policies, procedures, internal controls, and matrices for the management of these risks. iv.- Analyze and propose changes to the SIPAR ML/FT and the ML/FT Manual in accordance with laws, regulations, standards, instructions, and recommendations on the matter. v.- Continuously verify compliance with all components of the SIPAR ML/FT, paying greater attention to areas and activities with the highest ML/FT risk. For these purposes, the ML/FT Prevention Administrator must have the respective verification procedures. vi.- Present monthly reports on the compliance of the SIPAR ML/FT to their ML/FT Prevention Committee, or to the structure acting as such in Non-Banking Supervised Entities according to the exceptions provided in this Norm, and when relevant, also to the ML/FT Prevention Coordinator of the Financial Group as applicable. This report must contain, at a minimum, the following information:
vi.a.- Objectives of the report. vi.b.- Limitations and obstacles in its implementation. vi.c.- Results of its implementation. vi.d.- Degree of compliance with procedures by employees. vi.e.- Relevant internal control deficiencies detected. vi.f.- Internal administrative sanctions applied. vi.g.- Statistics of Reports presented. vi.h.- Improvement commitments of the reviewed areas. vi.i.- Follow-up on corrective actions reported in the preceding report. vi.j.- Recommendations for strengthening, improvement, and/or adjustments. vi.k.- Additional resource needs. vi.l.- Conclusions. vii.- Follow up on the implementation of recommendations made by supervisory bodies, internal and external auditors, and other internal control mechanisms, to remedy identified weaknesses and strengthen the SIPAR ML/FT. viii.- Review and monitor possible transactions that the Supervised Entity might have with persons included in special or suspicious lists, national or international, that link them to ML/FT issues and organized crime in general. ix.- Periodically analyze the market segments to which the entity's clients and products belong, in order to identify and know possible ML/FT patterns and trends. x.- Collaborate with the person responsible for the processes, business, and/or marketing area of the entity, in adopting prevention measures on the ML/FT topic prior to the launch of new products and services. xi.- Collaborate with the persons responsible for the Human Resources and Security areas of the Supervised Entity, in the formulation and implementation of the "Know Your Employee" policy. xii.- Participate in the development and execution of programs for awareness, training, and updating on ML/FT risk and its management, on the SIPAR ML/FT, on international standards and best practices in the matter, and on compliance with relevant laws and regulations. xiii.- Keep updated statistics, records, and supports on the application and development of the Supervised Entity's Institutional Training Program on the ML/FT topic. xiv.- Coordinate activities and exchange information with all offices of the Supervised Entity and, when relevant, with the Prevention Coordinator of the Financial Group, as applicable, for the effective implementation of the SIPAR ML/FT in the Entity and in the Group. xv.- Promote fluid communication with all offices of the Supervised Entity, seeking a harmonized and effective effort on the SIPAR ML/FT topic that contributes to embedding a culture of compliance in the Entity. xvi.- Prepare statistics, using its own Databases based on its risks, for the establishment of different prevention parameters that allow interrelating information for better management of monitoring, analysis, and cross-referencing of information, on topics such as: reports to the competent authority, concentration of operations by each market segment, consolidated transaction movement by client, classification of operations by amounts, consolidated movements of all products
and services of a client or group of linked clients, movements recorded by currencies, classification of clients by home addresses, and others that the entity decides to incorporate according to the industry in which it operates and the weighting of its risks. xvii.- Act as the direct and immediate counterpart or liaison before the Superintendence and other competent authorities, to attend and cooperate in everything related to the matter of prevention of ML/FT risks. xviii.- Promote joint and coordinated efforts with its counterparts at the industry level to strengthen and feed back the SIPAR ML/FT in each of the Supervised Entities and at the Financial Group level; and foster self-regulation on ML/FT prevention in the self-interest of the Financial System. b) Functions regarding KYC (Know Your Customer) policies:
i.- Propose and monitor compliance with policies, procedures, and internal controls for risk-based KYC. ii.- Execute and periodically review the SIPAR ML/FT requirements related to the documentation of identification and verification of identity of clients and beneficiaries, and for the purpose and monitoring of the commercial relationship; paying greater attention to sectors with higher ML/FT risk. iii.- Verify the periodic updating of documentation and the Customer Due Diligence (PIC), according to the importance and level of ML/FT risk. c) Functions regarding Detection and Reporting to the competent authority policies:
i.- Participate in the development and implementation of policies, systems, and procedures for the monitoring and early detection of unusual and suspicious activities. ii.- Administer procedures and controls for the security, confidentiality, and analysis of internal reports of unusual and/or suspicious operations, as well as procedures and controls for the preparation, issuance, and presentation of a Suspicious Activity Report (ROS). iii.- Analyze and document unusual and/or suspicious operations detected, in order to evaluate and determine if the issuance of a Suspicious Operation Report (ROS) is appropriate. Optionally, the ML/FT Prevention Administrator may develop this function in coordination with the ML/FT Prevention Committee. iv.- Administer systems and internal controls to monitor, detect, and register cash transactions by the amount or threshold established in the laws on the matter and in this Norm and its 5. v.- Review, prepare, sign, present, and remit to the competent authority, the reports provided for in this Norm, ROS, and RTE (Report of Transactions Exempt from Reporting), and any other report provided for in the legislation on ML/FT prevention; all with due quality, confidentiality, security, and in accordance with the mechanisms and forms established. d) Functions regarding Information Archiving and Conservation policies:
i.- Propose policies and verify the implementation of procedures for the adequate conservation of documents and information in accordance with what is established in this Norm and in the laws on the matter. ii.- Pay special attention to the security of documentation related to reports and analysis of transactions, including ROS, RTE, and information required by competent authorities. e) In the exercise of their functions, the ML/FT Prevention Administrator will always have access to client records and files, and any other information necessary for the fulfillment of their functions. f) It corresponds to the ML/FT Prevention Administrator the responsibility to inform the Superintendent, immediately, about facts that significantly prevent the adequate performance of their work, once such a problem has not been resolved by the Prevention Committee and the Board of Directors of the Entity. g) Without prejudice to all the functions previously stated, the ML/FT Prevention Administrator must immediately inform the ML/FT Prevention Committee and the Board of Directors of the Supervised Entity, and the Superintendence, of facts or findings of significance on any ML/FT situation that implies or requires immediate action.
CHAPTER VIII
ML/FT PREVENTION TRAINING
Art. 52.- ML/FT Training Program
The Supervised Entity must adopt, develop, finance, and implement an Institutional Training Program, to promote culture and awareness in the matter of prevention and detection of ML/FT, which must:
a) Be permanent, continuous, updated, adequate, and adjusted to its operational profile within the industry and according to ML/FT risks. b) Be directed to all its staff, including executives, officials, employees, and any authorized representative, according to the responsibilities and activities performed by each one. c) Have a focus, periodicity, and depth in correspondence with the nature of their respective businesses, in response to their needs and in consideration of their ML/FT risk.
Art. 53.- Minimum Elements of the Program
The Training Program must contain, at a minimum, the following elements:
a) Written policies and procedures that will govern the Training Program both for its design and formulation, as well as for its periodicity, execution, and evaluation. b) Establishment and approval of a specific and identifiable budget line within the general budget, designated annually to guarantee the execution of the Training Program. c) Induction and awareness for all new employees, within a reasonable period after being hired, in order to orient them regarding the ML/FT risks faced by the Supervised Entity, as well as the SIPAR ML/FT and its respective policies, procedures, and internal controls. d) Orientation, according to levels and responsibilities, to executives, officials, managers, operational staff, and other employees, covering the legislation and regulations regulating the ML/FT topic, the Code of Conduct, patterns, signals, or alert indicators, methods or techniques for early detection, analyze, document, and report unusual and/or suspicious activities, as well as guidelines that represent international standards and best practices on the matter. e) Specialized training for employees in all areas of activity of the Supervised Entity, paying greater attention to activities that entail a higher level of risk. For these purposes, the training must be segmented according to each level. f) Training on trends, typologies, schemes, and alert signals of ML/FT according to the nature of their respective businesses, for which they may rely on publications of specialized and reference international organizations and groups on the matter, as well as on examples of simulated cases or really detected internally, guaranteeing in this case secrecy and confidentiality through the non-disclosure of the identity of the clients involved, but rather, starting from the observed typology for preventive training purposes. g) Training on internal controls and procedures to monitor, detect early, and analyze unusual and/or suspicious operations, to document and report suspicious ones, on the prohibition of alerting clients, and on the conservation of records and files related. h) Specialized and high-depth training for the ML/FT Prevention Administrator and all staff of the Administrative Support Structure, or Prevention Area or Unit, as applicable. i) Special training for employees who are transferred to areas or functions within the Entity that entail different ML/FT responsibilities or risks. j) Specific policies to be followed with staff (officials and employees), who in their individual evaluations after each training, do not obtain the minimum approval score or score that each Supervised Entity must establish.
Art. 54.- Statistics and Records on Training
Each Supervised Entity must maintain updated statistics, records, controls, and supports on the application and development of its Training Program, all of which must be maintained for a minimum period of five years, particularly the following information:
a) Location, dates, program, and detailed content and instructors of each training. b) Copy of the contract and curriculum of the instructor if the internal training is provided by an external professional or Firm. c) Detailed attendance list identifying date, event name, participant name and signature, and area to which they belong within the Entity. d) Copy in the personnel file of the certificates, certifications, and supports of the respective trainings received on the ML/FT topic, as well as of the individual evaluations of participants when this applies.
CHAPTER IX
INSTITUTIONAL CODE OF CONDUCT
Art. 55.- Incorporation of the SIPAR ML/FT Topic a) Each Supervised Entity must expressly incorporate within its Institutional Code of Conduct the commitment of its Board of Directors, its highest authorities, and its general staff, to develop its business with honesty, integrity, and ethics, expressly manifesting in said Code the position of the Supervised Entity regarding ML/FT risks, promoting culture and awareness to prevent them. b) The Institutional Code of Conduct that includes the commitment on the ML/FT Prevention topic must be approved by the Board of Directors and be made known, under signed receipt, to all partners, executives, officials, employees, and any authorized representative by the Supervised Entity. In the personnel file of each employee, it must be recorded that they have received, read, and understood the Code of Conduct.
Art. 56.- Minimum ML/FT Aspects of the Code of Conduct Every Supervised Entity must guarantee that its Institutional Code of Conduct contemplates and includes, at a minimum, the following:
a) Delineate the risks that ML/FT pose to the integrity, reputation, and stability of the Supervised Entity and of the employees themselves. b) Include the declaration of principles adopted by the Supervised Entity for the prevention and early detection of ML/FT. c) Express the responsibility and commitment of the Board of Directors, in the adoption of policies, controls, and guidelines that preserve the integrity of the Supervised Entity and its employees on this topic. d) Express the legal and economic consequences that ML/FT risks would imply for the integrity, reputation, stability, continuity of business, and future of the Supervised Entity, as well as for its own executives, officials, and employees in general. e) Establish internal sanctions, and their graduality, for non-compliance with the Institutional Code of Conduct on the specific topic of ML/FT Prevention obligations. f) Establish verification mechanisms to periodically ensure that this Code is duly communicated, known, and clarified in its content and scope.
CHAPTER X
INDEPENDENT AUDIT ON THE SIPAR ML/FT
Art. 57.- Independent Audit
The Supervised Entity must implement an Internal and External Audit Program that guarantees the independent review of the compliance, effectiveness, and efficacy of the SIPAR ML/FT, and be carried out at least once a year, in all its areas of operation, including branches, subsidiaries, affiliates, representation offices, and other members of its Financial Group that operate within or outside the country, when the latter is applicable.
Art. 58.- Minimum Audit Functions
The performance of the Independent Audit of the SIPAR ML/FT must be based on the risks inherent to the most significant and highest ML/FT risk activities of the Supervised Entity, must be developed through personnel with the appropriate technical skills and adequately trained on these risks; and as a minimum and to the extent applicable according to the industry to which it belongs, must comply with the following functions:
a) Internal Audit Functions: The Internal Audit program related to the SIPAR ML/FT, its scope, focus, and frequency, must start from an ML/FT Risk Matrix that Internal Audit must perform and update annually. The procedures and techniques of
auditing that the Internal Audit Unit employs for the review of ML/TF risks, must be clearly and expressly stated in the respective Internal Audit Manual and must first comply with the provisions of this Norm, related Norms, and other instructions that the Superintendent may issue, and complementarily with what is established in generally accepted auditing standards and international internal auditing standards.
The Internal Audit Unit, within its Annual Plan referred to the SIPAR ML/TF topic, will evaluate and review at a minimum the following, and must report to the ML/TF Prevention Committee and the Audit Committee, including results and recommendations that add value in strengthening it:
i.- The compliance of the Entity and its directors, officials, and employees in their daily conduct, regarding the legal, regulatory, and Code of Conduct provisions on which the SIPAR ML/TF is based.
ii.- The compliance and correct application, including determining the sufficiency, effectiveness, efficiency, and results achieved from the implementation of the policies, procedures, and controls that support the SIPAR ML/FT and contained in the AML/FT Manual, and proposing recommendations for their improvement or modification.
iii. The sufficiency, effectiveness, gaps, and risks of the internal control systems of the SIPAR ML/FT.
iv.- The content, scope, coverage, frequency, and compliance of the Institutional Training and Awareness Program for the prevention of ML/FT risks, as well as the sufficiency of the budget allocation for its execution.
v.- The specialized monitoring procedures and systems, and determine if these allow the Entity to perform adequate, timely, and effective monitoring of transactions and all business relationships with its clients based on risk, to detect early, analyze, document, and report unusual and/or suspicious operations.
vi.- The management of prevention of ML/FT risks in the different products, services, activities, clients, and geographic areas, all in attention to the highest level of risk.
vii.- Representative samples of clients to verify compliance with the legal and regulatory provisions applicable to ML/FT risks, as well as the Entity's policies and procedures for client knowledge and identification, conducting retrospective reviews and analysis of transactions in their accounts and/or business relationships to establish if there are unusual activities derived from the lack of correspondence between the transactional activities declared by the client in their Profile regarding their actual activities and which have not been reported.
viii.- Representative point samples of clients and/or transactions or activities that have previously been detected, subject to alert signals, and investigated by the Entity, to which, after their documented review and analysis, it resolved that they were not reportable, with the purpose of establishing the quality and effectiveness of the process followed and the evidence on which it based its decision not to report them.
ix.- Evaluation of the quality of the measures implemented by the Supervised Entity to ensure the confidentiality, reliability, security, effectiveness, and timeliness of the process for the early detection and internal communication of unusual activities, as well as the presentation and sending of Suspicious Transaction Reports (STRs) to the competent authority.
x. Managerial information systems, including reports on unusual and/or suspicious transactions.
xi.- Evaluation of the management of the ML/TF Prevention Committee and the ML/TF Prevention Administrator in attention to their respective functions established in this Norm.
xii.- The adequacy of the methodologies, procedures, and tools implemented by the Entity for the elaboration and periodic update of its ML/FT risk matrix and diagnosis.
xiii.- The effectiveness of internal controls for the prevention of ML/FT risks, proposed and designed in the stage prior to the launch of a new operation, product, or service.
xiv.- Evaluation of the Reports and Reports to the ML/TF Prevention Committee presented by the ML/TF Risk Administrator, related to the results, limitations, or obstacles obtained in the implementation of the SIPAR ML/FT and present recommendations that add value in strengthening it.
xv.- The Sufficiency and effectiveness of the institutional AML/FT POA and budget for the prevention of ML/FT risks and the results of its execution.
xvi.- The compliance with other aspects regarding ML/FT risks that the Superintendent determines and instructs.
b) External Audit Functions: The SIPAR ML/FT must be audited at least annually by an External Auditor or External Audit Firm, and independent of the Supervised Entity, that is duly registered with the Superintendency. For the execution of this External Audit, the Entity must guarantee that the following is carried out:
i.- Define previously, taking into account the qualified opinion of its ML/TF Prevention Administrator, the terms of reference with the minimum basic scopes required for potential External Auditors to present their technical offers that facilitate the comparability and quality analysis among bidders.
ii.- Conduct a written comparative analysis of the technical offers received in relation to the objectives and scopes determined in the terms of reference for the review of the SIPAR ML/FT.
iii.- The selected External Auditor must include in its scopes for this review, the terms of reference with the minimum basic scopes proposed in its technical offer and susceptible to expansion by the Supervised Entity, which will form part of the contract governing their services.
iv.- Require and obtain the resume with the evidence that allows it to know in advance the technical and specialized competencies on these risks of the External Auditor or the personnel of the Firm that will audit the management of ML/FT risks.
v.- In the scope of the terms of reference to be included as an integral part of the contract, and in attention to its own risks, it must include as a minimum, the evaluation and review of the following:
v.a.- The effectiveness of the work of the Internal Audit Unit in relation to the SIPAR ML/FT.
v.b.- The Entity's compliance with the minimum requirements of the laws and norms applicable for the prevention of ML/FT risks.
v.c.- The monitoring procedures, systems, and reports, procedures for detection, investigation, analysis, and reporting of unusual and/or suspicious activities, as well as computer systems and measures for their security and backup.
v.d.- Through representative tests, the scope, quality, effectiveness, and efficiency of the SIPAR ML/FT, as well as whether it adjusts to the Entity's risk profile.
v.e.- Through representative tests, the scope, quality, effectiveness, and efficiency of the procedures established for the management of record retention both physically and electronically that are required in this Norm.
v.f.- Through representative tests, the effectiveness of the role of the Board of Directors in the implementation of the SIPAR ML/FT, as well as the effectiveness and timeliness with which directors are informed about the results and/or obstacles in its implementation.
v.g.- The compliance with the instructions and/or recommendations on the ML/FT prevention topic that the Superintendent or the previous Internal and External Audits have formulated prior to the date of the current Audit.
v.h.- The results achieved by the Entity in its ML/FT prevention work, determine its gaps, report significant facts, and present the pertinent recommendations to adapt and strengthen the SIPAR ML/FT.
v.i.- The compliance with other aspects regarding ML/FT risks that the Superintendent determines and instructs.
TITLE III
PARTICULAR AND EXCEPTION PROVISIONS
CHAPTER I
FINANCIAL GROUPS AND CONSOLIDATED ML/FT RISK MANAGEMENT Art. 59.- ML/FT Risk Management a) Supervised Entities that are part of a Local Financial Group must formulate and implement the SIPAR ML/FT in a consolidated manner at the level of said Group, complying at a minimum with the following, as applicable:
i.- The ML/FT risk management must be applied in a consolidated manner by the Controlling Company or Responsible Coordinator of the Group, adapting it to the specific requirements of each member of it, in accordance with the applicable provisions of this Norm, according to the business line, sector, and country where they operate.
ii.- It is the duty of the Controlling Company or Responsible Coordinator of the Group, to ensure the existence and implementation at the Group level of Systems and Procedures effective and in accordance with the technology used by its members in the provision of the different products and services they offer according to their business line; to perform in a consolidated manner the Monitoring of Accounts and Transactions of their clients, based on the ML/FT risk level. These Monitoring Systems must allow, at any time, to know the relevant information about clients, their accounts, and transactions, at least at the following levels:
ii.a.- Individually by each Supervised Entity member of the Financial Group.
ii.b.- At the level of the Local Financial Group in Nicaragua.
iii.c.- By Cross-Border Financial Group.
b) Each member of the Group must implement policies and procedures, as their Boards of Directors dispose, to exchange with other members of the Group the relevant information about their clients, accounts, and transactions when these maintain or wish to maintain business relationships with several members of the same, observing the legal provisions on security, secrecy, privacy, and confidentiality of information.
c) When any member of the Financial Group operates in another country in which the legal and/or regulatory requirements for the prevention and detection of ML/FT differ from those established in Nicaragua, said member must apply the measures that result in the strictest among the different jurisdictions in accordance with international standards. In the case that the legal requirements of other countries where some member of the Group operates prohibit or prevent the application of the SIPAR ML/FT, such situation must be communicated without delay to the Controlling Company or Responsible Coordinator of the Group and to the Superintendency.
d) For the acceptance of the country in which institutions that are members of the Financial Group, including the Controlling Company, may be constituted or domiciled, or invest in foreign financial institutions; it will be conditioned, among other requirements, that such countries have laws, regulations, or other provisions oriented to prevent money laundering from illicit activities and terrorism financing.
Art. 60.- Internal Audit of the Controlling Company The Internal Audit Unit of the Controlling Company, as appropriate, must incorporate in its Annual Work Plan, the evaluation of practices among members of the Financial Group, for compliance with the provisions established in laws and norms on ML/FT prevention in accordance with the respective countries in which they operate.
Art. 61.- Consolidated External Audit of the Financial Group For the purposes of an integral, independent, uniform, and consolidated view of the effectiveness and efficiency of the SIPAR ML/FT at the Financial Group level, the Supervised Entities that are members of the same, must ensure that the External Auditor who performs the Audit on the respective SIPAR ML/FT in each of them is the same for all members of the Group.
CHAPTER II
INSURANCE MARKET
Art. 62.- Applicability of the AML/FT Norm in the Insurance Market a) To Insurance and/or Reinsurance companies, and other companies operating in the Insurance Market provided for in special legislations; the provisions provided for in Titles I, II, and III (Chapter I) of this Norm are applicable; with the specific exceptions and particularities established in this Chapter, and in consideration of the nature and business line of their own businesses.
b) Regarding this Norm, Insurance Intermediaries, whether individual brokers, brokerages, brokerage societies, agents, agencies, and subagents; are only obligated to:
i.- Have an AML/FT Manual based on which they must develop the following policies:
i.a.- KYC Policy consistent with those applied by the Insurance and/or Reinsurance companies with which they are linked.
i.b.- Policy on Archiving and Preservation of Information, available to the competent authority.
ii.- Develop a permanent Training Program on the topic of ML/FT prevention, which must include the obligation to receive the trainings to which they are summoned by the Insurance and/or Reinsurance companies with which they have business links.
Art. 63.- Exceptions and Particularities
Insurance and/or Reinsurance companies, and other companies operating in the Insurance Market provided for in special legislations:
a) Must apply their SIPAR ML/FT when it comes to transactions or commercial relationships with clients and beneficiaries that involve the sale and placement of insurance contracts or policies in general. If in addition to insurance, they provide other related products or services, they must also adjust and apply their SIPAR ML/FT to these other businesses in accordance with what is authorized by law.
b) They are exempt from constituting the ML/TF Prevention Committee, whose functions in this case must be assumed, according to their nature, by the Audit Committee and/or by the Risk Committee and/or by the respective Board of Directors. In no case can the General Manager and the AML/FT Administrator and their Substitute of the Supervised Entity, participate as members nor as secretaries of the Committee that performs the functions of AML/FT.
c) At the formal request of the Supervised Entity, the Superintendent may authorize that the functions of the ML/TF Prevention Administrator fall to an official who simultaneously holds another position within the same, provided that the following requirements concur:
i.- That the Entity has a national payroll of fewer than 50 employees; or, as can be determined, said Entity has a small, reduced, or lesser organizational structure, capital, funds, client portfolio, and volume of activities.
ii.- That the AML/FT POA, functions, objectives, responsibilities, and budget as ML/TF Prevention Administrator, are clearly differentiated from the other tasks that the same official has assigned according to their other position.
iii.- That said other position and functions do not represent an obstacle or conflict of interest for the effective exercise of their work as ML/TF Prevention Administrator.
iv.- That the proposed official is not subject to the incompatibilities established for said position in this Norm.
d) The Substitute of the ML/TF Prevention Administrator may also simultaneously hold another position within the Entity, provided that this does not represent an obstacle or conflict of interest for the effective exercise of the substitution.
e) The Supervised Entity in its own interest of implementing an effective SIPAR ML/FT that corresponds to its ML/FT risk profile, size, number of clients, volume, and complexity of its products and services; must consider establishing and providing an Administrative Support Structure for its ML/TF Prevention Administrator.
f) In the Insurance Market, the following provisions on CDD established in this Norm do not apply:
i.- Literal "d", numeral "iii" of article 8.
ii.- Literal "l" of article 10.
iii.- Literal "n" of article 10 for the case of Mandatory Insurance for Motor Vehicles established in the law on the matter.
g) When the insured acquires a policy on the occasion of a main contractual relationship with a banking entity or in "bank-insurance" operations, Insurance and/or Reinsurance companies may obtain from the bank the relevant and updated information about the client, subject to what is provided in article 12, literal "h" of this Norm. This provision is without prejudice to the fact that each Supervised Entity, considered individually, is obligated to apply CDD to its clients in the course of their respective businesses. No entity may fail to comply with this responsibility under the argument that another entity has already done so.
Art. 64.- Subsequent Identification and Verification a) Operators of the Insurance Market are exempt from the general principle of obligation to identify and verify the beneficiary of the policy prior to or during the validity of the contract. For purposes of their identification and verification, the person designated in the policy by the insured, policyholder, or applicant for insurance, as the holder of the indemnity rights established in said document, is considered as the beneficiary.
b) Verification may be made subsequently, provided that:
i.- What is provided in articles 6, literal "l", and 11, literal "g", of this Norm is complied with.
ii.- The identification and verification is finalized before any payment to the beneficiary under the policy, or before the date on which the beneficiary can exercise rights created or acquired under the policy.
iii.- The person of the beneficiary is different from the person of the insured, policyholder, or applicant for insurance.
c) These exceptions may be applied in the following cases:
i.- Policies for pension and retirement plans.
ii.- Payment of insurance premium before the application is processed and the relationship accepted, provided that the payment is not in cash.
iii.- Contracting that does not include face-to-face interviews with the client at the time of establishing a relationship.
Art. 65.- Enhanced CDD
Without prejudice to what is provided in this Norm in its general part for enhanced CDD, all operators of the Insurance Market, including Insurance intermediaries, must gather additional information about the client according to their risk profile in the following situations:
i.- Bearer Insurance Policies, that require payment to the bearer, or in cases where the rights to receive benefits or payments under the policy could be endorsed to other persons without the knowledge or authorization of the Insurance Company.
ii.- Agreements, loans, or sales on or of the benefits under life insurance policies to other persons or companies that will be paid after the death of the insured. These policies or arrangements must be considered equivalent to endorsable policies under the previous clause. In these cases, the counterparty or buyer of the benefits and the beneficiaries thereof must be identified and verified.
Art. 66.- Simplified CDD a) In addition to what is provided in art. 17, literal "d", of this Norm in its general part, all operators of the Insurance Market, including Insurance intermediaries, in consideration of their own risks and by reason of the business line of their businesses, may apply a simplified CDD in the following cases:
i.- In policies with annual premiums lower than or equal to one thousand United States dollars (U$ 1,000.00) or its equivalent in national currency or any other currency.
ii.- In Mandatory Insurance for Motor Vehicles established in the law on the matter.
iii.- In policies for pension, retirement, and retirement plans, provided that there is no surrender clause and the policy cannot be used as collateral.
b) In the cases provided for in the previous literal, it will be sufficient to fill out the insurance application, as well as note the name, number, and type of identity document of the person who contracts the insurance; having at hand the respective legal, official, valid, reliable, and undeniable documents in accordance with the laws on the matter.
Art. 67.- Relationship of the Insurance and/or Reinsurance company with Insurance Intermediaries. a) The SIPAR ML/FT of Insurance and/or Reinsurance companies, and other companies operating in the Insurance Market provided for in special legislations; must contain specific policies, procedures, and controls to govern the relationship between them and their Insurance Intermediaries, and referred to, at a minimum, to the following aspects:
i.- To be able to obtain information about the identity of clients and beneficiaries of policies and verify it.
ii.- To be able to obtain information about the purpose and expected nature of the relationship with the client or beneficiary.
iii.- To be able to monitor the commercial relationship with High-Risk qualified clients.
iv.- To be able to know and make recommendations to the AML/FT Manual of Insurance Intermediaries, as well as to know the degree of compliance with the obligations that these have according to article 62, literal "b", of this Norm.
b) Insurance and/or Reinsurance companies, and other companies operating in the Insurance Market provided for in special legislations:
i.- Are the main and ultimate responsible parties for implementing their SIPAR ML/FT, even if the contracting of policies with the client is carried out through Insurance Intermediaries, without prejudice to the responsibilities of the latter established in this chapter.
ii.- Must develop a strict "Know Your Insurance Intermediary" policy that must be recorded in their respective AML/FT Manuals.
iii.- Must not maintain business or work relationships with Insurance Intermediaries that are not authorized by the Superintendency and/or that do not comply with the obligations provided for in literal "b" of article 62 of this Norm.
iv.- Must include Insurance Intermediaries, regardless of the contractual nature that links them, in their training and awareness programs on the topic of ML/FT Prevention.
v.- Must make known to their Insurance Intermediaries, the criteria they use to determine and apply differentiated CDD policies, including the additional requirements that based on their ML/FT risk evaluations they implement in their enhanced CDD policies.
vi.- Must seek common strategies and congruence between their CDD policies and those developed by Insurance Intermediaries.
CHAPTER III
SECURITIES MARKET
Art. 68.- Applicability of the AML/FT Norm in the Securities Market Operators participating in the Securities Market, whether natural or legal persons, such as Stock Exchanges, Securities Clearing Houses, Securities Compensation and Settlement Societies, Stock Brokers, and Stock Brokerage Agents and
Investment Fund and Securitization Administrators; must have the necessary means to effectively and efficiently carry out the monitoring and control of the provisions of this Regulation, to which the provisions set forth in Titles I, II, and III (Chapter I) apply, with the specific exceptions and particularities established in this Chapter, and considering the nature and scope of their own business.
Art. 69.- Exceptions and Particularities
The following exceptions and particularities are established for the Securities Market:
a) The present AML/CTF Regulation does not apply to Securities Issuers, without prejudice to what is provided in special laws on the matter. b) Stockbrokers are only obligated to develop the "Due Diligence for Customer Knowledge" (DDC) policy, as instructed by the respective Stock Exchange, which is ultimately responsible for having and executing its own AML/CTF SIPAR, including the permanent training it must offer to its Stockbrokers on the subject of AML/CTF Prevention. c) Stock Exchanges, based on their own supervision and regulation functions in the Securities Market according to the relevant law, must have their own AML/CTF SIPAR, and must apply DDC policies to Stock Exchanges and their Agents, and other entities provided for; and furthermore, they must ensure that these entities comply with the requirements of this Regulation to the extent applicable to them, including them in their training and awareness programs on the subject of AML/CTF Prevention. d) Operators participating in the Securities Market are exempt from constituting the AML/CTF Prevention Committee, whose functions in this case must be assumed, according to the nature of said functions, by the Audit Committee and/or by the Risk Committee and/or by the respective Board of Directors. In no case may the General Manager and the AML/CTF Administrator and his/her Substitute, of the Supervised Entity, participate as members or as secretaries of the Committee that performs the AML/CTF functions. e) Upon formal request of the Supervised Entity, the Superintendent may authorize that the functions of the AML/CTF Administrator fall to an official who simultaneously holds another position within the same entity, provided that the following requirements are met:
i.- That the Entity has a national payroll of fewer than 50 employees; or, as may be determined, said Entity has a small, reduced, or lesser magnitude organizational structure, capital, funds, client portfolio, and volume of activities.
ii.- That the AML/CTF POA, functions, objectives, responsibilities, and budget as AML/CTF Administrator, are clearly differentiated from the other tasks assigned to the same official according to his/her other position.
iii.- That said other position and functions do not represent an obstacle to the effective exercise of his/her work as AML/CTF Administrator.
iv.- That the official is not subject to the incompatibilities established for said position in this Regulation.
f) The Substitute for the AML/CTF Administrator may also hold another position within the Entity, provided that this does not represent an obstacle to the effective exercise of the substitute role.
g) The Supervised Entity, considering its risks, the size, volume, and complexity of its products and services, the number of clients, and according to its needs to implement the AML/CTF SIPAR; may optionally establish and provide an Administrative Support Structure for its AML/CTF Administrator.
Art. 70.- Operation Control
Stock Exchanges, Securities Clearinghouses, and Securities Compensation and Settlement Societies; must establish an alert system organized based on elements such as types of clients, markets, negotiated amounts, frequencies, and prices, which allow them to detect unusual behaviors or operations in the stock market negotiations being carried out and communicate this circumstance to the Stock Exchanges and their Agents, through which these are effected, in order to make the corresponding clarifications and evaluations, and to submit, as applicable, the respective ROS to the competent authority. If the unusual activity detected is classified as suspicious from the start, it shall be the Entities mentioned at the beginning of this paragraph that must submit the respective ROS to the competent authority.
CHAPTER IV
GENERAL WAREHOUSE MARKET
Art. 71.- Applicability of the AML/CTF Regulation in the General Warehouse Market General Warehouses, as credit auxiliaries; must have the necessary means to effectively and efficiently carry out the monitoring and control of the provisions of this Regulation, to which the provisions set forth in Titles I, II, and III (Chapter I) apply, with the specific exceptions and particularities established in this Chapter, considering the nature and scope of their own business.
Art. 72.- Exceptions and Particularities
The following exceptions and particularities are established for General Warehouses:
a) They are exempt from applying the AML/CTF SIPAR provided for in this Regulation, regarding the operations they carry out as Customs Deposits; without prejudice to the measures that the respective authority may instruct regarding this matter.
b) They are exempt from constituting the AML/CTF Prevention Committee, whose functions in this case must be assumed, according to the nature of said functions, by the Audit Committee and/or by the Risk Committee and/or by the respective Board of Directors. In no case may the General Manager and the AML/CTF Administrator and his/her Substitute, of the Supervised Entity, participate as members or as secretaries of the Committee that performs the AML/CTF functions.
c) Upon request of each General Warehouse, the Superintendent may authorize that the functions of the AML/CTF Administrator fall to an official who simultaneously holds another position within the Entity, provided that the following requirements are met:
i.- That the Entity has a national payroll of fewer than 50 employees; or, as may be determined, said Entity has a small, reduced, or lesser magnitude organizational structure, capital, funds, client portfolio, and volume of activities.
ii.- That the AML/CTF POA, functions, objectives, responsibilities, and budget as AML/CTF Administrator, are clearly differentiated from the other tasks assigned to the same official according to his/her other position.
iii.- That said other position and functions do not represent an obstacle to the effective exercise of his/her work as AML/CTF Administrator.
iv.- That the official is not subject to the incompatibilities established for said position in this Regulation.
d) The Substitute for the AML/CTF Administrator may also hold another position within the Entity, provided that this does not represent an obstacle to the effective exercise of the substitute role.
e) The Supervised Entity, considering its risks, the size, volume, and complexity of its products and services, the number of clients, and according to its needs to implement the AML/CTF SIPAR; may optionally establish and provide an Administrative Support Structure for its AML/CTF Administrator.
CHAPTER V
REPRESENTATION OFFICES AND "SECOND-TIER" BANKS
Art. 73.- Applicability of the Regulation to Representation Offices Any Representation Office of a Foreign Financial Entity authorized by the Superintendency must have an AML/CTF SIPAR and its respective AML/CTF Manual, and comply, where applicable, with the provisions set forth in Titles I, II, and III (Chapter I) of this Regulation, with the specific exceptions and particularities established in this Chapter, considering the nature and scope of their own business that they are authorized to carry out in Nicaragua.
Art. 74.- Application of the AML/CTF SIPAR regarding its jurisdiction of origin a) When there are significant differences between the laws, regulations, norms, and measures on AML/CTF prevention applied by the parent company of a Representation Office according to its jurisdiction of origin, and those that said Office must implement in Nicaragua; it must apply the stricter measures, in addition to the guidelines to be followed at the Financial Group level.
b) Without prejudice to the previous provision, the AML/CTF SIPAR and the respective AML/CTF Manual of a Representation Office, in addition to being based on the AML/CTF risk matrices of its jurisdiction of origin; must also adjust to and comply with the Laws and Norms of Nicaragua.
Art. 75.- Intensified DDC
The Representation Office must apply Intensified DDC to activities and clients considered high risk, including loans or other investments when the guarantee consists of property, deposit accounts, or guarantees located or issued in or from abroad.
Art. 76.- Exceptions and Particularities
For Representation Offices of Foreign Financial Entities, the following exceptions and particularities are established:
a) They are exempt from applying the provisions provided for the AML/CTF Prevention Committee, for the AML/CTF Administrator, and for the Administrative Support Structure; without prejudice to the fact that they must have their own AML/CTF Manual and execute the respective AML/CTF SIPAR to the extent applicable to them; in addition to maintaining fluid communication, coordination, and monitoring with the one acting as AML/CTF Administrator in their parent companies, to which they are obligated.
b) Only in the case of Representation Offices, the reports provided for in this Regulation and in the relevant law, will be submitted through the legal representative or main executive accredited in Nicaragua by said entities.
Art. 77. – "Second-Tier" Banks
For the so-called "Second-Tier" Banks, which are supervised institutions authorized and dedicated to raising resources through loans from international financial development institutions; the classification of "Second-Tier" Bank will be granted by the Superintendency, for which the following exceptional treatment is established:
a) This Regulation does not apply to them in cases where the funds thus raised are invested or placed in loans for predetermined purposes to banks or other financial entities operating in Nicaragua under the supervision of the Superintendency.
b) This Regulation does apply to them where pertinent, and with the exception of the provisions provided for the AML/CTF Prevention Committee, when the entities receiving the funds referred to in the previous letter are outside the supervision of the Superintendency. For this case, they must have their AML/CTF Risk Administrator under the same circumstances provided for in this Regulation for the Insurance, Securities, and Warehouses Markets; and they may also, optionally, establish and provide an Administrative Support Structure for said Administrator.
CHAPTER VI
SPECIAL REGIME FINANCIAL ENTERPRISES
Art. 78.- Entities under Consolidated Supervision Entities that, according to banking law and for the purposes of the consolidated supervision developed by the Superintendency, are classified as Special Regime Financial Enterprises; must comply with this Regulation to the extent applicable to them and have and implement their respective AML/CTF SIPAR and Prevention Manual in attention to the scope of their business and the weighting of their risks; without prejudice to what is provided in special laws and in regulations and instructions issued by the competent authorities.
Art. 79.- Exemptions
Special Regime Financial Enterprises are exempt from applying the provisions provided for the AML/CTF Prevention Committee; but they must have their AML/CTF Risk Administrator under the same circumstances provided for in this Regulation for the Insurance, Securities, and Warehouses Markets; and they may also, optionally, establish and provide an Administrative Support Structure for said Administrator.
TITLE IV
TRANSITIONAL AND FINAL PROVISIONS
SINGLE CHAPTER
Art. 80.- Modification and/or Inclusion of Annexes The Superintendent is empowered to modify and/or invalidate the Annexes of this Regulation, as well as include others, as he deems necessary to strengthen his supervisory work in the prevention of AML/CTF risks.
Art. 81.- Graduality for the application of some particular provisions of this Regulation a) The following deadlines are established for the application of the provisions of this Regulation indicated below, as they apply to each Supervised Entity:
| Articles | Regulated Matter | Deadline |
|---|---|---|
| 6 (“g”) | AML/CTF Prevention Committee | 3 months, counted from the entry into force of the AML/CTF Regulation. |
| 6 (“f”), 46 and 49 (“d”) | Administrative Support Structure, and the Substitute for the AML/CTF Administrator | 3 months, counted from the entry into force of the AML/CTF Regulation. |
| Annex 5 | Automated Dispatch of STR | 3 months, counted from the entry into force of the AML/CTF Regulation. |
| 4 (“b”) | AML/CTF SIPAR Manual | 3 months, counted from the entry into force of the AML/CTF Regulation. |
| 8 (letter “i”) and 24 | AML/CTF Risk Matrices | Until December 31, 2009. |
| 6 (“p”) and 11 (“ñ”) | Implementation of Specialized Systems for monitoring and for technological risk management. | Until December 31, 2009. |
| 16 (“ñ”, “ii”) | Application of Intensified DDC for existing clients at the date of entry into force of the AML/CTF Regulation. | Until December 31, 2009. |
| 6 (“ñ”), 12 (“h”), 26 (“e”), 44 (“c”) and Chapter I of Title III | Application of AML/CTF SIPAR at the Local Financial Group level. | Until December 31, 2009. |
b) Except for the provisions indicated in letter “a” of this article, the rest will have full application from the validity of this Regulation.
Art. 82.- Repeals
The following provisions are repealed:
a) The Regulation for the Prevention of Money Laundering and Other Assets, (Resolution: CDSIBOIF-197-2-MAR01-2002), published in La Gaceta, Official Journal, No. 71 of April 18, 2002, and its subsequent reforms; with the exception of its Chapter VI and its respective Annex, which will remain in force temporarily until the expiration of the deadline provided for in article 81 letter “a” of this Regulation regarding the Automated Dispatch of STR.
b) The Regulation on Compliance Officers (Resolution: CD-SIBOIF-422-1-MAY23-2006), published in La Gaceta, Official Journal, No. 117 of June 16, 2006.
c) Article 16, letter “k”, numeral “4”, of the Regulation on Internal Control and Audit (Resolution CD-SIB-155-3-ABR26-2001), published in La Gaceta, Official Journal, No. 116 and 118 of June 20 and 22, respectively, of 2001.
d) Any other provision or instruction that opposes or contradicts this Regulation, issued by the Superintendency through Norms, Resolutions, and Circulars.
Art. 83.- Validity
This Regulation will enter into force from its complete publication in La Gaceta, Official Journal.
ANNEXES
AML/CTF REGULATION
Annex 1: General Concepts for the Application of the AML/CTF Regulation
Annex 2: Formats for the Comprehensive Customer Profile (PIC)
i.- For the Banking and Financial Market ii.- For the Insurance Market iii.- For the Securities Market iv.- For the General Warehouse Market
Annex 3: Alert Signals and Indicators
i.- Common to all Supervised Entities ii.- Specific for the Banking and Financial Market iii.- Specific for the Insurance Market iv.- Specific for the Securities Market v.- Specific for the General Warehouse Market
Annex 4: Format and Instructions for completing, presenting, and sending the Suspicious Transaction Report (STR)
i.- Format for the STR ii.- Instructions for the presentation and dispatch of the STR
Annex 5: Manual and Format for the automated presentation of Cash Transaction Reports (CTR)
i. Conceptual Aspects (Data Flow)
ii. Types of Sendings
iii. File Formats According to Type of Sending
iv. SIBOIF Response Files
v. Annexed Catalogs
vi. User Manual for Loading the Cash Transaction Report - AML Data
vii. Formats with their Instructions
viii. GNUPG Manual
Annex 1: General Concepts for the Application of the AML/CTF Regulation
According to article 3 of the AML/CTF Regulation and for the purposes thereof, the following general concepts are established, which become part of the same:
AML/CTF Risk: It is the inherent risk that Supervised Entities have and face permanently due to their very nature of business; of being used, consciously or unconsciously, for Money Laundering, Goods or Assets; and for Terrorist Financing.
Residual or Net AML/CTF Risk: It is the level of AML/CTF risk resulting after applying controls for its prevention and mitigation.
AML/CTF Associated Risks: They are the risks through which AML/CTF risk can materialize, being these: legal, compliance, reputational, operational, technological, personnel, audit, and contagion risks.
AML/CTF Risk Factors: They are the inherent circumstances and characteristics, at a minimum, of clients, products, distribution channels, and jurisdictions, that increase the probability that the Supervised Entity is used, consciously or unconsciously, for Money Laundering, Goods or Assets; and for Terrorist Financing. These risk-generating factors allow determining, analyzing, and constructing the respective AML/CTF Risk Matrix.
Risk Matrix: It is the analytical tool that each Supervised Entity must prepare and update periodically to determine its degree of exposure to AML/CTF risk, and determine the existing gaps between its current AML/CTF Prevention programs, versus legal, regulatory, and normative requirements, and according to best practices, for the performance of Due Diligence in the knowledge of its clients, at its different levels of escalation (Intensified, standard, and simplified), and to establish or carry out the adaptation of the same, according to its own institutional profile of exposure to AML/CTF risk, supported by the results of the conjugation of risk factors.
Records: It is the set of physical documentation that must be part of client files, as well as all digital information or other forms of electronic storage of information and data about clients and their operations, whether active, passive, and fiduciary, and of all their business relationships with a Supervised Entity, which must be custodied and preserved for the legal term.
High-Risk Distribution Channels. They are all those channels used by the Supervised Entity to operationalize and make effective for its clients access to the provision of the products and services it offers and for which it is authorized, through the use of technologies, agents, or intermediaries, or similar ones, which have the characteristic of facilitating anonymity by allowing their execution without physical or "face-to-face" contact with who really contracts or makes use of the same, or with who effectively carries out the operations, transactions, or other business relationships, or said contact is minimized or not required.
High-Risk Countries, Jurisdictions, and Geographic Areas. They are considered such, those countries, jurisdictions, and national or international geographic areas, in which clients reside, or from or to which their operations are directed, and in whose financial transactions business relationships with the Supervised Entity intervene that merit special attention and intensified due diligence for AML/CTF prevention.
Private Banking: It is a department or area specially designated within a banking institution, intended to provide special and more expensive services to wealthy individuals and within what the law authorizes it to provide to its clients, whose transactions tend to be marked by high confidentiality and attended by an employee in charge of their account.
Owners or majority or significant partners: Natural or legal person who participates in the social capital of a legal person or commercial society with a percentage equal to or greater than 5% of its social capital.
Politically Exposed Persons (PEP): It is any identified natural person at the beginning or during the course of the contractual relationship, who performs or has performed as a high-ranking public official, in his/her own country or abroad. It includes his/her closest family members, closely associated persons, his/her close collaborators, and also, those persons who occupy first-level positions, belonging to any commercial society, business, or other entity that has been organized by or for the benefit or in ownership of a high-ranking official or because they are associated with it, and those with whom he/she publicly maintains financial or commercial relations. Furthermore, within PEPs are included Political Parties and Organizations and embassies or diplomatic and consular representations.
High-ranking public official: It is understood as such, those persons elected or not, who have or have been in charge of prominent public functions in his/her own country or abroad in the executive, legislative, electoral, judicial, municipal, administrative, diplomatic, military, or police branches; as well as, prominent figures belonging to political parties; or high-ranking executives of companies belonging to the State. This concept does not incorporate individuals of medium or lower rank of the categories previously exposed.
Close family members of a high-ranking public official: In this category are considered parents, siblings, spouse, children, and parents-in-law of such person and any person with whom he/she maintains permanent or de facto affinity relations.
Person closely associated with a high-ranking public official: Any person of whom it is known that he/she commonly maintains a close relationship with a high-ranking public official or legal entity in which said official has a position of administrative or shareholding control, or, in any way, an economic interest in the same. It includes persons who are in a position to conduct significant financial transactions in the country and/or abroad for the benefit of the high-ranking official.
Close collaborators: These are persons who, although not high-ranking officials, are commonly known to have a close relationship or link with a PEP, including those in a position to conduct significant financial transactions in the country and/or abroad for the benefit of the latter.
Originating or Ordering Financial Institution: The national or foreign financial institution that receives an order for a fund transfer from a person who is not another national or foreign financial institution.
Intermediary Financial Institution: The national or foreign financial institution that participates in any intermediate element of the process/chain of fund transfers/telegraphic transfers but is neither the originating institution nor the beneficiary.
Beneficiary Financial Institution: The national or foreign financial institution that pays or credits the fund transfer/telegraphic transfer order to the beneficiary person who is not a national or foreign financial institution.
Source of Funds: Economic, productive, industrial, financial, or labor activity that constitutes the legally documented source originating the funds or monetary resources that a client intends to place or manage in or through a Supervised Entity.
Source of Wealth: The legal source or economic, productive, industrial, financial, or labor activity that produces the wealth or monetary resources owned by a natural or legal person.
Source of Funds (Origin): The geographic location, company, person, or institution from which the funds originate.
Physical Presence: Financial Entities that have representation, management, and administrative structure, located and domiciled within the territory of the country where they are registered and authorized.
Prominent Public Figures: All natural persons who, due to their current or past political position, or due to their current public or private connotation or position, economic, social, or of another nature, are capable of influencing or obtaining treatment or dispensations in the handling and fulfillment of requirements and application of due diligence measures that, under normal or equal conditions with other persons who do not or have not had those qualities, could not obtain in their commercial or business relations with entities of the supervised financial system.
Products and Services: All operations that supervised entities are legally authorized to provide to their clients and users through the celebration of a contract or document accrediting the provision of the service.
Client: All natural (physical) or legal (moral) persons, national or foreign, with whom the Supervised Entity establishes or maintains, habitually or occasionally, a contractual or business relationship of a financial, economic, or commercial nature under any modality, whether in the scope of the business, products, or services it offers to the public as legally authorized; or for the obtaining or supply of products or services it requires for its normal functioning. This concept includes final beneficiaries, as well as persons on whose behalf or in whose name the relationship is established by professional intermediaries, and any person or entity linked to a financial transaction.
Habitual Client: Any person who establishes a contractual or business relationship with the Supervised Entity with the character of permanence, habituality, recurrence, or successive tract.
Occasional Client: Any person who develops or carries out some type of relationship or business, or who in any way uses the services provided by a Supervised Entity, whether only once or in an occasional, non-recurrent manner.
Unsafe Practices: All practices, conduct, and ways of operating that violate the most elementary principles of ethics and sound prudence, as well as strict adherence to the laws and regulations of the matter, and to the own internal policies and procedures for the management of banking and financial activities, to the detriment of the Entity, which leads to increasing its AML/CFT risk level.
Users: Those natural or legal persons to whom Supervised Entities provide their services, although not necessarily their clients.
Final Beneficiary: All natural or legal persons who, without being or having the status of clients of the Supervised Entity, are the ultimate owners or recipients of the resources, securities, or assets subject to the contract or business relationship, and/or those who are authorized or empowered to dispose of them, including those who exercise final effective control over a legal person.
Legal Beneficiary: Those depositors established by banking law for depositors constituted by natural persons.
Annex 2: Formats for the Integrated Customer Profile (ICP)
i.- Banking and Financial Market
A.- Format: “Integrated Customer Profile”
FOR NATURAL PERSON
(ICP-N)
I Name of the Account Holder Client
II Opening Data
III Type of Operation: 1. Demand Deposit 2. Savings Deposit
3. Time Deposit 4. Loan
5. Credit Line 6. Credit Card
7. Trust Operations 8. Other (specify)*
*____________________________
IV Personal Data (Complete with the account holder's data. In the case where the account holder is a minor or incapacitated, complete with the data of the tutor or legal representative of the latter)
First Name 2. Second Name
First Surname 4. Second Surname
Names by which they are known socially and publicly
Marital Status 7. Sex Male Female
Number of Dependents
Date of Birth 10. Country of Birth
Country of Nationality 12. Country of Residence
Home Address
Municipality 15. Department
Telephone 17. Mobile 18. Fax 19. Email
V Identification Means
VI Data on economic activity or employment
VII Data for spouse or stable union
First Name Second Name
First Surname Second Surname
Home Address Telephone Home
Mobile Email Personal
Profession Current Occupation
Name of the workplace Workplace Address
Work Email Work Website
Work Telephone Fax
Work PO Box Monthly Salary
VIII DDC Qualification
High Medium Low
IX.- Legal documents required for Economic Activity (in case of own business):
Document Type Issued By Issue Date Expiration Date
X References
Reference Data (1)
Names: Surnames:
Home Address: Home Telephone: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verifier Name: Date and time of verification:
Verifier Signature: Verification Summary:
Reference Data (2)
Name: Surnames:
Home Address: Home Telephone: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verifier Name: Date and time of verification:
Verifier Signature: Verification Summary:
XI Information Regarding the Account (must be filled for all accounts the client possesses)
Account Number 2. Account Type 3. Initial Deposit
Opening Date 5. Account Signers 6. Status
Source of Funds
Fund Transfer Salary Loan Sale of assets
Savings Inheritance Remittance Business Dividends Donation Others* _______________ Explain:
Purpose of the account
Income Savings Income from sale / rental
Staff / supplier Personal Expenses Others* ____________ Explain:
XII Accounts with other Financial Institutions Institution Account Type Currency Average Amounts
XIII.- Expected Monthly Activity (must be filled for each of the accounts the client possesses)
XIV.- Place and date of completion of this Profile:..................................................................
“I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts supporting this Profile.”
Client Signature
Account Officer / Business Executive Branch Manager or Authorized Official
XV.- Update History (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the Client's Physical File).
Account
No.
Account
Type
Currency
No. of
Transactions
Debits
No. of
Transactions
Credits
Average
Amount
Debit
Average
Amount
Debit
Average
Balance
B.- Format: “Integrated Customer Profile”
FOR LEGAL PERSON
(ICP-J)
I Name of the Account Holder Client
II Opening Data
III Type of Operation: 1. Demand Deposit 2. Savings Deposit
3. Time Deposit 4. Loan
5. Credit Line 6. Credit Card
7. Trust Operations 8. Other (specify)*
*________________________
IV Data of the Legal Person
Trade Name 2. Commercial Name
Other names used according to their constitutive documents:
RUC Number
Name of the Legal Representative or Attorney-in-fact
Type and Number of identification of the legal representative:
Board of Directors
Identification of Partners, Directors, and Administrators (mentioning the positions held)
Date of Constitution 10. Country of Constitution
Date of Registration in Competent Registry
Headquarters Address Municipality Department
Country
Address and country of branches
Telephone 15. Fax 16. Email 17. PO Box
Website
V Data on economic activity
VI Risk Qualification
High Medium Low
VII.- Information required to operate according to its activity:
Registering Entity Type of Registration Registration Date Expiration
VIII References
Reference Data (1)
Name: Address Home:
Telephone Home: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verified by: Date and time of verification:
Verifier Signature:
Reference Data (2)
Name: Address Home:
Telephone Home: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verifier Name: Date and time of verification:
Verifier Signature: Verification Summary:
IX Information Regarding the Account (must be filled for all accounts the client possesses)
Account Number 2. Account Type 3. Initial Deposit
Opening Date 5. Account Signers 6. Status
Source of Funds
Fund Transfer Salary Loan Sale of assets
Savings Inheritance Remittances Business Dividends Donation Others* ___________________ Explain:
Purpose of the account
Income Savings Income from sale / rental
Staff / supplier Personal Expenses Others*______________
Explain:
X Accounts with other Financial Institutions
Institution Account Type Currency Average Amounts Date
XI Expected Monthly Activity (must be filled for each of the accounts the client possesses) Account Number Account Type Currency Number of Transactions Debits Number of Transactions Credits Average Amount Debit Average Amount Debit Average Balance
XII.- Place and date of completion of this Profile:..................................................................
“I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts supporting this Profile.”
Client Representative/Legal Person Signature
Account Officer / Business Executive Branch Manager or Authorized Official
XIII Update History (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the Client's Physical File).
C.- Format: “Integrated Customer Profile”
FOR SIGNATORY:
(ICP-F)
I Name of the Account Holder Client
II Personal Data of the Signatory
III Identification Means
IV Data on economic activity or employment
US$1,001 – US$2,000 US$2,001 – US$3,000 US$3,001 – US$5,000 US$5,001 – US$7,500 US$7,501 – US$10,000 More than US$10,000
V References
Reference Data (1)
Name: Address Home:
Telephone Home: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verified by: Date and time of verification:
Verifier Signature:
Reference Data (2)
Name: Address Home:
Telephone Home: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verifier Name: Date and time of verification:
Verifier Signature: Verification Summary:
VI.- Place and date of completion of this Profile:..................................................................
“I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts supporting this Profile.”
Client Signature
Account Officer / Business Executive Branch Manager or Authorized Official
VII Update History (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the Client's Physical File).
D.- Format: “Integrated Customer Profile”
FOR CLIENT REPRESENTATIVE:
(applicable only in case that the representative is not also a signatory) (ICP-R)
I Name of the Account Holder Client
II Personal Data of the Representative
III Identification Means
IV Document accrediting the client's representation Document Type Issued By Issue Date Country of Issue
V Data on the economic activity or employment of the representative
Less than US$300 US$301 – US$500 US$501 – US$1,000 US$1,001 – US$2,000 US$2,001 – US$3,000 US$3,001 – US$5,000 US$5,001 – US$7,500 US$7,501 – US$10,000 More than US$10,000
VI References for the representative (applicable only in case of recently constituted legal persons) Reference Data (1) Name: Address Home:
Telephone Home: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verified by: Date and time of verification:
Verifier Signature:
Reference Data (2)
Name: Address Home:
Telephone Home: Mobile:
Place of work: Work Telephone:
Type and ID Number: Time knowing the reference:
Verifier Name: Date and time of verification:
Verifier Signature: Verification Summary:
VII.- Place and date of completion of this Profile:..................................................................
“I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts supporting this Profile.”
Client Representative Signature
Account Officer / Business Executive Branch Manager or Authorized Official
VII Update History (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the Client's Physical File).
ii.- Insurance Market
A.- FOR INSURED - NATURAL PERSON
A.-Full name of the policyholder, according to identity card:
First Surname Second Surname Names
B.- Type of operation: Insurance Surety Line Credit
C.- Personal data: complete with the policyholder's data.
D.- Data on the economic activity or employment of the policyholder:
E.- Information regarding insurance:
Policy: New Renewal
Branch: Life Accident Health Vehicle
Fire Surety Miscellaneous
Source of funds for the payment of the premium: Salary Inheritance
Savings Company Others (explain):_______________________
Insured amount in: Cordobas Dollars Other
Insurance with other insurers: Life Accident Health Vehicle
Fire Surety Miscellaneous
Name of the Insurer___________________________________________________________ “I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts supporting this Profile.” Client Signature Insurer Signature Date://200___
B.- FOR INSURED - LEGAL PERSON
A.-Full name of the policyholder (representative according to identity card):
First Surname Second Surname Names
B.- Type of operation: Insurance Surety Line Credit
C.- Data of the insured entity:
D.- Data on economic activity:
E.- Information regarding insurance:
Policy: New Renewal
Branch: Life Accident Health Vehicle Fire
..Surety Miscellaneous
Source of funds for the payment of the premium: Own Supplier Buyer
Others.Explain: _________________________________________________________________
Insured amount: Cordobas Dollars Other
Insurance with other insurers:
Life Accident Health Vehicle Fire Surety Miscellaneous Name of the Insurer_______________________________________________ "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile." Signature of the Policyholder and/or Legal Representative Signature of the Insurer Date://200___
iii.- Securities Market
A.- FOR NATURAL PERSONS
1 - Type of service provided by the entity:
Brokerage
Custody
Others
2 - Client's personal data
First Surname Second Surname Names
ID Passport Residence ID Other
Place and date of birth:
Nationality: Marital Status:
Sex: Male Female
Permanent home address:
Phone Cell Fax Email
3 - Client's professional and economic data
Profession or Trade:
Work address and postal code:
Phone Fax Email
Description of the company's activity:
Approximate annual income obtained or generated by the client:
Less than US$ 5,000 US$ 5001 – US$ 20,000
US$ 20,001 - US$39,000 greater than US$ 40,000 Source or origin of funds:
Transfer of funds from assets Salary Loan Sale
Savings Inheritance Others (Explain)
Expected monthly transactions:
4 – Commercial and personal references
Commercial:
Name of the entity: Contact person:
Years with the entity: Phone:
Address:
Personal:
Full name of the person:
First Surname Second Surname Names
Home address: Phone:
Place of work: Phone:
Time knowing the referred person:
5 – Background of commercial relationship with any entity of the Financial System Name of the entity:
Type of service received: Date:
Account number (if applicable):
6 - General Risk Profile
Self-evaluation of your knowledge of the national and international securities market:
Poor limited good professional
General risk disposition:
Conservative Moderate Risky Very risky
Currency in which you need the cash income from your investments:
Córdobas Dollars Not applicable
Investment Horizon:
One day to three months
Three months to one year
One to 5 years
More than 5 years.
Percentage of wealth you would be willing to invest: % "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile." Signature of the Client Signature of the stock exchange executive Date://200___
B.- FOR LEGAL ENTITIES
1 - Type of service provided by the entity:
Brokerage
Custody
Others
2 - Company identification data.
Corporate name as described in the legal constitutive document:
Registration data:
RUC Number:
Company nationality:
Headquarters or social domicile:
Name and country of subsidiaries and affiliates:
Phones Fax P.O. Box Email.
3 - Company's economic data
Approximate annual income:
Detail of the activities it is dedicated to and exact detail of the location where it carries out its activities:
In the case of a foreign legal entity not domiciled in Nicaragua, a detailed description of the profile of the operations to be carried out in Nicaragua must be requested:
Company Size:
1 to 10 employees 11 to 50 employees more than 51 employees 4 – Commercial references Commercial:
Name of the entity: Contact person:
Years with the entity: Phone:
Address:
5 – Background of commercial relationship with any entity of the Financial System Name of the entity:
Type of service received: Date:
Account number (if applicable):
6 - General Risk Profile
Self-evaluation of your knowledge of the national and international securities market:
Poor limited good professional
General risk disposition:
Conservative Moderate Risky Very risky
Currency in which you need the cash income from your investments:
Córdobas Dollars Not applicable
Investment Horizon:
One day to three months
Three months to one year
One to 5 years
More than 5 years.
Percentage of wealth you would be willing to invest: % "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile." Signature of the Policyholder and/or Legal Representative Signature of the stock exchange executive Date://200___
iv.- General Warehouses of Deposit
2.1 First surname: Second surname: Maiden surname:
First name: Second name:
2.2 Date of birth (dd/mm/yyyy) 2.3 Nationality:
2.4 Type of identification document: Number: Place of issue:
2.5 Tax Identification Number (RUC): 2.6 Profession or trade:
2.7 Private address (specify exactly):
2.8 Business address or main office (specify exactly):
2.8 Phones: 2.9 Fax:
2.10 Email:
2.11 Main economic activity:
CLIENT PROFILE
GENERAL WAREHOUSES OF DEPOSIT
FORM FOR STARTING RELATIONSHIPS
PLACE:
CLIENT DATA NATURAL PERSON
3.1 Type of Society or Entity:
3.2 Full name or corporate name:
3.3 Trade name:
3.4 Corporate Purpose:
3.5 Main economic activity:
3.6 Tax Identification Number (RUC):
3.7 Main office address (specify exactly):
3.8 Phones: 3.9 Fax:
3.10 Email: 3.11 Website:
3.12 Data from Public Deed of Constitution of the Entity:
3.13
3.14 Data of Registration in Public Registry:
No.: Folio: Volume: Book:
Registry:
3.15 Data of Registration as Merchant:
No.: Folio: Volume: Book:
Registry:
3.16 If not a Company or Commercial Society, indicate the information from the Decree or similar document:
3.17 Registry Data:
Name of the Registry No.: Folio: Book:
Modifications to the Constitutive Pact (if more than one, detail on separate sheets):
CLIENT DATA LEGAL ENTITY
Number: Date: Notary who authorized it:
Deed No.: Date: Notary who authorized it:
4.1 First surname: Second surname: Maiden surname:
First name: Second name:
4.2 Date of birth (dd/mm/yyyy) 4.3 Nationality:
4.4 Type of identification document: Number: Place of issue:
4.5 Tax Identification Number (RUC): 4.6 Profession or trade:
4.7 Private address (specify exactly):
4.8 Phones: 4.9 Fax:
4.10 Email:
4.11 Power of Attorney or Notarial Act of Appointment:
Notary who authorized it: Position for which appointed:
4.11.1 Nature of the Document:
4.11.2 Deed No.:
4.11.3 Registry Data:
Name of the Registry: No.: Folio: Volume:
Book: Registry:
4.12 For the purposes of this application, acts solely for the benefit of the entity described above:
Yes No
4.13 If the answer is negative, provide information about the entity or person on whose behalf they act:
4.13.1 Full name of the person and/or corporate name of the entity:
4.13.2 Complete address:
4.13.3 Date of Birth (dd/mm/yyyy): 4.13.4 Nationality:
4.13.5 Type of Identification Document: Number: Place of Issue:
4.13.6 Tax Identification Number (RUC): 4.13.7 Phones:
Date:
DATA OF THE LEGAL REPRESENTATIVE OR ATTORNEY-IN-FACT OF THE CLIENT
5.1 Type of merchandise to be deposited:
5.2 Projected monthly average of merchandise to be deposited for:
Value of the merchandise:
Quantity of merchandise (when possible to detail it):
5.3 Origin of the merchandise: 5.4 Destination of the merchandise to be deposited:
National: National Consumption:
Imported: Export:
5.5 Merchandise 5.6 Merchandise
Own: Taxed:
Consignment: Free:
In deposit:
DATA OF THE MERCHANDISE TO BE DEPOSITED
6.
6.1 Banking (names of the banks):
6.2 Commercial (names of the companies):
6.3 Operations with the financial group:
Bank Factoring
Financial Company Off-Shore
Exchange House Stock Exchange House Credit Card Insurance Company Surety Company Others (specify):
BANKING AND COMMERCIAL REFERENCES
Phones:
Phones:
7.
7.1 Full names of the owners, partners or shareholders of the entity
7.2 Name, surnames, address and phones of members of the Board of Directors or Executive Board:
7.3 Names, surnames, address and phones of the Administrator, Manager or similar
INFORMATION ABOUT THE ENTITY'S ADMINISTRATION
8.1 Details of the activity:
8.1.1 Average monthly income of the last 12 months:
8.1.2 Average monthly expenses of the last 12 months:
8.1.3 Average of inventories handled during the last two years:
Value of the merchandise:
Quantity of merchandise:
8.1.4 Estimated number of employees working in the entity:
8.2 Name, address, phones and website of main suppliers and clients:
ECONOMIC-FINANCIAL INFORMATION OF THE CLIENT
SUPPLIERS CLIENTS
9.
All documents referred to in this form and others that the warehouse deems necessary for better identification of clients, such as water, electricity, phone receipts, etc., of the property occupied by the company or business, must be detailed and attached. DOCUMENTS ATTACHED TO THE RELATIONSHIP STARTING FORM 10.
10.1 I commit to informing the General Warehouse of Deposit immediately when any change occurs in the information
recorded in this form.
10.2 I authorize the General Warehouse of Deposit to verify the information provided in this form.
CLIENT OBLIGATIONS
Signature of the client or their representative Name and signature of the person who filled out the form Employee Code Name and Signature of the person responsible for data verification and date of verification Employee Code Name and signature of the person who approves the operation and date of approval Employee Code
Annex 3: Alert Signals and Indicators
Money Laundering, of Goods or Assets and Terrorist Financing (ML/TF) accentuate the operational, legal and reputational risks of the Entities that make up the Financial System, regardless of their scope in national criminal legislation. As part of the measures to prevent them, it is necessary to have lists of an enumerative, reference and exemplary (non-exhaustive) nature, which guide Supervised Entities about the most common indicators, patterns, "red flags" or early alerts in which some activities linked to such phenomena could manifest in any of their phases. Supervised Entities must detect and pay special attention to the operations and/or colors that are indicated below so that, in combination with other signals, factors and criteria, they help them to be alert and determine if they constitute operations suspected of being linked to ML/TF risks. And although each of these alert signals, under certain circumstances, may expose the financial institution to significant risks, they should not be considered suspicious by themselves, but must be analyzed to determine if they are suspicious and generate the respective ROS. In this regard, it must be kept in mind that in many cases, the unusual operations detected are duly clarified by the institution and the client, and do not reach the category of suspicious. Below are some Alert Signals and Indicators under the following scheme: First, those that can be considered common and general for all Supervised Entities, then those that are applicable mainly to Banking and Financial Intermediation Entities, then those referred to Insurance Entities, next those specific to Securities or Brokerage Entities and finally some applicable to General Warehouses of Deposit as credit auxiliaries. I.- Common to all Supervised Entities A) Regarding operations or clients with markedly unusual, and/or incongruent, and/or abnormal, and/or strange and/or suspicious characteristics:
1.- Actual activity not congruent with the expected activity established in the Client's Comprehensive Profile, and/or that does not relate to the nature and size of the client's business or occupation. 2.- The client's occupation or trade does not match the volume of funds and assets linked in the operations. 3.- The occupation declared by the person making the transaction does not correspond to the level or type of activity. For example, a student or an unemployed individual who receives or sends large amounts in electronic transfers, or who makes daily withdrawals of the maximum cash amount in different places in a wide geographic area. 4.- The same address for individuals involved in cash transactions, particularly when the address is also a business. 5.- Public information about the client's alleged involvement in money laundering, drug trafficking, terrorism, government corruption, fraud, tax evasion and other serious crimes that involve significant amounts of funds and assets. 6.- Account applicants or commercial relationships that are included in national or international lists designated as (or presumed) money launderers, drug traffickers, terrorists, corrupt government officials, tax evaders, fugitives wanted by the authorities.
7.- Company administrators are very young people, with no history in the financial sector, who generally participate in other companies with similar characteristics.
8.- Companies that record high cash movements in their financial products, with characteristics of fragmentation and that do not relate to the activity they develop.
9.- Regarding non-profit or charitable organizations, financial transactions seem to have no logical economic purpose or there seems to be no link between the activity declared by the organization and the other parties involved in the transaction. 10.- The existence of a large number of clients with inexplicable links. For example, non-profit organizations that make transfers between themselves and share the same address, the same managers or staff. 11.- Clients who have high-risk businesses in also high-risk areas, and in which the Financial Entity has no branches. 12.- Increases in the amount of cash handled, without there being a corresponding increase in the number of transactions that have been reported. 13.- Significant movements of high-denomination bills, which does not relate to the area where the Financial Entity is located. 14.- Large increases in the use of small-denomination bills and the corresponding decrease in the use of high-denomination bills, without transaction reports having been filed. 15.- Persons who carry out an informal trade activity from which no payments are evidenced to a local or foreign supplier, when the merchandise is foreign. 16.- Financial operations where it is observed that the client is being directed by another person, especially when the client seems to have no knowledge of the details of the same. 17.- Clients whose companies offer extremely high profitability in a short period of time for the investments made in them. 18.- Clients who are executives or high-ranking officials of public entities who suddenly present changes in their standard of living, without any reasonable justification. 19.- Sudden and inconsistent changes in transactions and ways of handling money, funds or assets. 20.- Clients with known liquidity deficiencies who in a short time and without explanation, present reactivation of the cash flow in their accounts, products and commercial relationships. 21.- Clients with financial problems whose partners, after making modifications in the constitutive documents, reactivate their business without needing to incur debt. 22.- Clients with significant changes in the financial movements of their companies that are not in line with the general behavior of the sector.
23.- Clients who justify their wealth increase or financial transactions by having won a prize, or the sale or assignment thereof in favor of a third party, without there being an official record of the payment thereof. 24.- Clients who in short periods of time justify their income with several prizes from lotteries and games of chance. 25.- Clients who deposit cash justifying winnings in games of chance with little recognition in the market. 26.- Clients with sudden wealth increase that they justify in alleged prizes obtained abroad, but which are quickly transferred. 27.- Legal entities without physical presence or without history or background of wealth, economic, commercial, industrial or financial, according to their corporate purpose, nor of their owners or founding partners, or these are not identifiable. 28.- Exporting or importing company that justifies its financial transactions with service contracts that present incoherencies or do not relate to the service provided. 29.- Long-standing client who without any justification completely changes the behavior of their Accounts and commercial relationships with the Supervised Entity, and has a high-risk economic activity and business location. 30.- Client who exhibits unusual indifference regarding the risks they assume and/or the commissions or other costs of the transactions. 31.- Client who in a short period of time appears as the owner of important new businesses and/or assets. 32.- Clients whose financial statements reflect results very different from other companies in the same sector or with similar activity. 33- Clients dedicated to, and/or promoters of, activities that are internationally considered as vulnerable to facilitate and/or promote human trafficking, forms of slavery, prostitution or trade in human beings. B) Regarding clients who try to avoid giving information, or filling out records, or giving insufficient, contradictory, suspicious or false information:
1.- Unsatisfactory explanations, in the opinion of the Financial Entity, regarding the significant variation of the client's operations with respect to their Profile.
2.- Clients who refuse to justify the origin of funds or assets for the operation or to update the basic information already supplied at the time of renewing the commercial relationship.
3.- When opening an account and/or starting a commercial relationship, the client refuses to provide the information requested by the Financial Entity, attempts to minimize the level of information offered or offers false information or information that is difficult to verify. 4.- Companies that refrain from providing complete information about the purpose of the business, previous financial relationships, location or names of directors and officials.
5.- Clients who request to be exempted from supplying or confirming certain information by being a recommendation of another client, partner, executive, or official of the Supervised Entity. 6.- Reluctance to present information in accordance with the Financial Entity's requirements regarding consular certification of foreign documentation. 7.- Clients who frequently change, without apparent justification, their data such as address, phone, occupation. 8.- Clients who force or try to force a Bank employee not to keep in the file the report of any transaction. 9.- Rejection, attempt at bribery or threats to Financial Entity officials not to complete the information forms completely or to accept incomplete or false information. 10.- Inability to communicate with the client via the residential phone number provided to the Financial Entity. 11.- Request to open an account or credit relationship, without references, local address, nor identification, nor other appropriate documents. 12.- Omission of documents on previous or present jobs for a loan application. 13.- Non-existence of employment history in the past or present, but who make frequent transactions of money in large amounts; 14.- Presentation of strange and suspicious identification documents, which the Financial Entity cannot verify promptly. 15.- Clients from whom there is no evidence of on-site verification of the commercial or industrial establishment that allows confirming their address and real existence. 16.- Businesses that do not wish to reveal details about their activities nor provide financial statements thereof. 17.- Businesses that present financial statements notably different from other businesses of similar activity. 18.- Inexplicable incoherencies arise in the process of identification or verification of the Client, for example, regarding the current or previous country of residence, the country that issued the passport, the countries visited according to what the passport says, and the documents presented to confirm the name, the address and the date of birth. 19.- Commercial relationship from which it was detected that it was opened or initiated with false or altered data and documents, or that are of dubious authenticity. 20.- Local or international operations where unknown intermediaries or with few references in the medium act. 21.- Clients who register the same address and/or phone of other people with whom they have no apparent relationship.
22.- Natural or legal persons who demonstrate great economic solvency but nevertheless find it difficult to obtain or supply information regarding commercial references or co-debtors when filling out linkage and information forms.
23.- Persons who fill out linkage or information forms with illegible or "deceptive" handwriting, making verification difficult.
24.- Persons who show reluctance or annoyance when requested adequate identification or the mandatory completion of certain information forms.
25.- Persons who appear nervous, hesitate in their answers and/or consult data they have written down, when asked for information required to initiate the commercial relationship.
26.- Natural or legal persons, who act as agents or licensees of money remitting entities, who demonstrate great economic solvency but nevertheless find it difficult to obtain or supply information regarding commercial or financial references when filling out linkage forms.
27.- Any transaction in which a third party participates whose name is not revealed or that involves anonymous participants.
28.- Operations in which the client does not reveal possessing financial conditions for the operation to be carried out, configuring the possibility of not operating in their own name, but as an agent for a hidden principal, being reluctant to provide information regarding said person or entity.
29.- Client who refuses or suspends a transaction when requested information regarding the origin of the funds or the goods or merchandise involved.
30.- Any individual who pressures or attempts to pressure not to present the required background information to carry out a transaction.
31.- Companies that request payroll payment services through accounts or in cash in the name of their employees, and who refuse or do not prove their registration as an employer before the corresponding Social Security authority nor data regarding billing for employee contribution withholdings and payments made to Social Security.
C) Regarding transactions linked to risk, non-cooperative jurisdictions, or jurisdictions of concern:
1.- Sending and receiving international transactions to or from risk jurisdictions.
2.- Clients who acquire financial products of significant amounts, whose residence or business domicile is located in tax havens or whose corporate object is "off shore" operations.
3.- Transactions followed within a brief period of time, by electronic transfers to places that generate specific concerns, for example, countries, jurisdictions, or territories designated or qualified by national authorities or by the FATF as non-cooperative, of concern, or High Risk.
4.- Commercial relationships with persons from countries where the FATF Recommendations are not applied or are not sufficiently applied.
5.- The Client obtains a credit instrument or commits to commercial transactions involving the movement of funds from and to risk jurisdictions when there are illogical business reasons to deal with those jurisdictions.
6.- A business account through which a large number of cable transfer receipts and sendings occur and which appear incompatible with the business or other economic purposes.
7.- The use of multiple accounts to collect and then channel funds to a small number of foreign beneficiaries, both individuals and businesses, particularly when these are in places of concern or risk.
8.- The opening of accounts or the initiation of commercial relationships with institutions belonging to risk or non-cooperative jurisdictions.
9.- Followed deposits, in a short time, by a transfer of funds, particularly to, or through, a place of risk or non-cooperator.
10.- Sending or receiving funds by international transactions to risk jurisdictions.
11.- Funds generated by a business that belongs to individuals of the same origin or linkage of several individuals of the same origin, coming from countries that generate specific concern, acting on behalf of similar types of businesses.
12.- Transactions involving currencies, followed within a brief period of time, by electronic transfers to places that generate specific concern.
13.- A commercial account through which a large number of electronic transfers are made from and to the outside, and for which there does not seem to exist a logical commercial or economic purpose of another type, particularly when this activity is carried out through or from, places that generate concern.
14.- Use of multiple accounts to collect and then channel funds to a small number of foreign beneficiaries, both individuals and businesses, particularly when these are located in places that generate concern.
15.- Opening of accounts of financial institutions from places that generate concern.
16.- Sending or receiving funds by international transfers from or to places that generate concern.
17.- Funds generated by a business that belongs to individuals of the same origin or linkage of several individuals of the same origin, coming from countries that generate specific concern, acting on behalf of similar types of businesses.
18.- The presence of foreign directors of a non-profit organization, particularly in combination with the sending of large sums of money to the country of origin of said directors and especially if the destination is a high-risk jurisdiction.
19.- Clients presented by a branch, subsidiary, or Foreign Entity, based in countries or territories considered "tax havens" or non-cooperative by the FATF.
D) Regarding strange situations or behaviors of executives, officials, employees, representatives, agents, and intermediaries of Financial Entities:
1.- Executives, officials, or employees who repeatedly omit the preventive or due diligence acts to which they are obligated.
2.- Executives, officials, or employees who use or lend their own home address to receive client documentation.
3.- Executives, officials, or employees who without reasonable justification nor relating to the nature of their functions, personally carry out, in their name or through their accounts, transactions or operations of clients.
4.- Executives, officials, or employees who have a lifestyle or carry out financial and investment transactions that do not correspond to the amount of their known income.
5.- Executives and officials who refuse or in any way prevent general staff or personnel in specific positions from taking their restful vacations.
6.- Officials or employees who repeatedly refuse to take vacations.
7.- Officials or employees who show a sudden favorable and expensive change in their economic lifestyle, without a clear and reasonable justification.
8.- Officials or employees reluctant to accept changes, promotions, or raises in their labor activity, without a clear and reasonable justification.
9.- Officials or employees who present a broad, unexpected, sudden, and/or unusual growth in their operations or sales.
10.- Officials or employees who frequently process operations with exceptions for certain clients or users.
11.- Officials or employees who avoid certain internal controls or approvals established for certain transactions, financial products, or services.
12.- Officials or employees who frequently incur errors, discrepancies, or inconsistencies, and their explanations are insufficient or inadequate.
13.- Officials or employees who omit the verification of a person's identity or do not confront the data with the records supplied in the forms or databases of the entity, according to the functions assigned to them.
14.- Officials or employees who prevent other colleagues from attending to certain clients or users without an apparent justification.
15.- Officials or employees, mainly commercial advisors, who are repeat offenders in documenting or partially substantiating the information or transactions of a client or user, without a clear and reasonable justification.
16.- Officials or employees, mainly commercial advisors, who frequently attend to the same client or user whom they appear not to know.
17.- Officials or employees, mainly commercial advisors, who attend to certain clients in a preferential, exclusive, and permanent manner, or exempt them from certain controls, with arguments such as: "he is quite well known", "he is referenced by another entity", "he only trusts me", "I advise all his business" or similar.
18.- Officials or employees who frequently receive gifts, invitations, favors, or other presents from certain clients or users, without a clear and reasonable justification, or without being authorized by the entity's policies or codes.
19.- Officials or employees who frequently and without a clear and reasonable justification, absent themselves from their workplace, or remain in the office after the usual time, or attend it outside normal working hours.
20.- Repeated non-compliance with internal LD/FT (Money Laundering/Terrorism Financing) prevention rules.
II.- Specific for the Banking and Financial Market
A) Regarding Passive Accounts and Deposits:
1.- Account whose expected activity, according to the Client's Comprehensive Profile, is not congruent with the actual activity of the same.
2.- Account whose volume and frequency of transactions, such as withdrawals, check deposits, payment orders, or other instruments, do not relate to the nature and size of the business.
3.- Account with manifest incongruence between the apparent source of funds and the amount thereof. For example, funds raised or transferred by a non-profit organization in the case where large sums of money apparently come from communities with a very modest standard of living, or the case of the lack of contributions from donors.
4.- The opening of multiple Accounts by the same person, in which numerous small deposits are made, which, together, do not correspond to the client's expected income.
5.- Deposit of cash, checks, or monetary instruments that are atypical or incongruent with the income or activities normally developed by the depositor.
6.- Account that has frequent transactions with high amounts or large volume of deposits in cash and in checks, payment orders, transfers, and other negotiable instruments; but that do not relate to the real income and/or type of business of the client.
7.- Accounts of the same person in which deposits are made in small amounts, but which added up are disproportionate to the expected and/or declared income of said account holder.
8.- Account of a recently constituted entity, in which a higher level of expected deposits is made compared to the income of the entity's founders and/or compared to entities whose businesses or activities are similar.
9.- Accounts that receive funds from activities or businesses, but whose movements and speed of rotation are unusual, are outside the parameters of normality, or do not relate to the current situation through which the business in which the account holder operates is going. For example, individuals who claim that the large sums moved in the Account come from certain crops, when in reality the product is depressed in the national or international market; or conversely, claims lack of movement in the Account due to a bad situation in the market when in reality it is not so.
10.- Companies whose Accounts have movements at a level of sales that does not relate to the economic capacity and consumption of the population in the area.
11.- Foreign resident, opens an account with a cash deposit from another local bank, however the local bank informs that this has not been their client.
12.- Inactive account containing a minimum sum, and suddenly receives a deposit or a series of deposits followed by daily cash withdrawals, which continue until the transferred sums have been withdrawn or removed completely.
13.- Inactive business account, notwithstanding the account holder carries out frequent operations of exchange desk and purchase of foreign currency consignment instruments, a situation that does not adequately justify.
14.- Regional account in personal name with little or no activity in certain periods of time but that occasionally receives deposits from abroad by natural persons for high sums of money without a reason congruent with the purpose of the Account.
15.- Account that receives relevant periodic deposits and remains inactive in other periods, then is used in the creation of a financial background through which fraudulent activities can be carried out.
16.- Deposits of high volumes of checks for smaller amounts, issued abroad that do not relate to the declared purpose for the management of the Account.
17.- Opening of Account in a branch different from the domicile despite having a closer branch, in which a transfer from abroad is received for the sale of shares abroad, and the economic activity is not compatible with the amount of the international transfer received.
18.- Deposits of funds in several Accounts, generally in amounts below the limit to be reported, which are then consolidated in another Account and transferred outside the country.
19.- Account from which telegraphic transfers are sent and received without apparent commercial reason nor consistency with the client's business history.
20.- Use of multiple personal and commercial accounts or accounts of non-profit or charitable organizations, to collect funds and then channel them, immediately or after a brief period of time, to a small number of foreign beneficiaries.
21.- Accounts where payment orders are deposited by mail with strange signs or symbols.
22.- Significant cash deposits, in low denomination bills and without clarification of their origin.
23.- Account that reflects frequent and large deposits of low denomination cash, for a business that generally does not handle significant sums of cash.
24.- Account where funds from casino and slot machine businesses are managed, from which it is not possible to obtain evidence that they operate within the established legal regulations nor of the volumes of funds managed.
25.- Fiduciary accounts that show substantial deposits of cash.
26.- Significant cash deposits to the Account of an individual or entity, when normally made by means of checks or other payment instruments.
27.- Large cash withdrawals from a commercial Account not normally associated with cash transactions.
28.- Frequent deposits of large sums of cash wrapped in bands of paper from another Bank.
29.- Frequent deposits of large amounts of cash outside of public service hours, thereby avoiding direct contact with the financial entity's staff.
30.- Deposits and withdrawals of funds from corporate Accounts that are commonly made in cash, instead of checks.
31.- Rapid increases in the size and frequency of cash deposits, without the corresponding decrease in non-cash deposits.
32.- Reduced number of deposits using considerable amounts of checks, in which, however, withdrawals for daily operations are rarely made.
33.- Non-commercial personal Accounts, used for the deposit and management of funds from commercial and/or industrial activities.
34.- Mix of cash deposits and monetary instruments in an Account in which this type of transaction does not seem to have any relation with the normal use of the Account.
35.- Account opened supposedly for personal expenses that receives transfers from abroad for high sums remitted by companies domiciled abroad, followed by the issuance of checks to a single beneficiary who cashes them in cash.
36.- Frequent and significant deposits with dirty, mutilated, moldy bills, or marked with strange symbols.
37.- Frequent deposits or withdrawals from an Account, which fall just below the amount specified by law to be reported.
38.- Accounts that show several deposits under the cap amount made at an ATM.
39.- The deposit or withdrawal of multiple monetary instruments in amounts that systematically fall below the identification or reporting limits, particularly if the instruments are numbered in sequence.
40.- Deposits made on the same day in different branches of the same Bank or of several Banks.
41.- Multiple transactions carried out on the same day, in the same branch of a Financial Entity, but in an apparent attempt to use different Accounts.
42.- Deposits to a legal entity combining monetary instruments that are atypical for the activity normally associated with said business. For example, deposits that include a mix of commercial deposits, salary checks, and social security checks.
43.- Company acting as an agent for the business of remittances of foreign owners residing in the country, which mixed funds from Accounts in the name of the business with Accounts in the name of the principal shareholder without a logical business justification.
44.- Structuring of deposits through multiple branches of the same Financial Entity or through groups of individuals who enter a branch at the same time.
45.- Account on which several people have authorized signature, but among them there does not seem to exist any relationship, either familial or commercial.
46.- Accounts whose authorized signature is or are the same persons, but among them there is no apparent economic or legal reason for that type of agreement. For example, individuals acting as directors of companies for multiple businesses whose headquarters are located in the same place.
47.- Accounts of state institutions that do not adjust to the internal control policies as such they are obligated according to the technical standards issued by the entity controlling state accounts, mainly in topics of Account Management, Issuing Signatures, Check Disbursement, and Electronic Transfer of Funds.
48.- Frequent deposit of checks drawn from Public Entity Accounts that are deposited in Private Accounts and that are immediately withdrawn or transferred.
49.- Account opened by a legal entity or organization that has the same home address of other legal entities or organizations without any reasonable explanation.
50.- Account for clients whose addresses are outside the service area of the Financial Entity.
51.- Account opened in the name of a legal entity that is involved in the activities of an association or foundation whose objectives are related to the claims or demands of a terrorist organization.
52.- Account opened in the name of a legal entity, a foundation, or an association, which may be linked to a terrorist organization and which shows fund movements above the expected income level.
53.- The money is withdrawn from local Bank Accounts by issuing checks in favor of several beneficiaries, who generally endorse them irregularly.
54.- The infrastructure of the companies, generally limited to an office or a place of residence that apparently does not relate to the amounts moved in Accounts and the activity the company carries out.
55.- Account with exaggerated increase in the volume of funds moved after going through financial difficulties, without an apparent justification.
56.- Frequent transfer of money by bank transfers to border zones of the country, without any justification.
57.- Accounts where cash deposits are frequently made by third parties (sometimes foreigners) who are not the account holders, without any justification.
58.- Companies that record consignments in their Accounts with signs of fragmentation, made in cities different from the area where they conduct their commercial activity.
59.- Companies that do not make purchases or expenses, only cash withdrawals from their Accounts.
60.- Opening of several Current Accounts under one or more names, in all of them with the same authorized person to draw or issue checks.
61.- Persons who open a Current Account at a bank branch whose location is different, distant, and without apparent justification from the locality where the client conducts their business or economic activity. For example, if it is a salaried individual, when there is no adequate relationship with the location of their employer or with the place of their residence.
62.- Current Account applicants who, due to their age, experience, or economic activity, do not have a record of financial products with the sector when they should be able to demonstrate it.
63.- Current Account applicants who demand to be attended to or manifest a marked preference for a specific commercial advisor, manager, or bank official.
64.- Persons authorized for signature and financial management of the Current Account when they do not have a direct link or apparent justification regarding the relationship with the holder, or said link is incoherent or inconvenient. For example, if an external auditor is authorized to manage the Account of their audited party.
65.- Person who appears as an authorized signature for the management of numerous Current Accounts of different persons or companies, without any apparent justification.
66.- Persons considered as Politically Exposed Persons (PEPs) who appear or attempt to be registered as authorized to manage one or more current accounts of third parties, without a clear and justified link.
67.- Current Accounts that record only deposits for a period of time, accumulate a considerable balance, and then the money is withdrawn in a single day or in a very short period.
68.- Consignments of high sums of money for Current Accounts that are or have been inactive.
69.- Consecutive opening of several Savings Accounts in the names of different persons, to which the financial entity assigns debit cards for their management, and which are in turn delivered to the same person or used to carry out simultaneous operations.
70.- Persons or entities that frequently close and open new Savings Accounts in the same bank or in others in the locality, without justification.
71.- Certificates of Deposit cancelled prematurely, without reasonable justification for the origin of funds for this purpose.
72.- Applicant for a Certificate of Deposit whose amount is high and who identifies themselves with a document that cannot be easily verified or is expired and which correspond, for example, to foreigners, tourists, non-residents, minors.
73.- Establishment of Certificates of Deposit for high sums of money, with one or multiple transfers from accounts of the same holder and/or third parties, from the same or different financial entity, without apparent justification.
74.- Applicant for a Certificate of Deposit who does not define a specific economic activity or defines it as “independent” and the value of their investment is high.
75.- Companies applying for a Certificate of Deposit whose high amount is not in line with the low capital, operating income, or average available resources of their treasury and/or have been created very recently.
76.- Applicants for a Certificate of Deposit who invest high sums of money without caring or asking about profitability and feign ignorance regarding the market.
77.- Establishment of Certificates of Deposit frequently and for high sums of money, in cash, in favor of a company that, due to its commercial activity, normally does not receive or is not associated with this type of operation.
78.- Establishment of Certificates of Deposit for high sums of money, with one or multiple checks that, due to the information of their drawers, do not correspond to the economic activity of the holder or the justification is not satisfactory for the issuing entity.
79.- Opening of Accounts and/or establishment of Certificates of Deposit of different companies that have in common partners, managers, administrators, or legal representatives.
80.- Consecutive opening of several Accounts and/or establishment of Certificates of Deposit in the names of different persons with similar characteristics (age, economic activity, location, kinship) who apparently do not know each other.
81.- Opening of several Certificates of Deposit in the name of one or more persons, in all of them with the same person registered as co-holder.
82.- Certificates of Deposit that are frequently cancelled shortly after being issued or are endorsed to third parties, who also cancel them, in order to recover the invested capital.
83.- Establishment of a Certificate of Deposit with cash by a natural person in favor of a legal entity that has no commercial relations with said holder nor apparent justification.
84.- Addition or change of one or more persons, designated as beneficiaries, at the time of issuance of a Certificate of Deposit, different from the purchaser of the title.
85.- Titles that are initially issued for small amounts in favor of the same beneficiary but that shortly after, or at the time of their maturity, are added with large sums of money.
86.- Realization of multiple endorsements, especially of Certificates of Deposit whose amount is considerable, by several beneficiaries with similar characteristics (for example: companies of the same “financial group”, persons related by family, persons commercially linked), which are registered with the issuer of the title.
87.- Request by a holder to fragment a Certificate of Deposit into several titles in favor of different natural or legal persons without apparent or justified relationship with the initial beneficiary.
88.- Issuance, renewal, endorsement, or fragmentation of a Certificate of Deposit for a high amount, where one or more persons considered as Politically Exposed Persons (PEPs) participate.
89.- Multiple endorsements of a Certificate of Deposit, for a high amount, that were not registered timely with the issuing entity of the title and are only known at the time of its renewal or cancellation.
90.- Endorsement of nominative Certificates of Time Deposits without notification or registration with the depositary-issuing bank and whose new owner (new bank client) is not or cannot be known by said bank.
91.- Cancellation of a Certificate of Deposit in cash or by check, effected by the beneficiary of the title, when the amount is lower and very close to the limit established for the control of cash transactions.
92.- Cancellation of several Certificates of Deposit in cash, on the same day or in a very short period of time, initially issued to different beneficiaries, which are collected by the same person.
93.- Cancellation of multiple Certificates of Deposit in cash, issued in favor of different companies, which are collected by the same person in the capacity of legal representative, attorney, or legitimate beneficiary.
94.- Cancellation of several Certificates of Deposit in cash, issued in favor of different persons who present themselves in a group to collect the titles.
95.- Cancellation of a Certificate of Deposit, whose holder and beneficiary is a company, which requests payment in several checks for amounts lower and very close to the limit established for the control of cash transactions, drawn in favor of the same holder or in favor of different persons.
96.- Cancellation of several Certificates of Deposit in checks, issued in favor of different beneficiaries, which after being endorsed (sometimes with similar graphological traits) are collected by the same person.
97.- Cancellation of a Certificate of Deposit for a high amount, whose holder is a company, which requests payment by means of a check that is subsequently collected in cash by the same manager or another official of the same.
98.- Cancellation of one or several Certificates of Deposit by local transfers (or international if possible), to different cities (or countries), when the holder does not have clients or businesses in those localities that justify such operations.
99.- Cancellation of one or several Certificates of Deposit by local transfers (or international if possible) to localities different and distant from the headquarters of the business of the beneficiary of the title without apparent justification.
100.- Cancellation of one or several Certificates of Deposit by transfers, with instructions to pay them only in cash.
101.- Cancellation of one or several Certificates of Deposit by local transfers, in favor of the same person or in the name of several third parties, in amounts lower and very close to the limit established as control for cash transactions.
102.- Cancellation of one or several Certificates of Deposit by transfers to current, savings, or other financial accounts, whose money is withdrawn immediately or in very little time through ATMs.
103.- Accounts opened in the name of Exchange Houses in which telegraphic transfers and/or structured deposits are received.
104.- The use of multiple personnel and Business Accounts or Accounts of Associations without Profit Motive, of charity or benevolence, to collect and concentrate funds, immediately or in short times, in favor of a small number of foreign beneficiaries.
105.- Account holders who have businesses whose projection, organization, number of employees, construction of infrastructure, and rental of premises; is disproportionate and does not hold congruence with the current situation of the market in which it operates.
106.- Client dedicated to export, whose Account movements, payments, or drafts come from countries different from that of the exports being made.
107.- Use of Accounts for payments to suppliers of a company, made on behalf of third parties who apparently do not have a link with it.
108.- Consignments made in different offices in the city or country, on the same day, in which the depositor (apparent client of the current account holder) does not have businesses or agencies.
109.- Consignments made by natural persons in favor of a Current Account whose holder is a legal entity that has no commercial relations with said depositors.
110.- Simultaneous consignments by the same person to several Current Accounts of different companies of the same “financial group”.
111.- Frequent consignments and for high sums of cash in the Current Account of a company that, due to its commercial activity, normally does not receive or is not associated with this type of operation.
112.- Client who makes a deposit of money with the purpose of carrying out a long-term operation, followed immediately by a request to liquidate the position and transfer the benefits outside the account.
113.- Client who, without apparent justification, maintains multiple accounts under a single name or in the name of family members or companies, with a large number of transfers in favor of third parties.
114.- Deposit accounts used, without apparent reason, for consolidation of funds managed in other accounts of the same client within the entity or directly or indirectly linked to him to then transfer them and/or buy monetary instruments.
115.- Accounts that receive deposits for various concepts that are not regularized and are later returned to the client or applied to other accounts.
116.- Use of unauthorized accounts in the MUC to use them as generic or operational accounts for the recording of transactions related to exchange desk, sale of consignment instruments and related, which hinder their identification and monitoring.
B) Regarding Active Accounts and Credits:
1.- Clients who suddenly pay off a problematic loan, without any explanation regarding the origin of the money.
2.- Early cancellation of large loans (pre-payments) without apparent justification for the reason for the sudden payment or the origin of the funds.
3.- Loans with liquid collateral cancelled prematurely, without reasonable justification for the origin of funds for this purpose.
4.- Credit with liquid collateral that do not receive deposits during the term of said credit and contact with the debtor is difficult, being finally cancelled through the internal application of the guarantee.
5.- High loans that have Certificates of Deposit or other investment vehicles as guarantees, after these were established with cash.
6.- Clients who request a credit and the analysis of their financial situation does not reflect any credit need.
7.- Credit lines for significant amounts in favor of clients of whom sufficient sources of funds with which the credit is being paid are not known.
8.- Credit lines for significant amounts in favor of businesses that do not hold proportion with their modest size and presence in the market.
9.- Loans that are suddenly cancelled on behalf of third parties, in cash or by transfers, both in the country and abroad.
10.- Companies with economic problems that suddenly pay in advance the total of their debts.
11.- Credit Cards with high monthly consumption volumes and with immediate total payment, and which do not adjust to the economic and income profile of the cardholder.
12.- Credit Cards with high available limits that present frequent pre-payments without reasonable justification.
13.- Loans paid by automatic debits to deposit or investment accounts that do not correspond to the client's profile,
14.- Loans cancelled by voluntary dations or judicial adjudications with little or no opposition.
15.- Loans used for the immediate opening of Time Deposit Certificates, which are then used as guarantees.
16.- Clients who request Letters of Credit in order to guarantee loans granted to them or international operations with other financial institutions abroad that do not relate to the client's profile.
17.- Debtor and/or creditor accounting accounts, in which operations such as disbursed and unformalized loans that are cancelled by the client or debits for applications to loans when the funds that are later received from the client to close the accounting record have not yet been received
C) Regarding Neutral Operations, Services, Transfers, and Drafts:
1.- Collection of checks against an Account on the same day and in different branches, with short time intervals and below the limit indicated in the law to be reported.
2.- Issuance of checks only in favor of the signatories and officials of the company.
3.- Large amounts of money that are withdrawn by majority shareholders, by checks in their names.
4.- Checks drawn by the company that present irregular endorsements and are generally collected in cash.
5.- Purchase of a large number of payment orders, checks, or other negotiable instruments in large quantities, using cash.
6.- Frequent exchange of low-denomination bills for high-denomination bills and vice versa.
7.- Clients who, without apparent reason, buy consignment instruments with large sums of cash and/or just below the limit indicated in the law to be reported.
8.- Purchase of bank drafts in a short time in favor of the same beneficiary, where the orderer and beneficiary are resident foreigners.
9.- Multiple transactions carried out on the same day in the same branch, but through different ATMs.
10.- A safe deposit box is opened in the name of a commercial entity when the commercial activity of the client is unknown or said activity does not seem to justify the use of said service.
11.- Exchange of large amounts of low-denomination bills for others of higher denomination, without a lawful business to justify it.
12.- Daily withdrawals via ATM in a country different from that of the account opening.
13.- Instructions to the bank to transfer funds abroad and then wait for the same amount to be transferred from other sources.
14.- International transfers from or to an Account, of high sums of money, with instructions to pay them only in cash.
15.- Transfers, drafts, and checks for significant amounts in favor of supposed suppliers of the account holder, without there being supports of commercial links between them.
16.- Account in which many small money transfers, or deposits of checks and payment orders, are received, and almost all funds are immediately transferred to another city or country, when the activity is not consistent with the client's history or business.
17.- Deposits and withdrawals of large sums of money by means of transfers, through countries whose level of economic activity, in the opinion of the intermediary bank, do not justify amounts and frequencies of such transactions.
18.- Transfer of funds or earnings of deposits to another country, without changing the type of currency.
19.- Receipt of transfers and immediate purchase of monetary instruments to make payments to third parties.
20.- Electronic or cable transfers of funds carried out in small amounts, in an apparent effort to avoid that identification or reporting requirements come into effect.
21.- Electronic or cable transfers where the information of the originator, or the person in whose name the transaction was made, was not provided in or with the transfer, when the inclusion of said data was expected and would allow clearly identifying said transactions.
22.- Foreign currency exchange transactions that are executed on behalf of a client or by a third party followed by electronic transfer of funds to places where there is no business connection with the client.
23.- Client of few resources who receives a significant transfer from abroad in the concept of distributions of profits from a company.
24.- Currency transactions that are carried out on behalf of a client by a third party, followed by electronic transfers of funds to places that apparently have no commercial connection with the client or to countries that generate specific concern.
25.- International transfers received supposedly for the purchase of real estate but that are returned to the sender a few days after having been received.
26.- Transfer of money from a person who apparently won a contest, prize, event, lottery, bet abroad, to third parties of whom no clear relationship or formal commercial transaction is evidenced.
27.- Current Account that records multiple local or international transfers, for high amounts of money, to different cities or countries, when the holder does not have clients or businesses in those localities that justify such operations.
28.- Local transfers in favor of the same person or in the name of third parties in amounts with signs of fragmentation; that is, amounts lower and very close to the limit established for its reporting.
29.- Electronic transfers received in favor of or ordered from a Current Account, whose money is withdrawn immediately or in very little time through checks drawn in favor of third parties, ATMs, or transfers to other beneficiaries.
30.- Current Account that receives many local transfers, for small amounts of money, which is immediately transferred to another Account in another city where the economic activity of the holder has no apparent justification.
31.- Local or international transfers in favor of beneficiaries considered Politically Exposed Persons (PEP), or checks drawn in favor of them, without a clear and justified link.
32.- Funds from Internet bets received as family remittances, subsequently forwarded via international transfers to banks located in tax havens.
33.- Accumulation of large balances that are not consistent with the sales or billing of the client's business, and subsequent transfers to Accounts abroad.
34.- Electronic transfers of funds carried out by clients, with immediate entry and exit of the Account, or without passing through an Account of the same.
35.- Requests information on the possibility of receiving transfers for significant sums without clarifying on the origin, data, and relationship with the orderer.
36.- Current account holders who suddenly change the type of transactions and the way in which they receive or transfer money.
37.- Sale and purchase of Adjudicated Goods without the Supervised Entity knowing the origin of the buyer's funds nor the true beneficiaries of said operation.
38.- The money is withdrawn from local Bank Accounts by means of checks drawn in favor of several beneficiaries, who generally endorse them irregularly.
39.- Structured remittances to unrelated persons, sent by the same beneficiary.
40.- There are no checks drawn in the name of suppliers or service companies in favor of the client dedicated to export or import.
41.- Checks drawn for similar amounts in favor of different persons that are finally collected by a single one.
42.- Checks drawn and collected in cash whose amounts are just below the limit indicated in the law to be reported.
43.- Checks drawn by a company, for high sums of money that are collected in cash by the manager or officials of the same company.
44.- Checks drawn in favor of different persons that are collected in cash by others that show similar graphological traits in the endorsement.
45.- Checks drawn in favor of a person but collected or credited to the Account of another with a similar or apparent name.
46.- Paid checks that present symbols, stamps, or annotations (such as initials) written on the front or back of said checks.
47.- Exchange of checks over the counter for high sums of money that affect the Accounts of state entities.
48.- Consecutive opening of several "Money Transfer Accounts" or sending of international money orders on behalf of different people with similar characteristics (age, economic activity, location, family ties), who apparently do not know each other, with the aim of sending international money orders to the same or different countries.
49.- Receipt of money orders from various senders, in different countries, and in favor of the same beneficiary.
50.- The same sender sending money orders to several beneficiaries with no apparent relationship.
51.- Money orders sent in favor of a group of people, with no apparent relationship or who do not know each other, with the same phone number or address to contact them.
52.- Sending of international money orders by different senders in favor of a common beneficiary.
53.- Sending of consecutive international money orders for equal or similar amounts of money, destined for the same country.
54.- Sending of international money orders for the same amount, on the same date, to the same city or country, in the name of different people who apparently do not know each other.
55.- Sending of multiple international money orders, to the same country, on behalf of one or several senders, when the amount is lower and very close to the limit established for control of cash transactions.
56.- Multiple international money orders, coming from different places and/or different senders, cashed by the same beneficiary and/or in different cities of the country without an apparent justification.
57.- International money orders for the same amount, generally consecutive, which are cashed simultaneously on the same date and city, in the name of different people who apparently do not know each other.
58.- International money orders paid by checks, in favor of different beneficiaries, which after being endorsed (sometimes with similar graphological traits) are cashed by the same person, or which are endorsed illegibly and cashed in cash in such a way that the identity of the final beneficiary cannot be verified.
59.- International money orders in which the beneficiary wants to cash them in cash and initially refuses to accept payment by check, due to the amount of the operation or the policies of the Entity.
60.- International money orders paid by credit to a bank Account different from that of the beneficiary, without an apparent justification or relationship.
61.- International money orders paid by transfers to checking, savings or other financial instruments, the money from which is withdrawn immediately or in a very short time through ATMs.
62.- International money orders to pay beneficiaries who have been contacted by telephone and who at the time of cashing declare that they do not know the sender or that they do not have people or relatives abroad.
63.- Beneficiaries who periodically present themselves (weekly or more frequently) to cash international money orders without the Entity having contacted them and even without the financial entity having received the transfer.
64.- Beneficiaries of money orders who are unaware of the sender's name, the origin, the amount and the purpose of the money.
65.- Failure to withdraw funds against checks deposited, by a client who operates a retail business and provides the service of buying checks. This suggests that such a client has another source of funds.
66.- Clients who often visit the safe deposit box area immediately before making a deposit of cash whose amount is just below the limit required to generate a report.
67.- Significant changes in the patterns of sending cash between correspondent banks.
68.- Persons carrying out numerous and frequent transactions on electronic ATMs charged to Bank Accounts abroad.
69.- Purchase and sale of cash foreign exchange frequently carried out by persons or businesses that are not authorized to carry out this activity.
70.- Purchase and sale of cash foreign exchange that show signs of structuring just below the limit indicated in the law to be reported.
71.- An entrepreneur receives money from a "third party" to put non-existent persons or straw men on his Payroll List that he designates, with the aim that through the Payroll Bank Accounts service, he pays or returns said money under the justification of salaries.
72.- Unusual or suspicious flows or activities in the movement of internal or external physical money, from or to the Supervised Entity.
73.- Branches that reflect atypical behavior in the composition of their cash in box regarding amounts or types of denominations and currencies that do not relate to their profile, whether it be a net cash collector or net cash placer, in relation to the characteristics of the market in which it operates or economic seasonality.
III.- Specific to the Insurance Market
1.- Request for transactions that do not correspond to the normal operations profile of the policyholder or are outside the ordinary pattern of the insured.
2.- Insurance policies with premiums that exceed the client's apparent means or possibilities.
3.- Payment of premium by international transfer in which the identity of the orderer or the number of the source account is not contained.
4.- Insurance policies with values that seem incompatible with the client's insurance needs.
5.- The client requests an insurance product that has no discernible purpose and is reluctant to reveal the reason for the investment.
6.- The short period between the establishment of a considerable value policy and the time of its redemption, especially when it is requested that the surrender value be returned in favor of a third party.
7.- Clients who suspiciously seek to have the insured value be higher than initially established, including expensive accessories within the policy.
8.- Dubious origin of the insured goods as there is no apparent reason for the client to possess or hold them.
9.- Policies in which the interveners are crossed (for example, the policyholder of one policy is the insured of another policy in which the insured of the first policy appears as the policyholder) and no reasons justifying this are appreciated.
10.- Plurality of policies with a single beneficiary.
11.- Insurance in multiple policies by the same person for very significant amounts, whether with one or different insurers.
12.- Collective insurance for companies with high employee turnover.
13.- Early surrender of life insurance within a relatively short interval of time from contracting.
14.- The same beneficiary of life or retirement insurance policies for very significant amounts, contracted by different people.
15.- Policies that cover death, and this occurs abroad.
16.- Early cancellation of a life insurance without penalty or indication of the reasons.
17.- Life insurance contracted with conditions outside the market.
18.- An atypical incidence of early payment of insurance premiums.
19.- Early conclusion of an insurance product, especially with loss, or transaction in which cash and/or a refund check is issued to a third party.
20.- The client does not seem to be concerned about the price of the policy, or the convenience of the product for their needs.
21.- The applicant for an insurance product shows no interest in the performance of the policy, but does show great interest in knowing the procedure for early cancellation of the contract.
22.- The client arranges or seeks to cancel, before its maturity, an expensive single-premium life insurance policy, without worrying about the additional costs or charges this represents.
23.- The client contracts a policy for a very significant amount and after a short period of time requires the refund of the funds, requesting that they be credited to a third party, not caring about the discount for early cancellation.
24.- The client accepts very unfavorable conditions in the policy that have no relation to their health or age.
25.- The client seeks the purchase of a single-premium policy, or to prepay premiums and thus borrow the maximum cash value, or use said policy as collateral for a loan.
26.- Request for a policy by a potential client from a distant geographical location, when close to their home they could obtain a contract of similar characteristics.
27.- Involvement of an Agent, Intermediary or Insurance Broker coming from a jurisdiction or geographical area that is not regulated, or whose regulation is very lax, or where organized crime activities are frequent.
28.- Large flows of funds through Insurance Brokers for non-resident accounts.
29.- Transfer of the benefit of an insurance product in favor of a third party who apparently has no relation with the client.
30.- Change of designated beneficiaries, with an apparent reason, especially if this can be done without the knowledge or consent of the insurer and/or the right to receive payment can be transferred simply by endorsing the policy.
31.- Policies in which, shortly before the payment of the benefit, the beneficiary is changed.
32.- Substitution, during the term of an insurance contract, of the final beneficiary by a person who apparently has no connection with the policyholder.
33.- Attempt to use a third party's check to buy a policy.
34.- The applicant for an insurance product attempts to use cash to conclude a transaction that is normally settled by means of checks or other payment instruments.
35.- The applicant for an insurance product seems to have policies with several institutions.
36.- The Insurer receives instructions to accelerate the maturity of a life insurance policy just at the moment when the client is mentioned in news or trials linked to organized crime.
37.- Purchase of insurance that covers risks to which the client is not effectively exposed, for example, marine liability insurance for a "ghost" ship.
38.- Payment of very high premiums for the policy, and frequent claims for smaller amounts, in order to receive the amounts related to them through checks, leaving the respective and reasonable profit margin to the Insurer.
39.- Agreement for the assignment and payment of claims, through which persons or legal businesses authorize and request that the payment of claims or indemnification for loss be made in favor of a third party, who has previously promised to pay them in cash, traveler's checks or payment orders for the amount of said claim plus a commission, all in exchange for the Insurer's check.
40.- Claim for "ghost" losses or alleged loss (for example, car theft) of valuable insured goods.
41.- Insurance of "ghost" or non-existent goods, or supported with false documentation; and subsequent claim for alleged losses on the same.
42.- Delivering checks for claim payments and in the respective receipt the beneficiary is not identified with an official document.
43.- False phone numbers and addresses of policy beneficiaries.
44.- Premiums that are commonly paid in one type of currency and claims are requested in another currency; or it is requested that the unearned premium be collected in a currency different from that in which the insurance was originally contracted.
45.- A number of low-denomination policies are contracted and cancelled immediately by the same agent.
46.- The crediting of the unearned premium is made to an account different from that from which the funds originally came.
47.- Insurance of goods and businesses that represent excessively large sums, and in an "accidental" but recurrent manner, the client makes overpayments of premiums and consequently requests the respective refund by check or electronic transfer.
48.- When the overpayment of premiums is made through an agent and has the following characteristics: it is of considerable or significant magnitude and the request for reimbursement or refund of the funds is made in favor of a third party and the insured is in a jurisdiction with frequent cases associated with money laundering.
49.- An Insurance Broker receives premium payment in cash and deposits the funds in their bank but does not notify it.
50.- Insurers that are willing to pay a value much higher than the average market rate in reinsurance, in favor of companies whose owners are not clearly identified nor can any public domain information be verified.
51.- Official or employee of an Insurer or Agent, Intermediary or Insurance Broker who suddenly and without reasonable explanation, has an exaggerated level in their portfolio of single-premium life insurance sales.
52.- Notable and unexpected increase in sales or results by Insurance intermediaries.
IV.- Specific to the Securities Market
1.- Investment operations in negotiable securities for unusual large amounts that do not correspond to the declared activity and/or the client's financial/net worth situation.
2.- Operations arranged at prices that do not relate to market conditions.
3.- Payment/collection of premiums excessively higher/lower than those negotiated in the options market.
4.- Purchase/Sale of negotiable securities in the spot market at prices notably higher/lower than the quotes being negotiated.
5.- Purchase/sale of the underlying asset — by exercise of the option — at prices that do not have a convenient relationship with the exercise price.
6.- Purchase/Sale of futures contracts at prices considerably higher/lower than the quotes being negotiated.
7.- Purchase of negotiable securities for very notable amounts.
8.- Very relevant amounts in the guarantee margins paid for open positions in the futures and options markets.
9.- Very high investment in premiums in the options market.
10.- Very relevant investment in stock lending or margin operations.
11.- Client requests for investment portfolio administration services, where the origin of the funds is not clear or is not consistent with the type of business or declared activity.
12.- Investment operations in negotiable securities for very high nominal volumes, which do not relate to the volumes traditionally operated in the species for the type of client.
13.- Operations carried out repeatedly between the same parties, in which there are continuous gains or losses for any of them.
14.- Client who carries out succession of transactions and/or transfers to other principal accounts without apparent justification.
15.- Client who carries out complex financial operations (financial engineering) without a concrete purpose.
16.- Purchase of participation quotas in investment funds, without respecting the stipulated deadlines, redeeming the investment early, despite the penalties.
17.- Purchases of high-risk securities on successive occasions and early resale for values lower than those initially agreed.
18.- Investments in negotiable banking securities from sensitive regions (tax havens or countries related to terrorism).
19.- Frequent investments in uninteresting securities by companies that do not dedicate themselves to the investment sector.
20.- Frequent investments by Non-Profit Organizations, with request for early termination in the name of third parties through manager's checks.
21.- Requests for "interesting" investments, from tax haven intermediaries.
22.- Early termination of investments, with request by the intermediary, for the transfer of resources to a tax haven.
23.- Significant investments by companies with low liquidity rating.
V.- Specific to the General Warehouse Market
1.- Merchandise in the process of nationalization whose weight, size, or physical characteristics in general do not seem consistent with the data recorded in the documentation supporting the operation.
2.- Differences between the different boxes, bundles or packages of a merchandise that is exported/imported in block.
3.- Transport of merchandise of foreign origin from ports or border places to the interior of the country without the transporter presenting the documentation that accredits the legal importation of merchandise.
4.- Natural or legal persons who carry out a considerable volume of exports/imports without having sufficient infrastructure and economic capacity.
5.- Importers/exporters mentioned in the media for belonging or having links with criminal activities or organizations.
6.- Atypical exports/imports not in accordance with the country of origin and/or destination.
7.- Companies that shortly after being created, carry out very significant foreign trade operations and then become inactive or are liquidated.
8.- Exports/imports of products sensitive to smuggling carried out to countries with lax regulation in foreign trade and with free zones.
9.- Exports/imports of goods or merchandise in poor condition, expired or with short expiration and/or request for issuance of deposit certificates and pledge bonds on this type of merchandise.
10.- Request for issuance of deposit certificates and pledge bonds on agricultural products or merchandise destined for export carried out by natural or legal persons without antecedents in this type of activities and/or who buy directly from the producer in cash and their banking references are not in accordance with the sums of money handled.
11.- Goods or merchandise abandoned without justification on which financing has been granted.
12.- Overvaluation of goods or merchandise on which the issuance of deposit certificates and pledge bonds is requested.
13.- Export/import of goods or merchandise overvalued and undervalued.
14.- Change of owners of the merchandise and the history of the new owners that is not consistent with the nature of the client's business or the new owners are reluctant to provide personal or financial information.
15.- Changes of ownership of deposit certificates and/or pledge bonds without there being coherence between the type of business and the history of the new owner(s) and/or the latter evade the delivery of their financial antecedents.
16.- Carrying out consecutive and/or simultaneous purchases and sales of deposit certificates and/or pledge bonds, with the aim of generating an artificial volume of investments.
17.- Non-payment of credits intentionally so that the pledged goods or merchandise are auctioned.
18.- Transactions with deposit certificates and pledge bonds, which repeat in short intervals of time and involve cash, especially if the counterparties are in vulnerable geographical areas.
Annex 4: Instruction and Format for the Presentation of the Suspicious Operations Report (ROS).
I.- Instruction for the presentation and transmission of the Suspicious Operations Report (ROS):
i. The ROS must be sent by the entity to the competent authority in a single copy within a hermetically closed envelope, sealed and stamped by the entity, accompanied by an original transmission letter attached to the envelope, having as the only addressee the representative of the competent authority.
ii. The entity must not send a copy of the ROS or the transmission letter to any person or other authority.
iii. On the cover of both documents (the envelope containing the ROS and the transmission letter) the indicative note CONFIDENTIAL will be placed.
iv. Both documents (the envelope containing the ROS and the transmission letter) must be delivered directly to the offices of the competent authority, who will stamp the respective Acknowledgment of Receipt on the transmission letter and its copy. The copy of the transmission letter will be returned to the reporting entity as support for the delivery of the closed envelope containing the ROS.
v. Each ROS will be identified with a Numerical Code that will be configured by the union of four aspects or sections, in the following way:
vi. The Numerical Code that identifies each ROS, will be inscribed on the cover of the envelope, on the transmission letter and on each page of the Report itself.
vii. For each ROS there will be an exclusive envelope, therefore, if two or more ROS are presented at the same time, each one will come in its own envelope, and in the transmission letter the Numerical Codes that identify each of the envelopes with the ROS will be specified.
viii. In the transmission letter and in the envelope containing the ROS, no type of explanation or narration about the content of the envelope or the ROS itself, nor about the reported suspicious activity, nor about the documents attached, nor about the name(s) mentioned in the ROS, must be made.
ix. In corrections, additions, supplements, expansions or complements to a previous ROS, these same measures of quality, confidentiality and security will apply.
x. Each ROS will always retain its Numeric Code that identifies it; therefore, that same Numeric Code will be applied to any corrections, additions, supplements, expansions, or complements made to the same ROS subsequently, indicating this circumstance on the envelope and in the transmittal letter, as follows.
Example: EXPANSION: R-XXXX-017-2008 / A-1 This indicates that this is expansion information (the first) of Report number 17 issued in the year 2008 by entity XXXX.
Example: CORRECTION: R-XXXX-017-2008 / C-1 This indicates that this is correction information (the first) of Report number 17 issued in the year 2008 by entity XXXX.
Example: CORRECTION: R-XXXX-017-2008 / C-2 This indicates that this is correction information (the second) of Report number 17 issued in the year 2008 by entity XXXX.
xi. When a ROS, even having direct or indirect linkage with a previous ROS, refers to different clients and operations, it will be considered a new ROS, and consequently will have its own Numeric Code. However, within the information, it must be mentioned that the linkage exists with other ROSs.
xii. The ROS (within the envelope) must contain the Numerically Encoded Signature of the AML/CFT Administrator (or their Substitute, as the case may be) of the Supervised Entity. The ROS will not contain the name of said official nor their autograph signature. Said Encoded Signature will be permanent and will be configured by the union of four aspects or sections, as follows:
Example: F-XXXX-AB-XXXXXX
xiii. Each page of the ROS will contain the Encoded Signature of the AML/CFT Risk Manager and the seal of the reporting Supervised Entity.
xiv. The transmittal letter of the ROS must be autographically signed by the AML/CFT Risk Manager of the Supervised Entity, in addition to containing the entity's seal.
xv. ROSs presented without meeting these requirements will be returned by the competent authority.
xvi. Each time a ROS is generated, the entity must update the respective Comprehensive Client Profile.
II.- Format for the Presentation of the Suspicious Operation Report (ROS)
FORMAT
SUSPICIOUS OPERATION REPORT (ROS)
Initial Report Correction Expansion
I.- Reporting Supervised Entity
1 Name
2 Headquarters Address
II Person(s) linked to the Suspicious Operation (Note: For each person linked directly or indirectly, as client, beneficiary, or manager, the following table must be completed with all pertinent information)
A. Full Name:
B. Sex:
C. Nationality of Origin and Acquired:
D. Marital Status:
E. Profession or Occupation:
F. Date of Birth:
G. Spouse's Name:
H. Address (Residential and Work):
I. Identification Document for Natural Person:
Passport Nicaraguan ID Residency Card Other
Document Number:_______________________________ Document Registration Number:_____________________ J. Identification Document for Legal Entity:
RUC Number:_____________________________________ Commercial Registry Number:_____________________ Number of Other Registries: _______________________ K. Contact Data:
Conventional Phone:_________________
ROS Code:
Cell Phone:_______________________
Fax:__________________________________
Email:_____________________
Postal Code:_________________________
L. Economic Activity:
M. Type of Relationship with the Supervised Entity:
Client Potential Client Manager
Employee Legal Representative Official Director Shareholder Other____________________________________
III Information Regarding the Suspicious Operation
A. Date of Detection of the Operation:
B. Indicate whether the transaction was carried out, attempted, or rejected; and also whether it was decided to terminate or continue the relationship with the client.
C. Type(s) of Financial Means and Instruments Used:
Currency Cash Fund Transfer Personal Check
Cashier Check Management Check Traveler Check
Bonds Securities Credit Card Credit Line Other D. Description of Financial Means and Instruments Used (Describe the instrument including type, issuer, serial number, amount) E. Amount of the Operation (Indicate the value in dollars and in national currency. Indicate aggregated values if the activity involves more than one transaction related to the same person during the same period. Leave blank if the exact total value is not known) F. Description of the Operation (Provide a complete chronological narrative of the unusual or irregular facts that may constitute a violation of the Law and its regulations. The narrative must be explicit and clear. The narrative must include, without limitation, the following: Details regarding supporting documentation and retain the documentation at the Supervised Entity for a period of five years; Indicate the person(s) who benefited through the transaction, the amount, and the circumstances of their benefit; Identify the Branch where the operation took place. Identify the Start Date of the Relationship. Describe and retain explanations provided by the actor of the unusual activity; Provide detail on the instruments used and accounts involved in the activity) G. Accounts related to the Suspicious Operation Account No. Type Status
H. Observations:
Encoded Number of the AML/CFT Risk Manager
Seal of the Supervised Entity
ANNEX 5: Manual and Format for the Automated Presentation of Cash Transaction Reports (RTE)
i.- Conceptual Aspects (Data Flow)
:: General data sending process
Generates data files from proprietary systems
Compresses files with ZIP format
Uploads compressed file to SIBOIF server
Validates user and key on SIBOIF server
Validates file format
Validates form, consistency, substance, and balance Unifies data Encrypts (ciphers) the file (GNUPG) Data okay?
Yes
Generates incident file
No
Data okay?
Yes
No
Yes
Notification via email
Note:
If there are incidents, the files will be compressed with Zip format and then encrypted with GNUPG only and exclusively for the corresponding Financial Institution.
The files will be located in the corresponding folder of the Financial Institution to be downloaded via SSH from FTP.
Figure 1 General process of data sending and reception
The main data sending flow is shown in “Figure 2: General process of data sending and reception.”:
ii.- Types of Sendings
ii.1 Sendings from Financial Institutions to SIBOIF
Type of sending Files Description
PLdD_Datos General data on transactions
PLdD_Personas General information on persons (Beneficiaries and/or Managers) PLdD_PLdD_Datos_Persona Relacion Data vs. Persons
Table 1 Types of sendings from Financial Institutions to SIBOIF
PLdD_Datos id_transaccion: int fecha: datetime id_sucursal: int id_tipo_reporte: int id_tipo_transaccion: char(1) id_numero_cuenta: varchar(20) id_tipo_operacion: int monto: numeric(20,2)
PLdD_Datos_Persona id_persona: varchar(20) id_tipo_documento: int id_transaccion: int id_tipo_relacion: char(1)
PLdD_Personas id_persona: varchar(20) id_tipo_documento: int id_cedula_residencia: varchar(20) direccion: varchar(250) id_pais: int nombre: varchar(100) numero_de_registro: varchar(20)
ii.2 Format of the files
The format of the files to be used for data sending to SIBOIF is a text file (ASCII). The fields must be separated by the “|” (vertical bar) character, and the fields/variables that are characters (varchar) must be delimited by double quotes.
For example, the Money Laundering Prevention file is composed of a series of fields (see Annex A.1: Type of sending: Money Laundering Prevention). An example of the content of said file for the first five fields is shown below:
"20060301"|999|"0071"|"VALERIA"|"LISSETH"|"CARCAMO"|"PRADO"|"BO. J. GONZALEZ, CENTRO COMUNITARIO 620VRS.E."|9|"0060105930006H"|"NI"|""|""|""|""|"EMPRESA NICARAGUENSE AGUA, S.A"|"EDIFICIO VILLA FONTANA 4TO PISO"|4|"301F195D9520"|"--"|"I"|54547.873|91|"" "20060301"|999|"0071"|"SALVADOR"|"AUGUSTO"|"BALDIZON"|""|"REPARTO J.R. PADILLA, 6TA. CALLE"|1|"0021302360000X"|"NI"|""|""|""|""|"ACME S.A"|"KM. 5 1/2 C. NORTE COMPLEJO INDUSTRIAL"|7|"2107909551"|"--"|"X"|27636.860000000001|91|"" "20060301"|999|"0071"|"ALVARO"|"JOSE"|"FLORES"|"GARCIA"|"VILLA DON BOSCO, FTE. A LA CRUZ ROJA"|1|"0042810790006L"|"NI"|""|""|""|""|"ACME #2 S. A."|"DE LA ROTONDA EL GUEGUENSE 175VRS AL SUR"|4|"180883759502"|"--"|"I"|13239.440000000001|11|"" "20060301"|999|"0071"|"DAE"|"KYU"|"JOHN"|"CC"|"VILLA FONTANA ENITEL 250MTS AL SUR 4C ABAJO"|1|"40348515"|"NI"|"KANG AE"|""|"LEE"|""|""|"CONDOMINIO LOMA,DEL PARQUE 150 MTS AL SUR"|2|"2036679D65"|"KR"|"I"|20941.43|11|""
The names of the files to be sent must have the name found in parentheses in “Table 1 Types of sendings from Financial Institutions to SIBOIF” with the .txt extension with the format previously stated.
The sendings must be compressed with Zip format. Then they must be encrypted with GNUPG with the .dat extension.
The name of the encrypted file must contain at the end of it the underscore symbol (“_”) followed by the code generated by the cryptographic Sha-1 function. This code serves to guarantee that the sent file has not been altered during transmission.
Example: ACME200510_c477cd741fe913af75dc92ffd27ece78a7348760.dat
ii.3 Sendings from SIBOIF to Supervised Entities
SIBOIF will make available to Supervised Entities a dedicated folder on an FTP (File Transfer Protocol) server to locate incident files, credit references, consolidations, among others. This site will be accessed via SSH (Secure Shell). Each Supervised Entity will have unique and exclusive access to its folder; additionally, the files located in these folders will be encrypted only and exclusively for the respective Supervised Entity. Figure 2 shows an example of the site structure.
FTP Server Institutions
B1
Bn
F1
Fn
Figure 2 FTP Server
SIBOIF has a type of sending to Financial Institutions:
The format of these files will be text (ASCII) as stated in section (1.3.2 Format of the files).
The names of the files will be found compressed (Zip) and in turn encrypted (GNUPG):
File Name Nomenclature
Incidents (errors) yyyymmdd_hh_mi_ss_mmm_[id_carga]_SiglasInstFin_PLdD_Errores_SHA1.dat
Example:
20051104_16_41_14_030_[635]_ACME_PLdD_Error_es_4a578ecd09a2d0c8431bdd8cf3d5c5f3ddcddfc9.dat
yyyy Year mm Month dd Day hh Hour mm Minutes ss Seconds mmm Milliseconds id_carga Load ID SiglasInstFin Supervised Entity Initials PLdD Money Laundering Prevention SHA1 Code generated by the cryptographic Sha-1 function
Table 2 Nomenclature of the names of files to be sent by SIBOIF
iii.- File formats according to type of sending
iii.1: General Data Money Laundering Prevention (PLdD_Datos)
Order Field Data Type Description Required Related Table 1 id_transaccion int Unique transaction number defined by the Entity Yes 2 fecha yyyymmdd Date of transaction or transactions Yes 3 id_sucursal int Code assigned by the Supervised Entity Yes 4 id_tipo_reporte int id_tipo_reporte 5 id_tipo_transaccion char(1) Type of transaction Yes id_tipo_transaccion 6 id_numero_cuenta varchar(20) Account number Yes 7 id_tipo_operacion int Operation type Yes id_tipo_operacion 8 monto numeric(20,2) Transaction amount Yes
iii.2: Persons (PLdD_Persona)
Order Field Data Type Description Required Related Table 1 id_persona varchar(20) Person Identification. Number of the identification of the natural or legal person, national or foreign, who maintains some type of relationship (debtor, guarantor, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) of the Supervised Entity, according to the type of document established in this Manual. Yes 2 id_tipo_documento int Document Type. Indicates the code of the type of document corresponding to the identification used by the natural or legal person, national or foreign, who maintains some type of relationship (debtor, guarantor, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) with the financial institution, Yes id_tipo_documento 3 id_cedula_residencia varchar(20), Residency Card Yes 4 direccion varchar(250) Person's address Yes 5 id_pais int Country ID Yes id_pais 6 nombre varchar(100) Name. Indicates the name or trade name of the natural or legal person, national or foreign, which must be in correspondence with the identification document presented by the same. In the case of natural persons, they must report first the names and then the surnames. Yes 7 numero_de_registro varchar(20) Registration number Yes
iii.3: Data versus Person Relationship (PLdD_Datos_Persona)
Order Field Data Type Description Required Related Table 1 id_persona varchar(20) Person Identification. Number of the identification of the natural or legal person, national or foreign, who maintains some type of relationship (debtor, guarantor, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) of the Supervised Entity, according to the type of document established in this Manual. Yes 2 id_tipo_documento int Document Type. Indicates the code of the type of document corresponding to the identification used by the natural or legal person, national or foreign, who Yes id_tipo_documento
Order Field Data Type Description Required Related Table maintains some type of relationship (debtor, guarantor, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) with the Supervised Entity, according to the corresponding catalog established in this Manual. 3 id_transaccion int Transaction number Yes 4 id_tipo_relacion char(1) Type of relationship Yes id_tipo_relacion
iv.- SIBOIF response files
iv.1: Incidents
Order Field Data Type Description Related Table 8 Linea Int Original line of transmission of the file where the incident is found 9 Id_validacion varchar(500) Validation codes separated by commas if more than one error is found in the indicated line.
Example:
"20060301"|999|"0071"|"VALERIA"|"LISSETH"|"CARCAMO"|"PRADO"|"BO. J. GONZALEZ, CENTRO COMUNITARIO 620VRS.E."|9|"0060105930006H"|"NI"|""|""|""|""|"EMPRESA NICARAGUENSE AGUA, S.A"|"EDIFICIO VILLA FONTANA 4TO PISO"|4|"301F195D9520"|"--"|"I"|54547.873|91|""|1|"50.001.0005, 50.001.0008" "20060301"|999|"0071"|"SALVADOR"|"AUGUSTO"|"BALDIZON"|""|"REPARTO J.R. PADILLA, 6TA. CALLE"|1|"0021302360000X"|"NI"|""|""|""|""|"ACME S.A"|"KM. 5 1/2 C. NORTE COMPLEJO INDUSTRIAL"|7|"2107909551"|"--"|"X"|27636.860000000001|91|""|2|"50.001.0001, 50.001.0002, 50.001.0008, 50.001.0003"
iv.2: Statistics
Order Field Data Type Description Related Table 1 Id_consecutivo int Consecutive number 2 Id_validacion Varchar(20) Validation code.
3 Descripcion varchar(500) Description of the validation that was violated
Example
1|"50.001.0002"|"0060105930006H: The type of identification of the Beneficiary/Manager is not found in {1, 2, 3, 4, 5, 6, 7, 9}."
2|"50.001.0005"|"0060105930006H: Transaction Type is not found in {11, 12, …, 27}."
3|"50.001.0001"|"0021302360000C: The identifier 'Individual Fractional' does not … in {I, F}."
4|"50.001.0002"|"0021302360000C: The type of identification of the Beneficiary/Manager does not … {1, 2, 3, 4, 5}."
5|"50.001.0005"|"0021302360000C: Transaction Type is not found in {11, 12, …, 27}."
6|"50.001.0003"|"0021302360000C: The beneficiary/manager's residency card does not comply with the algorithm ...."
Note: With the objective of saving space, the last two messages were cut off. In practice, the corresponding description from the Validation Catalog (Annex C.3) will appear.
v.- Annex catalogs
v.1: General catalogs
id_tipo_documento 1 Foreign Natural Residents (Residency Card).
2 Legal Entities (RUC -Nicaragua).
3 Foreign Natural Non-Residents (Passport).
4 Nicaraguan (Citizen Identity Card)
5 Nicaraguan Residents Abroad (Passport).
6 Foreign Natural Diplomatic, Consular Officials, International Organizations, and Special Guests (Chancellery Card of the Republic).
7 Legal Entities without Profit Purposes (MIGOB Card) 9 Generic Identification / Identification Unknown by the Supervised Entity.
id_tipo_reporte
1 Cash Transaction Report above determined threshold (RTE ) 2 Financial Transfer Report (RTF) 3 Consignment Instrument Purchase/Sale Report (RCIC)
id_tipo_transaccion
I Individual
F Fractional
id_tipo_operacion
11 Deposits
12 National transfers sent
13 International transfers sent
14 Purchase of consignment instruments
15 Exchange desk (Inflows)
16 Credit Payments
17 Service Payments
18 Various Inflows
21 Account withdrawal
22 National transfers received
23 International transfers received
24 Payment of consignment instruments
25 Exchange desk (Outflows)
26 Credit Disbursements
27 Various Outflows
id_tipo_relacion G Manager
B Beneficiary
A Both (Beneficiary and Manager)
Id_nacionalidad, id_pais
[1, 80 ]
4 AFGHANISTAN
8 ALBANIA
10 ANTARCTICA
12 ALGERIA
16 AMERICAN SAMOA
20 ANDORRA
24 ANGOLA
28 ANTIGUA AND BARBUDA
31 AZERBAIJAN
32 ARGENTINA
36 AUSTRALIA
40 AUSTRIA
44 BAHAMAS
48 BAHRAIN
50 BANGLADESH
51 ARMENIA
52 BARBADOS ISLAND
56 BELGIUM
60 BERMUDA
64 BHUTAN
68 BOLIVIA
70 BOSNIA AND HERZEGOVINA
72 BOTSWANA
74 BOUVET ISLAND
76 BRAZIL
84 BELIZE
86 BRITISH TERRITORY IN THE INDIAN OCEAN
90 SOLOMON ISLANDS
92 VIRGIN ISLANDS (BRITISH)
96 BRUNEI DARUSSALAM
100 BULGARIA
104 MYANMAR
108 BURUNDI
112 BELARUS
116 CAMBODIA
120 CAMEROON
124 CANADA
132 CAPE VERDE
136 CAYMAN ISLANDS
140 REPUBLIC OF CENTRAL AFRICA
144 SRI LANKA
148 CHAD
152 CHILE
156 CHINA
158 TAIWAN
162 CHRISTMAS ISLAND
166 COCOS (KEELING) ISLANDS
170 COLOMBIA
174 COMOROS
175 MAYOTTE
178 REPUBLIC OF CONGO
180 DEMOCRATIC REPUBLIC OF CONGO, (FORMERLY ZAIRE) 184 COOK ISLANDS 188 COSTA RICA 191 CROATIA 192 CUBA 196 CYPRUS 203 CZECH REPUBLIC 204 BENIN 208 DENMARK 212 DOMINICA 214 DOMINICAN REPUBLIC 218 ECUADOR 222 EL SALVADOR 226 EQUATORIAL GUINEA 231 ETHIOPIA 232 ERITREA 233 ESTONIA 234 FAROE ISLANDS 238 FALKLAND ISLANDS (MALVINAS) 239 GEORGIA ISLANDS SOUTH AND SOUTH SANDWICH 242 FIJI 246 FINLAND 248 ALAND ISLANDS 250 FRANCE 254 FRENCH GUIANA 258 POLYNESIA (FRENCH) 260 FRENCH SOUTHERN TERRITORIES 262 DJIBOUTI 266 GABON 268 GEORGIA 270 GAMBIA 275 PALESTINIAN TERRITORY (OCCUPIED) 276 GERMANY 288 GHANA 292 GIBRALTAR 296 KIRIBATI 300 GREECE 304 GREENLAND (GREENLANDIA) 308 GRENADA 312 GUADELOUPE (FRENCH) 316 AMERICAN GUAM 320 GUATEMALA 324 GUINEA 328 GUYANA 332 HAITI 334 HEARD ISLAND AND MCDONALD ISLANDS 336 THE VATICAN 340 HONDURAS 344 HONG KONG 348 HUNGARY 352 ICELAND 356 INDIA 360 INDONESIA 364 IRAN (ISLAMIC REPUBLIC) 368 IRAQ 372 IRELAND 376 ISRAEL 380 ITALY 384 COTE D'IVOIRE (COTE D´IVOIRE) 388 JAMAICA 392 JAPAN 398 KAZAKHSTAN 400 JORDANIA 404 KENYA 408 DEMOCRATIC PEOPLE'S REPUBLIC OF KOREA 410 REPUBLIC OF KOREA 414 KUWAIT 417 KYRGYZSTAN 418 DEMOCRATIC PEOPLE'S REPUBLIC OF LAOS 422 LEBANON 426 LESOTHO 428 LATVIA 430 LIBERIA 434 LIBYAN ARAB JAMAHIRIYA POPULAR AND SOCIALIST (LIBYA) 438 PRINCIPALITY OF LIECHTENSTEIN 440 LITHUANIA 442 LUXEMBOURG 446 MACAO 450 MADAGASCAR 454 MALAWI 458 MALAYSIA 462 MALDIVES 466 MALI 470 MALTA 474 MARTINIQUE 478 MAURITANIA 480 MAURITIUS ISLAND 484 MEXICO 492 MONACO 496 MONGOLIA 498 REPUBLIC OF MOLDOVA 500 MONTSERRAT 504 MOROCCO 508 MOZAMBIQUE 512 OMAN 516 NAMIBIA 520 NAURU 524 NEPAL 528 HOLLAND 530 DUTCH ANTILLES 533 ARUBA 540 NEW CALEDONIA 548 VANUATU 554 NEW ZEALAND 558 NICARAGUA 562 NIGER 566 NIGERIA 570 NIUE 574 NORFOLK ISLANDS 578 NORWAY 580 NORTHERN MARIANA ISLANDS 581 MINOR OUTLYING ISLANDS OF THE UNITED STATES 583 FEDERATED STATES OF MICRONESIA 584 MARSHALL ISLANDS 585 PALAU 586 PAKISTAN 591 PANAMA 598 PAPUA NEW GUINEA 600 PARAGUAY 604 PERU 608 PHILIPPINES 612 PITCAIRN (PITCAIRN ISLANDS) 616 POLAND 620 PORTUGAL 624 GUINEA-BISSAU 626 EAST TIMOR 630 PUERTO RICO 634 QATAR 638 REUNION 642 ROMANIA 643 RUSSIAN FEDERATION 646 RWANDA 654 HELENA ISLAND 659 SAINT KITTS AND NEVIS 660 ANGUILLA
662 SAINT LUCIA
666 SAINT PIERRE AND MIQUELON
670 SAINT VINCENT AND THE GRENADINES
674 SAN MARINO
678 SAO TOME AND PRINCIPE
682 SAUDI ARABIA
686 SENEGAL
690 SEYCHELLES
694 SIERRA LEONE
702 SINGAPORE
703 SLOVAKIA
704 VIETNAM
705 SLOVENIA
706 SOMALIA
710 SOUTH AFRICA
716 ZIMBABWE
724 SPAIN
732 WESTERN SAHARA
736 SUDAN
740 SURINAME
744 SVALBARD AND JAN MAYEN
748 ESWATINI
752 SWEDEN
756 SWITZERLAND
760 SYRIAN ARAB REPUBLIC
762 TAJIKISTAN
764 THAILAND
768 TOGO
772 TOKELAU
776 TONGA
780 TRINIDAD AND TOBAGO
784 UNITED ARAB EMIRATES
788 TUNISIA
795 TURKMENISTAN
796 TURKS AND CAICOS ISLANDS
798 TUVALU
800 UGANDA
804 UKRAINE
807 REPUBLIC OF NORTH MACEDONIA (FORMER YUGOSLAV REPUBLIC OF) 818 EGYPT 826 UNITED KINGDOM
834 UNITED REPUBLIC OF TANZANIA
840 UNITED STATES OF AMERICA
850 VIRGIN ISLANDS (U.S.A)
854 BURKINA FASO
858 URUGUAY
860 UZBEKISTAN
862 VENEZUELA
876 WALLIS AND FUTUNA ISLANDS
882 SAMOA
887 YEMEN
891 SERBIA AND MONTENEGRO
894 ZAMBIA
Reporting Entity ID
1105 BANCO DE LA PRODUCCION, S.A.
1106 BANCO DE CREDITO CENTROAMERICANO, S.A.
1107 BANCO DE AMERICA CENTRAL, S.A.
1108 BANCO DE FINANZAS, S.A.
1109 BANCO UNO, S.A.
1113 BANCO PROCREDIT, S.A.
1119 FINANCIERA ARREDADORA CENTROAMERICANA, S.A.
1120 FINANCIERA NICARAGUENSE DE DESARROLLO, S.A.
1125 BANCO HSBC NICARAGUA, S.A.
1132 FINANCIERA FAMA, S.A
1133 FINANCIERA NICARAGUENSE DE INVERSIONES, S.A.
2101 INVERSIONES DE CENTROAMÉRICA, S.A.
2103 LAFISE VALORES, S.A.
2105 BAC VALORES, S.A.
2107 INVERSIONES BURSÁTILES EXPO, S.A.
2109 INVERSIONES DE NICARAGUA, S.A.
2110 PROVALORES S.A.
2120 CENTRAL NICARAGUENSE DE VALORES
2121 BOLSA DE VALORES DE NICARAGUA
3101 INSTITUTO NICARAGUENSE DE SEGUROS Y REASEGUROS METROPOLITANA COMPAÑÍA DE SEGUROS, S.A.
3103 SEGUROS AMÉRICA, S.A.
3104 SEGUROS LAFISE, S.A.
3105 ASEGURADORA MUNDIAL, S.A.
4101 ALMACENADORA FINANCIERA DE NICARAGUA S.A
4102 ALMACENADORA LAFISE, S.A
4103 ALMACENADORA DE EXPORTACIONES, S.A
4104 ALMACEN FINANCIERO BAC, S.A v.2: Validation Catalog Validation Table Description
50.001.0001 PLdD_Datos The id_transaction is not unique
50.001.0002 PLdD_Datos The id_report_type is not found in the catalog {1, 2, 3}
50.001.0003 PLdD_Datos The id_transaction_type is not found in the catalog {I, F}.
50.001.0004 PLdD_Datos
The id_operation_type is not found in the catalog {11, 12, 13, 14, 15, 16, 17, 18, 21, 22, 23, 24, 25, 26, 27}
50.001.0005 PLdD_Datos The amount cannot be zero or negative
50.002.0001 PLdD_Personas
The Beneficiary/Manager identification type is not found in {1, 2, 3, 4, 5, 6, 7, 9}
50.002.0002 PLdD_Personas
The nationality code (id_country) of the beneficiary/manager is not valid.
50.002.0003 PLdD_Personas Beneficiary/Manager identifications with different names.
50.002.0004 PLdD_Personas The name cannot be empty or with non-significant names {}
50.002.0005 PLdD_Personas
The Beneficiary/Manager ID card does not comply with the check digit algorithm.
50.002.0006 PLdD_Personas
The Beneficiary/Manager RUC does not comply with the check digit algorithm.
50.003.0001 PLdD_Datos_Persona The {id_relationship_type} was not reported in PLdD_Datos
50.003.0002 PLdD_Datos_Persona
The {id_person, id_document_type} was not reported in PLdD_Personas
50.003.0003 PLdD_Datos_Persona The id_relationship_type is not found in the catalog {G, B, A}
vi- User Manual for uploading the Cash Transaction Report (CTR) vi.1 Introduction The manual presents a general description of the system, as well as the characteristics of each of the process blocks. For each screen, a brief description of the characteristics and functionality is provided, the data fields are described, values of the lists in case the field has an associated one, and usage instructions. vi.2 General System Description The Data Sending System for different applications and/or systems in a simplified mode can be seen as a tool that allows uploading files from Financial Institutions and then consulting their progress, complying with the validations established by the Superintendence of Banks and Other Financial Institutions (SIBOIF). vi.2.1 System Structuring The System is structured in the following function blocks: File Management and Security.
vi.2.1.2 File Management
Figure 4 Menu Options
The File Management Function Block presents the following options:
Figure 5 Information Upload Screen
General Description
Through this screen, the user uploads the files corresponding to their Supervised Entity.
The screen contains the following fields:
Field Description
Upload Type List of values that allows specifying the type of upload to perform.
In this case, as the upload type is for the upload of accounting balances, the user must select the upload type "" Data Date List of dates that allows the user to specify the cutoff date of the data sent. File Allows specifying the file to be uploaded via the local path, the file field has a Browse button for uploading information. When clicking on Browse, the file explorer is accessed:
Figure 6 Choose file window
In this file exploration, the file to be uploaded to the system is specified, the extension of the files must be .dat, once the file is selected, the Open button is pressed. If the Cancel button is pressed, the file selection operation is cancelled. Usage Instructions
vi.2.1.4 Query of Uploads
Figure 7 Upload Query Screen
General Description
Through this screen, the user queries the files previously uploaded in the System. The Upload Query screen has a Date range to show the desired uploads, at the same time the results are limited to the selected Upload type. The screen contains the following fields:
Field Description
Upload Type It is a list of values that allows specifying if the file is of CDR, MUC, Credit Reference Request and/or Equivalences of Persons or of the Annexes of the Bank Superintendence, Anti-Money Laundering, etc. Initial Date Starting point where the query is to be initiated Final Date Final point where the query is to be finished Query Manages the uploads made in the previously established date range. When clicking on the Initial Date or Final Date field, the following Calendar is shown:
Figure 8 Upload Query - Calendar
With which the user will have the flexibility to select the date in an exact and precise way, thus avoiding typing it.
When clicking the Query button, the following results are shown on screen:
Figure 9 Upload Query Detail
Usage Instructions
vii.- Formats with their Instructions vii.1: Exchange of GNUPG public keys This procedure serves as a guide for activities related to the exchange of public keys between Financial Institutions and SIBOIF, with the objective of protecting the information that is transmitted between them. For this, the data files to be exchanged will be encrypted using the GNUPG encryption tool. The requests for public key exchange in financial institutions will be prepared by the security officer or similar position, authorized by their operations manager or similar and sent to SIBOIF so that the superintendence owning the system and the IT director approve them. And these will be exchanged directly with the Database Administrator (DBA) of SIBOIF. This procedure will be carried out taking into consideration that the validity of the public keys will have a duration of one year and must be regenerated by each of the parties involved and exchanged again. The exchange will be carried out on a physical storage medium at the SIBOIF facilities.
Figure 12 Public key exchange process between SIBOIF and Financial Institutions
This procedure will be executed whenever the involved parties need to update the keyrings due to the expiration period of the public keys established by SIBOIF or well by early changes in the keys by any of the involved parties. In case of expiration it must be done one week before the expiration date established by SIBOIF. For the changes in the public keys it will be done at the moment it is necessary.
InstitutionAcronyms Acronyms of the Supervised Entity yyyy Current year 999 Three-digit consecutive number
vii.1.1.1: GNUPG Public Key Exchange Request Format Superintendence of Banks and Other Financial Institutions (SIBOIF) Information Technology Directorate (DTI) Technical Support Area GNUPG Public Key Exchange Request Reference No.:
General Data
To:
Name and Surname Position Signature
From:
Authorizes:
Institution:
Date:
Request Data
Description:
Observations:
Authorizing Signatures
Status Name Position Date Time Signature
Received
Authorization
Superintendence
Authorization
DTI
Received
Prepared
Figure 13 GNUPG Public Key Exchange Request Format
vii.1.1.2: GNUPG Public Key Exchange Request Instructions Instructions for the GNUPG Public Key Exchange Request Format To Direct the request to the system coordinator of the superintendence owning it at SIBOIF. From / Authorizes Write who is requesting and authorizing the changes (Security Officer or similar position of the Supervised Entity and Operations Manager or similar position). Institution Write the name of the institution which is requesting the update of the new set of keys Date Preparation Write the date on which the request is prepared at the Supervised Entity with the dd/mm/yyyy format. This number will be filled by the DBA.
vii.1.2.1: GNUPG Public Key Exchange Acceptance Act Format Superintendence of Banks and Other Financial Institutions (SIBOIF) Information Technology Directorate (DTI) Technical Support Area GNUPG Public Key Exchange Acceptance Act Reference No. To From Institution Exchange Date Exchange Time Current Situation Process Result Expired Keys Keys About to Expire New Requirements Keyring Modifications Others Keys Regenerated Keys Modified Keys Exchanged Others Passes to production Yes No
Signature Security Officer or Similar Signature of the DBA Name Specialist Observations
Figure 14 GNUPG Public Key Exchange Acceptance Act Format
vii.1.2.2: GNUPG Public Key Exchange Acceptance Act Instructions Instructions for the GNUPG Public Key Exchange Acceptance Act Format To Write the Name of the Official and the position they hold. This request must be directed to the DBA of SIBOIF. From Write the Name of the Official and the position they hold. For this format in particular, the sender is the Security Officer of the Supervised Entity or similar position, as the authority that approves the exchange. Exchange Date Write the date on which the exchange is accepted with the dd/mm/yyyy format. Exchange Time Write the time at which the exchange is accepted with the HH:MM; a.m or p.m. format. Institution Write the name of the institution which requested the update of the new set of keys Reference No. Corresponds to the Reference No. of the exchange request that corresponds to the institution. Current Situation Indicate which of the indicated options represents the current situation in the system of the Supervised Entity. Expired Keys Keys About to Expire New Requirements Keyring Modifications Others Process Results Indicate what was the result of the processes that were elaborated Keys Regenerated Keys Modified Keys Exchanged Others Passes to production The DBA indicates if the key exchange procedure ended successfully. Write if you accept to pass to production or not, this will depend on the tests performed by the DBA. If everything is as requested, you must accept to be able to see the change reflected in the systems. Observations If you consider including any observations, or in case the category is Others. Specialist Name Name of the systems and database administrator or person in charge of making the changes at SIBOIF. Signature Any exchange act must be signed by both parties, both by the security officer or similar position who requests the exchange as well as by the systems and database administrator who is who administers the keyrings of SIBOIF.
Table 4 GNUPG Public Key Exchange Acceptance Act Instructions
vii.2 Request for creation, deletion, and changes of access accounts.
This procedure is the basic guide to be used in activities of creation, deletion, and/or modification of access accounts (users) to SIBOIF systems. Through this, each action performed in the global security module of systems is documented and controlled regarding the administration of users and access to specific modules through the assignment of roles.
These requests are used both in the creation and in the administration of internal or external users and are prepared depending on the type and location of the user, whether for a Supervised Entity or for a specific superintendence within SIBOIF. vii.2.1: Request for creation, deletion, and change of access accounts for external user :: Creation, deletion, and change of access accounts to SISBANF - External User - IT Directorate DBA SIBOIF System-owning Superintendence Financial Institution Fills the format of access accounts according to its needs Sends the format Receives notification Notifies to involved users Receives notification End Reviews notification Performs actions Receives notification and/or privileges Receives, Evaluates and Authorizes request Receives request, authorizes and guides the attention of the request
Figure 15 Process for request for creation, deletion, and change of access accounts
This process occurs when a Supervised Entity to which access has been granted to use one or more SIBOIF systems wishes to create or modify an existing access account.
The requests for creation or change in access accounts are prepared by the area head of the Supervised Entity which has access to the system and authorized by the operations manager or similar of the Supervised Entity, sent to SIBOIF for review and approval by the superintendence owning the system and the IT director and executed directly by the Database Administrator (DBA).
The Supervised Entity creates a "Request for creation, deletion, and change of access accounts for external user" (Annex F.2) and sends it to the system owner at the
facilities of SIBOIF.
The superintendence owning the system together with the IT director, receive
the request, evaluate the feasibility and approve it.
The IT director sends the request to the DBA, so that he executes it.
The DBA receives the request and assigns a consecutive reference number per
system. This number must be generated in the following way:
SystemAcronyms_yyyy_999
SystemAcronyms CdR Risk Central (CdR)
MUC Manual Unique of Accounts (MUC)
LdD Money Laundering (LdD)
MAR Risk Analysis Model (MAR)
ANXBCO Annexes of the Bank Superintendence yyyy Current year 999 Three-digit consecutive number per system
The DBA proceeds to execute the request, as indicated in it.
In the case of user creation when they are created, the following nomenclature must be followed.
InstitutionName_UserName_999
InstitutionName The short name or acronyms of the Financial Institution UserName The name of the user to whom access is granted, this will be composed of:
First letter of first name + First Last Name
Pedro Pérez = pperez
999 Three-position consecutive number per user with the same name and surname
The DBA notifies via email the conclusion of the process.
End of procedure.
vii.2.1.1: Format for Request for creation, deletion, and change of access accounts for external user Superintendence of Banks and Other Financial Institutions (SIBOIF) Information Technology Directorate (DTI) Technical Support Area Request for creation, deletion, and change of access accounts Reference No.:
General Data
To:
Name and Surnames Positions Signatures
From:
Authorizes:
Institution:
Date:
Request Data
Actions to Perform User Information
User Full Name:
Username:
Create New User
Modify Existing Profile
Delete Existing User
Profile Information
1 Risk Central
1.1 Data Loading
1.1.1 Risk Central
1.1.2 Person Equivalences
1.2 Credit References
1.2.1 By Batch
1.2.2 Web Services
2 Single Chart of Accounts Manual
2.1 Data Loading
2.1.1 SCOA (MUC)
2.1.2 Stratifications
2.1.3 Annexes
3 AML/CFT - RTE
3.1 Data Loading
4. Others
4.1 Information Download
Observations:
Authorizing Signatures
Status Name Position Signature Date Time
Received
Intendencia Authorization
DTI Authorization
Received
Prepared
Figure 16 Format for the Request for creation, deletion, and changes to access accounts
vii.2.1.2: Instruction for the Request for creation, deletion, and changes to access accounts for external user Instruction for the Request format for creation, deletion, and changes to access accounts A Direct the request to the coordinator of the Intendencia owning the system Senders Write who is requesting and authorizing the changes (Head of Area of the Supervised Entity and Operations Manager or similar position). Institution Write the name of the institution making the request Date of Preparation Write the date on which the request is prepared at the Supervised Entity using the dd/mm/yyyy format. This number will be filled in by the DBA. InstitutionAcronyms_yyyy_999 InstitutionAcronyms Acronyms of the Supervised Entity yyyy Year Ref. No. 999 Consecutive number Actions to Perform Indicate which of the indicated options represents the action or actions to be performed in your request according to your needs:
Creation of New User
Modify Existing Profile
Delete Existing User
User Data Write the full name of the user on whom the action will be performed, as well as their username for the system Profile Information Indicate which of the indicated options represents the functions or profiles that the user must possess within the system:
Risk Central
Online Credit Ref.
Credit Ref. By Batch
Annexes
Information Download (Consolidated, Errors, etc.)
Single Chart of Accounts Manual
Money Laundering Prevention
Signatures This section is used exclusively by siboif to track the status of the request regarding its attention through the signature of the different people involved in this process:
Received
Intendencia Authorization
DTI Authorization
Received
Prepared
Observations Observations indicated by the system coordinator, IT director, or the siboif DBA if necessary.
Table 5 Instruction for Request for creation, deletion, and changes to access accounts
viii.- GNUPG Manual viii.1 Introduction
GNUpg is the free software world's implementation of PGP; this is an asymmetric encryption system, meaning it consists of a public key and a private key. With this system, one can perform both data encryption (with the public key) and file signing to ensure authenticity (using the private key and the recipient to sign). This document intends to be only a brief guide for encrypting and decrypting files; for exhaustive consultations:
http://www.gnupg.org/gph/es/manual/book1.html http://www.gnupg.org/gph/es/manual/book1.html viii.2 Generation of keys First of all, we need a computer that has the GNUpg package.
The installation program is located on the main GnuPG page. http://www.gnupg.org/ http://www.gnupg.org/download/ The installation file for Windows can be located directly at the following link:
ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.1.exe Once the program has been downloaded, you must double-click it, and it will install itself (gnupg-w32cli-1.4.1.exe).
Modify the c:\autoexec.bat with the following instruction:
SET PATH=%PATH%;C:\Program Files\GNU\GnuPG
Once this is done, we generate the pair of keys, the public and the private, with the command:
gpg --gen-key
If it is the first time we run it, it will create the file “C:/Documents and Settings/jperez/Application Data/gnupg\pubring.gpg” where configurations and keys are saved, and it must be run again to launch the creation process, which is a menu system shown and commented on below. gpg --gen-key gpg (GnuPG) 1.4.1; Copyright (C) 2005 Free Software Foundation, Inc. This program comes with ABSOLUTELY NO WARRANTY. This is free software, and you are welcome to redistribute it under certain conditions. See the file COPYING for details. gpg: keyring C:/Documents and Settings/pparamo/Application Data/gnupg\secring.gpg' created gpg: keyring C:/Documents and Settings/pparamo/Application Data/gnupg\pubring.gpg' created Please select what kind of key you want:
(1) DSA and Elgamal (default)
(2) DSA (sign only)
(5) RSA (sign only)
Your selection? 1
We select the default key type, ElGamal.
DSA keypair will have 1024 bits.
ELG-E keys may be between 1024 and 4096 bits long.
What keysize do you want? (2048) 2048
With this, we select the key length. The key length required by SIBOIF for this process is 2048 bits.
Requested keysize is 2048 bits
Please specify how long the key should be valid.
0 = key does not expire
<n> = key expires in n days
<n>w = key expires in n weeks
<n>m = key expires in n months
<n>y = key expires in n years
Key is valid for? (0) 1y
Key expires at 06/06/06 10:35:53
Is this correct? (y/N) y
Next, we are asked for the time for which the public key will be valid. For our example, we consider one year sufficient. We answer yes and continue.
You need a user ID to identify your key; the software constructs the user ID from the Real Name, Comment and Email Address in this form:
"Heinrich Heine (Der Dichter) heinrichh@duesseldorf.de" Real name: Pedro Páramo Email address: pparamo@siboif.gob.ni Comment: SIBOIF_DTI_Technical Support.
The fields are filled in with the identifiers we are going to use.
You are using the `CP850' character set.
You selected this USER-ID:
"Pedro Páramo (SIBOIF_DTI_Technical Support.) pparamo@siboif.gob.ni" Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? o You need a Passphrase to protect your secret key.
If it is correct, we press O and continue.
You need a Passphrase to protect your private key.
Enter passphrase:
We need a key to protect our private key; it is advisable to choose one that is as long and complex as possible, since the weak point of asymmetric encryption is the protection of this key.
Repeat passphrase:
We repeat the key.
With this process, we already have the keys generated and we can sign and encrypt documents. To check that everything is correct, we look to see if the keys have been generated. gpg --list-keys viii.3 Encrypting files To encrypt documents, we proceed as follows: we look for the file we want to encrypt and execute the following command:
gpg -o encrypted_file -e original_file
You did not specify a user ID. (you may use "-r") Current recipients:
Enter the user ID. End with an empty line: jperez@siboif.gob.ni Current recipients:
2048g/2B993C22 2005-06-02 "Pedro Páramo pparamo@siboif.gob.ni" Enter the user ID. End with an empty line:
It is advisable to delete the unencrypted file once we are sure that the encrypted file has been created. viii.4 Decrypting files To decrypt the file we had previously encrypted:
gpg -o file -d encrypted_file
You need a passphrase to unlock the secret key for user: "José Pérez jperez@siboif.gob.ni" 2048-bit ELG-E key, ID 7C4D8652, created 2005-06-03 (main key ID A216DAED) gpg: encrypted with 2048-bit ELG-E key, ID 7C4D8652, created 2005-06-03 "José Pérez jperez@siboif.gob.ni"
It will ask for the key we set when we created the keys; with this, we ensure that only those who know it can decrypt it.
With this brief document, we have intended to give a quick description of how to encrypt and decrypt files simply and quickly. viii.5 Generate the public key To send the public key to a third party, you must give the following command:
gpg --armor --export pparamo@siboif.gob.ni > pparamo_pk To view the content of the public key:
type pparamo_pk viii.6 Importing a public key to your keyring To import a public key, you must give the following command:
gpg --import jperez_pk gpg: key 9104CDDA: public key "Josè jperez@siboif.gob.ni" imported gpg: Total number processed: 1 gpg: imported: 1
Read the rest free
Source: Superintendencia de Bancos y de Otras Instituciones Financieras — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works