2008-03-05 | CD-SIBOIF-524-1-MAR5-2008 (Norma Original)

Added · Updated

Norma for the Management of Prevention of Risks of Money Laundering, Goods or Assets; and Terrorism Financing (PLD/FT Standard)

This resolution establishes a comprehensive regulatory framework for banks, financial institutions, insurance companies, securities firms, and general warehouse entities to prevent money laundering and terrorism financing. It mandates the implementation of an Integrated System for Prevention and Risk Management (SIPAR LD/FT), including specific due diligence policies, risk assessment matrices, monitoring procedures, and reporting obligations for suspicious transactions and cash transfers above defined thresholds. The regulation also defines institutional responsibilities, governance structures such as prevention committees, and requirements for independent audits, training, and code of conduct.

Superintendencia de Bancos y de Otras Instituciones Financieras logo

Nicaragua

Superintendencia de Bancos y de Otras Instituciones Financieras

Click to view thumbnail

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008

STANDARD FOR THE MANAGEMENT OF PREVENTION OF RISKS OF MONEY LAUNDERING, GOODS OR ASSETS; AND TERRORISM FINANCING¹.

Approved by the Board of Directors of SIBOIF through Resolution: CD-SIBOIF-524-1-MAR5-2008 dated March 5, 2008, and published in the Official Gazette La Gaceta, editions numbers: 63, 64, 65, 66 and 67 corresponding to the days April 4, 7, 8, 9 and 10, 2008.

Managua, Nicaragua April, 2008

¹ Effective from April 10, 2008, the date on which its publication in the Official Gazette La Gaceta was completed.


RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008

Standard for the Management of Prevention of Risks of Money Laundering, Goods or Assets; and Terrorism Financing.

TABLE OF CONTENTS

RESOLUTION NO. CD-SIBOIF-524-1-MAR5-2008 ............................................................................................ 7 CONSIDERING .................................................................................................................................................. 7 TITLE I ................................................................................................................................................................ 9 GENERAL PROVISIONS ............................................................................................................................ 9 UNIQUE CHAPTER ............................................................................................................... 9 SCOPE, OBJECTIVE AND CONCEPTS ................................................................................ 9 Art. 1.- Scope .................................................................................................................. 9 Art. 2.- Objective .................................................................................................................... 9 Art. 3.- General Concepts ............................................................................................ 10 TITLE II ............................................................................................................................................................. 10 PROVISIONS APPLICABLE TO BANKS AND FINANCIAL INSTITUTIONS ................................................................ 10 CHAPTER I ........................................................................................................................ 10 PREVENTION PROGRAM AND RESPONSIBILITY ............................................. 10 Art. 4.- Prevention Program or Integrated System for Prevention and Administration of Risks of Money Laundering, Goods or Assets; and Terrorism Financing (SIPAR LD/FT) ................................................................................................................ 10 Art. 5.- Institutional Responsibility .............................................................................. 12 Art. 6.- Responsibility of the Board of Directors ................................................................. 12 Art. 7.- Integration of SIPAR LD/FT ............................................................................. 15 CHAPTER II ....................................................................................................................... 17 POLICY OF "DUE DILIGENCE FOR CUSTOMER KNOWLEDGE" (CDD) ................................................................................................................................... 17 Art. 8.- CDD Policy ........................................................................................................ 17 Art. 9.- Identification ....................................................................................................... 19 Art. 10.- Required Documents .................................................................................... 20 Art. 11.- Verification ....................................................................................................... 23 Art. 12.- Customer Comprehensive Profile (CCP) ......................................................................... 26 Art. 13.- Client File ....................................................................................... 30 Art. 14.- Standard CDD .................................................................................................... 30 Art. 15.- Enhanced CDD ............................................................................................. 31 Art. 16.- Measures of Enhanced CDD .......................................................................... 34 Art. 17.- Simplified CDD ............................................................................................. 36 CHAPTER III ..................................................................................................................... 37 COMPLEMENTARY POLICIES OF KNOWLEDGE ........................................... 37 Art. 18.- Policy "Know Your Customers' Customers" (CCC) for high-risk clients ................................................................................................................................ 37 Art. 19.- Policy "Know Your Employee" ................................................................... 37

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008

3 Art. 20.- Policy "Know Your Correspondent Relationships" .................................... 38 Art. 21.- Policy "Know Your Electronic Fund Transfers" ...................... 38 Art. 22.- Policy "Know Your Buyers of Consignment Instruments" ..... 39 Art. 23.- Policy "Know Your Suppliers" ............................................................. 40 CHAPTER IV ..................................................................................................................... 40 MATRICES FOR RISK ASSESSMENT LD/FT ............................................... 40 Art. 24.- LD/FT Risk Matrices ............................................................................... 40 Art. 25.- New Technologies, Products and Services ...................................................... 41 CHAPTER V ...................................................................................................................... 41 MONITORING AND REPORTS ............................................................................................. 41 Art. 26.- Monitoring, Detection and Security .................................................................... 41 Art. 27.- Signals and Alert Indicators ....................................................................... 43 Art. 28.- Determination of suspicion and obligation to present Suspicious Transaction Report (STR) ............................................................................................................ 43 Art. 29.- Special measures for the presentation of an STR ......................................... 44 Art. 30.- Monitoring and Detection of Cash Transactions above the determined threshold ...................................................................................................................... 45 Art. 31.- Obligation to Report Cash Transactions above determined threshold (CTR) ........................................................................................................... 46 Art. 32.- Exceptions of the CTR ......................................................................................... 46 Art. 33.- Cash Transaction that also qualifies for an STR ............................ 47 CHAPTER VI ..................................................................................................................... 47 ARCHIVING AND PRESERVATION OF INFORMATION .................................................... 47 Art. 34.- Safeguarding of Information and Supporting Documents ........................................ 47 Art. 35.- Availability of information and supporting documentation .......................... 48 Art. 36.- Updating and extraction of information ....................................................... 48 CHAPTER VII .................................................................................................................... 48 IMPLEMENTATION AND CONTROL OF SIPAR LD/FT ................................................. 48 Art. 37.- Implementation and control function ............................................................... 48 Art. 38.- LD/FT Prevention Committee ............................................................................ 49 Art. 39.- Integration of the LD/FT Prevention Committee ................................................... 49 Art. 40.- Functions of the LD/FT Prevention Committee .......................................................... 50 Art. 41.- Administrator of LD/FT Risk Prevention ........................................ 53 Art. 42.- Appointment ................................................................................................... 53 Art. 43.- Characteristics of the position .................................................................................... 54 Art. 44.- Case of Financial Group ................................................................................. 54 Art. 45.- Objection ............................................................................................................. 55 Art. 46.- Administrative Support Structure ................................................................. 55 Art. 47.- Professional Profile of the LD/FT Prevention Administrator ............................. 55 Art. 48.- Incompatibilities ............................................................................................. 55 Art. 49.- Temporary or interim substitution .......................................................................... 56 Art. 50.- Removal ........................................................................................................... 56 Art. 51.- Functions of the LD/FT Prevention Administrator ......................................... 57 CHAPTER VIII .................................................................................................................. 60 TRAINING IN LD/FT PREVENTION ................................................................... 60

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008

4 Art. 52.- PLD/FT Training Program .............................................................. 60 Art. 53.- Minimum Elements of the Program ..................................................................... 61 Art. 54.- Statistics and Records on Training ...................................................... 62 CHAPTER IX ..................................................................................................................... 62 INSTITUTIONAL CODE OF CONDUCT ................................................................. 62 Art. 55.- Incorporation of the SIPAR LD/FT topic .............................................................. 62 Art. 56.- Minimum LD/FT Aspects of the Code of Conduct ......................................... 63 CHAPTER X ...................................................................................................................... 63 INDEPENDENT AUDIT ON SIPAR LD/FT ........................................... 63 Art. 57.- Independent Audit .................................................................................... 63 Art. 58.- Minimum Audit Functions ....................................................................... 63 TITLE III ............................................................................................................................................................ 67 PARTICULAR AND EXCEPTION PROVISIONS .................................................................................. 67 CHAPTER I ........................................................................................................................ 67 FINANCIAL GROUPS AND CONSOLIDATED LD/FT RISK MANAGEMENT ............. 67 Art. 59.- LD/FT Risk Management ................................................................................. 67 Art. 60.- Internal Audit of the Controlling Company ................................................. 68 Art. 61.- Consolidated External Audit of the Financial Group ......................................... 68 CHAPTER II ....................................................................................................................... 68 INSURANCE MARKET ................................................................................................ 68 Art. 62.- Applicability of the PLD/FT Standard in the Insurance Market .................... 68 Art. 63.- Exceptions and Particularities ......................................................................... 69 Art. 64.- Subsequent Identification and Verification .............................................................. 70 Art. 65.- Enhanced CDD ............................................................................................. 70 Art. 66.- Simplified CDD ............................................................................................. 71 Art. 67.- Relationship of the Insurer and/or Reinsurer company with insurance intermediaries ....................................................................................................................... 71 CHAPTER III ..................................................................................................................... 72 SECURITIES MARKET ................................................................................................ 72 Art. 68.- Applicability of the PLD/FT Standard in the Securities Market .................... 72 Art. 69.- Exceptions and Particularities ......................................................................... 72 Art. 70.- Control of Operations ..................................................................................... 74 CHAPTER IV ..................................................................................................................... 74 GENERAL WAREHOUSE MARKET ....................................................................... 74 Art. 71.- Applicability of the PLD/FT Standard in the General Warehouse Market ............................................................................................................................ 74 Art. 72.- Exceptions and Particularities ......................................................................... 74 CHAPTER V ...................................................................................................................... 75 REPRESENTATIVE OFFICES AND "SECOND-TIER" BANKS .................... 75 Art. 73.- Applicability of the Standard to Representative Offices ............................ 75 Art. 74.- Application of SIPAR LD/FT regarding its jurisdiction of origin .................. 75 Art. 75.- Enhanced CDD ............................................................................................. 76 Art. 76.- Exceptions and Particularities ......................................................................... 76 Art. 77. – "Second-Tier" Banks .............................................................................. 76

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008

5 CHAPTER VI ..................................................................................................................... 77 SPECIAL REGIME FINANCIAL COMPANIES ................................................. 77 Art. 78.- Companies under Consolidated Supervision .............................................................. 77 Art. 79.- Exceptions ....................................................................................................... 77 TITLE IV............................................................................................................................................................ 77 TRANSITIONAL AND FINAL PROVISIONS ............................................................................................... 77 UNIQUE CHAPTER ............................................................................................................. 77 Art. 80.- Modification and/or Inclusion of Annexes .............................................................. 77 Art. 81.- Graduality for the application of some particular provisions of the present Standard ................................................................................................................. 77 Art. 82.- Repeals ..................................................................................................... 78 Art. 83.- Validity ............................................................................................................. 78 ANNEXES ............................................................................................................................................................... 79 ANNEX 1: GENERAL CONCEPTS FOR THE APPLICATION OF THE PLD/FT STANDARD .................. 80 ANNEX 2: FORMATS FOR THE CUSTOMER COMPREHENSIVE PROFILE (CCP) ......................................... 84 i.- Banking and Financial Market ............................................................................ 84 ii.- Insurance Market ................................................................................................. 96 iii.- Securities Market ................................................................................................ 100 iv.- General Warehouse Market ..................................................... 105 ANNEX 3: SIGNALS AND ALERT INDICATORS .............................................................................. 110 I.- Common to all Supervised Entities ................................................................ 110 II.- Specific to the Banking and Financial Market .................................................. 117 III.- Specific to the Insurance Market ...................................................................... 130 IV.- Specific to the Securities Market ...................................................................... 133 V.- Specific to the General Warehouse Market ............................. 135 ANNEX 4: INSTRUCTIONS AND FORMAT FOR THE PRESENTATION OF THE SUSPICIOUS TRANSACTION REPORT (STR). ......................................................................................................... 137 I.- Instructions for the presentation and transmission of the Suspicious Transaction Report (STR): ................................................................................................................................ 137 II.- Format for the presentation of the Suspicious Transaction Report (STR) .......... 139 ANNEX 5: MANUAL AND FORMAT FOR THE AUTOMATED PRESENTATION OF CASH TRANSACTION REPORTS (CTR) ................................................................................................ 142 i.- Conceptual aspects (Data Flow) ......................................................................... 142 ii.- Types of submissions ............................................................................................................. 143 ii.1 Submissions of Financial Institutions to SIBOIF ............................................... 143 ii.2 Format of the files ........................................................................................... 143 ii.3 Submissions of SIBOIF to Supervised Entities ................................................. 144 iii.- File formats according to submission type ................................................................... 145 iii.1: General Data Anti-Money Laundering (AML_Data) ....................... 145 iii.2: Persons (AML_Person) ..................................................................................... 146 iii.3: Relationship Data versus Persons (AML_Data_Person) ..................................... 147

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008

6 iv.- SIBOIF response files .......................................................................... 148 iv.1: Incidents .............................................................................................................. 148 iv.2: Statistics ............................................................................................................. 149 v.- Annex catalogs ........................................................................................................... 149 v.1: General catalogs ................................................................................................. 149 v.2: Validation Catalog ........................................................................................ 156 vi- User Manual for uploading the Cash Transaction Report (CTR) .... 157 vi.1 Introduction............................................................................................................. 157 vi.2 General Description of the System ............................................................................ 157 vi.2.1 System Structuring ................................................................................... 158 vii.- Formats with their Instructions ..................................................................................... 166 vii.1: Exchange of GNUPG public keys .......................................................... 166 vii.2 Request for registration, deregistration and changes of access accounts. ...................................... 171 viii.- GNUPG Manual................................................................................................... 175 viii.1 Introduction .......................................................................................................... 175 viii.2 Generation of keys ....................................................................................... 176 viii.3 Encrypt files ....................................................................................................... 178 viii.4 Decrypt files .................................................................................................. 178 viii.5 Generate the public key ........................................................................................ 179 viii.6 Importing a public key to your keyring ............................................................ 179

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 7 RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 dated March 5, 2008 STANDARD FOR THE MANAGEMENT OF PREVENTION OF THE RISKS OF MONEY LAUNDERING, GOODS OR ASSETS; AND TERRORIST FINANCING

The Board of Directors of the Superintendence of Banks and Other Financial Institutions decides to approve and issue the Standard for the Management of Prevention of the Risks of Money Laundering, Goods or Assets; and Terrorist Financing, in accordance with the considerations, legal basis, and content set forth below:

CONSIDERING

I

That the Political Constitution of the Republic of Nicaragua, in its articles 24 and 99, establishes as one of its guarantor pillars the just demands of the common good above particular or individual interests, which, translated into economic-financial management, results in the promotion of a responsible and healthy development of the Financial System as an activity classified as being of public interest in the Laws governing it by mandate of the Constitution itself, and from whose legal basis emanated the Standard for the Prevention of Money Laundering and Other Assets in the year 2002 and the Standard on Compliance Officers in the year 2006, approved by this Board of Directors in the exercise of its indelegable power to issue standards expressly attributed to it by article 10 of Law No. 316: "Law of the Superintendence of Banks and Other Financial Institutions" and for the specific topic in articles 28 (second paragraph) and 36 (second paragraph) of Law No. 285: "Law on Narcotics, Psychotropics and Other Controlled Substances; Money Laundering and Assets Proceeding from Illicit Activities."

II

That it is necessary to issue a new and updated Standard that integrates the previous ones and that, with a risk-based approach, seeks to adjust to legislative developments and trends, to the conventions and agreements to which Nicaragua is a signatory, to experiences and alert indicators, to guidelines, principles, recommendations, standards and best international practices, and adapted to the local reality of the different sectors that compose our supervised Financial System; promoting greater effectiveness in the labor of prevention and detection of cross-border risks of Money Laundering, Goods or Assets; and Terrorist Financing, and consequently also on the risks legal, operational and reputational that these entail.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 8

III

That by its very nature, the Financial System faces various risks of internal and external origin, and in this context each Supervised Entity, considering that regardless of its size and its particular business specificity, will always be exposed to being used for Money Laundering, Goods or Assets and/or for Terrorist Financing; must, therefore, strengthen its permanent labor of prevention and administration of these transnational risks through a permanent review and improvement of its programs, measures, procedures, policies and internal controls.

IV

That it is necessary to highlight that the mechanisms for the administration of the risks of Money Laundering, Goods or Assets; and Terrorist Financing, are directed specifically to control and mitigate them, and respond to the need to prevent them, detect and report them timely, efficiently and effectively; and this is only possible if the Supervised Entity truly knows the usual and reasonable financial activities of its clients. Therefore, this special prevention task differs substantially from mechanisms for the administration of other typical financial risks and/or general compliance with laws and regulations applicable to the particular activity within the industry in which the Supervised Entity operates, which are differently directed to be assumed by it wholly or partially based on its profile and relationship of profitability versus risk, and covering them through capital contributions in correspondence with the intent or willingness of its partners to assume higher levels of risk.

V

That the measures established in this Standard do not constitute disincentives or obstacles for Supervised Entities in carrying out their financial activity with clients and legitimate capital, but, on the contrary, are technical tools for the safe promotion of business, of an eminently preventive nature and of self-interest, with minimum requirements to be followed; from which it corresponds to each Entity to adjust and strengthen them according to the changing activities of its industry and as part of its corporate responsibility, in order to achieve a sound, prudent, adequate and efficient management of prevention of the risks of Money Laundering, Goods or Assets; and of Terrorist Financing, and in that way avoid that funds that have their origin in criminal activities or that attempt to finance them, are channeled through the Financial System.

THEREFORE

In accordance with the considerations, and in application of the provisions set forth in article 36, second paragraph, of Law No. 285: "Law on Narcotics, Psychotropics and Other Controlled Substances; Money Laundering and Assets Proceeding from Illicit Activities" published in La Gaceta, Official Journal, No. 69 of April 15, 1999; in articles 10 (items 1, 3 and 5) and 19 (item 18) of Law No. 316: "Law of the Superintendence of Banks and Other Financial Institutions" published in La Gaceta, Official Journal, No. 16 of October 14, 1999 (reformed by Laws No. 552, 564 and 576); in articles 4 (item 6, letters "c" and "g" and item 7, letter "a"), 113 (item 1) and 164 (second part) of Law No. 561: "General Law of Banks, Non-Bank Financial Institutions and Financial Groups", published in La Gaceta, Official Journal, No. 232 of November 30, 2005; and in article 212 of Law No. 587, "Law of the Capital Market", published in La Gaceta, Official Journal, No. 222 of November 15, 2006; the Board of Directors of the Superintendence of Banks and Other Financial Institutions, in the exercise of its powers,

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 9

RESOLVES:

APPROVE THE FOLLOWING

STANDARD FOR THE MANAGEMENT OF PREVENTION OF THE RISKS OF MONEY LAUNDERING, GOODS OR ASSETS; AND TERRORIST FINANCING

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008

TITLE I GENERAL PROVISIONS

SINGLE CHAPTER SCOPE, OBJECTIVE AND CONCEPTS

Art. 1.- Scope The Standard for the Management of Prevention of the Risks of Money Laundering, Goods or Assets; and Terrorist Financing, hereinafter referred to as the PLD/FT Prevention Standard or simply the PLD/FT Standard; is applicable, with the exceptions and particularities that it expressly establishes itself; to all Entities that are under the authorization, regulation, supervision, surveillance and audit of the Superintendence of Banks and Other Financial Institutions, hereinafter Superintendence, and that operate, among others, in the sectors of Banks, Financial Institutions, Insurance, Securities and General Warehouses of Deposit as credit auxiliaries, individually or as members of a Financial Group; all referred to as Supervised Entity (ies) for the purposes of this Standard.

Art. 2.- Objective a) This Standard aims to establish the requirements, guidelines and basic and minimum aspects regarding the measures that the Supervised Entities that make up the Financial System of Nicaragua must adopt, implement, update and improve, under their own initiative and responsibility, in accordance with the nature of the industry and market in which each of them operates and according to the level of risk of their respective structures, clients, businesses, products, services, distribution channels and jurisdictions in which they operate; to manage, prevent and mitigate the risk of being used, consciously or unconsciously, in a local or cross-border manner, for Money Laundering, Goods or Assets; and for Terrorist Financing, hereinafter PLD/FT. b) The PLD/FT risk is the inherent risk that Supervised Entities have and face permanently due to their very nature of business; of being used, consciously or unconsciously, for Money Laundering, Goods or Assets; and for Terrorist Financing; and consequently, are obligated to develop a sound and prudent management of prevention of said risk.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 10

c) It is the responsibility of each Supervised Entity to make adjustments as necessary, with regard to the nature of their business and the weighting of their own PLD/FT risks as high, medium or low; or, when legal and/or regulatory changes occur in the matter; in order to develop an adequate, efficient and effective management of prevention of the same.

Art. 3.- General Concepts For the purposes of this Standard, a list of general concepts is established in Annex 1, which is an integral part of it.

TITLE II PROVISIONS APPLICABLE TO BANKS AND FINANCIAL INSTITUTIONS

CHAPTER I PREVENTION PROGRAM AND RESPONSIBILITY

Art. 4.- Prevention Program or Integrated System for Prevention and Administration of the Risks of Money Laundering, Goods or Assets; and Terrorist Financing (SIPAR PLD/FT)

a) Every Supervised Entity, considering the industry in which it operates, its own specificity within the same, the nature and complexity of its business, products and financial services, the volume of operations, its geographic presence, the technology used for the provision of its services, in weighting its risks and in compliance with the specific legal provisions of the matter and general provisions contemplated by this Standard; must formulate, adopt, implement and develop with effectiveness and efficiency, a Prevention Program or Integrated System for Prevention and Administration of the Risk of Money Laundering, Goods or Assets; and of Terrorist Financing, which may also be referred to briefly as SIPAR PLD/FT. b) The SIPAR PLD/FT must include: policies, procedures and internal controls expressed in their respective Manual for the Prevention of the Risks of Money Laundering, Goods or Assets; and Terrorist Financing, hereinafter PLD/FT Manual; periodically updated risk matrices; monitoring system; and operational plans; all of which must comply and adjust, insofar as applicable, to the national legal framework, including the international conventions on the matter to which Nicaragua is a party; as well as, resolutions, instructions and guidelines of the SIBOIF; to codes of conduct, guides, corporate mandates, recommendations of audits, evaluations and periodic self-evaluations, among others; that are related to the prevention of the risks of Money Laundering, Goods or Assets; and Terrorist Financing in the Financial System. International best practices and standards constitute guidelines and references that must be taken into account to strengthen the SIPAR PLD/FT. c) The policies, procedures, internal controls, weightings, criteria and variables for determining the PLD/FT risk levels and their rating matrix, must be properly documented.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 11

d) The intensity of the policies, procedures, internal controls, tasks and measures that each Supervised Entity decides to establish in its SIPAR PLD/FT, will be subject to its PLD/FT risk level classified as high, medium or low in all areas of its business and activities, that of its clients and to the size of the entity; and are mandatory and strict compliance for them. The SIPAR PLD/FT of each Supervised Entity is considered an extension of this Standard, and non-compliance will be subject to the same regime of administrative measures provided for in the respective Standards. e) The SIPAR PLD/FT must have an integrative and comprehensive approach, allowing the Supervised Entity to prevent, detect and report possible suspicious activities of PLD/FT in any of its three stages known internationally: placement, layering and integration; starting from the four basic administrative tasks of an effective SIPAR PLD/FT:

i.- Prevention: of the risk that resources from activities related to PLD/FT are introduced or placed in the Financial System; through policies, procedures and internal controls for adequate customer knowledge, complemented by robust training and staff training at all levels of the entity.

ii.- Detection: of activities that are intended to be carried out or have been carried out, to layer, integrate or give the appearance of legality to operations related to PLD/FT; through the implementation of adequate, timely and effective monitoring controls and tools.

iii.- Reporting: timely, efficient and effective reporting to the competent authority designated by law, of detected operations that are intended to be carried out or have been carried out and that are suspected to be related to PLD/FT.

iv.- Retention: for the legal period, of all files, transaction records and documentation, both physical and electronic derived from the preceding tasks.

f) The Supervised Entity will keep informed and trained in general about its respective SIPAR PLD/FT, all its directors, officials and employees; and in a special and focused manner towards those who belong to areas or are in charge of products that according to their profile, need, linkage and impact are more exposed to these risks. This information and training, general or special as appropriate, must apply to all levels of the Entity.

g) The SIPAR PLD/FT must be subject to review and update in accordance with legislative, regulatory and normative changes in the matter, or due to new and better risk management practices for PLD/FT; as well as in response to new schemes, indicators, signals and patterns of PLD/FT detected by the Entity itself, or communicated by the SIBOIF or by any other competent authority, or accessible through other national and international sources recognized in the topic.

h) When appropriate, Supervised Entities must implement the SIPAR PLD/FT at the level of the Financial Group constituted in Nicaragua, including all its branches, subsidiaries and representative offices abroad. In this case, if the requirements

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 12

legal, regulatory, normative and practices for PLD/FT prevention of other countries where any member of the Financial Group operates differ from those established in Nicaragua, the member of said Group must apply the measures that result in the strictest among the different jurisdictions according to international standards; and likewise, when in another country the application of the SIPAR PLD/FT is prohibited or prevented, such situation must be communicated without delay to the head office and to the Superintendence, and comply with local Law.

Art. 5.- Institutional Responsibility

a) It is the responsibility of the General Assembly of Partners or Shareholders, Board of Directors, officials and employees of each Supervised Entity, to protect its integrity against PLD/FT risks, in its own interest and that of the Financial System; and to comply with laws, regulations and standards on the matter.

b) According to the law, Supervised Entities must not have as shareholders, partners, other investors and representatives, including beneficiaries of such investments, persons:

i.- Who cannot demonstrate the legitimate origin of the funds to acquire shares, rights to shares or equity participations within the Supervised Entity.

ii.- Who have been judicially proven to participate in activities related to drug trafficking and related crimes, and to PLD/FT.

Art. 6.- Responsibility of the Board of Directors

Without prejudice to the institutional responsibilities that the respective laws and standards assign and delimit to the Boards of Directors of Supervised Entities regarding the management of risks and internal control in general; all members of a Board of Directors must have a vigilant and proactive participation in the implementation and permanent monitoring of the effectiveness and efficiency of the SIPAR PLD/FT. Each Board of Directors is responsible for:

a) Promoting at all levels of the organization and as a component of good Corporate Governance, a culture of compliance with legal and normative requirements in matters of PLD/FT prevention.

b) Approving the SIPAR PLD/FT with its respective PLD/FT Manual which must be autonomous, integral, complete, updated and which identifies the legal, normative and best practices provisions on which it is based; and its Annual PLD/FT Operational Plan, hereinafter referred to as POA PLD/FT; as well as instruct and monitor compliance with them.

c) Keeping informed about the progress of the SIPAR PLD/FT, as well as the performance of the officials directly in charge of its execution. In the Board of Directors Minutes it must be recorded not only the mere fact that it received and knew certain periodic report or information related to the SIPAR PLD/FT, received through its surveillance and control bodies, but also, at a minimum, the following:

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 13

i.- What type of report or information was presented to it. ii.- Position and name of the official presenting it. iii.- What analysis or deliberation was carried out. iv.- What agreements, resolutions and actions were derived and adopted from its analysis. v.- What follow-up will be given to the decisions, their frequency and by what means. vi.- A copy of the report must be part of the annexes of the Minutes.

d) If what is stipulated in the previous letter cannot be evidenced through Board of Directors Minutes, the internal and external control bodies must highlight this weakness in the functioning of an essential part of Corporate Governance.

e) Approve and verify the implementation, through reports, of the control mechanisms and audit to ensure compliance with legal requirements and with the policies and procedures established in the SIPAR PLD/FT; including the adoption of measures to overcome gaps, weaknesses and infractions detected by internal control bodies, external audit, or by the supervisory body.

f) Assign, in a specific and identifiable manner, the budget that guarantees the necessary human, financial and technological resources, adequate and in accordance with the nature, size and magnitude of the operations offered by the Supervised Entity, for the efficient and effective implementation of the SIPAR PLD/FT; and for the functioning of the respective Administrative Support Structure provided for in article 46 of this Standard as applicable.

g) Establish, by resolution recorded in the Minutes, a Committee for the Prevention of Money Laundering, Goods or Assets; and Terrorist Financing, hereinafter PLD/FT Prevention Committee, as an instance that assists but does not relieve the Board of Directors or the highest local authority in the country of foreign financial entity branches, of its direct responsibility in the approval, guidance and monitoring of compliance with the SIPAR PLD/FT.

h) Appoint, by resolution recorded in the Minutes, the Administrator for the Prevention of the Risks of Money Laundering, Goods or Assets; and Terrorist Financing, hereinafter PLD/FT Prevention Administrator, as the main official of the direction, administration and execution of the SIPAR PLD/FT.

i) Ensure that only nominal accounts are maintained in the Supervised Entity, and that anonymous accounts or transactions, or those appearing under fictitious or inaccurate names, coded or encrypted, or whose high-risk clients do not present all the required information to obtain full certainty about the identity and origin of the funds, are rejected.

j) Define and establish, within its PLD/FT Manual, an express and written policy of acceptance of clients and/or market segments.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 14 k) Establish and verify the implementation of a risk-based Customer Due Diligence (CDD) for the knowledge of its customers and their activities, including procedures and controls for the approval of new customers that must consider the inherent risk level that the customer or the transaction may present. The greater the risk represented by the customer, the higher the hierarchy of the Official of the Supervised Entity that must approve or authorize their linkage and/or transaction, and/or the product or service derived from the linkage. l) Determine, through duly approved policies and procedures in accordance with their respective AML/CFT risk matrices, the exceptional cases in which, in order not to interrupt the course of business and the development of its commercial activity, the Supervised Entity may conclude the customer identity verification after establishing a new commercial relationship. These policies must be established clearly and specifically in the AML/CFT Manual, and where procedures must be foreseen that contemplate, at a minimum, the following aspects: i.- The manner in which risk management and mitigation will be carried out in relation to the conditions under which verification is contemplated to be performed subsequently. ii.- Determination of the maximum deadline within a short and reasonable period of time to perform the subsequent verification. iii.- Criteria that allow identifying the absence of suspicion of AML/CFT or the manner to reasonably ensure that there is no such suspicion. iv.- The conditions under which the customer may use the commercial relationship before verification, including measures to limit the number, types, and/or amounts of operations. m) Ensure that policies and procedures aimed at evaluating AML/CFT risks are formulated and implemented within the AML/CFT Manual, in: i.- New products, services, or distribution channels, which must be applied prior to approval and launch to the market, in their design, development, and testing phases, in order that, once these products are launched to the market or new distribution channels are used, the risk profile of target customers and the pertinent policies, procedures, controls, and transaction monitoring and AML/CFT risk mitigation measures are already in place. ii.- The development of new products and services in which, upon operationalizing them, the use of new or developing technologies is required, and in which, due to these, anonymity is favored and/or physical contact (face-to-face) with end-beneficiary customers is not required or is minimized, including services to beneficiary customers that use agents or intermediaries such as law firms, tax experts, accounting firms, or other forms of representation.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 15 n) Establish specific policies and procedures that allow the Supervised Entity, in consideration of its own risks, to perform due diligence to obtain reasonable knowledge of "Customers of its Customers," which must always be applied in the cases of its high-risk customers. ñ) Establish specific policies and procedures to administer and control the process of sharing customer information with other Supervised Entities that are members of its Financial Group, and determine the type of information to be shared, when so agreed within the normal administrative process for the approval of operations, all of which must be recorded in the Board of Directors' Minutes Book. o) Establish specific policies and procedures with an AML/CFT prevention focus to know its external service providers. p) Provide adequate specialized monitoring systems for the early detection of unusual and/or suspicious operations, which are consistent with the technology used for the provision of its services. q) Ensure that all policies, procedures, and internal controls comprising the AML/CFT SIPAR are contained, clearly defined, and updated in their respective AML/CFT Manual, as well as duly communicated to relevant personnel. r) Establish internal policies and controls that discourage the use of unsafe practices in the handling and management of banking and financial activities, which, if they occur, lead to raising the AML/CFT risk level of the Supervised Entity. s) Ensure that the Supervised Entity provides all the collaboration required by the Superintendence and other competent authorities, in all matters related to AML/CFT prevention as provided by law. t) Present a report to the General Assembly of Partners or Shareholders on the compliance with the AML/CFT SIPAR, a topic that must be included and treated as an agenda item in the Annual Session of said Assembly, leaving a record of it in the respective Minutes Book. This report must refer, at a minimum, to the most relevant aspects of the fundamental pillars that compose the AML/CFT SIPAR, including the work environment in which the AML/CFT Prevention Administrator operates, sanctions imposed on the entity for non-compliance with the AML/CFT SIPAR, number of STRs (Suspicious Transaction Reports) presented to the competent authority; number of employees trained on the subject, summary of relevant findings detected by the Supervisor, by Internal Audit, and by External Audit referred to weaknesses in its AML/CFT SIPAR, as well as the results of its own self-assessment.

Art. 7.- Integration of the AML/CFT SIPAR The AML/CFT SIPAR is integrated by the following five fundamental pillars: a) Policies, procedures, and internal controls of due diligence with a risk-based approach, which must be contained in the respective AML/CFT Manual, in which, at a minimum, the following aspects must be foreseen:

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 16 i.- "Customer Due Diligence" (CDD) Policy, which includes, at a minimum: i.a.- Identification and verification of the customer, and creation of their Profile. i.b.- Identification and verification of the ultimate beneficiary of the transaction or commercial relationship. i.c.- Identification and verification of the nature and purpose of the transaction or commercial relationship. i.d.- Update of the Customer Comprehensive Profile (CCP) based on the validity or documentary, transactional, and/or economic activity changes of the customer. ii.- Complementary Knowledge Policies: ii.a.- "Know the Customers of its Customers" Policy with emphasis on high-risk customers. ii.b.- "Know your Employee" Policy.

ii.c.- "Know your Correspondent Relationships" Policy ii.d.- "Know your Electronic Funds Transfers" Policy ii.e.- "Know your Purchasers of Consignment Instruments" Policy ii.f.- "Know your Suppliers" Policy iii.- Policy for Matrices for Periodic Evaluation of AML/CFT Risks, including specific ones for new products. iv.- Policy for Permanent Monitoring of the commercial relationship in attention to AML/CFT risk. v.- Policy for Early Detection of Unusual Operations. vi.- Policy for Reporting of Suspicious Operations in accordance with the laws and regulations of the subject. vii.- Policy for Detection and Reporting of Cash Transactions for specific amounts in accordance with the laws and regulations of the subject. viii.- Policy for retention, conservation, and archiving of physical and/or electronic information, available to the competent authority. ix.- Policy for consolidated management of AML/CFT risk at the Financial Group level, as applicable.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 17 b) Implementation and Control Function of the AML/CFT SIPAR, in charge of the following structures: i.- Money Laundering, Asset or Property, and Terrorism Financing Prevention Committee (AML/CFT Prevention Committee). ii.- Administrator for the Prevention of Money Laundering, Asset or Property, and Terrorism Financing Risks (AML/CFT Prevention Administrator).

c) Institutional Program of permanent and specialized training on the subject of AML/CFT Prevention. d) Institutional Code of Conduct that includes the minimum aspects of AML/CFT Prevention. e) Independent Audit to verify the efficiency, effectiveness, compliance, and results obtained by the Supervised Entity in the implementation of the AML/CFT SIPAR, through: i.- Permanent Internal Audit. ii.- Annual External Audit.

CHAPTER II "CUSTOMER DUE DILIGENCE" (CDD) POLICY Art. 8.- CDD Policy a) The Supervised Entity, based on its specificity and risk profile within the industry in which it operates, must implement its own procedures, measures, and internal controls to develop adequate and continuous "Customer Due Diligence" (CDD) Policy in accordance with the minimum provisions indicated in this chapter. b) The CDD Policy will be applied differently according to the sensitivity and AML/CFT risk level that each Supervised Entity determines according to its own qualification matrix and in consideration of risk circumstances and factors. The high risk level corresponds to an enhanced CDD, the medium or normal risk level corresponds to a standard CDD, and the low risk level corresponds to a simplified CDD. c) It is the inalienable responsibility of each Supervised Entity, in the development of its CDD, to identify, verify, know, and adequately monitor all its regular customers, including co-owners, representatives, signatories, and ultimate beneficiaries thereof; whether natural or legal persons, national or foreign; as well as to leave evidence in the customer files on the verification performed on the information obtained. Regarding merely occasional customers who are non-recurring, non-permanent, and of low AML/CFT risk, or other persons who intervene such as brokers, the Supervised Entity must at least identify them, taking note of the name, number, and type of identity document, and having the respective legal, official, valid, reliable, and indubitable documents in view in accordance with the laws of the subject.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 18 d) The Supervised Entity, upon opening an account or starting the commercial relationship with the customer, must obtain adequate information to know about: i.- The origin of the funds and assets to be managed. ii.- The purpose and nature of the relationship. iii.- The volume of expected monthly activity. e) The Supervised Entity must not initiate, establish, accept, maintain, execute, or develop: i.- Anonymous accounts or relationships, or those under fictitious, inaccurate, coded, or encoded names; or that in any way are not in the name of the customer-owner thereof. ii.- Accounts of a person (natural or legal) used to serve as a nest or bridge with the purpose of depositing, managing, or facilitating the transfer of funds coming from businesses and/or income belonging to another person (natural or legal) or company, own or not of the account holder, and with which the supervised entity has no contractual relationship. iii.- Any commercial relationship or transaction with high-risk customers who, even applying what is provided in articles 6, letter "l" and 11, letter "g", of this Standard; do not present the complete information required to obtain full certainty about their identity, the purpose of said relationship, and the specific justification of the origin of the funds or assets managed or to be used. f) The CDD on commercial relationships with customers and the transactions they carry out, including monitoring, must be developed in a continuous and permanent manner, and will include the maintenance and periodic update of information. g) The Supervised Entity, to ensure that customer records remain updated, must perform regular and periodic reviews of them according to the deadlines indicated in article 12, letter "e", of this Standard, mainly when an important or significant transaction is carried out; when a relevant change occurs in the way the account and/or commercial relationship and/or expected activity operates; or when the documentation standards of a customer vary. The periodicity and depth of this diligence may be lower, in attention to the importance of commercial relationships and AML/CFT risk levels according to the policies of the Entity itself. h) Each Supervised Entity will determine the scope of CDD procedures for existing customers, according to the importance and AML/CFT risk level according to the results of its risk qualification matrix, which it must previously elaborate and document, giving special attention to relationships and accounts where the customer's or ultimate beneficiary's identity is not duly established, verified, or is not transparent.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 19 i) To update the Customer Comprehensive Profile (CCP) with respect to new requirements for all existing customers as of the date of entry into force of this Standard, the CDD must be carried out based on the results of the AML/CFT risk qualification matrix. j) Procedures for the approval of new customers must consider the inherent AML/CFT risk levels that they and/or their transactions may present. The greater the risk, the higher the hierarchy of the Official of the Supervised Entity that must approve their incorporation and/or transaction, which must be different from that which manages it.

Art. 9.- Identification a) The CDD must include requirements, procedures, and forms for the identification of customers, representatives, brokers, and ultimate beneficiaries, using legal, official, valid, reliable, and indubitable sources and documents in accordance with the laws of the subject. b) The Supervised Entity, upon starting a contractual relationship with regular customers in active, passive, or trust operations or any other service; must perform the identification of the customer, including their representatives or brokers thereof, and their ultimate beneficiaries, as applicable; requiring the original of the legal, official, valid, reliable, and indubitable identity document in accordance with the laws of the subject; and other documents provided for in the next article as applicable; conserving a legible and clear photocopy thereof with the respective reason for comparison. In the case of customers or operations that are merely occasional, non-recurring, non-permanent, and of low AML/CFT risk, it will not be necessary to physically conserve the photocopy of said documents, but the type and number of said documents must be verified and recorded in the respective forms. c) When the customer is a legal person, the Supervised Entity must obtain updated documentation and evidence on its legal constitution and registration in the competent registry according to the activity to which it is dedicated, its domicile, the names of its owners or majority or significant partners, directors, trustees (when applicable), or other persons who exercise control over the customer; as well as the identification of persons authorized to represent, sign, or act on behalf of the customer, or link this with the Supervised Entity, which must understand the ownership and control structure of the customer. Depending on the nature of these documents, they must be reviewed by the respective legal area of the Supervised Entity. d) The identification requirement is exempted for those persons who make payments for public services such as water, electricity, and telephone through the respective bank accounts of the companies providing them, and official payments to State entity accounts, provided that the amounts paid are less than the threshold established in the Law of the subject to be reported. This exception does not exempt the Supervised Entity from the obligation to present reports to the competent authority, as applicable, in accordance with the law of the subject.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 20 e) For the purposes of the identification process, the Supervised Entity must have forms, physical or electronic, that contain and collect, at a minimum, the following requirements: i.- Full name, number, and type of the legal, official, valid, reliable, and indubitable identity document in accordance with the laws of the subject; their signature according to identity document, address, and telephone; of the person who physically carries out the transaction or business relationship. ii.- Full name (and when possible, number and type of the legal, official, valid, reliable, and indubitable identity document in accordance with the laws of the subject), address, and telephone of the person in whose name the transaction is carried out. iii.- Full name (and when possible, number and type of the legal, official, valid, reliable, and indubitable identity document in accordance with the laws of the subject), address, and telephone of the beneficiary or recipient of the transaction. iv.- The identity of the affected accounts (numbers and holders) and type of transaction in question, such as deposits, withdrawal of funds, currency exchange, collection of checks, purchase of certified checks, manager's checks, purchase of drafts, payment orders, or other payments or transfers carried out through the Supervised Entity.

f) The Supervised Entity may not carry out the identification of the customer each time this personally carries out a transaction, provided that when attending to it, its identity already registered, documented, and previously verified can be confirmed by internal and reasonable means.

Art. 10.- Required Documents The Supervised Entity must require the following documents, as applicable in each case: a) Legal, official, valid, reliable, and indubitable Identity Document for natural persons, in accordance with the laws of the subject: i.- Identity Card for Nicaraguans residing in the country. ii.- Identity Card or Residence Card and/or Passport for Nicaraguans not residing in the country. iii.- Residence Card for foreigners residing in the country. iv.- Passport with valid entry stamp for foreigners not residing in the country. v.- Passport or Identity Card for foreigners not residing in Nicaragua and coming from a CA-4 member country.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 21 vi.- Card or Official Document issued by the competent national authority, for foreigners who are members of representations or organizations with diplomatic rank; and/or the Passport issued by their respective country. b) Official certification of registration in the competent Registry for the different legal persons, with which they accredit their respective legal standing in accordance with the laws of the subject, among others the following: i.- Certification of registration as a Non-Profit Civil Association, Foundation, or Non-Governmental Organization. ii.- Certification of registration as a Cooperative. iii.- Certification of registration as a Commercial Company. iv.- Certification of registration as a Union, Federation, Confederation, or Central Union. v.- Certification of registration as a Political Party. c) Photocopy of the Official Journal in which the creation of the legal person is published, as applicable. d) Constitutive Deed and Bylaws duly registered in the competent Registry, in which the purpose or corporate object of the legal person is appreciated. e) Document accrediting the power, mandate, or representation authority that a person has regarding another, natural or legal, to open and manage accounts, have a drawing signature, contract, or carry out the requested operation before the Supervised Entity. f) Certification of the Board of Directors' Minutes in which the granted authority to represent a society or entity is demonstrated. g) Official certification of the Minutes, Agreement, or Decree of appointment and/or taking office of the public official responsible for a State entity and/or copy of its publication in the State Official Journal. h) Certificates and/or Licenses and/or Permits, or equivalent documents, valid and issued by the competent public registries, according to the activity to which the customer is dedicated. i) RUC Document or Card (Unique Taxpayer Registry) for legal persons or equivalent document from the country corresponding for persons not domiciled in Nicaragua. j) Certification of the Minutes where the members of the current Board of Directors of the legal person are recorded at the time of carrying out the operation with the Supervised Entity. In this case, the identification, with official, legal, and indubitable document, of the natural person accredited as representative and the certification of the Minutes by which that authority is granted will also be required.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 22

k) Updated Financial Statements and their annexes for high-risk clients.

l) Bank, commercial, or personal reference letters in favor of the client and of the persons designated by them before the Supervised Entity as their representatives, attorneys-in-fact, and/or signatories. The number of references shall be defined in the internal policies of each Supervised Entity according to the CDD level that applies. The following exceptions or differentiated treatment regarding this requirement are established:

i.- For accounts in the name of government entities, it will not be necessary to require references.

ii.- When it comes to deposit accounts for the payment and withdrawal of salaries or wages, only the employer's reference letter and a copy of the employee's Social Security stub for the holder of said account will be required. This exception only applies when the account is used exclusively for the purpose of deposits and withdrawals of the employee's salary or wage; otherwise, the Supervised Entity must apply the corresponding CDD in accordance with this Norm.

iii.- Only one reference letter will be required for the opening and/or management of Deposit Accounts for persons residing in Nicaragua (natural or legal persons, national or foreign) who individually or adding up all accounts of the same person, the amount of their initial deposits or their final monthly balances in the same entity, do not exceed in national currency or in any other currency the equivalent of US$500.00 (five hundred United States dollars); or the sum of their debits or credits that individually or adding up all accounts of the same person do not exceed in one month in national currency or any other currency the equivalent of US$2,000.00 (two thousand United States dollars).

iv.- For the case of the preceding numeral, the Supervised Entity must implement adequate and timely control and monitoring systems to ensure that in such accounts or adding up the operations of all accounts, they cannot receive deposits or make withdrawals that added up in the month are greater than the limits indicated, without written authorization from the manager of the office that manages or oversees the account, with prior support of the reasons that justify the variations or excesses.

v.- If the contractual relationship is limited to loan operations, it will be sufficient for the Supervised Entity to require references from the client, through the loan application forms, which must be verified through acceptable means, such as telephone, fax, email, mandatory consultation to the Risk Central of the Superintendence, and Private Risk or Credit Information Centers when the latter have established this in their policies, and additionally, leave written evidence of the manner in which such verification was executed. This exception also applies to the case of loans where the client must open a deposit account for the exclusive purpose of crediting the disbursement thereof, making deposits for its payment and/or depositing funds resulting from their economic activity according to the declared Profile.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 23

m) All required documents that have been issued abroad and/or in a foreign language must be duly:

i.- Translated into Spanish, as appropriate.

ii.- When it comes to legal or official documents, they must also be authenticated by the corresponding authorities in accordance with the laws and conventions on the matter.

n) In the acceptance of the required documents, the Supervised Entity will adopt reasonable measures to:

i.- Prevent or avoid that they present or receive identification documents that are notoriously altered or doubtful; for which and according to their own policies, they may use technological tools or require additional documents to corroborate the true identity of their clients, representatives, and managers, as necessary.

ii.- Ensure that Certifications, and/or Certificates, and/or Licenses and/or Permits issued by the competent public registries, are valid at the time of initiating the commercial relationship with the client.

iii.- Obtain a ruling from their legal advice, mainly for the case of documentation presented by legal person clients.

Art. 11.- Verification

The CDD must include policies, procedures, and requirements to verify, before or during the course of establishing the usual commercial relationship, by means of legal, reliable, and indisputable documents and other pertinent and trustworthy information and sources; the real existence, the identity, the representation, the domicile, the legal capacity, the corporate purpose, the purpose of the operation, and the origin of funds to be used. For occasional clients who are non-recurring, non-permanent, and of low ML/TF risk, or other persons who intervene such as managers, the Supervised Entity must at least verify their identity. In the verification process, the Supervised Entity must at least:

a) Obtain, verify, and conserve the required and necessary information to determine the true existence and identity of the clients and of all persons in whose benefit an account is opened and/or the services offered by the Entity are used; as well as the owners or majority or significant partners of the legal person client, their representatives, and the persons who have authorized signatures on said accounts and/or to authorize and/or carry out the transaction.

b) Verify that the document identifying the client is not notoriously altered or doubtful, being able to require additional documents to corroborate the true identity, as necessary.

c) Review, the names of clients, beneficiaries, partners, guarantors, representatives, and/or signatories, against internal and/or external databases of publicly available risk lists or provided by competent authority or international organizations on persons (natural or legal) in attention or designated, known as money launderers, terrorists, or financiers of terrorism, or by being linked to organized crime; and against updated lists with public or private information from the Entity itself on unacceptable clients according to their own policies. This review must be done at the start of the relationship, and periodically with the frequency defined in their internal policies.

d) Carry out in-situ verification on the real existence of legal person clients.

e) Implement measures to verify the identity of the ultimate beneficial owners or real beneficiaries of accounts or transactions in all cases where the client acts, or where there are reasons to believe that they act on behalf of others as a representative, attorney-in-fact, agent, or fiduciary. The measures must include procedures to investigate whether the client is acting or not on behalf of another person, and on the legal capacity under which the client is acting.

f) Banks and financial institutions must implement policies and procedures to verify the information of the new endorsee client in the following cases:

i.- Time Deposit Certificates that according to the law on the matter and the respective internal regulations are issued as a Negotiable Instrument with nominative character.

ii.- Payment of checks that present more than one endorsement.

g) Only in the exceptional cases expressly provided for in the policies and procedures approved by their Board of Directors according to article 6, letter "l", of this Norm; the Supervised Entity may conclude the verification of the client's identity after the establishment of a new commercial relationship. It corresponds to each entity to determine which cases it will consider as exceptional according to their respective ML/TF risk level matrices.

h) Verify the purpose or reason for opening operations, accounts, and any other contractual or business relationship with a client according to the products and services for which the Supervised Entity is authorized.

i) Verify, within the legal framework and according to the ML/TF risk level, the origin of the funds, assets, or goods deposited by the client, or that intervene in the transaction or that they use to pay for their operations with the Entity.

j) Control and monitor, effectively and timely, all accounts and services received by the same client.

k) Determine the existing relationships between the accounts, business or commercial operations of the same client, or group of clients linked to each other, managed within the Supervised Entity; in order to detect if there are interrelations without apparent reason or that do not correspond to the normal economic and transactional profile expected of them.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 24

l) Verify that the accounts opened by state institutions in the Supervised Entity, are in correspondence with the technical norms applicable to them for the management of accounts, check issuers, electronic fund transfer.

m) Obtain adequate references on the clients, verifying that these must be independent to avoid cross-references between the same persons.

n) Establish an adequate segregation of functions of the personnel of the Supervised Entity: the one that promotes business, the one that obtains information about the client, the one that verifies it, and the one that approves the contractual or commercial relationship with the client.

ñ) The Supervised Entity, according to the complexity of its business and the weighting of its ML/TF risks, must have the necessary specialized tools for adequate and reasonable management of technological risk in the monitoring and prevention of ML/TF risks. These tools must allow, at minimum:

i.- Consult online the Comprehensive Client Profile (PIC).

ii.- Automatically and periodically compare, the entire client portfolio against internal and/or external databases of publicly available risk lists.

iii.- Facilitate queries on the relationships between linked clients and accounts.

iv.- Detect transactions by clients, risk levels, structuring, types of payment.

v.- Flexibilize the parametrization and implementation of alerts on unusual and/or suspicious behavior in client operations.

vi.- Document the workflow of follow-ups on clients generated by alerts, as well as for the management of the history of how many times a client has been the object of alerts, what type of alerts and reports.

vii.- Speed up the generation of reports.

viii.- Follow up on Audit trails.

o) Based on all the documentation and information obtained, the Supervised Entity must develop an initial risk profile of the client, and when it indicates a risk level higher than normal or qualifies as high risk, it must develop additional verification measures according to the Enhanced Due Diligence policy provided for in articles 15 and 16 of this Norm.

p) When the Supervised Entity cannot comply with the legal, regulatory, and its own policies for the identification and verification of existing clients, or potential clients, as the case may be, nor can it obtain the necessary information about the purpose and nature of the commercial relationship; even applying what is provided for in articles 6, letter "l" and 11, letter "g", of this Norm; it must terminate said relationship or not initiate it according to article 8, letter "e", also of this Norm. In these cases

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 25

it must also consider, under its own decision, to issue a Suspicious Operation Report (SOSR). What is executed in compliance with the provision contained in the present letter must be duly documented.

Art. 12.- Comprehensive Client Profile (PIC)

The Supervised Entity must structure, adopt, and keep updated a "Comprehensive Client Profile" (PIC) that it will fill for its usual clients (natural or legal persons, national or foreign) with whom it establishes contractual business relationships; including their co-owners, representatives, and signatories, according to the Formats established in Annex 2 of this Norm, according to the supervised industry to which they belong, and in which at minimum the information provided by the client themselves, indicated in the following letters "a" and "b" must be included.

a) Data on the client - natural person:

i.- Names and surnames according to official and indisputable identification document. Type and number of identification means, date of issue, date of expiration, issuing country, sex, marital status, date of birth, country of birth, nationality.

ii.- Names by which they are socially and publicly known.

iii.- Home address and phone, cell phone, personal email address, profession, current occupation, name of their workplace, address of their workplace as applicable, work email address, site or work center website, work center phone, fax, post office box. Monthly salary if salaried. Income range in which they qualify.

iv.- The same previous data for the spouse or in stable union of the client.

v.- Data on the certificates and/or licenses and/or permits, or equivalent documents, as applicable by the client's activity; including the entity that issues it, date of issue and expiration.

vi.- Account numbers and/or business contractual relationships maintained between the client and the Entity, including types, dates of linkages, currency, initial deposit, and payment methods as applicable.

vii.- Annual income and/or approximate sales volume obtained or generated by the client.

viii.- The origin of the funds and assets to be managed, purpose and nature of the relationship.

ix.- Volume of the activity and/or normal expected transactions of the client monthly in each of their accounts and/or contractual relationships with the Entity, including number of transactions, amounts in debits, credits, transfers, and average balances, among other criteria, that allow their monitoring and comparison in an agile and timely manner with the real activity of the client.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 26

x.- General data on the accounts and/or business relationships with other financial institutions, national or foreign.

xi.- The ML/TF risk level of the client according to their own risk classification system.

xii.- Data on the references in favor of the client, including the name of the grantor, number of their identification document, address, phone, workplace, time of knowing the referred client, and brief description of the result of the verification of the references indicating the employee who verifies it, date, time, name and signature of the verifier.

xiii.- The names of their largest clients and suppliers, as applicable.

xiv.- The set of information established in articles 8 to 11, inclusive, of this Norm, as applicable.

b) Data on the client - legal person:

i.- Trade Name (full and abbreviated), commercial name, country in which it was constituted, date of constitution, date of registration in the competent Registry, RUC No.

ii.- Number and date of the State Official Journal in which the creation of the legal person is published, as applicable.

iii.- Address of the headquarters or main office or matrix, phone, fax, PBX, post office box, page or website, email address.

iv.- Corporate purpose, main economic or social activity to which the client is dedicated, indicating the type of operations, the profile of operations either at retail or wholesale, identification of the geographic regions in which it operates, identity and domicile of its largest clients and suppliers. In the case of foreign legal persons, in addition, describe the profile of operations outside the country and to be carried out in Nicaragua.

v.- Data on the certificates and/or licenses and/or permits, or equivalent documents, as applicable by the client's activity; including the entity that issues it, date of issue and expiration.

vi.- Identification of directors and administrators.

vii.- Account numbers and/or business contractual relationships maintained between the client and the Entity, including types, dates of linkages, currency, initial deposit, and payment methods as applicable.

viii.- Annual income and/or approximate sales volume obtained or generated by the client.

ix.- The origin of the funds and assets to be managed, purpose and nature of the relationship.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 27

x.- Volume of the activity and/or normal expected transactions of the client monthly in each of their accounts and/or contractual relationships with the Entity, including number of transactions, amounts in debits, credits, transfers, and average balances, among other criteria, that allow their monitoring and comparison in an agile and timely manner with the real activity of the client.

xi.- General data on the accounts and/or business relationships with other financial institutions, national or foreign.

xii.- The ML/TF risk level of the client according to their own risk classification system.

xiii.- Data on the references in favor of the client, including the name of the grantor, number of their identification document, address, phone, workplace, time of knowing the referred client, and brief description of the result of the verification of the references indicating the employee who verifies it, date, time, name and signature of the verifier.

xiv.- The names of their largest clients and suppliers, as applicable.

xv.- The set of information established in articles 8 to 11, inclusive, of this Norm, as applicable.

c) The information contained in the PIC and its supports, must allow identifying the client and obtaining a reasonable knowledge of them, of their main activity, the purpose of the relationship with the Entity, and the origin of the funds.

d) In addition to the PIC in physical form, the Supervised Entity according to the complexity of business, number of clients, volume of operations, technology used for service provision, and the weighting of its ML/TF risks, must maintain the PIC in an automated manner to facilitate monitoring and comparison between the expected activity declared by the client and their real monthly activity.

e) The Supervised Entity must not update and modify the PIC ex officio. The update of the PIC will be done in the following cases, requiring the client the respective explanations and supports that justify it:

i.- As a maximum every four years when it comes to low-risk clients; as a maximum every three years when it comes to medium-risk clients and as a maximum annually when it comes to high-risk clients. These terms will be counted from the date of opening of the relationship and creation of the initial PIC, and then from each update. This periodicity may be lower in attention to the importance of the commercial relationships and the ML/TF risk levels according to the Entity's own policies.

ii.- When their economic activities in terms of markets, sales, and/or annual income, experience atypical or significant changes, variations, or increases in relation to their original PIC. It is the responsibility of each Supervised Entity to define in their ML/FT Prevention policies from what percentage or reasonable parameter they will consider it a significant variation.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 29 iii.- When atypical or significant changes, variations, or increases are reflected in the actual activity compared to the monthly transactional activity originally declared by the client. It is the responsibility of each Supervised Entity to define in its AML/CFT Prevention policies from what percentage or reasonable parameter it will consider a significant variation.

f) The initial PIC and its updates must be signed by the client, by the official who fills it out and reviews it, and by the one who authorizes it. In the PIC, before the client's signature, there must be a note stating: "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile."

g) Exceptionally, it will not be necessary for the Supervised Entity to complete a PIC in cases where the contractual relationship with the client is limited exclusively to loan operations; provided that the Entity maintains internal forms where it collects the minimum set of information required in articles 8 to 11, inclusive, of this Standard, as applicable. This exception does not apply in the case of loans on the occasion of which the client must also open a deposit account in accordance with the Entity's policies.

h) When the client makes use of the services of more than one Supervised Entity belonging to the same Financial Group supervised that operates in Nicaragua, and the main contractual relationship includes operations with a banking entity of said Group and that it meets at least the minimum requirements established by this Standard; the Board of Directors of the respective banking entity, assuming its own risks, may authorize that the other members of the Group can obtain from the bank the pertinent and updated information about the client. The foregoing will be permissible, under the following conditions:

i.- That the Supervised Entity that obtains the information is not relieved of its responsibility to directly request from its client the data and information particular to its business, necessary for the reasonable knowledge and verification of the client and the elaboration of their Profile.

ii.- That the banking entity that shares the information with the other members of its Financial Group, has the prior written authorization of the client and the information is necessary as part of the normal administrative process for the approval of operations with them.

iii. That the Financial Group to which the Information Requesting Entity belongs, has implemented a centralized and consolidated process for AML/CFT risk management at the Group level and in a manner consistent with the requirements established in this Standard.

iv. That the Financial Group has adequate, secure, and periodically audited mechanisms for the exchange of information about clients among its members.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 30 v. That there are internal and external audit programs for the periodic and integral evaluation of the application of AML/CFT risk-based controls, which include the review of the efficiency and effectiveness of information exchange among members within the Financial Group.

Art. 13.- Client File The Supervised Entity must form and conserve, in good condition and updated, a physical file for each client, in which a copy of the PIC and its duly signed updates, the supports for the application of CDD according to the risk level, as well as all the information and documents indicated in articles 8 to 11, inclusive, of this Standard, as applicable, must be archived.

Art. 14.- Standard CDD a) The Supervised Entity must apply a standard or ordinary CDD to clients and operations that, according to its AML/CFT risk level classification matrix, classify as medium or normal risk clients; applying the measures provided for in articles 8 to 13, inclusive, of this Standard, as appropriate.

b) The Supervised Entity must apply a differentiated or stepped CDD in terms of intensifying or simplifying it with respect to the standard CDD, according to how the risk levels of clients or the commercial relationship vary according to updates to its matrix; considering the changes that occur, among others, in the following circumstances:

i.- The legal structure of the client and their background.

ii.- The geographic location, jurisdiction, or country of origin of the client.

iii.- The economic sector where the client operates and their activity within the sector.

iv.- The client's labor and professional environment, including determining if they hold a significant public or private position.

v.- The characteristics, complexity, and changes in the transactions, product, or service required by the client.

vi.- Significant changes in the monthly expected activity declared by the client compared to their actual activity.

vii.- The channels and means of delivery or distribution of services and products, including the use of intermediaries, agents, brokers, managers, or electronic banking.

viii.- The use of complex and low-transparency legal or fiduciary structures and the use of bearer instruments or shares or convertible to bearer.

ix.- The payment methods used.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 31 x.- The use of intermediaries and third parties.

xi.- The linking of accounts, or businesses with family members, representatives, or with the Supervised Entity or a group affiliated with it.

xii.- Any other indicator that each Supervised Entity deems pertinent according to its own business and risk level, or according to any directive or other mechanisms issued by the Superintendence or competent authority.

Art. 15.- Intensified CDD a) Intensified, reinforced, enhanced, expanded, or deeper CDD is the set of policies, procedures, and measures of internal control that are reasonably more rigorous, deep, demanding, and exhaustive than the Supervised Entity must design and apply to clients classified as high risk, based on the analysis of AML/CFT risk factors and/or according to the results of the AML/CFT risk level classification matrix. Risk factors are all those circumstances and characteristics of the client and operations that generate a higher probability of AML/CFT risk that warrant special attention and intensified CDD.

b) Without prejudice to what may additionally be included and qualified in these categories according to the AML/CFT risk classification matrices specific to each Supervised Entity, or as instructed by another authority with competence in the matter, or according to international best practices for AML/CFT prevention; among the risk factors are considered the following: High-Risk Clients; Products, and/or Services, and/or High-Risk Accounts; High-Risk Distribution Channels; High-Risk Countries, Jurisdictions, and/or Geographic Areas.

i.- High-Risk Clients:

i.a.- Persons dedicated to the following business lines or activities: Exchange Houses; Companies dedicated to the Transfer or Sending of Funds or Remittances; Casinos or Games of Chance; Savings and Credit Cooperatives; Lenders; Unregulated Microfinance Institutions; Unregulated Financial Activities; Pawnshops; Civil Associations Without Profit Motive; Foundations or Non-Governmental Organizations (NGOs); Investors and Real Estate Agencies; Commercializers and Lessors of Motor Vehicles; Commercializer and Lessor of Vessels and Aircraft; Free Trade Zones; Commercializers under Multi-Level or Pyramid Sales Systems (network marketing); Sellers of antiques, jewelry, metals and precious stones, coins, art objects and postage stamps; Sellers of weapons, explosives and ammunition.

i.b.- Persons who individually or jointly, maintain balances at the end of each month in the Supervised Entity in amounts in national currency or any other, equal to or greater than one hundred thousand United States dollars (US$ 100,000), in their accounts under any business modality, including passive, active, or trust operations, or who in any way intervene in accumulated monthly movements by said amount, whether in debits or withdrawals and/or in credits or deposits.

i.c.- Persons with accounts that present high activity in cash and/or transfers.

i.d.- Politically Exposed Persons (PEPs), including close family members, associates, and close collaborators of such persons.

i.e.- Persons providing professional services such as Lawyers, Notaries, and Public Accountants; provided that their services are related to the following activities: sale and purchase of real estate and commercial, industrial, or financial entities; administration of money, accounts, securities, and other assets; and creation, organization, operation, or administration of partnerships, companies, legal persons, or legal structures.

i.f.- Commercial Companies or Companies with bearer shares or convertible to bearer.

i.g.- Trusts or legal structures especially when they function as Share Holders (holding) abroad for the administration of assets and goods, or as providers of fiduciary services.

i.h.- Legal persons constituted and established in Tax Havens (Off Shore).

i.i.- Notoriously Public Persons (NPP).

i.j.- Persons domiciled abroad.

i.k.- Persons domiciled in countries or jurisdictions that are considered by specialized international bodies in the matter as non-cooperators in the fight against AML/CFT; and/or as tax havens and/or high banking secrecy; and/or with low or null legislation on AML/CFT prevention, or, if these exist, weak application or lax supervision prevails.

ii.- Products, and/or Services, and/or High-Risk Accounts:

ii.a.- Private Banking.

ii.b.- Correspondent Banking and/or Correspondent Relationships.

ii.c.- Electronic Banking, via Internet or Telephone, and/or businesses or transactions that are not "face to face", or that do not imply the physical presence of the parties, or that facilitate anonymity.

ii.d.- Electronic or cable transfers of funds.

ii.e.- Monetary instruments.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 33 ii.f.- Safety Deposit Boxes.

ii.g.- Exchange Desk or Foreign Currency Purchase and Sale.

ii.h.- Loans guaranteed with liquid collateral (cash previously deposited in accounts, commercial securities, Certificates of Time Deposit, Government Bonds, etc.).

ii.i.- Trusts and asset administration services.

ii.j.- Payable Through Accounts services.

ii.k.- Accounts managed by Representative Offices.

ii.l.- Brokerage accounts, intermediaries, or investment agent accounts or those acting on behalf of third parties.

iii.- High-Risk Distribution Channels:

iii.a.- Electronic Banking, via Internet or Online Branches.

iii.b.- Telephone Banking.

iii.c.- Automated Teller Machines (ATMs).

iii.d.- Businesses or transactions that are not "face to face", or that do not require the physical presence of the parties, or that facilitate anonymity.

iii.e.- Businesses or transactions through agents or intermediaries.

iv.- High-Risk Countries, Jurisdictions, and/or Geographic Areas:

iv.a.- Those considered by specialized bodies such as FATF as non-cooperative or whose AML/CFT risk prevention systems are considered non-existent or, if they exist, are not applied effectively.

iv.b.- Those considered by international bodies, such as the UN, as collaborators of international terrorism.

iv.c.- Those considered of special attention due to their high incidence in the production, and/or trafficking, and/or consumption of illicit drugs.

iv.d.- Those considered by international bodies working in the fight against AML/CFT and/or in favor of international transparency; as offshore financial centers, tax havens, with high banking and fiscal secrecy, or with a high level of perceived public corruption.

iv.e.- Those that have been subject to sanctions by international bodies or included in special attention lists due to the high AML/CFT risk they represent.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 34 iv.f.- National or internal geographic areas of the country itself, when there is public information from official entities that these are being frequently used for the transit or trafficking of illicit drugs, illegal immigrants, or any other form of human trafficking, smuggling of goods, or illegal smuggling or trafficking of cash.

iv.g.- Those identified by the Supervised Entity itself as deserving special attention based on its experience with them, by the history of monitored transactions originating from them, by the presence of high indicators of public corruption, among others.

Art. 16.- Intensified CDD Measures For clients, products, distribution channels, and geographic areas classified as high AML/CFT risk, the Supervised Entity must apply more exhaustive or rigorous procedures and controls with respect to standard CDD. In addition to the measures provided for in articles 8 to 13, inclusive, of this Standard, as appropriate; the following must be applied at a minimum:

a) Establish and execute more rigorous verification procedures on all information supplied by the client.

b) Obtain, evaluate, and archive relevant and complete information about the client regarding their activity or function, their authorization to operate, their current certification of registration in the competent registry according to the activity they are dedicated to, their appointment as applicable, their internal client knowledge policies as applicable, and the quality of supervision when they are subject to it.

c) Conduct on-site inspections to verify the real existence and establishment of the client, in order to corroborate the congruence of the infrastructure and physical appearance of the business with the level of economic activity, annual sales, and transactional profile declared by the client.

d) Require updated Financial Statements and their annexes, as applicable.

e) Execute necessary mechanisms to justify, evidence, and document the origin of the funds, assets, or merchandise deposited by the client, or that intervene in the transaction or that they use to pay for their operations with the Entity.

f) The contractual relationship, transaction, or link with the client must be approved by a senior management official or Board of Directors.

g) Exercise permanent, intensified, and more exhaustive surveillance and monitoring over accounts, transactions, and commercial relationships.

h) Adopt measures to prevent the improper use of technological advances that could raise AML/CFT risk in the provision of those services offered by the Supervised Entity that facilitate anonymity due to lack of physical contact or that are not "face to face" with the person or persons who actually carry out such operations, transactions, or other business relationships.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 35 i) Require the AML/CFT prevention program that their high-risk clients apply, as they are obligated by the relevant law, complemented with the most recent certification of the audit carried out on said program. This requirement will not be demanded when the client is a Supervised Entity supervised by the Superintendence.

j) Know, reasonably, who the owners and majority or significant partners that make up a legal person who is in turn a partner of the legal person client of the Entity, as well as the true beneficiaries and/or owners of the funds managed; and particularly in the case of Commercial Companies, it is also necessary to identify:

i.- Persons who exercise real control over their operations, assets, properties, and businesses in general.

ii.- Main shareholders/partners, authorized signatories, or other persons who exercise significant control over the company.

iii.- Partners and other persons who exercise ownership control in the case of General and Limited Partnerships.

iv.- Controlling persons, when other companies or trusts exercise control over the company.

k) The Supervised Entity must also apply intensified CDD to clients and transactions that, originally considered normal risk, present any of the following circumstances:

i.- There are doubts about the validity or sufficiency of the information about the client derived from the identification and verification process.

ii.- The client is included in lists of persons convicted, prosecuted, or under investigation for AML/CFT matters by competent national authorities; or who appear in national, foreign, international, or specialized body lists, on persons linked to these risks; or by any other information of which the Entity itself has knowledge.

iii.- There are sudden and unjustified changes in the client's expected activity.

iv.- It concerns transactions and commercial relationships with clients who are operating from, countries, jurisdictions, and geographic areas of high risk that do not meet or do not sufficiently implement international standards in the matter of AML/CFT prevention.

v.- The Entity itself has suspicion or reasons to suspect that there is AML/CFT risk, regardless of the amount of the operation or the type of client; or, when said client has been the subject of a Suspicious Transaction Report (STR) and the Entity decides to continue with the contractual relationship.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 36 l) When the Supervised Entity considers that carrying out the intensified CDD process could directly or indirectly alert or warn the client, or potential client, of an eventual Suspicious Transaction Report (STR) as it should or could be derived from said process; it must then execute the following measures:

i.- Do not continue with the intensified CDD process.

ii.- Consider the possibility of issuing, immediately, a Suspicious Transaction Report (STR).

m) In cases where the Supervised Entity, according to its business, applies what is stipulated in the preceding letters "k" and "l", it corresponds to it to decide whether or not to continue with said contractual or business relationship. The compliance with this provision must be duly documented.

n) Any other measure that the Superintendence or any other competent authority may eventually dispose of through guidelines, guides, circulars, instructions, or other mechanisms.

ñ) The intensified CDD measures for high-risk clients will be applied as follows:

i.- For new clients after the date of entry into force of this Standard, immediately.

ii.- For existing clients on the date of entry into force of this Standard, within a period not exceeding 12 months in congruence with the period indicated in its article 12, letter "e", without prejudice to the permanent monitoring to which they must be subject.

Art. 17.- Simplified CDD a) For clients and operations classified as low AML/CFT risk, the Supervised Entity may apply simplified, reduced, lesser, or attenuated procedures and controls with respect to standard CDD.

b) The Supervised Entity may only simplify CDD when, applying matrices and adequate mechanisms to establish the AML/CFT risk level, it has determined the existence of low risk.

c) In simplified CDD, the identification of the client by indisputable document, the accreditation of representatives, the creation of the PIC and the respective client file must not be omitted; in addition to any other requirement that the Entity itself establishes according to its own policies on the occasion of the product or service it offers and contracts.

d) In correspondence with the preceding letters, the Supervised Entity may apply simplified CDD, among others, to the following types of clients:

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 37 i.- Entities Supervised by the Superintendence. ii.- Anonymous Companies that trade on the Stock Exchange and that by law must comply with disclosure requirements. iii.- State and municipal entities of Nicaragua. iv.- Occasional, non-recurrent, and low-risk clients.

CHAPTER III COMPLEMENTARY POLICIES FOR KNOWLEDGE

Art. 18. “Know Your Customer’s Customer” (CCC) Policy for High-Risk Clients The Supervised Entity, according to its nature and line of business, will develop a “Know Your Customer’s Customer” policy for cases of its clients considered high-risk who in turn carry out operations with high-risk clients; in which, as a minimum, the following must be reasonably foreseen: a) Corroborate that the high-risk client of the Supervised Entity has an AML/CFT prevention program, as required by the relevant law. b) Determine if the high-risk client of the Supervised Entity offers its services or products to persons (its own high-risk clients) who do not have physical presence and authorization to operate according to their respective activity. c) Determine if the high-risk client of the Supervised Entity acts on behalf of third parties.

Art. 19. “Know Your Employee” Policy The Supervised Entity, including the Human Resources and Security Area, must formulate and implement a “Know Your Employee” policy that forms part of the recruitment and selection program for new, permanent, and temporary staff, ensuring a high level of integrity, professionalism, and capability of the personnel. In this policy, as a minimum, the following aspects will be included: a) Requirements for personal and professional background checks, and abstaining from hiring employees who do not meet them. b) Specifically incorporate into the “Job Descriptions and Functions” that must form part of the Organizational Manual of the Supervised Entity, the functions of AML/CFT risk prevention, according to the nature of each position. c) Create an Employee Profile and update it periodically, particularly when the employee assumes different responsibilities and with a higher AML/CFT risk level, within the Entity.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 38 d) Measures to detect possible changes in the lifestyle of an employee, at any level, that allow deducing conduct not in line with their personal economic situation or family environment or with their professional profile; in consideration, additionally, of the Alert Signals and Indicators provided for in Annex 3 of this Standard.

Art. 20. “Know Your Correspondent Relationships” Policy a) Each Supervised Entity, according to its nature and line of business, will develop a “Know Your Correspondent Relationships” policy, including Accounts, Investments, Deposits, and Reinsurance abroad. b) When the Supervised Entity provides or receives services in correspondent relationships, it must: i.- Verify that the client financial institution maintains physical presence in the country where it is constituted, authorized, administered, and regulated. ii.- Abstain from establishing or continuing correspondent relationships with fictitious financial institutions or those constituted and authorized in a jurisdiction where they do not have physical presence or, having it, are not under an effective supervision regime; and also with financial institutions that in turn provide correspondent relationships to other fictitious financial institutions or those lacking such physical presence and supervision. iii.- Obtain, evaluate, and archive complete information of the client financial institution regarding its commercial activity, its authorization to operate, the quality of official supervision to which it is subject, its reputation, evaluate the sufficiency and effectiveness of its AML/CFT prevention programs, the history of legal and/or regulatory actions to which they have been subjected in relation to the AML/CFT topic, and the respective responsibilities for AML/CFT risk control that each client financial institution has adopted. iv.- Determine if the client financial institution offers its correspondent services to other financial entities, identifying them and ensuring they have physical presence, authorization to operate, and AML/CFT prevention programs.

Art. 21. “Know Your Electronic Fund Transfers” Policy a) In the case of national or international Electronic Fund Transfers and Remittances or Money Transfer, whether habitual or occasional; the Supervised Entity when acting as the originator, intermediary, or beneficiary, must: i.- Include in the electronic fund transfer forms and related messages connected through the payment chain, the exact, precise, and valid information about the sender (name, type and number of identification, address, phone, and account number). ii.- Ensure that the aforementioned information is maintained with the transfer and messages throughout the entire payment cycle.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 39 iii.- Examine more thoroughly fund transfers that do not contain complete information about the sender, or abstain from receiving them. b) The Supervised Entity must maintain an automated system for extracting data related to all transactions involving fund transfers or internal and external payment orders; that facilitates their monitoring. The Supervised Entity must not execute transfers without prior registration. The information to be registered in each transaction carried out and transmitted by the Originating or Beneficiary financial institution as applicable, will be as a minimum the following: i.- Name and address of the person originating the payment order or transfer. ii.- The means of identification (with legal and undeniable document) of the person managing the transaction. iii.- Account number, if the funds are debited from an account in the financial institution. iv.- Amount of the payment order or transfer. v.- The date on which the payment order or transfer was made. vi.- Instructions included in the payment order or transfer received from the originating person. vii.- Identity of the beneficiary financial institution; and viii.- Name, address, account number of the beneficiary person. ix.- If the funds instead of being deposited into the beneficiary person's account are disbursed in cash, cashier's check, manager's check, or through another monetary instrument, the beneficiary financial institution must identify the form of payment carried out. x.- If the beneficiary person is not an established client of the beneficiary financial institution, the latter must retain the name, address, and identification (with legal and undeniable document) of the beneficiary. c) The requirements provided for in the aforementioned letters “a” and “b” may be simplified when it comes to transfers and settlements from one financial institution to another financial institution, provided that both are acting on their own behalf.

Art. 22. “Know Your Buyers of Consignment Instruments” Policy a) The Supervised Entity must maintain an automated system for extracting data related to all its transactions for the sale of Consignment Instruments, such as manager's checks, cashier's checks, traveler's checks, bank drafts, and others similar; that facilitates their monitoring.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 40 b) The information to be registered in each transaction for the sale of Consignment Instruments will be as a minimum the following: i.- Name, address, and phone of the person managing the transaction and of any other person on whose behalf or for whose benefit the same is carried out. ii.- Type and number of the means of identification (with legal and undeniable document) of the person managing the transaction. iii.- Account number if carried out by an established client. iv.- Form of payment, amount, and type of currency used for its payment. v.- Description and identification of the instrument sold.

Art. 23. “Know Your Suppliers” Policy The Supervised Entity is obliged to develop “Know Your Suppliers” policies that include AML/CFT prevention procedures for the knowledge of the Suppliers of Goods and External Services of the Supervised Entity, and the handling of individual files duly documented showing the contracted services, modalities and forms of payment, frequency of service provision and delivery of goods; all in attention to the materiality of the contracting and risk qualification of the supplier.

CHAPTER IV MATRICES FOR AML/CFT RISK ASSESSMENT

Art. 24. AML/CFT Risk Matrices Each Supervised Entity must develop matrix or matrices with their respective procedures and systems, for the periodic evaluation of their AML/CFT risks, which include all areas of operation, clients, products, and services offered. a) The results of this evaluation will serve as elements for: i.- The classification of the AML/CFT risk level of clients. ii.- The type of CDD to apply according to the risk classification levels. iii.- The development of controls for AML/CFT risk management. iv.- The intensity of monitoring procedures and systems for the detection of unusual and/or suspicious operations. b) In the AML/CFT risk evaluation, Supervised Entities must take into account the guidelines, typologies, and other standards issued by competent authorities and specialized bodies on the topic, as well as their own experience in the markets where they operate. International standards must be taken into consideration.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 41 c) The periodicity of this evaluation must take into account the AML/CFT risk level of its clients, and be established in the respective policies. d) Each Supervised Entity must carry out an annual institutional self-assessment of its level of compliance with the AML/CFT SIPAR; and of the legislation and regulations on the matter applicable to them, developing the respective policies and procedures. The results of this process must be part of the report provided for in article 6, letter “t” of this Standard.

Art. 25. New Technologies, Products, and Services a) Each Supervised Entity must develop policies, procedures, and systems for the evaluation of AML/CFT risks, including the definition of the matrix or matrices applicable to the evaluation of new products and services, the technologies used, and distribution channels, to be applied prior to their launch in the design, development, testing, approval, and implementation phases. In this process, entities must pay special attention to the following: i.- Products and services that use technologies that give rise to relationships that are not “face-to-face”, which favor anonymity and/or do not require or minimize physical contact with beneficiary clients. ii.- Services to beneficiary clients using agents, intermediaries, or other similar distribution channels. b) The systems and technological tools for the classification of the AML/CFT risk level in new or sophisticated financial products or services and/or that facilitate anonymity, for the monitoring of these and for the early detection of unusual and/or suspicious AML/CFT operations; must be in correspondence with the technology that the Supervised Entity is using in the provision of the same.

CHAPTER V MONITORING AND REPORTS

Art. 26. Monitoring, Detection, and Security a) The Supervised Entity must detect and pay special attention to all activities, transactions, or operations, that are unusually complex, unusual, significant, atypical, unusual, incongruent, disproportionate, or inconsistent, or that do not have an evident legal or commercial basis, or that do not maintain consistency with the economic and transactional profile declared by the client. This obligation applies both to transactions carried out and to those merely attempted, whether or not they are suspected of AML/CFT, as well as for individual transactions, periodic, and patterns of multiple transactions that meet one or more of the characteristics mentioned here or fit into and/or combine with the Alert Signals and Indicators of Annex 3 of this Standard.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 42 b) When the Supervised Entity detects or in any way has knowledge of activities, transactions, or operations according to the aforementioned letter, it must carry out its examination, scrutiny, or analysis documented within a maximum period of 45 days counted from the date of detection or the moment it has knowledge, to rule out or confirm the need to report it as a suspicious operation to the competent authority. From this process and its conclusions, written evidence must be left and archived for the legal period. c) Suspicious operations are those activities and/or transactions of civil, commercial, or financial nature, whether carried out or not, in cash or other types of assets and regardless of their amount; that have an unusual, atypical, incongruent, or inconsistent magnitude, periodicity, origin, or geographic destination or speed of rotation, that do not relate to the economic and transactional activity declared by the client in their profile and this does not offer the appropriate, logical, and documented explanations and justifications of the case; or, that the conditions of unusual complexity, unusualness, disproportion, or significance manifested in them, go beyond the parameters of normality with respect to the transactions that are normally expected of the client according to their profile and the market in which they operate; or that for any reason do not have an economic basis or apparent legal justification or purpose of legality; for which the Supervised Entity has or should have knowledge, presumes, or has objective reasons to suspect, after having carried out the scrutiny and review of the case, that such activity or operation proceeds, and/or is linked and/or is destined to illicit activities, or to AML/CFT; or in any way attempts to evade the laws and regulations on the matter. d) It corresponds to each Supervised Entity to establish its own policies, procedures, monitoring systems, determination, and parametrization of alerts, in attention to the risk level, for the detection of unusual and/or suspicious activities, transactions, or operations. e) The procedures and systems for the monitoring referred to in the aforementioned letter must also be applied at the Financial Group level when applicable. These procedures must provide for adequate monitoring that groups the accounts and activities of each client or group of related clients in a consolidated manner through the Supervised Entity or Financial Group. f) The systems and tools for the monitoring and detection of unusual and/or suspicious AML/CFT operations must be in correspondence with the technology used by the Supervised Entity in the provision of the services it offers; which must allow their effective, early, and timely detection in relation to the AML/CFT Administrator. g) The Supervised Entity must implement secure internal procedures that guarantee the strictest confidentiality in the handling, processing, analysis, reporting, and recording of operations, transactions, or activities referred to in letter “a” of this article. In these cases, the AML/CFT Administrator must be informed for the timely and without delay analysis of all relevant information regarding the operation, transaction, activity, or client, to determine if there is or not a reasonable legal, financial, economic, or commercial explanation. The conclusions of said analysis must be sufficiently documented, archived, and retained for the period established by the relevant law.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 43 Art. 27. Alert Signals and Indicators a) To comply with the obligation to monitor and detect operations, transactions, or activities referred to in letter “a” of article 26 of this Standard; the Supervised Entity must take into account Annex 3 on Alert Signals and Indicators, as well as any other guide or instruction issued by competent authorities or recognized international bodies specialized in the AML/CFT prevention topic that contain examples and indicators of unusual and/or suspicious transactions. b) The Supervised Entity must detect and pay special attention to clients, operations, and/or behaviors that are provided for in Annex 3 on Alert Signals and Indicators, according to its financial sector and line of business, in order to be analyzed in combination with other indicators, factors, criteria, and available information, and determine if they constitute operations suspected of being linked to AML/CFT risks. c) Alert Signals and Indicators, considered individually, should not be considered as suspicious, but as reference elements or “red flags” that allow determining early the possible presence of suspicious AML/CFT activities.

Art. 28. Determination of Suspicion and Obligation to Present Suspicious Operation Report (ROS) a) When in the process of examination, scrutiny, or analysis of transactions, operations, or activities initially detected as unusual and/or suspicious; a reasonable and documented explanation is obtained that justifies them or dispels the reason why it was subject to such scrutiny; it will not be necessary to report them as suspicious operations. The information of this process must be archived and retained for the period established by the relevant law. b) When the conclusions obtained by the Supervised Entity from the examination, scrutiny, or documented analysis of transactions, operations, or activities detected with similar characteristics or that fit into those referred to in letter “a” of article 26 and/or those provided for in Annex 3 on Alert Signals and Indicators of this Standard, and the client does not document a legal, financial, economic, or commercial basis, explanation, and justification evident and reasonable about them; or that even presenting the above, the Entity in any way presumes, suspects, has reasons to suspect, has indications, knows, or should know, that the funds come from or are destined to an illicit activity or to AML/CFT, regardless of whether they do not fit into any Alert Signal or Indicator; the Supervised Entity must proceed to: i.- Determine and qualify such activity as a suspicious operation. ii.- Immediately present a Suspicious Operation Report (ROS) to the competent authority according to the relevant law.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 44 c) The ROS must also be presented: i.- When the Supervised Entity cannot comply with intensified CDD. ii.- When in the process of scrutiny, request for information to the client for the justification and analysis of the transactions, operations, or activities detected from the implementation of the monitoring procedures and systems; the Supervised Entity could thereby directly or indirectly warn said client that it is being subject to analysis for a possible ROS. In this case, the scrutiny process and request for information to the client must also be discontinued. d) The Supervised Entity will present the ROS regardless of the amount, nature, or type of client involved. The sending of a ROS to the competent authority does not constitute a criminal complaint, but only basic information for subsequent financial analysis and investigations by the competent authority designated in the relevant law, as applicable. e) The ROS will be prepared and presented by the AML/CFT Administrator in accordance with what is established in the applicable legislation, in this Standard, and in Annex 4 thereof, without prejudice to the instructions and guidelines that the competent authority may emit regarding its analysis. f) All suspicious operations must be reported, including attempted operations that were not carried out. g) The ROS must clearly indicate if the transaction was carried out, attempted, or rejected, and also if it was decided to terminate or continue the relationship with the client. h) As established by the legislation on the matter, ROS prepared and presented in good faith by a Supervised Entity in compliance with the same and this Standard, do not constitute a violation of the restrictions on information disclosure existing by contractual or legal or regulatory provision for the Supervised Entity, its directors, officials, and employees, nor will they imply any type of responsibility for them. i) The termination or continuation of the commercial relationship with the client on the occasion of sending a ROS depends on the free decision of each Supervised Entity.

Art. 29. Special Measures for the Presentation of a ROS a) The ROS will be sent and presented to the competent authority physically, according to the format and instructions provided for in Annex 4 of this Standard, which may eventually be modified by the authority empowered for its analysis. b) The ROS may also be sent electronically or magnetically using the automated security mechanisms that the Superintendent may eventually authorize through an Annex to this Standard; or as determined or instructed by the authority empowered for its analysis.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 45 c) It shall be the responsibility of each Reporting Supervised Entity to ensure that each ROS contains relevant and complete information, and additionally a clear analysis and explanation regarding the background and reasons why the operation is considered suspicious. d) The ROS that is submitted without meeting these requirements will be returned by the competent authority to the Supervised Entity with notification to the Superintendence, all through channels of strict confidentiality. e) The procedures and handling of all ROS and related information are of restricted access and must guarantee the strictest confidentiality and high security. No Supervised Entity, director, executive, official, employee, or agent linked to it may notify, disclose, or inform in any way, directly or indirectly, to persons not authorized by the relevant law, regarding the detection, scrutiny, or analysis of unusual/suspicious operations, or regarding the issuance, submission, and content of a ROS. f) The Supervised Entity, with respect to ROS, must supply the competent authority with any additional information required by it in strict adherence to legal provisions, and comply with any instructions or orders issued by them for the fulfillment of their functions. g) The ROS and the information supporting it must be kept in a special file, individual per client and centralized under the strict custody and confidentiality of the AML/CFT Prevention Administrator. The same treatment shall apply to information regarding the operations, transactions, or activities referred to in paragraph “a” of Article 26 that have been subject to examination, scrutiny, or analysis and did not warrant the issuance of a ROS.

Art. 30.- Monitoring and Detection of Cash Transactions Above the Determined Threshold a) It corresponds to each Supervised Entity to establish its own procedures and monitoring systems for the detection and grouping of Cash Transactions, for regular or occasional clients linked to the same client or beneficiary; in concept of deposits, withdrawals, credits, currency exchange, purchase and sale of securities, electronic transfers through or to said Entity, or other operations; that in one day, individually or singly, multiple or fractional; and in national or foreign currency; involve the exchange of currency in cash reaching an amount equal to or greater than the amount or threshold determined in the relevant Law. These transactions by themselves do not constitute suspicious operations. b) The adopted monitoring mechanisms must include adequate computer systems that orderly collect the data indicated in Annex 5 of this Norm. Additionally, these monitoring systems must allow the comparison of transactions, accounts, and activities of each client with their respective Profile established according to this Norm.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 46 Art. 31.- Obligation to Report Cash Transactions Above the Determined Threshold (RTE) a) Supervised Entities, without claiming secrecy, confidentiality, or reserve, must inform and report to the competent authority according to the relevant Law, those Cash Transactions provided for in the previous article. b) This information is called Report of Cash Transactions (RTE) and must be presented with the data indicated in Annex 5 of this Norm, within the first ten (10) days of the month following the one corresponding to the report, that is, Cash Transactions carried out during a calendar month will be reported to the competent authority within the first ten (10) calendar days of the following month. c) To comply with this obligation, the Supervised Entity must include in the RTE those multiple or fractional transactions linked to the same client or beneficiary that in 1 working day reach an amount lower than the threshold established in the relevant Law, but that added together are equal to or greater than said amount, in national or foreign currency. d) The RTE will be presented electronically or magnetically, always complying with the procedures and instructions to ensure quality, security, and strict confidentiality according to this Norm and its Annex 5, which may eventually be modified by the competent authority receiving and analyzing the RTE according to the relevant Law.

Art. 32.- Exceptions to the RTE a) The Supervised Entity, according to policies approved by its Board of Directors, may exempt certain clients from the RTE, provided that the following conditions concur: i. That the client is not included in the list of High-Risk Clients provided for in Article 15, paragraph “b”, numeral “i”, of this Norm. ii. That the client has maintained an account and commercial relationship with the Supervised Entity for a period greater than twelve (12) consecutive months. iii. That the client carries out cash transactions with some frequency each month, which exceed the amount or threshold that establishes the relevant Law for its report, for a period greater than twelve (12) consecutive months. Such activity must be consistent with the PIC, compatible with the business line to which it is dedicated, and consistent with the activity in the economic and geographic sectors in which it operates. iv. That the client has domicile and operates in and from Nicaragua, v.- That the Supervised Entity has carried out on-site verifications in the client's commercial or industrial establishment, on the occasion of authorizing and/or renewing said exception. The results of this verification must be documented.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 47 b) In the relationship with its clients exempted from the RTE, the Supervised Entity must apply the procedures established in Annex 5, and subject them to monitoring. c) In the preparation of the register of clients exempted from the RTE, the following procedures must be applied: i.- Design an appropriate form or computer register that allows documenting the authorization and review process of the criteria considered for granting and/or renewing the exception, maintaining a centralized file. ii.- Evaluate individually the exposure and risk of exempted clients, taking into account the purposes described in this Norm and leaving evidence thereof in the aforementioned form or register. The AML/CFT Prevention Administrator must review the evaluations performed. iii.- The authorization must include at least two favorable and independent opinions, one of which corresponds to the official who has direct contact with the client. iv.- Supervised Entities must permanently evaluate and monitor the exposure and risk of exempted clients, and at least semi-annually, carry out a formal review of the register of exempted clients to verify if they continue to adjust to the criteria that allowed their exemption, leaving evidence and comments thereof in the corresponding form or register. v.- The authorization of the renewals of the exceptions, considered individually, must be documented.

Art. 33.- Cash Transaction that Also Qualifies for a ROS If a reportable cash transaction also meets characteristics to be reported as a ROS, both reports must be submitted separately.

CHAPTER VI ARCHIVING AND PRESERVATION OF INFORMATION

Art. 34.- Safekeeping of Information and Supporting Documents a) Every Supervised Entity must adopt measures to archive, preserve, and safeguard properly, physically and/or magnetically, all information and documentation derived from the application of its policies, procedures, and internal AML/CFT controls; for the term established by the relevant Law, counted from the date of finalization or closure of the relationships, transactions, and/or accounts with the client. b) The information and documentation that the Supervised Entity must conserve, retain, and archive physically or electronically, as appropriate, must be adequate and sufficient to be able to reconstruct transactional links or individual accounts, and so that they may eventually serve as elements or clues in analyses,

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 48 investigations, or judicial processes in the matter of AML/CFT. For these purposes, as a minimum, the information to be retained by the Entity must include the following elements: i.- The Client File and Comprehensive Profile, and all documents and information that lead to the true identity of the person with whom the Supervised Entity carries out operations habitually and the client's history. ii. Identification data of the client, representative, manager, and beneficiary, including name and domicile. iii. Account files and commercial correspondence. iv. Date, type, and account number used in transactions. v. Type and sum of currency used in transactions. vi. As the case may be, reports and statistics on ROS including the related analysis. vii. As the case may be, reports and statistics on RTE. viii. Statistics on investigations or inquiries related to AML/CFT.

Art. 35.- Availability of Information and Supporting Documentation At the request of the Superintendence or any other competent authority, the Supervised Entity will have available all the information and documentation referred to in this Norm, which must be delivered without delay and without claiming any secrecy, within a reasonable time depending on the complexity and volume of the information required.

Art. 36.- Update and Extraction of Information a) The Supervised Entity must carry out updates of the records and files on clients and transactions. b) The Supervised Entity must maintain a manual and/or computer system or by any other means, that enables and facilitates the effective extraction of data relative to all operations, transactions, accounts, contracts, or services involving the commercialization, transfer, intermediation of funds or monetary instruments via internal and/or external (electronic, telephone, fax, or by other means) channels carried out by the Entity on behalf of or at the request of the client.

CHAPTER VII IMPLEMENTATION AND CONTROL OF THE AML/CFT SIPAR

Art. 37.- Implementation and Control Function Each Supervised Entity, and when applicable, each Financial Group, must effectively develop an Implementation and Control Function directly of the AML/CFT SIPAR, which is developed by the following structure and position:

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 49 a) A Committee for the Prevention of Money Laundering, Property or Assets, and Terrorism Financing, hereinafter AML/CFT Prevention Committee. b) An Administrator for the Prevention of AML/CFT Risks, hereinafter AML/CFT Prevention Administrator.

Art. 38.- AML/CFT Prevention Committee Without prejudice to the responsibilities and functions of the Board of Directors, the AML/CFT Prevention Administrator, the Administration, and the Audits on the subject of AML/CFT Prevention, the Supervised Entity must constitute a Committee for the Prevention of Money Laundering, Property or Assets, and Terrorism Financing (AML/CFT Prevention Committee).

Art. 39.- Integration of the AML/CFT Prevention Committee The Board of Directors of the Supervised Entity will establish the AML/CFT Prevention Committee, by resolution reflected in the Minutes, which will be integrated according to the following conditions: a) At least with three members of the Board of Directors. b) The President, Executive Director, General Manager, or any other official who holds the condition of being a full or alternate member of the Board of Directors and who at the same time also exercises positions, roles, or executive or management functions in said entity, cannot be members. c) The Executive President, Executive Director, or General Manager, any other official who holds the condition of being a full or alternate member of the Board of Directors and who at the same time also exercises positions, roles, or executive or management functions in said entity, cannot be members. These officials and executives may participate as guests at Committee sessions as appropriate. d) It must adopt the necessary measures to: i.- That at least one of the directors who integrate it, has a broad base of legal, regulatory knowledge, and on best practices and international standards for the prevention of AML/CFT risks, as well as, on the operationality and business of the industry and institution to which it belongs. ii.- To make a rotation that allows all directors to become familiar with the operations of their institution and become aware of the importance of the function of proactively managing the prevention of AML/CFT risks. e) When any member of the Committee has a personal interest or conflict of interest on any issue that is addressed within the Committee, they must abstain from knowing the case, not be present during the discussion, nor influence the related topic, which must be recorded in the Minutes.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 50 f) In the case of branches of foreign financial entities, two first-level officials designated by the head office will be incorporated into said Committee in place of the members of the Board of Directors.

Art. 40.- Functions of the AML/CFT Prevention Committee The functions established below in no way signify that the AML/CFT Prevention Committee will replace the Board of Directors, the AML/CFT Prevention Administrator, the Administration, or the Internal and External Auditors, in the execution of the work that each performs on the subject of Prevention of AML/CFT risks. The Prevention Committee will have, among others, the following minimum functions: a) General Functions: i.- To be a support instance that contributes to the execution of the AML/CFT SIPAR. ii.- To plan, coordinate, and ensure the effective compliance with the policies on the matter approved by the Board of Directors of the Supervised Entity or the highest authority in the country of branches of foreign financial entities. iii.- To establish its regulations regarding its functioning, which will be approved by the Board of Directors, which as a minimum, regulates its internal organization, its functioning, the periodicity of its sessions, the way to document meetings and to communicate and follow up on its agreements. iv.- To meet ordinarily at least once a month, without prejudice to extraordinary meetings that must be held to deal with issues that merit prompt attention. v.- To keep a Minute Book with numbered pages, where the known and resolved issues are reflected. These Minutes must be signed by each of the members of the Committee. vi.- To ensure the execution and compliance with the institutional AML/CFT Action Plan and the annual Training Plan for the prevention of AML/CFT risks prepared by the AML/CFT Prevention Administrator and duly approved by the Board of Directors. vii.- To inform the full Board of Directors, quarterly and in writing, the results of its activities so that each and every director is informed of the efficiency and effectiveness of the results obtained or the problems found in the implementation of the AML/CFT SIPAR. viii.- To coordinate the carrying out of the self-evaluation provided for in Article 24, paragraph “d”, of this Norm. ix.- To recommend to the Board of Directors the removal of the AML/CFT Prevention Administrator when their performance does not adjust to what is established in this Norm or as a consequence of the weaknesses and/or non-compliance resulting from the Inspection Reports of the supervisory organs authorized according to the law, or in the Internal or External Audit reports. x.- Without prejudice to the faculty and obligation of the AML/CFT Prevention Administrator to access or present their reports directly and personally before the full Board of Directors, the Committee will also serve as a means of communication between the Board of Directors and said official with respect to: x.a.- To know the monthly reports of the AML/CFT Prevention Administrator on the results and problems or limitations in the implementation of the AML/CFT SIPAR. x.b.- To review the effectiveness and quality of the results of the implementation of the existing system for the monitoring of accounts and transactions for the detection and timely reporting of suspicious operations. x.c.- To promote the investigation and adoption of international best practices for the prevention of these risks, as well as, to adapt them to the own particularities of the Supervised Entity in accordance with the industry in which it operates. x.d.- To carry out at least one annual technical review of the policies, procedures, and controls for the prevention of these risks, in order to adapt them to their needs and institutional risk profile. x.e.- To know any other new matter related to the AML/CFT SIPAR ordered by the Board of Directors. b) Functions with respect to Resolutions, Circulars, and Reports on the subject of AML/CFT Prevention by the regulation and supervision entities: i.- To evaluate the way in which the most important problems or weaknesses found by the Superintendence in its supervisory labor or by other competent authorities were or are being resolved by the administration. ii.- To evaluate the way in which the most important problems or weaknesses in their AML/CFT SIPAR found by the Superintendence or by other competent authorities were or are being resolved by the administration of the Supervised Entity. iii.- To know in detail and integral form the results of each and every final inspection report issued by the Superintendence on their AML/CFT SIPAR, and give them special attention through the follow-up to the compliance with all instructions and/or recommendations. iv.- To require the management of the Supervised Entity to present to them the action plans adopted by it to attend and comply with the instructions and/or recommendations of the Superintendence, and evaluate their viability. v.- To verify that the tasks and deadlines established by the Superintendence for the implementation and compliance with the instructions derived from their Inspection Reports or established through Resolutions, Circulars, and/or Instructions on their AML/CFT SIPAR are fulfilled.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 52 c) Functions with respect to Audit Reports related to AML/CFT Prevention: i.- To analyze the content and quality of the recommendations of the audit reports on the AML/CFT SIPAR, evaluating any difference between the scope of the work planned by the internal auditors or the contracted with the external auditors, respectively, in relation to that finally carried out, and that had not previously been reported by said auditors or the respective Audit Committee. ii.- To evaluate the way in which the most important problems or weaknesses on Prevention of AML/CFT risks, that Internal and/or External Audit during the course, was or has been informing, found by them while carrying out their respective reviews, were or are being resolved by the administration, and not wait for their attention until they are reported in a Final Report. iii.- To know in detail the content of the specific final reports or that being referred to other risks but that also contain aspects directly related to the management of AML/CFT risks issued by Internal and External Audit. iv.- To verify that internal and external auditors formulate and propose suggestions and/or recommendations of quality and with technical foundation on the matter of Prevention of AML/CFT risks, to improve those areas that present weaknesses or deficiencies and/or to strengthen the policies, procedures, monitoring, and internal control that make up the AML/CFT SIPAR, or because they are not being fulfilled, or are outdated in relation to the own risk profile of the Entity or with respect to legal and/or regulatory requirements. v.- To evaluate the recommendations to overcome the weaknesses found or to strengthen the AML/CFT Prevention system presented in their respective reports by Internal and External Audit. vi.- To evaluate the written comments on AML/CFT Prevention by internal or external auditors with respect to the matters, operations, or transactions of an irregular, unusual, or suspicious nature that they may have noticed during the examination of business operations, files, and/or transactions of the reviewed clients that merit being reported to the authority designated according to the Law of the matter. vii.- To evaluate the points of view or opinion of internal and/or external auditors with respect to the technical competence of the AML/CFT Prevention Administrator and/or their performance in the position. viii.- To require the management of the Entity to present to them the action plans adopted by it to attend and comply with the suggestions and/or

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 53 recommendations of Internal and External Audit, evaluating their viability and the effectiveness of their implementation. ix.- To evaluate the comments written by internal or external auditors on the matters, operations, or transactions of an irregular, unusual, or suspicious nature that they may have noticed during the examination of business operations, files, and/or transactions of the reviewed clients that merit being reported to the authority designated according to the Law of the matter. x.- To evaluate the points of view or opinion of internal and/or external auditors with respect to the technical competence of the AML/CFT Prevention Administrator and/or their performance in the position. xi.- To require the management of the Entity to present to them the action plans adopted by it to attend and comply with the suggestions and/or recommendations of Internal and External Audit, evaluating their viability and the effectiveness of their implementation.

Art. 41.- AML/CFT Prevention Administrator a) The Supervised Entity must designate an AML/CFT Prevention Administrator, who will be responsible for the implementation, coordination, and control of the AML/CFT SIPAR, reporting directly to the Board of Directors or to the highest authority in the country of branches of foreign financial entities. b) The AML/CFT Prevention Administrator must have sufficient authority, independence, and resources to carry out their functions effectively. c) The AML/CFT Prevention Administrator must have adequate knowledge, training, and experience in AML/CFT matters. d) The AML/CFT Prevention Administrator must report to the Board of Directors or to the highest authority in the country of branches of foreign financial entities, at least quarterly, on the implementation of the AML/CFT SIPAR, the results of the monitoring and detection of suspicious operations, and the compliance with the obligations established in this Norm. e) The AML/CFT Prevention Administrator must coordinate with the Internal Audit function to ensure the effectiveness of the AML/CFT SIPAR. f) The AML/CFT Prevention Administrator must participate in the training programs for the prevention of AML/CFT risks. g) The AML/CFT Prevention Administrator must maintain a file with the reports and documentation related to the AML/CFT SIPAR.

Art. 42.- Training and Awareness a) The Supervised Entity must implement a training and awareness program on AML/CFT risks for all employees, including senior management. b) The training program must be updated regularly and must cover the relevant laws, regulations, and internal policies on AML/CFT prevention. c) The training program must include specific training for employees involved in high-risk activities. d) The Supervised Entity must maintain records of the training provided to its employees.

Art. 43.- Independent Audit a) The Supervised Entity must have an independent internal audit function that evaluates the effectiveness of the AML/CFT SIPAR. b) The internal audit function must report directly to the Board of Directors or to the Audit Committee. c) The internal audit function must have adequate knowledge, training, and experience in AML/CFT matters. d) The internal audit function must carry out audits at least annually. e) The internal audit function must report the results of the audits to the Board of Directors or to the Audit Committee.

Art. 44.- External Audit a) The Supervised Entity may engage external auditors to evaluate the effectiveness of the AML/CFT SIPAR. b) The external auditors must have adequate knowledge, training, and experience in AML/CFT matters. c) The external auditors must report the results of the audits to the Board of Directors or to the Audit Committee.

Art. 45.- Sanctions a) The Supervised Entity must establish internal sanctions for non-compliance with the AML/CFT policies and procedures. b) The sanctions must be proportional to the severity of the non-compliance.

Art. 46.- Entry into Force This Resolution enters into force on the date of its publication.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 54

ANNEX 5 DATA TO BE REPORTED IN THE RTE

  1. Date of the transaction.
  2. Type of transaction.
  3. Amount of the transaction.
  4. Currency of the transaction.
  5. Identification data of the client.
  6. Identification data of the beneficiary.
  7. Identification data of the account holder.
  8. Identification data of the account.
  9. Identification data of the branch.
  10. Identification data of the employee who processed the transaction.

ANNEX 6 DATA TO BE REPORTED IN THE ROS

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 7 FORM FOR THE REGISTRATION OF EXEMPTED CLIENTS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 8 FORM FOR THE REGISTRATION OF THE AML/CFT PREVENTION COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 9 FORM FOR THE REGISTRATION OF THE AML/CFT PREVENTION ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 10 FORM FOR THE REGISTRATION OF THE TRAINING PROGRAM

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 11 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 12 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 13 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 14 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 15 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 16 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 17 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 18 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 19 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 20 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 21 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 22 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 23 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 24 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 25 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 26 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 27 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 28 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 29 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 30 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 31 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 32 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 33 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 34 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 35 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 36 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 37 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 38 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 39 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 40 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 41 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 42 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 43 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 44 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 45 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 46 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 47 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 48 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 49 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 50 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 51 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 52 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 53 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 54 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 55 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 56 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 57 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 58 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 59 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 60 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 61 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 62 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 63 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 64 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 65 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 66 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 67 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 68 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 69 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 70 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 71 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 72 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 73 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 74 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 75 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 76 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 77 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 78 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 79 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 80 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 81 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 82 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 83 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 84 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 85 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 86 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 87 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 88 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 89 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 90 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 91 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 92 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 93 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

ANNEX 94 FORM FOR THE REGISTRATION OF THE TRAINING

  1. Date of the training.
  2. Participants.
  3. Topic.
  4. Trainer.
  5. Evaluation.

ANNEX 95 FORM FOR THE REGISTRATION OF THE INTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 96 FORM FOR THE REGISTRATION OF THE EXTERNAL AUDIT

  1. Date of the audit.
  2. Auditor.
  3. Scope.
  4. Findings.
  5. Recommendations.
  6. Follow-up.

ANNEX 97 FORM FOR THE REGISTRATION OF THE SANCTIONS

  1. Date of the sanction.
  2. Employee.
  3. Reason for the sanction.
  4. Type of sanction.
  5. Follow-up.

ANNEX 98 FORM FOR THE REGISTRATION OF THE EXCEPTIONS

  1. Client identification data.
  2. Date of the exception.
  3. Date of the renewal of the exception.
  4. Reasons for the exception.
  5. Evaluation of the risk.
  6. Approval of the exception.
  7. Approval of the renewal of the exception.

ANNEX 99 FORM FOR THE REGISTRATION OF THE COMMITTEE

  1. Date of the meeting.
  2. Attendees.
  3. Agenda.
  4. Decisions.
  5. Follow-up.

ANNEX 100 FORM FOR THE REGISTRATION OF THE ADMINISTRATOR

  1. Date of the report.
  2. Identification data of the reporting entity.
  3. Identification data of the client.
  4. Identification data of the beneficiary.
  5. Identification data of the account holder.
  6. Identification data of the account.
  7. Identification data of the branch.
  8. Description of the suspicious operation.
  9. Reasons for the suspicion.
  10. Amount of the transaction.
  11. Currency of the transaction.
  12. Date of the transaction.
  13. Type of transaction.
  14. Identification data of the employee who prepared the report.
  15. Identification data of the employee who reviewed the report.
  16. Identification data of the employee who approved the report.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 53 recommendations on AML/CFT prevention by auditors, and evaluate the feasibility of the same.

ix.- Know, through the AML/CFT Prevention Administrator, on a monthly basis, the compliance with the action plans that management adopts to remedy and resolve legal and regulatory non-compliance, internal policies and procedures, or weaknesses in the AML/CFT SIPAR.

d) Functions with respect to senior Management or Executive Direction levels: The AML/CFT Prevention Committee may convene or invite senior Management or Executive Direction levels to Committee sessions, whenever it deems necessary, to:

i.- Address and discuss at the appropriate level, particularly with those involved in decision-making, business, processes, and technology, matters concerning the concept of the Entity's policies and procedures related to the AML/CFT SIPAR, as well as compliance with laws and regulations issued on the subject by the Superintendency or other competent state institutions.

ii.- Obtain management's views regarding the recommendations of internal and external auditors on the subject of internal control policies for AML/CFT prevention, and the cost/benefit analysis in the execution of those recommendations.

iii.- Know directly from Management the reports on their action plans and the results of their execution for the attention of the Superintendency's instructions and audit recommendations on the subject of AML/CFT prevention.

Art. 41.- AML/CFT Risk Prevention Administrator Without prejudice to the specific functions and responsibilities assigned by this Norm to the Board of Directors, the AML/CFT Prevention Committee (as applicable), and Audit; each Supervised Entity must have an AML/CFT Risk Prevention Administrator (Administrator of Prevention of Money Laundering, Assets or Assets; and Terrorism Financing Risks) (AML/CFT Prevention Administrator or PLD/FT Administrator), as the main executive official for the coordination, administration, and execution of the AML/CFT SIPAR.

Art. 42.- Appointment The appointment of the AML/CFT Prevention Administrator must meet the following conditions:

a) Carried out directly by the Board of Directors of each Supervised Entity, before whose body said official must report and from which they will depend functionally, organizationally, and administratively.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 54

b) By Board of Directors Agreement, duly recorded in the Minutes of the corresponding Session.

c) Hired under a permanent labor regime; and with first-level managerial authority.

d) With administrative treatment comparable, in all aspects, to that granted to other first-level managerial bodies that make up the administrative structure of the Supervised Entity.

e) Giving notice to the Superintendent, presenting the following documents: Certification of the appointment minutes, resume, notarial declaration of the AML/CFT Prevention Administrator confirming that they are not subject to any of the incompatibilities for the position established in this Norm, notarized and reasoned photocopy of the official identity document, notarized and reasoned photocopy of the respective academic title, and photocopy of the supports that accredit training in AML/CFT prevention matters.

Art. 43.- Characteristics of the Position The position of AML/CFT Prevention Administrator must have the following characteristics:

a) Be exercised ethically, diligently, efficiently, and specialized.

b) Invested with the administrative, functional, and technical authority and independence necessary to guarantee adequate and effective management and implementation of the AML/CFT SIPAR, in coordination with those in charge of the different strategic business units or technical and operational support. All areas of the Supervised Entity must provide the AML/CFT Prevention Administrator with immediate and effective support and collaboration for the exercise of their functions.

c) Exclusive for administering the AML/CFT SIPAR. Exceptionally, the Supervised Entity may also assign to its PLD/FT Administrator other functions known as "Compliance" with specific work plans, budget, and resources for this other responsibility.

Art. 44.- Case of Financial Group For the case of a Financial Group, the following conditions will be attended to:

a) Each Supervised Entity that is part of a Financial Group must have its own AML/CFT Prevention Administrator, who cannot hold the same position or develop the functions of this position for more than one Entity within the same Group.

b) One of the AML/CFT Prevention Administrators within each Financial Group will be designated as the AML/CFT Prevention Coordinator for the effective global implementation of the AML/CFT SIPAR in all Supervised Entities that are part of the Group and with a view to consolidated supervision. In general, the Prevention Coordinator must be an official of the parent house in Nicaragua or of the most significant Supervised Entity of the Group, and in case of uncertainty, of the banking entity if it exists.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 55

c) The AML/CFT Prevention Coordinator of a Financial Group will be appointed in the same manner by the Board of Directors of the parent house or the corresponding Supervised Entity.

Art. 45.- Objection The Superintendent may at any time object to and invalidate, by reasoned resolution, the appointment of the AML/CFT Prevention Administrator and the AML/CFT Prevention Coordinator within the Financial Group.

Art. 46.- Support Administrative Structure Banks and Finance Companies must establish and provide a Support Administrative Structure for the work developed by the AML/CFT Prevention Administrator, equipped with the necessary personnel and resources for the adequate implementation of the AML/CFT SIPAR, including conditions that allow an environment of privacy and confidentiality for the handling of information.

Art. 47.- Professional Profile of the AML/CFT Prevention Administrator The person holding the position of AML/CFT Prevention Administrator must have, at a minimum, the following requirements:

a) Be a Professional, duly accredited with a University Degree of Bachelor's or Engineering, preferably in the areas of Business Administration, Economics, Finance, Public Accounting, Audit, Law, or Informatics. It is desirable to possess postgraduate degrees or specializations in these sciences, particularly if they relate to Banking Management, Financial Intermediation, or the Financial, Insurance, Securities, or General Warehouses of Deposit Markets.

b) Have at least 3 years of relevant work experience and/or specialized training, duly accredited, within the industry in which the Supervised Entity that appoints them operates, as well as broad knowledge of the operations and products of the Financial Markets as applicable: Banking Market, Insurance Market, Securities Market, and General Warehouses of Deposit Market, or in areas related to the business of the entity that appoints them.

Art. 48.- Incompatibilities Persons subject to any of the following situations cannot be appointed to the position of AML/CFT Prevention Administrator or AML/CFT Prevention Coordinator for the Financial Group case:

a) Shareholders, partners, directors, general manager, highest-ranking executive, and related parties to the Supervised Entity, according to banking law.

b) The internal and external auditor of the Supervised Entity.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 56

c) Those with criminal records for intentional crimes, and those who have been convicted administratively or judicially by final resolution, for serious violations of laws and regulations of a financial nature or related to AML/CFT, within or outside Nicaragua.

d) Those who have been directors, managers, deputy managers, or high-level officials of a Supervised Entity subjected to intervention and/or forced liquidation processes; or when by judicial or administrative resolution of the Superintendent, responsibilities, presumptions, or indications linking them to the aforementioned situations have been or are established.

Art. 49.- Temporary or Interim Substitution

a) The Supervised Entity must have officials with the necessary capacity to temporarily substitute the AML/CFT Prevention Administrator in case of temporary absence, according to their administrative succession plans.

b) The Board of Directors of the Supervised Entity must appoint the Substitute for the AML/CFT Prevention Administrator and inform the Superintendent thereof.

c) When the substitute is to assume the position of PLD/FT Administrator temporarily for more than 45 days, they must inform the Superintendent thereof. The position of PLD/FT Administrator, in the absence of the holder, cannot be performed temporarily by their substitute for more than 90 days without appointing the new holder.

d) The Substitute must meet the same qualities as the AML/CFT Prevention Administrator and exercise the same functions in their absence.

e) The Substitute for the AML/CFT Prevention Administrator of Banks and Finance Companies must necessarily belong to the personnel of the Support Administrative Structure that the AML/CFT Prevention Administrator must have.

Art. 50.- Removal

a) Any removal, separation, or assignment to another position of the AML/CFT Prevention Administrator or the Coordinator for the Financial Group case, must be approved by the Board of Directors of the Supervised Entity by resolution, and communicated to the Superintendent with an explanation of the reasons motivating the measure. The Superintendent will express their consent or objection to such removal, within a period not exceeding 15 business days counted from when the communication is presented.

b) The Superintendent, according to the power granted by law, in exercise of their supervisory function and by reasoned resolution, may instruct the Board of Directors of the entity to remove the AML/CFT Prevention Administrator and the AML/CFT Prevention Coordinator for the Financial Group case.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 57

Art. 51.- Functions of the AML/CFT Prevention Administrator The AML/CFT Prevention Administrator is the main executive official in the coordination, administration, and execution of the AML/CFT SIPAR. The same responsibility will have the AML/CFT Prevention Coordinator at the Financial Group level, as applicable. Among others, the AML/CFT Prevention Administrator must execute the following functions:

a) General Functions:

i.- Execute the policies, procedures, and internal controls for prevention that integrate the AML/CFT SIPAR.

ii.- Coordinate the elaboration, implementation, and updating, together with the pertinent areas of the Supervised Entity, of the PLD/FT Manual and the PLD/FT POA (Annual Operating Plan).

iii.- Participate in the periodic risk assessment of AML/CFT faced by the Supervised Entity and in the development of policies, procedures, internal controls, and matrices for the management of these risks.

iv.- Analyze and propose changes to the AML/CFT SIPAR and the PLD/FT Manual according to laws, regulations, standards, instructions, and recommendations on the matter.

v.- Continuously verify compliance with all components of the AML/CFT SIPAR, paying greater attention to the areas and activities with the highest AML/CFT risk. For these effects, the AML/CFT Prevention Administrator must have the respective verification procedures.

vi.- Present periodic reports on the compliance of the AML/CFT SIPAR to their Board of Directors and the Prevention Committee as structured, and when relevant, also to the AML/CFT Prevention Coordinator of the Financial Group as applicable. The Board of Directors establishes the periodicity of these reports, which will not be greater than 6 months, and must contain, at a minimum, the following information:

vi.a.- Objectives of the report.

vi.b.- Limitations and obstacles in its implementation.

vi.c.- Results of its implementation.

vi.d.- Degree of compliance with procedures by employees.

vi.e.- Relevant internal control deficiencies detected.

vi.f.- Internal administrative sanctions applied.

vi.g.- Statistics of Reports presented.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 58

vi.h.- Commitments for improvement of the reviewed areas.

vi.i.- Follow-up on corrective actions reported in the preceding report.

vi.j.- Recommendations for strengthening, improvement, and/or adjustments.

vi.k.- Additional resource needs.

vi.l.- Conclusions.

vii.- Follow up on the implementation of recommendations pointed out by supervisory bodies, internal and external auditors, and other internal control mechanisms, to remedy identified weaknesses and strengthen the AML/CFT SIPAR.

viii.- Review and monitor possible transactions that the Supervised Entity might have with persons included in special or suspicious lists, national or international, that link them to AML/CFT issues and organized crime in general.

ix.- Periodically analyze the market segments to which the entity's clients and products belong, in order to identify and know possible AML/CFT patterns and trends.

x.- Collaborate with the person responsible for the processes, business, and/or marketing area of the entity, in the adoption of prevention measures on the AML/CFT subject prior to the launch of new products and services.

xi.- Collaborate with the persons responsible for the Human Resources and Security areas of the Supervised Entity, in the formulation and implementation of the "Know Your Employee" policy.

xii.- Participate in the development and execution of awareness, training, and updating programs on AML/CFT risk and its management, on the AML/CFT SIPAR, on international standards and best practices in the matter, and on compliance with relevant laws and regulations.

xiii.- Keep updated statistics, records, and supports on the application and development of the Supervised Entity's Institutional Training Program on the AML/CFT subject.

xiv.- Coordinate activities and exchange information with all offices of the Supervised Entity and when relevant, with the Prevention Coordinator of the Financial Group, as applicable, for the effective implementation of the AML/CFT SIPAR in the Entity and in the Group.

xv.- Promote fluid communication with all offices of the Supervised Entity, seeking a harmonized and effective effort on the subject of the AML/CFT SIPAR that contributes to the rooting of a compliance culture in the Entity.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 59

xvi.- Elaborate statistics, using their own Databases based on their risks for the establishment of different prevention parameters that allow interrelating information for better management of monitoring, analysis, and information cross-referencing, on topics such as, for example: reports to the competent authority, concentration of operations by each market segment, consolidated movement of transactions by client, classification of operations by amounts, consolidated movements of all products and services of a client or group of linked clients, movements registered by currencies, classification of clients by home addresses, and others that the entity decides to incorporate according to the industry in which it operates and the weighting of its risks.

xvii.- Act as the counterparty or direct liaison with the Superintendency and other competent authorities, to cooperate in everything related to the subject of AML/CFT prevention.

xviii.- Promote joint and coordinated efforts with their counterparts at the industry level to strengthen and feed back the AML/CFT SIPAR in each of the Supervised Entities and at the Financial Group level; and foster self-regulation on AML/CFT prevention in the self-interest of the Financial System.

b) Functions regarding CDD (Customer Due Diligence) policies:

i.- Propose and monitor compliance with policies, procedures, and internal controls for risk-based CDD.

ii.- Execute and periodically review the AML/CFT SIPAR requirements related to the documentation of identification and verification of identity of clients and beneficiaries, and for the purpose and monitoring of the commercial relationship; paying greater attention to sectors with higher AML/CFT risk.

iii.- Verify the periodic updating of documentation and the CDD (Customer Due Diligence) file, according to the importance and level of AML/CFT risk.

c) Functions regarding Detection and Reporting to the competent authority policies:

i.- Participate in the development and implementation of policies, systems, and procedures for the monitoring and early detection of unusual and suspicious activities.

ii.- Administer the procedures and controls for the security, confidentiality, and analysis of internal reports of unusual and/or suspicious operations, as well as the procedures and controls for the preparation, issuance, and presentation of a STR (Suspicious Transaction Report).

iii.- Analyze and document the unusual and/or suspicious operations detected, in order to evaluate and determine if the issuance of a Suspicious Transaction Report (STR) is appropriate. Optionally, the AML/CFT Prevention Administrator may develop this function in coordination with the AML/CFT Prevention Committee.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 60

iv.- Administer the systems and internal controls to monitor, detect, and register cash transactions by the amount or threshold established in the laws on the matter and in this Norm and its 5.

v.- Review, prepare, sign, present, and remit to the competent authority, the reports provided for in this Norm, STRs, and CTRs (Cash Transaction Reports), and any other report provided for in the legislation on AML/CFT prevention; all with the due quality, confidentiality, security, and according to the mechanisms and forms established.

d) Functions regarding Information Archiving and Conservation policies:

i.- Propose policies and verify the implementation of procedures for the adequate conservation of documents and information according to what is established in this Norm and in the laws on the matter.

ii.- Pay special attention to the security of documentation related to reports and analysis of transactions, including STRs, CTRs, and information required by competent authorities.

e) In the exercise of their functions, the PLD/FT Administrator will always have access to client records and files, and any other information that is necessary for the fulfillment of their functions.

f) It corresponds to the AML/CFT Prevention Administrator the responsibility to inform the Superintendent, immediately, about facts that significantly prevent the adequate performance of their labor, once said problem has not been able to be resolved by the Prevention Committee and the Board of Directors of the Entity.

g) Without prejudice to all the functions previously mentioned, the AML/CFT Prevention Administrator must immediately inform the AML/CFT Prevention Committee and the Board of Directors of the Supervised Entity, and the Superintendency, of significant facts or findings on any AML/CFT situation that implies or requires immediate action.

CHAPTER VIII AML/CFT TRAINING

Art. 52.- PLD/FT Training Program The Supervised Entity must adopt, develop, finance, and implement an Institutional Training Program, to promote the culture and awareness in matters of prevention and detection of AML/CFT, which must:

a) Be permanent, continuous, updated, adequate, and adjusted to its operational profile within the industry and according to AML/CFT risks.


RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 61

b) Be directed to all its personnel, including directors, executives, officials, employees, and any authorized representative, according to the responsibilities and activities performed by each one.

c) Have an approach, periodicity, and depth corresponding to the nature of their respective businesses, in response to their needs and considering their ML/FT risk.

Art. 53.- Minimum Elements of the Program The Training Program must contain, as a minimum, the following elements:

a) Written policies and procedures that will govern the Training Program both for its design and formulation, as well as for its periodicity, execution, and evaluation.

b) Establishment and approval of a specific and identifiable budget item within the general budget, designated annually to guarantee the execution of the Training Program.

c) Induction and sensitization for all new employees, within a reasonable period after being hired, in order to orient them regarding the ML/FT risks faced by the Supervised Entity, as well as the AML/CFT ISMS and its respective policies, procedures, and internal controls.

d) Orientation, according to levels and responsibilities, to directors, officials, executives, operational staff, and other employees, covering the legislation and regulations governing the ML/FT topic, the Code of Conduct, patterns, signals, or alert indicators, methods or techniques for early detection, analyzing, documenting, and reporting unusual and/or suspicious activities, as well as guidelines representing international standards and best practices on the matter.

e) Specialized training for employees in all areas of activity of the Supervised Entity, paying greater attention to activities that entail a higher level of risk. To this end, the training must be segmented according to each level.

f) Training on trends, typologies, schemes, and alert signals of ML/FT according to the nature of their respective businesses, for which they may rely on publications of specialized and reference international organizations and groups on the matter, as well as on examples of simulated cases or actually detected internally, guaranteeing in this case secrecy and confidentiality through the non-disclosure of the identity of the clients involved, but rather, starting from the observed typology for preventive training purposes.

g) Training on internal controls and procedures to monitor, detect early, and analyze unusual and/or suspicious operations, to document and report suspicious ones, on the prohibition of alerting clients, and on the preservation of records and files related thereto.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 62

h) Specialized and high-depth training for the ML/FT Prevention Manager and all personnel of the Administrative Support Structure, or Prevention Area or Unit, as applicable.

i) Special training for employees who are transferred to areas or functions within the Entity that entail different ML/FT responsibilities or risks.

j) Specific policies to be followed with personnel (officials and employees) who, in their individual evaluations after each training, do not obtain the minimum passing score or score that each Supervised Entity must establish.

Art. 54.- Statistics and Records on Training Each Supervised Entity must maintain updated statistics, records, controls, and supports on the application and development of its Training Program, all of which must be maintained for a minimum period of five years, particularly the following information:

a) Location, dates, program, and detailed content and instructors of each training.

b) Copies of the contract and curriculum of the instructor if the internal training is provided by an external professional or Firm.

c) Detailed attendance list identifying the date, name of the event, name and signature of the participant, and the area to which they belong within the Entity.

d) Copy in the personnel file of the certificates, certifications, and supports of the respective trainings received on the ML/FT topic, as well as of the individual evaluations of the participants when applicable.

CHAPTER IX INSTITUTIONAL CODE OF CONDUCT

Art. 55.- Incorporation of the AML/CFT ISMS topic a) Each Supervised Entity must expressly incorporate within its Institutional Code of Conduct the commitment of its Board of Directors, its highest authorities, and its general personnel, to conduct its business with honesty, integrity, and ethics, expressly stating in said Code the position of the Supervised Entity regarding ML/FT risks, promoting culture and sensitization to prevent them.

b) The Institutional Code of Conduct that includes the commitment on the AML/CFT topic must be approved by the Board of Directors and be made known, under signed acknowledgment of receipt, to all partners, directors, executives, officials, employees, and any authorized representative by the Supervised Entity. In the personnel file of each employee, it must be recorded that they have received, read, and understood the Code of Conduct.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 63

Art. 56.- Minimum AML/CFT Aspects of the Code of Conduct Every Supervised Entity must guarantee that its Institutional Code of Conduct contemplates and includes, as a minimum, the following:

a) Delineate the risks that ML/FT pose to the integrity, reputation, and stability of the Supervised Entity and of the employees themselves.

b) Include the declaration of principles adopted by the Supervised Entity for the prevention and early detection of ML/FT.

c) Express the responsibility and commitment of the Board of Directors, in the adoption of policies, controls, and guidelines that preserve the integrity of the Supervised Entity and its employees on this topic.

d) Express the legal and economic consequences that ML/FT risks would imply for the integrity, reputation, stability, continuity of business, and future of the Supervised Entity, as well as for its own directors, officials, and employees in general.

e) Establish internal sanctions, and their gradation, for non-compliance with the Institutional Code of Conduct on the specific topic of AML/CFT Prevention obligations.

f) Establish verification mechanisms to periodically ensure that this Code is duly communicated, known, and clarified in its content and scope.

CHAPTER X INDEPENDENT AUDIT ON THE AML/CFT ISMS

Art. 57.- Independent Audit The Supervised Entity must implement an Audit Program, internal and external, that guarantees the independent review of the compliance, effectiveness, and efficacy of the AML/CFT ISMS, and be carried out at least once a year, in all its areas of operation, including branches, subsidiaries, affiliates, representation offices, and other members of its Financial Group that operate within or outside the country, when the latter is applicable.

Art. 58.- Minimum Audit Functions The performance of the Independent Audit of the AML/CFT ISMS must be based on the risks inherent to the most significant and highest ML/FT risk activities of the Supervised Entity, must be developed by personnel with the appropriate technical skills and adequately trained on these risks; and as a minimum and insofar as applicable according to the industry to which it belongs, must comply with the following functions:

a) Internal Audit Functions: The Internal Audit program related to the AML/CFT ISMS, its scope, focus, and frequency, must start from an ML/FT Risk Matrix that Internal Audit must perform and update annually. The procedures and techniques of audit that the Internal Audit Unit employs for the review of ML/FT risks, must be contained in a clear and expressly stated manner in the respective Internal Audit Manual and must first adapt to the provisions of this Norm, related norms, and other instructions that the Superintendent may issue, and complementarily with what is established in generally accepted audit standards and international audit standards.

The Internal Audit Unit within its Annual Plan regarding the AML/CFT ISMS topic, will evaluate and review as a minimum the following, and of which it must inform the AML/CFT Prevention Committee and the Audit Committee, including results and recommendations that add value in strengthening the same:

i.- The compliance of the Entity and its directors, officials, and employees in their daily conduct, regarding the legal, regulatory, and Code of Conduct provisions on which the AML/CFT ISMS is based.

ii.- The compliance and correct application, including determining the sufficiency, effectiveness, efficacy, and results achieved derived from the implementation of the policies, procedures, and controls that support the AML/CFT ISMS and contained in the AML/CFT Manual, and propose recommendations for the improvement or modification thereof.

iii. The sufficiency, efficacy, gaps, and risks of the internal control systems of the AML/CFT ISMS.

iv.- The content, scope, coverage, frequency, and compliance of the Institutional Training and sensitization Program for the prevention of ML/FT risks, as well as the sufficiency of the budget allocation for its execution.

v.- The specialized monitoring procedures and systems, and determine if these allow the Entity to perform adequate, timely, and effective monitoring of transactions and all business relationships with its clients based on risk, to detect early, analyze, document, and report unusual and/or suspicious operations.

vi.- The management of the prevention of ML/FT risks in the different products, services, activities, clients, and geographic areas, all in attention to the higher level of risk.

vii.- Client samples to verify compliance with the legal and regulatory provisions applicable to ML/FT risks, as well as the Entity's policies and procedures for client knowledge and identification, conducting retrospective reviews and analyses of transactions in their accounts and/or business relationships to establish if there are unusual activities derived from the lack of correspondence between the transactional activities declared by the client in their Profile regarding their real activities and which have not been reported.

viii.- Point samples of clients and/or transactions or activities that have previously been detected, subject to alert signals, and investigated by the Entity, to which, after their documented review and analysis, it resolved that they were not

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 64

reportable, with the purpose of establishing the quality and effectiveness of the process followed and of the evidence on which it based its decision not to report them.

ix.- Evaluation of the quality of the measures implemented by the Supervised Entity to ensure the confidentiality, reliability, security, effectiveness, and timeliness of the process for the early detection and internal communication of unusual activities, as well as of the presentation and sending of Suspicious Transaction Reports (STRs) to the competent authority.

x. Managerial information systems, including reports on unusual and/or suspicious transactions.

xi.- Evaluation of the management of the AML/CFT Prevention Committee and the AML/CFT Prevention Manager in attention to their respective functions established in this Norm.

xii.- The adequacy of the methodologies, procedures, and tools implemented by the Entity for the elaboration and periodic update of its ML/FT risk matrix and diagnosis.

xiii.- The efficacy of internal controls for the prevention of ML/FT risks, proposed and designed in the stage prior to the launch of a new operation, product, or service.

xiv.- Evaluation of the Reports and Reports to the AML/CFT Prevention Committee presented by the AML/CFT Risk Manager, related to the results, limitations, or obstacles obtained in the implementation of the AML/CFT ISMS and present recommendations that add value in strengthening the same.

xv.- The Sufficiency and effectiveness of the institutional AML/CFT Action Plan and budget for the prevention of ML/FT risks and the results of its execution.

xvi.- The compliance with other aspects regarding ML/FT risks that the Superintendent determines and instructs.

b) External Audit Functions: The AML/CFT ISMS must be audited at least annually by an External Auditor or Firm of External Auditors, and independent of the Supervised Entity, that is duly registered with the Superintendence. For the execution of this External Audit, the Entity must guarantee that the following is carried out:

i.- Define previously, taking into account the qualified opinion of its AML/CFT Prevention Manager, the terms of reference with the minimum basic scopes required so that potential External Auditors present their technical offers that facilitate the comparability and quality analysis among bidders.

ii.- Carry out a written comparative analysis of the technical offers received in relation to the objectives and scopes determined in the terms of reference for the review of the AML/CFT ISMS.

iii.- The selected External Auditor must include in its scopes for this review, the terms of reference with the minimum basic scopes proposed in its technical offer and susceptible to expansion by the Supervised Entity, which will form part of the contract that will govern their services.

iv.- Require and obtain the resume with the evidence that allows knowing in advance the technical and specialized competencies on these risks of the External Auditor or the personnel of the Firm that will audit the management of ML/FT risks.

v.- In the scope of the terms of reference, in attention to its own risks, it must include as a minimum, the evaluation and review of the following:

v.a.- The effectiveness of the work of the Internal Audit Unit in relation to the AML/CFT ISMS.

v.b.- The compliance of the Entity with the minimum requirements of the laws and norms applicable for the prevention of ML/FT risks.

v.c.- The monitoring procedures, system, and reports, procedures for detection, investigation, analysis, and reporting of unusual and/or suspicious activities, as well as, of the computer systems and measures for the security and backup thereof.

v.d.- Through reasonable testing, the scope, quality, effectiveness, and efficacy of the AML/CFT ISMS, as well as whether the same adjusts to the Entity's risk profile.

v.e.- Through reasonable testing, the scope, quality, effectiveness, and efficacy of the procedures established for the management of record retention both in physical and electronic form required in this Norm.

v.f.- Through reasonable testing, the effectiveness of the role of the Board of Directors in the implementation of the AML/CFT ISMS, as well as, the effectiveness and timeliness with which directors are kept informed about the results and/or obstacles in its implementation.

v.g.- The compliance with the instructions and/or recommendations that on the AML/CFT prevention topic have been formulated by the Superintendent or the previous Internal and External Audits, prior to the date of the current Audit.

v.h.- The results achieved by the Entity in its AML/CFT prevention labor, determine its gaps, report on significant facts, and present the pertinent recommendations to adapt and strengthen the AML/CFT ISMS.

v.i.- The compliance with other aspects regarding ML/FT risks that the Superintendent determines and instructs.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 65

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 66

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 67

TITLE III PARTICULAR AND EXCEPTIONAL PROVISIONS

CHAPTER I FINANCIAL GROUPS AND CONSOLIDATED ML/FT RISK MANAGEMENT

Art. 59.- ML/FT Risk Management a) Supervised Entities that are part of a Financial Group must formulate and implement the AML/CFT ISMS on a consolidated basis at the Group level, complying as a minimum in what is applicable, with the following:

i.- ML/FT risk management must be applied on a consolidated basis by the Controlling Company or Responsible Coordinator of the Group, adapting it to the specific requirements of each member thereof, according to the applicable provisions of this Norm, according to the nature of business, sector, and country where they operate.

ii.- It is the duty of the Controlling Company or Responsible Coordinator of the Group, to ensure the existence and implementation at the Group level, of effective Systems and Procedures in accordance with the technology used by its members in the provision of the different products and services they offer according to their nature; to carry out on a consolidated basis the Monitoring of Accounts and Transactions of their clients, based on the ML/FT risk level. These Monitoring Systems must allow, at any time, to know the relevant information about clients, their accounts, and transactions, at least at the following levels:

ii.a.- Individually by each Supervised Entity member of the Financial Group.

ii.b.- At the level of the Local Financial Group in Nicaragua.

iii.c.- By Transborder Financial Group.

b) Each member of the Group must implement policies and procedures, according to the dispositions of their Boards of Directors, to exchange with other members of the Group the relevant information about their clients, accounts, and transactions when these maintain or wish to maintain business relationships with several members of the same, observing the legal provisions on security, secrecy, privacy, and confidentiality of the information.

c) When any member of the Financial Group operates in another country in which the legal and/or regulatory requirements for the prevention and detection of ML/FT differ from those established in Nicaragua, said member must apply the measures that result in the strictest among the different jurisdictions according to international standards. In the case that the legal requirements of other countries where some member of the Group operates prohibit or prevent the application of the AML/CFT ISMS, such situation must be communicated without delay to the Controlling Company or Responsible Coordinator of the Group and to the Superintendence.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 68

d) For the acceptance of the country in which institutions that are members of the Financial Group, including the Controlling Company, may be constituted or domiciled, or invest in financial institutions abroad; it will be conditioned, among other requirements, that said countries have laws, regulations, or other provisions oriented to prevent money laundering from illicit activities and terrorism financing.

Art. 60.- Internal Audit of the Controlling Company The Internal Audit Unit of the Controlling Company, as applicable, must incorporate in its Annual Work Plan, the evaluation of practices among members of the Financial Group, for compliance with the provisions established in the laws and norms on AML/CFT prevention according to the respective countries in which they operate.

Art. 61.- Consolidated External Audit to the Financial Group For the purposes of an integral, independent, uniform, and consolidated vision of the effectiveness and efficacy of the AML/CFT ISMS at the Financial Group level, the Supervised Entities that are members thereof must ensure that the External Auditor that carries out the Audit on the respective AML/CFT ISMS in each of them, is the same for all members of the Group.

CHAPTER II INSURANCE MARKET

Art. 62.- Applicability of the AML/CFT Norm in the Insurance Market a) To Insurance and/or Reinsurance companies, and other companies that operate in the Insurance Market provided for in special legislations; the provisions provided for in Titles I, II, and III (Chapter I) of this Norm are applicable; with the exceptions and specific particularities established in this Chapter, and in consideration to the nature and nature of their own businesses.

b) Regarding this Norm, Insurance Intermediaries, whether individual brokers, brokerages, brokerage societies, agents, agencies, and subagents; are only obligated to:

i.- Have an AML/CFT Manual based on which they must develop the following policies:

i.a.- KYC Policy consistent with those applied by the Insurance and/or Reinsurance companies with which they are linked.

i.b.- Policy on Archiving and Information Retention, available to the competent authority.

ii.- Develop a permanent Training Program on the AML/CFT prevention topic, which must include the obligation to receive the trainings to which they are summoned by the Insurance and/or Reinsurance companies with which they have business links.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 69 Art. 63.- Exceptions and Particularities Insurance and/or Reinsurance companies, and other companies operating in the Insurance Market provided for in special legislations: a) They must apply their PLD/FT SIPAR when it comes to transactions or commercial relationships with clients and beneficiaries involving the sale and placement of insurance contracts or policies in general. If, in addition to insurance, they provide other related products or services, they must also adjust and apply their PLD/FT SIPAR to these other businesses as authorized by law. b) They are exempt from constituting the PLD/FT Prevention Committee, whose functions in this case must be assumed, according to their nature, by the Audit Committee and/or the Risk Committee and/or the respective Board of Directors. c) At the formal request of the Supervised Entity, the Superintendent may authorize that the functions of the PLD/FT Prevention Administrator fall to an official who simultaneously holds another position within the same entity, provided that the following requirements are met: i.- That the Entity has a national payroll of fewer than 50 employees; or, as can be determined, said Entity has a small, reduced, or lesser-scale organizational structure, capital, funds, client portfolio, and volume of activities. ii.- That the PLD/FT POA, functions, objectives, responsibilities, and budget as PLD/FT Prevention Administrator, are clearly differentiated from the other tasks assigned to the same official according to their other position. iii.- That said other position and functions do not represent an obstacle or conflict of interest for the effective exercise of their work as PLD/FT Prevention Administrator. iv.- That the proposed official is not subject to the incompatibilities established for said position in this Norm. d) The Substitute for the PLD/FT Prevention Administrator may also simultaneously hold another position within the Entity, provided that this does not represent an obstacle or conflict of interest for the effective exercise of the substitution. e) The Supervised Entity, in its own interest to implement an effective PLD/FT SIPAR that corresponds to its PLD/FT risk profile, size, number of clients, volume, and complexity of its products and services, must consider establishing and providing an Administrative Support Structure for its PLD/FT Prevention Administrator. f) In the Insurance Market, the following provisions on CDD (Customer Due Diligence) established in this Norm do not apply: i.- Literal "d", numeral "iii" of article 8. ii.- Literal "l" of article 10.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 70 iii.- Literal "n" of article 10 in the case of Mandatory Insurance for Motor Vehicles established in the relevant law. g) When the insured acquires a policy on the occasion of a main contractual relationship with a banking entity or in "bank-insurance" operations, Insurance and/or Reinsurance companies may obtain relevant and updated information about the client from the bank, subject to what is provided in article 12, literal "h" of this Norm. This provision is without prejudice to the fact that each Supervised Entity, considered individually, is obligated to apply CDD to its clients in the course of their respective businesses. No entity may fail to comply with this responsibility on the argument that another entity has already done so. Art. 64.- Subsequent Identification and Verification a) Operators of the Insurance Market are exempt from the general principle of obligation to identify and verify the policy beneficiary prior to or during the validity of the contract. For purposes of their identification and verification, the beneficiary is considered to be the person designated in the policy by the insured, policyholder, or applicant, as the holder of the indemnity rights established in said document. b) Verification may be done subsequently, provided that: i.- The provisions of article 6, literal "l", and article 11, literal "g", of this Norm are complied with. ii.- The identification and verification is completed before any payment to the beneficiary under the policy, or before the date on which the beneficiary may exercise rights created or acquired under the policy. c) These exceptions may be applied in the following cases: i.- Policies for pension and retirement plans. ii.- Payment of insurance premiums before the application is processed and the relationship accepted, provided that the payment is not in cash. iii.- Contracting that does not include face-to-face interviews with the client at the time of establishing a relationship. Art. 65.- Intensified CDD Without prejudice to what is provided in this Norm in its general part for intensified CDD, all operators of the Insurance Market, including Insurance intermediaries, must gather additional information about the client according to their risk profile in the following situations: i.- Bearer Insurance Policies, which require payment to the bearer, or in cases where the rights to receive benefits or payments under the policy could be endorsed to other persons without the knowledge or authorization of the Insurance Company.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 71 ii.- Agreements, loans, or sales regarding or of the benefits under life insurance policies to other persons or companies that will be paid after the death of the insured. These policies or arrangements must be considered equivalent to endorsable policies under the previous clause. In these cases, the counterparty or buyer of the benefits and the beneficiaries thereof must be identified and verified. Art. 66.- Simplified CDD a) Without prejudice to what is provided in this Norm in its general part, all operators of the Insurance Market, including Insurance intermediaries, considering their own risks and by reason of their business, may apply a simplified CDD in the following cases: i.- In policies with annual premiums lower than or equal to one thousand United States dollars (U$ 1,000.00) or its equivalent in national currency or any other currency. ii.- In Mandatory Insurance for Motor Vehicles established in the relevant law. iii.- In policies for pension, retirement, and retirement plans, provided there is no surrender clause and the policy cannot be used as collateral. b) In the cases provided for in the previous literal, it will suffice to fill out the insurance application, as well as note the name, number, and type of identity document of the person contracting the insurance; having at hand the respective legal, official, valid, reliable, and unquestionable documents according to the laws of the matter. Art. 67.- Relationship of the Insurance and/or Reinsurance Company with Insurance Intermediaries. a) The PLD/FT SIPAR of Insurance and/or Reinsurance companies, and other companies operating in the Insurance Market provided for in special legislations, must contain specific policies, procedures, and controls to govern the relationship between them and their Insurance Intermediaries, and referred to, at a minimum, to the following aspects: i.- To be able to obtain information regarding the identity of clients and beneficiaries of policies and verify the same. ii.- To be able to obtain information about the purpose and expected nature of the relationship with the client or beneficiary. iii.- To be able to monitor the commercial relationship with High-Risk qualified clients. iv.- To be able to know and make recommendations to the PLD/FT Manual of Insurance Intermediaries, as well as to know the degree of compliance with the obligations that these have according to article 62, literal "b", of this Norm.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 72 b) Insurance and/or Reinsurance companies, and other companies operating in the Insurance Market provided for in special legislations: i.- Are the main and ultimate responsible parties for implementing their PLD/FT SIPAR, even if the contracting of policies with the client is carried out through Insurance Intermediaries, without prejudice to the responsibilities of the latter established in this chapter. ii.- Must develop a strict "Know Your Insurance Intermediary" policy in congruence with the "Know Your Customer's Customer" policy. iii.- Must not maintain business or working relationships with Insurance Intermediaries that are not authorized by the Superintendent and/or that do not comply with the obligations provided in literal "b" of article 62 of this Norm. iv.- Must include Insurance Intermediaries, regardless of the contractual nature linking them, in their training and awareness programs on the subject of PLD/FT Prevention. v.- Must make known to their Insurance Intermediaries the criteria they use to determine and apply differentiated CDD policies, including the additional requirements implemented in their intensified CDD policies based on their PLD/FT risk assessments. vi.- Must seek common and congruent strategies between their CDD policies and those developed by the Insurance Intermediaries. CHAPTER III SECURITIES MARKET Art. 68.- Applicability of the PLD/FT Norm in the Securities Market Participant operators in the Securities Market, whether natural or legal persons, such as Stock Exchanges, Securities Clearing Houses, Securities Compensation and Settlement Societies, Stock Brokers, Stockbroker Agents, and Investment and Securitization Fund Management Companies; must have the necessary means to allow them to carry out, in an adequate and efficient manner, the monitoring and control of what is provided by this Norm, of which the provisions provided in Titles I, II, and III (Chapter I) are applicable to them, with the specific exceptions and particularities established in this Chapter, and considering the nature and business of their own operations. Art. 69.- Exceptions and Particularities The following exceptions and particularities are established for the Securities Market: a) Issuers of Securities are not subject to this PLD/FT Norm, without prejudice to what is provided in special laws on the matter.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 73 b) Stockbroker Agents are only obligated to develop the "Customer Due Diligence" (CDD) policy, as instructed by the respective Stock Broker, which is ultimately responsible for having and executing its own PLD/FT SIPAR, including the permanent training it must offer to its Stockbroker Agents on the subject of PLD/FT Prevention. c) Stock Exchanges, based on their own supervision and regulation functions in the Securities Market according to the relevant law, must have their own PLD/FT SIPAR, and must apply CDD policies to Stock Brokers and their Agents, and other entities provided for; and furthermore, they must ensure that these comply with the requirements of this Norm insofar as applicable to them, including them in their training and awareness programs on the subject of PLD/FT Prevention. d) Participant operators in the Securities Market are exempt from constituting the PLD/FT Prevention Committee, whose functions in this case must be assumed, according to their nature, by the Audit Committee and/or the Risk Committee and/or the respective Board of Directors. e) At the formal request of the Supervised Entity, the Superintendent may authorize that the functions of the PLD/FT Prevention Administrator fall to an official who simultaneously holds another position within the same entity, provided that the following requirements are met: i.- That the Entity has a national payroll of fewer than 50 employees; or, as can be determined, said Entity has a small, reduced, or lesser-scale organizational structure, capital, funds, client portfolio, and volume of activities. ii.- That the PLD/FT POA, functions, objectives, responsibilities, and budget as PLD/FT Prevention Administrator, are clearly differentiated from the other tasks assigned to the same official according to their other position. iii.- That said other position and functions do not represent an obstacle for the effective exercise of their work as PLD/FT Prevention Administrator. iv.- That the official is not subject to the incompatibilities established for said position in this Norm. f) The Substitute for the PLD/FT Prevention Administrator may also hold another position within the Entity, provided that this does not represent an obstacle for the effective exercise of the substitution. g) The Supervised Entity, considering its risks, the size, volume, and complexity of its products and services, the number of clients, and according to its needs to implement the PLD/FT SIPAR; may optionally establish and provide an Administrative Support Structure for its PLD/FT Prevention Administrator.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 74 Art. 70.- Operational Control Stock Exchanges, Securities Clearing Houses, and Securities Compensation and Settlement Societies; must establish an alert system organized based on elements such as types of clients, markets, negotiated amounts, frequencies, and prices, which allow them to detect unusual behaviors or operations in the stock negotiations carried out and communicate this circumstance to the Stock Brokers and their Agents, through which they are effected, in order to make the corresponding clarifications and evaluations, and to present, as appropriate, the respective STR (Suspicious Transaction Report) to the competent authority. If the unusual activity detected is qualified as suspicious from the start, it will be the Entities mentioned at the beginning of this paragraph that must present the respective STR to the competent authority. CHAPTER IV GENERAL WAREHOUSES OF DEPOSIT MARKET Art. 71.- Applicability of the PLD/FT Norm in the General Warehouses of Deposit Market General Warehouses of Deposit, as credit auxiliaries; must have the necessary means to allow them to carry out, in an adequate and efficient manner, the monitoring and control of what is provided by this Norm, of which the provisions provided in Titles I, II, and III (Chapter I) are applicable to them, with the specific exceptions and particularities established in this Chapter, considering the nature and business of their own operations. Art. 72.- Exceptions and Particularities The following exceptions and particularities are established for General Warehouses of Deposit: a) They are exempt from applying the LD/LD SIPAR provided in this Norm, regarding the operations they carry out as Customs Deposits; without prejudice to the measures that the respective authority may instruct regarding this matter. b) They are exempt from constituting the PLD/FT Prevention Committee, whose functions in this case must be assumed, according to their nature, by the Audit Committee and/or the Risk Committee and/or the respective Board of Directors. c) At the request of each General Warehouse of Deposit, the Superintendent may authorize that the functions of the PLD/FT Prevention Administrator fall to an official who simultaneously holds another position within the Entity, provided that the following requirements are met: i.- That the Entity has a national payroll of fewer than 50 employees; or, as can be determined, said Entity has a small, reduced, or lesser-scale organizational structure, capital, funds, client portfolio, and volume of activities.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 75 ii.- That the PLD/FT POA, functions, objectives, responsibilities, and budget as PLD/FT Prevention Administrator, are clearly differentiated from the other tasks assigned to the same official according to their other position. iii.- That said other position and functions do not represent an obstacle for the effective exercise of their work as PLD/FT Prevention Administrator. iv.- That the official is not subject to the incompatibilities established for said position in this Norm. d) The Substitute for the PLD/FT Prevention Administrator may also hold another position within the Entity, provided that this does not represent an obstacle for the effective exercise of the substitution. e) The Supervised Entity, considering its risks, the size, volume, and complexity of its products and services, the number of clients, and according to its needs to implement the PLD/FT SIPAR; may optionally establish and provide an Administrative Support Structure for its PLD/FT Prevention Administrator. CHAPTER V REPRESENTATION OFFICES AND "SECOND-TIER" BANKS Art. 73.- Applicability of the Norm to Representation Offices Any Representation Office of a Foreign Financial Entity authorized by the Superintendent must have a PLD/FT SIPAR and its respective PLD/FT Manual, and comply insofar as applicable with what is established in the provisions provided in Titles I, II, and III (Chapter I) of this Norm, with the specific exceptions and particularities established in this Chapter, considering the nature and business of their own operations that they are authorized to carry out in Nicaragua. Art. 74.- Application of the PLD/FT SIPAR regarding its jurisdiction of origin a) When there are significant differences between the laws, regulations, norms, and measures on PLD/FT prevention applied by the head office of a Representation Office according to its jurisdiction of origin, and those that said Office must implement in Nicaragua; it must apply the measures that result in the strictest standards, in addition to the guidelines to be followed at the Financial Group level. b) Without prejudice to the previous provision, the PLD/FT SIPAR and the respective PLD/FT Manual of a Representation Office, in addition to being based on the PLD/FT risk matrices of its jurisdiction of origin; must also adjust to and comply with the Laws and Norms of Nicaragua.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 76 Art. 75.- Intensified CDD The Representation Office must apply Intensified CDD to activities and clients considered high risk, including loans or other investments when the guarantee consists of property, deposit accounts, or guarantees located or issued in or from abroad. Art. 76.- Exceptions and Particularities For Representation Offices of Foreign Financial Entities, the following exceptions and particularities are established: a) They are exempt from applying the provisions provided for the PLD/FT Prevention Committee, for the PLD/FT Prevention Administrator, and for the Administrative Support Structure; without prejudice to the fact that they must have their own PLD/FT Manual and execute the respective PLD/FT SIPAR insofar as applicable to them; in addition to maintaining fluid communication, coordination, and monitoring with the one acting as PLD/FT Prevention Administrator in their head offices, to which they are obligated. b) Only in the case of Representation Offices, the reports provided in this Norm and in the relevant law will be presented through the legal representative or principal executive accredited in Nicaragua by said entities. Art. 77. – "Second-Tier" Banks For the so-called "Second-Tier" Banks, which are supervised institutions authorized and dedicated to capturing resources through loans from international financial development institutions; the qualification of "Second-Tier" Bank will be granted by the Superintendent, for which the following exceptional treatment is established: a) This Norm does not apply to them in cases where the funds thus raised are invested or placed in loans for predetermined purposes to banks or other financial entities operating in Nicaragua under the supervision of the Superintendent. b) This Norm does apply to them insofar as pertinent, and with the exception of the provisions provided for the PLD/FT Prevention Committee, when the entities receiving the funds referred to in the previous literal are outside the supervision of the Superintendent. For this case, they must have their PLD/FT Risk Administrator under the same circumstances provided in this Norm for the Insurance, Securities, and Warehouses Markets; and they may also, optionally, establish and provide an Administrative Support Structure for said Administrator.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 77 CHAPTER VI SPECIAL REGIME FINANCIAL ENTERPRISES Art. 78.- Enterprises in Consolidated Supervision Entities that, according to banking law and for the purposes of the consolidated supervision developed by the Superintendent, are qualified as Special Regime Financial Enterprises; must comply with this Norm insofar as applicable to them and have and implement their respective PLD/FT SIPAR and Prevention Manual in attention to the business of their operations and to the weighting of their risks; without prejudice to what is provided in special laws and in regulations and instructions issued by the competent authorities. Art. 79.- Exceptions Special Regime Financial Enterprises are exempt from applying the provisions provided for the PLD/FT Prevention Committee; but they must have their PLD/FT Risk Administrator under the same circumstances provided in this Norm for the Insurance, Securities, and Warehouses Markets; and they may also, optionally, establish and provide an Administrative Support Structure for said Administrator. TITLE IV TRANSITIONAL AND FINAL PROVISIONS SINGLE CHAPTER Art. 80.- Modification and/or Inclusion of Annexes The Superintendent is empowered to modify and/or invalidate the Annexes of this Norm, as well as include others, as he deems necessary to strengthen his supervisory labor in the prevention of LD/FT risks.

Art. 81.- Gradualness for the application of some particular provisions of the present Norm

a) The following deadlines are established for the application of the provisions of the present Norm indicated below, as applicable to each Supervised Entity, counted from the entry into force of the same:

ArticlesRegulated MatterDeadline
6 (“g”)Prevention Committee for ML/FT3 months
6 (“f”), 46 and 49 (“d”)Administrative Support Structure, and the Substitute Administrator for Prevention ML/FT3 months
Annex 5Automated Submission of CTRs3 months
4 (“b”)SIPAR ML/FT Manual3 months
24ML/FT Risk Matrices9 months
6 (“p”)Implementation of Specialized Monitoring Systems12 months
16 (“ñ”, “ii”)Intensive CDD application for existing clients12 months
Chapter I, Title IIISIPAR ML/FT Application in Financial Group12 months

b) Except for the provisions indicated in letter “a” of this article, the rest will have full application from the entry into force of the present Norm.

Art. 82.- Repeals

The following provisions are repealed:

a) The Norm for the Prevention of Money Laundering and of Other Assets, (Resolution: CD-SIBOIF-197-2-MAR01-2002), published in La Gaceta, Official Diary, No. 71 of April 18, 2002, and its subsequent reforms; with the exception of its Chapter VI and its respective Annex, which will remain in force temporarily until the expiration of the deadline provided for in article 81 letter “a” of the present Norm regarding the Automated Submission of CTRs.

b) The Norm on Compliance Officers (Resolution: CD-SIBOIF-422-1-MAY23-2006), published in La Gaceta, Official Diary, No. 117 of June 16, 2006.

c) Article 16, letter “k”, numeral “4”, of the Norm on Internal Control and Audit (Resolution CD-SIB-155-3-ABR26-2001), published in La Gaceta, Official Diary, No. 116 and 118 of June 20 and 22, respectively, of 2001.

d) Any other provision or instruction that opposes or contradicts the present Norm, issued by the Superintendency through Norms, Resolutions and Circulars.

Art. 83.- Entry into Force

The present Norm will enter into force from its complete publication in La Gaceta, Official Diary.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 79

ANNEXES PLD/FT NORM

Annex 1: General concepts for the application of the PLD/FT Norm Annex 2: Formats for the Comprehensive Customer Profile (PIC) i.- For the Banks and Financial Institutions Market ii.- For the Insurance Market iii.- For the Securities Market iv.- For the General Warehouses Market

Annex 3: Alert Signals and Indicators i.- Common to all Supervised Entities ii.- Specific for the Banks and Financial Institutions Market iii.- Specific for the Insurance Market iv.- Specific for the Securities Market v.- Specific for the General Warehouses Market

Annex 4: Format and Instructions for completing, presenting and sending the Suspicious Transaction Report (STR) i.- Format for the STR ii.- Instructions for the presentation and submission of the STR

Annex 5: Manual and Format for the automated presentation of the Cash Transaction Reports (CTR) i.- Conceptual Aspects (Data Flow) ii.- Types of Submissions iii.- File Formats According to Submission Type iv.- SIBOIF Response Files v.- Annex Catalogs vi.- User Manual for Loading the Cash Transaction Report - AML Data vii.- Formats with their Instructions viii.- GNUPG Manual

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 80

Annex 1: General concepts for the application of the PLD/FT Norm

Pursuant to article 3 of the PLD/FT Norm and for its purposes, the following general concepts are established, which become part of the same:

  1. ML/FT Risk: Is the inherent risk that Supervised Entities have and permanently face by their very nature of business; if they are used, consciously or unconsciously, for Money Laundering, Goods or Assets; and for Terrorism Financing.

  2. Residual or Net ML/FT Risk: Is the level of ML/FT risk resulting after applying controls for its prevention and mitigation.

  3. ML/FT Associated Risks: Are the risks through which the ML/FT risk can materialize, being these: legal, compliance, reputational, operational, technological, personnel, audit and contagion risks.

  4. ML/FT Risk Factors: Are the circumstances and characteristics inherent, at a minimum, to clients, to products, to distribution channels and to jurisdictions, that raise the probability that the Supervised Entity is used, consciously or unconsciously, for Money Laundering, Goods or Assets; and for Terrorism Financing. These risk-generating factors allow determining, analyzing and constructing the respective ML/FT Risk Matrix.

  5. Risk Matrix: Is the analytical tool that each Supervised Entity must prepare and update periodically to determine its degree of exposure to ML/FT risk, and to determine the existing gaps between its current ML/FT Prevention programs, versus legal, regulatory and normative requirements, and in accordance with best practices, for the performance of Due Diligence in the knowledge of its clients, at its different levels of scaling (Enhanced, standard and simplified), and to establish or carry out the adaptation of the same, according to its own institutional risk exposure profile, supported by the results of the combination of risk factors.

  6. Records: Is the set of physical documentation that must be part of client files, as well as all digital information or other forms of electronic storage of information and data about clients and their operations, whether active, passive and fiduciary, and of all their business relationships with a Supervised Entity and which must be custodied and preserved for the legal period.

  7. High-Risk Distribution Channels. Are all those channels used by the Supervised Entity to operationalize and make effective for its clients access to the provision of the products and services it offers and for which it is authorized, through the use of technologies, agents or intermediaries, or other similar ones, which have the characteristic of facilitating anonymity by allowing their execution without physical or “face-to-face” contact with the person who actually contracts or makes use of them, or with the person who effectively carries out the operations, transactions or other business relationships, or said contact is minimized or not required.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 81

  1. High-Risk Countries, Jurisdictions and Geographic Areas. Those countries, jurisdictions and national or international geographic areas are considered as such, in which clients reside, or from or to which their operations are directed, and in whose financial transactions business relationships with the Supervised Entity intervene that merit special attention and enhanced due diligence for ML/FT prevention from it.

  2. Private Banking: Is a department or area especially designated within a banking institution, intended to provide special and more expensive services to wealthy individuals and within what the law authorizes it to provide to its clients, whose transactions tend to be marked by high confidentiality and attended by an employee in charge of their account.

  3. Owners or majority or significant partners: Natural or legal person that participates in the social capital of a legal person or commercial company with a percentage equal to or greater than 5% of its social capital.

  4. Politically Exposed Persons (PEP): Is any natural person identified at the beginning or during the course of the contractual relationship, who performs or has performed as a high-ranking public official, in their own country or abroad. It includes their closest family members, closely associated persons, their close collaborators and also, those persons who occupy first-level positions, belonging to any commercial company, business or other entity that has been organized by or for the benefit or in ownership of a high-ranking official or because they are associated with it, and those with whom they publicly maintain financial or commercial relationships. In addition, within the PEPs are included Political Parties and Organizations and embassies or diplomatic and consular representations.

  5. High-ranking public official: Is understood as such, those persons elected or not, who have or have been in charge of prominent public functions in their own country or abroad in the executive, legislative, electoral, judicial, municipal, administrative, diplomatic, military or police branches; as well as, prominent figures belonging to political parties; or high-ranking executives of companies belonging to the State. This concept does not incorporate individuals of medium or lower rank in the categories previously exposed.

  6. Close family members of a high-ranking public official: In this category are considered the parents, siblings, spouse, children and parents-in-law of such person and any person with whom they maintain permanent or de facto affinity relationships.

  7. Person closely associated with a high-ranking public official: Any person of whom it is known that they commonly maintain a close relationship with a high-ranking public official or legal person in which said official has a position of administrative or shareholding control, or, in any way, an economic interest in the same. It includes persons who are in a position to conduct significant financial transactions in the country and/or abroad for the benefit of the high-ranking official.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 82

  1. Close collaborators: Are those persons who, without being high-ranking officials, are commonly known to have a close relationship or link with a PEP, including those who are in a position to conduct significant financial transactions in the country and/or abroad for the benefit of this.

  2. Originating or Ordering Financial Institution: The national or foreign financial institution that receives the order for a fund transfer from a person who is not another national or foreign financial institution.

  3. Intermediary Financial Institution: The national or foreign financial institution that participates in any intermediate element of the process/chain of fund transfers/telegraphic transfers but that is neither the originating institution nor the beneficiary.

  4. Beneficiary Financial Institution: The national or foreign financial institution that pays or credits the fund transfer order/telegraphic transfer to the beneficiary person who is not a national or foreign financial institution.

  5. Source of funds: Economic, productive, industrial, financial or labor activity that constitutes the legally accredited source that originates the funds or monetary resources that a client intends to place or manage in or through a Supervised Entity.

  6. Source of Wealth: Is the legal source or economic, productive, industrial, financial or labor activity that produces the wealth or monetary resources owned by a natural or legal person.

  7. Source of Funds: Geographic place, company, person or institution from where the funds come.

  8. Physical presence: Financial Entities that have representation, management and administrative structure, located and domiciled within the territory of the country where they are registered and authorized.

  9. Notoriously public persons: Are all those natural persons who, in view of their present or past political position, or by their connotation or current public or private position, economic, social or of any other nature, are in a position to influence or obtain treatment or dispensations in the treatment and compliance with requirements and application of due diligence measures that, under normal or equal conditions with other persons who do not have or have not had those qualities, could not obtain in their commercial or business relationships with the entities of the supervised financial system.

  10. Products and services: Are all operations that legally the supervised entities are authorized to provide to their clients and users through the celebration of a contract or document that accredits the provision of the service.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 83

  1. Client: Are all natural (physical) or legal (moral) persons, national or foreign, with whom the Supervised Entity establishes or maintains, habitually or occasionally, a contractual relationship or business relationships of a financial, economic or commercial nature under any modality, whether in the scope of the business, products or services it offers to the public as it is legally authorized to do so; or for the obtaining or supply of products or services that it requires for its normal functioning. In this concept are included the beneficial owners, as well as, the persons on whose behalf or in whose name the relationship is established by professional intermediaries, and any person or entity linked to a financial transaction.

  2. Regular Client: Is any person who establishes a contractual or business relationship with the Supervised Entity with a character of permanence, habituality, recurrence or successive tract.

  3. Occasional Client: Is any person who develops or carries out some type of relationship or business, or, in any way, uses the services provided by a Supervised Entity, whether only once or in an occasional non-recurring manner.

  4. Unsafe Practices: Are all those practices, behaviors and ways of operating that contravene the most elementary principles of ethics and sound prudence, as well as, strict adherence to the laws and norms of the matter, and to their own internal policies and procedures for the handling of banking and financial activities to the detriment of the Entity that leads to raising its ML/FT risk level.

  5. Users: Are those natural or legal persons to whom, without necessarily being their clients, the Supervised Entities provide their services.

  6. Beneficial Owner: Are all those natural or legal persons who, without being or not having the condition of clients of the Supervised Entity, are the final owners or recipients of the resources, securities or goods object of the contract or business relationship, and/or who are authorized or empowered to dispose of them, including those who exercise final effective control over a legal person.

  7. Legal Beneficiary: Are those depositaries established by banking law for depositors constituted by natural persons.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 84

Annex 2: Formats for the Comprehensive Customer Profile (PIC) i.- Banks and Financial Institutions Market

A.- Format: “Comprehensive Customer Profile” FOR NATURAL PERSON (PIC-N)

I Name of the Account Holder Client II Opening Data

  1. Start date of the relationship 2. Branch
  2. Unique client number assigned by the entity

III Type of Operation: 1. Demand Deposit 2. Savings Deposit 3. Time Deposit 4. Loan 5. Credit Line 6. Credit Card 7. Fiduciary Operations 8. Other (specify)*

*____________________________

IV Personal Data (Complete with the data of the account holder. In the case when the account holder is a minor or incapacitated, complete with the data of the tutor or legal representative of this)

  1. First Name 2. Second Name
  2. First Surname 4. Second Surname
  3. Names by which they are known socially and publicly
  4. Marital Status 7. Sex Male Female
  5. Number of Dependents
  6. Date of Birth 10. Country of Birth
  7. Country of Nationality 12. Country of Residence
  8. Home Address
  9. Municipality 15. Department

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 85

  1. Telephone 17. Cell Phone 18. Fax 19. Email

V Identification Means


  1. Type 2. Date and country of issue 3. Number 4. Registration No. 5. Expiration Date

VI Data on economic activity or employment

  1. Category Employee Own Business Student Housewife Retired Other (specify)___________________
  2. Occupation 3. Profession or Trade 4. Seniority
  3. Name of the workplace 6. Address
  4. Telephone 8. Fax 9. Coverage (in case of own business)
  5. Work email 11. Work Website
  6. Description of the economic activity of the workplace
  7. Postal Code of the workplace
  8. Monthly income equivalent to: Less than US$300 US$301 – US$500 US$501 – US$1,000 US$1,001 – US$2,000 US$2,001 – US$3,000 US$3,001 – US$5,000 US$5,001 – US$7,500 US$7,501 – US$10,000 Greater than US$10,000

VII Data for spouse or stable union First Name Second Name First Surname Second Surname Home Address Home Telephone Cell Phone Personal Email Profession Current Occupation Name of the workplace Address of the workplace

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 86

Work Email Work Website Work Telephone Fax Work PO Box Monthly Salary

VIII CDD Qualification High Medium Low

IX.- Legal documents required for Economic Activity (in case of own business): Type of document Issued by Date of Issue Expiration Date

X References Data of Reference (1) Names: Surnames: Home Address: Home Telephone: Cell Phone: Place of work: Work Telephone: Type and No of identification: Time knowing the reference: Name of verifier: Date and time of verification: Verifier's Signature: Summary of verification:

Data of Reference (2) Name: Surnames: Home Address: Home Telephone: Cell Phone: Place of work: Work Telephone: Type and No of identification: Time knowing the reference: Name of verifier: Date and time of verification: Verifier's Signature: Summary of verification:

XI Information About the Account (must be filled for all accounts the client has)

  1. Account number 2. Account type 3. Initial Deposit

  2. Opening date 5. Account signers 6. Status

  3. Source of funds Fund Transfer Salary Loan Sale of assets

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 87 Savings Inheritance Remittance Business Dividends Donation Others* _______________ Explain: 8. Purpose of the account Income Savings Income from sale / rental Staff / supplier Personal Expenses Others* ____________ Explain:

XII Accounts with other Financial Institutions Institution Type of Account Currency Average Amounts

XIII.- Expected Monthly Activity (must be filled for each of the accounts the client has)

XIV.- Place and date of filling out this Profile:.................................................................. “I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile”.


Client Signature Account Officer / Business Executive Branch Manager or Authorized Official

XV.- Update History (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the Client's Physical File). Account No Account Type Currency No of Transactions Debits No of Transactions Credits Average Amount Debit Average Amount Debit Average Balance

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 88

B.- Format: “Comprehensive Customer Profile” FOR LEGAL PERSON (PIC-J)

I Name of the Account Holder Client II Opening Data

  1. Start date of the relationship 2. Branch
  2. Unique client number assigned by the entity

III Type of Operation: 1. Demand Deposit 2. Savings Deposit 3. Time Deposit 4. Loan 5. Credit Line 6. Credit Card 7. Fiduciary Operations 8. Other (specify)*

*________________________

IV Data of the Legal Person

  1. Trade Name 2. Commercial Name
  2. Other names used according to its constitutive documents:
  3. RUC Number
  4. Name of the Legal Representative or Attorney
  5. Type and Number of identification of the legal representative:
  6. Board of Directors
  7. Identification of Partners, Directors and Administrators (mentioning the positions held)
  8. Date of Constitution 10. Country of Constitution
  9. Date of Registration in Competent Registry
  10. Headquarters Address Municipality Department Country

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 89

  1. Address and country of branches
  2. Telephone 15. Fax 16. Email 17. PO Box
  3. Website

V Data on economic activity

  1. Corporate Object:
  2. Geographic area of business activity (coverage) Local National Regional (C.A.) International
  3. Business Activity Industrial Services Agricultural Commerce Tourism Others (explain)
  4. Profile of operations Detail Wholesale
  5. Identification of the geographic regions in which it operates
  6. Description of the economic activity of the legal entity
  7. Annual Sales
  8. Main clients, suppliers and providers (identity and address)
  9. Detailed description of the profile of operations to be carried out in Nicaragua (only for legal persons constituted and domiciled abroad)

VI Risk Qualification High Medium Low

VII.- Information required to operate according to its activity: Registering Entity Type of Registration Registration Date Expiration

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 98 VIII References Referent Data (1) Name: Address: Home Phone: Mobile: Place of work: Work Phone: ID Type and No: Time knowing the referent: Verified by: Date and time of verification: Verifier's Signature: Referent Data (2) Name: Address: Home Phone: Mobile: Place of work: Work Phone: ID Type and No: Time knowing the referent: Verifier's Name: Date and time of verification: Verifier's Signature: Verification Summary: IX Information About the Account (must be filled for all accounts the client holds)

  1. Account Number 2. Account Type 3. Initial Deposit

  2. Opening Date 5. Account Signatories 6. Status

  3. Source of Funds Fund Transfer Salary Loan Sale of assets Savings Inheritance Remittances Business Dividends Donation Others* ___________________ Explain:

  4. Purpose of the Account Income Savings Income from sale / rental Payroll / Supplier Personal Expenses Others*______________

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 91 Explain:

X Accounts with Other Financial Institutions Institution Account Type Currency Average Amounts Date

XI Expected Monthly Activity (must be filled for each of the accounts the client holds) Account Number Account Type Currency Number of Transactions Debits Number of Transactions Credits Average Amount Debit Average Amount Debit Average Balance

XII.- Place and date of completion of this Profile:.................................................................. "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile."


Signature Client Representative/Legal Entity Accounts Officer / Business Executive Branch Manager or Authorized Official XIII History of updates (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the physical Client File).

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 92 C.- Format: "Customer Profile" FOR SIGNATORY: (PIC-F) I Name of the Account Holder Client II Personal Data of the Signatory

  1. First Name 2. Second Name
  2. First Surname 4. Second Surname
  3. Names by which they are known socially and publicly
  4. Marital Status 7. Sex Male Female
  5. No. of Dependents 9. Date of Birth

  1. Country of Birth 11. Nationality 12. Country of Residence
  2. Home Address
  3. Municipality 15. Department
  4. Phone 17. Mobile 18. Fax 19. Email III Identification Means

  1. Type 2. Date and country of issue 3. Number 4. NO of Registration 5. Expiration Date IV Data on economic activity or employment
  2. Category Employee Own Business Student Homemaker Retiree Others (specify)______________
  3. Occupation 3. Profession or Trade 4. Seniority
  4. Name of workplace 6. Address
  5. Phone 8. Fax 9. Coverage (of the business it represents)
  6. Work email 11. Work Website
  7. Description of the company's activity
  8. Postal Code of the workplace
  9. Monthly income equivalent to: Less than US$300 US$301 – US$500 US$501 – US$1,000

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 93 US$1,001 – US$2,000 US$2,001 – US$3,000 US$3,001 – US$5,000 US$5,001 – US$7,500 US$7,001 – US$10,000 Greater than US$10,000 V References Referent Data (1) Name: Address: Home Phone: Mobile: Place of work: Work Phone: ID Type and No: Time knowing the referent: Verified by: Date and time of verification: Verifier's Signature: Referent Data (2) Name: Address: Home Phone: Mobile: Place of work: Work Phone: ID Type and No: Time knowing the referent: Verifier's Name: Date and time of verification: Verifier's Signature: Verification Summary: VI.- Place and date of completion of this Profile:.................................................................. "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile."


Signature of the Client Accounts Officer / Business Executive Branch Manager or Authorized Official VII History of updates (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the physical Client File).

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 94 D.- Format: "Customer Profile" FOR CLIENT REPRESENTATIVE: (applicable only in case the representative is not also a signatory) (PIC-R) I Name of the Account Holder Client II Personal Data of the Representative

  1. First Name 2. Second Name
  2. First Surname 4. Second Surname
  3. Names by which they are known socially and publicly
  4. Marital Status 7. Sex Male Female
  5. No. of Dependents 9. Date of Birth

  1. Country of Birth 11. Nationality 12. Country of Residence
  2. Home Address
  3. Municipality 15. Department
  4. Phone 17. Mobile 18. Fax 19. Email III Identification Means

  1. Type 2. Date and country of issue 3. Number 4. NO of Registration 5. Expiration Date IV Document accrediting the client's representation Document Type Issued by Issue Date Country of Issue

V Data on the economic activity or employment of the representative

  1. Category Employee Own Business Student Homemaker Retiree Others (specify)______________
  2. Occupation 3. Profession or Trade 4. Seniority
  3. Name of workplace 6. Address
  4. Phone 8. Fax 9. Work email
  5. Work Website 11. Description of the company's activity
  6. Postal Code of the workplace 13. Monthly income equivalent to:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 95 Less than US$300 US$301 – US$500 US$501 – US$1,000 US$1,001 – US$2,000 US$2,001 – US$3,000 US$3,001 – US$5,000 US$5,001 – US$7,500 US$7,001 – US$10,000 Greater than US$10,000 VI References for the representative (applicable only in case of recently constituted legal entities) Referent Data (1) Name: Address: Home Phone: Mobile: Place of work: Work Phone: ID Type and No: Time knowing the referent: Verified by: Date and time of verification: Verifier's Signature: Referent Data (2) Name: Address: Home Phone: Mobile: Place of work: Work Phone: ID Type and No: Time knowing the referent: Verifier's Name: Date and time of verification: Verifier's Signature: Verification Summary: VII.- Place and date of completion of this Profile:.................................................................. "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile."


Signature of the Client Representative Accounts Officer / Business Executive Branch Manager or Authorized Official VII History of updates (each update must indicate its date, be signed by the persons related in the previous point who intervene, keeping a copy in the physical Client File).

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 96 ii.- Insurance Market Format: "Customer Profile" A.- FOR INSURED - NATURAL PERSON A.- Full name of the policyholder, according to identity card: First Surname Second Surname Names B.- Type of operation: Insurance Surety Line Credit C.- Personal data: complete with the policyholder's data.

  1. ID Number:_________________________________________________________________ Residence ID Number (For Foreigners):_______________________________________
  2. Sex: Male Female
  3. Marital status:______________ 4) Date of birth:5)Nationality_
  4. Maiden Name:________________________________________________________________
  5. Home Address:_____________________________________________________________
  6. Phone:________9)Mobile:____10)Fax:11)Email: D.- Data on the economic activity or employment of the policyholder:
  7. Employee Owner Student Homemaker Other:___________
  8. Occupation:____________________ 3) Position or Title:______________________
  9. Name of the Company:________________________________________________________________ 5) Address of the company:_______________________________________________________________
  10. Phone:_____________________ 7) Fax:____________________
  11. Monthly Income____________________________________________ E.- Information regarding the insurance:
  12. Policy: New Renewal
  13. Branch: Life Accident Health Vehicle Fire Surety Miscellaneous

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 97 3) Source of funds for the payment of the premium: Salary Inheritance Savings Company Others (explain):_______________________ 4) Sum Insured in: Cordobas Dollars Other 5) Insurance with other insurers: Life Accident Health Vehicle Fire Surety Miscellaneous Name of the Insurer___________________________________________________________ "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile." Client Signature Insurer Signature Date://200___

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 98 Format: "Customer Profile" B.- FOR INSURED - LEGAL PERSON A.- Full name of the policyholder (representative according to identity card): First Surname Second Surname Names B.- Type of operation: Insurance Surety Line Credit C.- Data of the insured entity:

  1. Name of the company or legal entity:_________________________________________________
  2. RUC Number:_____________________________________________________________________
  3. Name of the legal representative or attorney:____________________________________________
  4. ID Number of the Legal Representative:____________________________________________ Residence ID Number (For Foreigners):_____________________________________
  5. Address of the company or legal entity:________________________________________________
  6. Phone:7)Mobile_ 8)Fax:9)Email____ D.- Data on economic activity:
  7. Local National Central America International
  8. Main business activity: Industrial Services Agricultural Commerce Tourism Others. Explain:___________________________________________________________________ Monthly economic income________________________________________________________ E.- Information regarding the insurance:
  9. Policy: New Renewal
  10. Branch: Life Accident Health Vehicle Fire ..Surety Miscellaneous
  11. Source of funds for the payment of the premium: Own Supplier Buyer Others.Explain: _________________________________________________________________
  12. Sum Insured: Cordobas Dollars Other

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 99 5) Insurance with other insurers: Life Accident Health Vehicle Fire Surety Miscellaneous Name of the Insurer_______________________________________________ "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile." Signature of the Policyholder and/or Legal Representative Insurer Signature Date://200___

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 100 iii.- Securities Market Format: "Customer Profile" A.- FOR NATURAL PERSON 1 - Type of service provided by the entity: Bursary Custody Others 2 - Client's personal data First Surname Second Surname Names ID Passport Residence ID Other Place and date of birth: Nationality: Marital Status: Sex: Male Female Permanent home address: Phone Mobile Fax Email 3 - Client's professional and economic data Profession or Trade: Work address and postal code: Phone Fax Email Description of the company's activity: Approximate annual income obtained or generated by the client:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 101 Less than US$ 5,000 US$ 5001 – US$ 20,000 US$ 20,001 - US$39,000 greater than US$ 40,000 Source or origin of funds: Fund transfer from assets Salary Loan Sale Savings Inheritance Others (Explain) Expected monthly transactions: 4 – Commercial and personal references Commercial: Name of the entity: Contact Person:

Years with the entity: Phone: Address: Personal: Full name of the person: First Surname Second Surname Names Home Address: Phone: Place of work: Phone: Time knowing the referent: 5 – History of commercial relationship with any entity of the Financial System Name of the entity: Type of service received: Date: Account Number (if applicable):

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 102 6 - General Risk Profile Self-evaluation of your knowledge of the national and international securities market: Poor limited good professional General risk disposition: Conservative Moderate Risky Very risky Currency in which you need the cash income from your investments: Cordobas Dollars N/A Investment Horizon: One day to three months Three months to one year One to 5 years More than 5 years. Percentage of wealth you would be willing to invest: % "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile." Client Signature Brokerage Executive Signature Date://200___

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 103 Format: "Customer Profile" B.- FOR LEGAL PERSON 1 - Type of service provided by the entity: Bursary Custody Others 2 - Company identification data. Social name as described in the legal constitutive document: Registration data: RUC Number: Company Nationality: Domicile or headquarters: Name and country of subsidiaries and affiliates: Phones Fax P.O. Box Email. 3 - Company economic data Approximate annual income: Detail of the activities it is dedicated to and exact detail of the location where they execute their activities: In case of a foreign legal person not domiciled in Nicaragua, a detailed description of the profile of the operations to be carried out in Nicaragua must be requested: Company Size: 1 to 10 employees 11 to 50 employees more than 51 employees 4 – Commercial references Commercial: Name of the entity: Contact Person:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 104 Years with the entity: Phone: Address: 5 – History of commercial relationship with any entity of the Financial System Name of the entity: Type of service received: Date: Account Number (if applicable):

6 - General Risk Profile Self-evaluation of your knowledge of the national and international securities market: Poor limited good professional General risk disposition: Conservative Moderate Risky Very risky Currency in which you need the cash income from your investments: Cordobas Dollars N/A Investment Horizon: One day to three months Three months to one year One to 5 years More than 5 years. Percentage of wealth you would be willing to invest: % "I authorize the entity to verify, by any legal means, all the information I have provided for the purposes of the relationships or accounts that support this Profile." Signature of the Policyholder and/or Legal Representative Brokerage Executive Signature Date://200___

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 105 iv.- General Warehouses of Deposit Market Format: "Customer Profile"

  1. 2. DATE (dd/mm/yyyy):

2.1 First surname: Second surname: Maiden name: First name: Second name: 2.2 Date of birth (dd/mm/yyyy) 2.3 Nationality: 2.4 Type of identification document: Number: Place of issue: 2.5 Tax Identification Number (RUC): 2.6 Profession or trade: 2.7 Private address (specify exactly): 2.8 Business address or main office (specify exactly): 2.8 Phones: 2.9 Fax: 2.10 Email: 2.11 Main economic activity: CUSTOMER PROFILE GENERAL WAREHOUSES OF DEPOSIT FORM FOR STARTING RELATIONSHIPS PLACE: NATURAL PERSON CUSTOMER DATA

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 106 3. 3.1 Type of Society or Entity: 3.2 Full name or trade name: 3.3 Trade name: 3.4 Corporate Purpose: 3.5 Main economic activity: 3.6 Tax Identification Number (RUC): 3.7 Main office address (specify exactly): 3.8 Phones: 3.9 Fax: 3.10 Email: 3.11 Website: 3.12 Data from Public Deed of Constitution of the Entity: 3.13 3.14 Data from Registration in the Public Registry: No.: Folio: Volume: Book: Registry: 3.15 Data from Registration as Merchant: No.: Folio: Volume: Book: Registry: 3.16 If not a Company or Commercial Society, indicate the information from the Decree or similar document: 3.17 Registry Data: Registry Name No.: Folio: Book: Modifications to the Constitutive Pact (if more than one, detail on separate sheets): CUSTOMER DATA LEGAL PERSON Number: Date: Notary who authorized it: Deed No.: Date: Notary who authorized it:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 107 4. 4.1 First surname: Second surname: Maiden name: First name: Second name: 4.2 Date of birth (dd/mm/yyyy) 4.3 Nationality: 4.4 Type of identification document: Number: Place of issue: 4.5 Tax Identification Number (RUC): 4.6 Profession or trade: 4.7 Private address (specify exactly): 4.8 Phones: 4.9 Fax: 4.10 Email: 4.11 Power of Attorney or Notarial Act of Appointment: Notary who authorized it: Position for which appointed: 4.11.1 Nature of the Document: 4.11.2 Deed No.: 4.11.3 Registry Data: Registry Name: No.: Folio: Volume: Book: Registry: 4.12 For the purposes of this application, acts solely for the benefit of the entity described above: Yes No 4.13 If the answer is negative, provide information about the entity or person on whose behalf they act: 4.13.1 Full name of the person and/or trade name of the entity: 4.13.2 Complete address: 4.13.3 Date of Birth (dd/mm/yyyy): 4.13.4 Nationality: 4.13.5 Type of Identification Document: Number: Place of Issue: 4.13.6 Tax Identification Number (RUC): 4.13.7 Phones: Date: LEGAL REPRESENTATIVE OR ATTORNEY DATA OF THE CUSTOMER

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 108 5. 5.1 Type of merchandise to deposit: 5.2 Projected monthly average of merchandise to deposit for: Value of the merchandise: Quantity of merchandise (when possible to detail it): 5.3 Origin of the merchandise: 5.4 Destination of the merchandise to deposit: National: National Consumption: Imported: Export: 5.5 Merchandise 5.6 Merchandise Own: Taxed: Consignment: Free: In deposit: DATA OF THE MERCHANDISE TO DEPOSIT 6. 6.1 Banking (names of the banks): 6.2 Commercial (names of the companies): 6.3 Operations with the financial group: Bank Factoring Financial Company Off-Shore Exchange House Brokerage House Credit Card Insurance Company Surety Company Others (specify): BANKING AND COMMERCIAL REFERENCES Phones: Phones: 7. 7.1 Full names of the owners, partners or shareholders of the entity 7.2 Name, surnames, address and phones of members of the Board of Directors or Executive Board: 7.3 Names, surnames, address and phones of the Administrator, Manager or similar ENTITY ADMINISTRATION INFORMATION

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 109 8. 8.1 Activity details: 8.1.1 Average monthly income of the last 12 months: 8.1.2 Average monthly expenses of the last 12 months: 8.1.3 Average of inventories handled during the last two years: Value of the merchandise: Quantity of merchandise: 8.1.4 Estimated number of employees working in the entity: 8.2 Name, address, phones and website of main suppliers and clients: CLIENT ECONOMIC-FINANCIAL INFORMATION SUPPLIERS CLIENTS 9. All documents referred to in this form and others that the warehouse deems necessary for better identification of clients, PE water, electricity, phone receipts among others of the property occupied by the company or business must be detailed and attached. DOCUMENTS ATTACHED TO THE STARTING RELATIONSHIPS FORM 10. 10.1 I commit to informing the General Warehouse of Deposit immediately, when any change in the information contained in this form occurs. 10.2 I authorize the General Warehouse of Deposit to verify the information provided in this form. CLIENT OBLIGATIONS Signature of the client or their representative Name and signature of the person who filled out the form Employee Code Name and signature of the data verification responsible person and date of verification Employee Code Name and signature of the person who approves the operation and date of approval Employee Code

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 110 Annex 3: Alert Signals and Indicators Money Laundering, Asset Confiscation, and Terrorist Financing (ML/TF) accentuate the operational, legal, and reputational risks of the Entities that make up the Financial System, regardless of their scope in national criminal legislation. As part of the measures to prevent them, it is necessary to have lists that are illustrative, referential, and exemplary (not exhaustive), which guide Supervised Entities regarding the most common indicators, patterns, "red flags," or early alerts in which some activities linked to these phenomena could manifest in any of their phases.

Supervised Entities must detect and pay special attention to the operations and/or behaviors indicated below so that, in combination with other signals, factors, and criteria, they help remain alert and determine if they constitute operations suspected of being linked to ML/TF risks. And although each of these alert signals, under certain circumstances, may expose the financial institution to significant risks, they should not be considered suspicious by themselves, but must be analyzed to determine if they are suspicious and generate the respective Suspicious Operation Report (ROS). In this regard, it must be kept in mind that in many cases, the unusual operations detected are duly clarified by the institution and the client, and do not reach the category of suspicious.

Below are some Alert Signals and Indicators under the following scheme: First, those that can be considered common and general for all Supervised Entities, then those applicable mainly to Banking and Financial Intermediation Entities, then those referring to Insurance Entities, next those specific to Securities or Stock Exchange Entities, and finally some applicable to General Warehouses of Deposit as credit auxiliaries.

I.- Common to all Supervised Entities A) Regarding operations or clients with markedly unusual, and/or incongruent, and/or abnormal, and/or strange, and/or suspicious characteristics:

1.- Actual activity not congruent with the expected activity established in the Client's Comprehensive Profile, and/or that has no relation to the nature and size of the business or the client's occupation. 2.- The client's occupation or trade does not match the volume of funds and assets linked in the operations. 3.- The occupation declared by the person making the transaction does not correspond to the level or type of activity. For example, a student or an unemployed individual who receives or sends large amounts in electronic transfers, or who makes daily withdrawals of the maximum cash amount in different places in a wide geographic area. 4.- The same address for individuals involved in cash transactions, particularly when the address is also a business. 5.- Public information about the client's alleged involvement in money laundering, drug trafficking, terrorism, government corruption, fraud, tax evasion, and other serious crimes involving significant amounts of funds and assets. 6.- Account applicants or commercial relationships that are included in national or international lists designated as (or presumed) money launderers, drug traffickers, terrorists, corrupt government officials, tax evaders, fugitives wanted by authorities.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 111 7.- The administrators of the companies are very young people, with no history in the financial sector, who generally participate in other companies with similar characteristics. 8.- Companies that register high cash movements in their financial products, with characteristics of fragmentation, and that have no relation to the activity they develop. 9.- Regarding non-profit or charitable organizations, financial transactions do not seem to have a logical economic purpose or there seems to be no link between the activity declared by the organization and the other parties involved in the transaction. 10.- The existence of a large number of clients with inexplicable links. For example, non-profit organizations that make transfers between themselves and share the same address, the same managers, or staff. 11.- Clients who have high-risk businesses in also high-risk zones, and in which the Financial Entity has no branches. 12.- Increases in the amount of cash handled, without a corresponding increase in the number of transactions that have been reported. 13.- Significant movements of high-denomination banknotes, which has no relation to the area where the Financial Entity is located. 14.- Large increases in the use of small-denomination banknotes and the corresponding decrease in the use of high-denomination banknotes, without transaction reports having been filed. 15.- Persons who engage in informal trade activity from which no payments to a local or foreign supplier are evidenced, when the merchandise is foreign. 16.- Financial operations where it is observed that the client is being directed by another person, especially when the client seems to have no knowledge of the details of said operations. 17.- Clients whose companies offer extremely high profitability in a short period of time for the investments made in them. 18.- Clients who are executives or high-ranking officials of public entities who suddenly present changes in their standard of living, without any reasonable justification. 19.- Sudden and inconsistent changes in transactions and forms of handling money, funds, or assets. 20.- Clients with known liquidity deficiencies who, in a short time and without explanation, present a reactivation of cash flow in their accounts, products, and commercial relationships. 21.- Clients with financial problems whose partners, after making modifications in the incorporation documents, reactivate their business without the need to incur debt. 22.- Clients with significant changes in the financial movements of their companies that are not in line with the general behavior of the sector.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 112 23.- Clients who justify their asset increase or financial transactions by having won a prize, or the sale or assignment thereof in favor of a third party, without there being an official record of the payment thereof. 24.- Clients who, in short periods of time, justify their income with several prizes from lotteries and games of chance. 25.- Clients who deposit cash justifying winnings in games of chance with little recognition in the market. 26.- Clients with sudden asset increases that they justify in presumed prizes obtained abroad, but which are quickly transferred. 27.- Legal entities without physical presence or without history or antecedents of assets, economic, commercial, industrial, or financial, according to their corporate purpose, nor of their owners or founding partners, or these are not identifiable. 28.- Exporting or importing company that justifies its financial transactions with service provision contracts that present inconsistencies or have no relation to the service provided. 29.- Long-standing client who, without any justification, completely changes the behavior of its Accounts and commercial relationships with the Supervised Entity, and has high-risk economic activity and business location. 30.- Client who exhibits unusual indifference regarding the risks assumed and/or the commissions or other costs of the transactions. 31.- Client who, in a short period of time, appears as the owner of important and new businesses and/or assets. 32.- Clients whose financial statements reflect results very different from other companies in the same sector or with similar activity. 33.- Clients dedicated to, and/or promoters of, activities that are internationally considered vulnerable to facilitate and/or promote human trafficking, forms of slavery, prostitution, or human trade.

B) Regarding clients who try to avoid providing information, filling out records, or providing insufficient, contradictory, suspicious, or false information:

1.- Unsatisfactory explanations, in the opinion of the Financial Entity, regarding the significant variation of the client's operations with respect to their Profile. 2.- Clients who refuse to justify the origin of funds or assets for the operation or to update the basic information already provided at the time of renewing the commercial relationship. 3.- When opening an account and/or initiating a commercial relationship, the client refuses to offer the information requested by the Financial Entity, attempts to minimize the level of information offered, or offers false information or information that is difficult to verify. 4.- Companies that refrain from providing complete information about the purpose of the business, previous financial relationships, location, or names of directors and officials.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 113 5.- Clients who request to be exempted from providing or confirming certain information because they are recommended by another client, partner, executive, or official of the Supervised Entity. 6.- Reluctance to present information in accordance with the Financial Entity's requirements regarding the consular certification of foreign documentation. 7.- Clients who frequently change, without apparent justification, their data such as address, phone, occupation. 8.- Clients who force or try to force a Bank employee not to keep a report of any transaction on file. 9.- Rejection, attempt at bribery, or threats to Financial Entity officials to not fully complete information forms or to accept incomplete or false information. 10.- Inability to communicate with the client via the residential phone number provided to the Financial Entity. 11.- Request to open an account or credit relationship, without references, local address, identification, or other appropriate documents. 12.- Omission of documents on previous or present employment for a loan application. 13.- Non-existence of employment history in the past or present, but who frequently make money transactions in large amounts; 14.- Presentation of strange and suspicious identification documents, which the Financial Entity cannot verify promptly. 15.- Clients for whom there is no evidence of on-site verification of the commercial or industrial establishment that allows confirming their address and real existence. 16.- Businesses that do not wish to reveal details about their activities nor provide financial statements thereof. 17.- Businesses that present financial statements notably different from other businesses of similar activity. 18.- Inexplicable inconsistencies arise in the client identification or verification process, for example, regarding the current or previous country of residence, the country that issued the passport, the countries visited according to what the passport says, and the documents presented to confirm the name, address, and date of birth. 19.- Commercial relationship detected as having been opened or initiated with false or altered data and documents, or of dubious authenticity. 20.- Local or international operations in which unknown intermediaries or those with few references in the field act. 21.- Clients who register the same address and/or phone number of other people with whom they have no apparent relationship.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 114 22.- Natural or legal persons who demonstrate great economic solvency and yet find it difficult to obtain or provide information about commercial references or co-signers when filling out the linkage and information forms. 23.- Persons who fill out the linkage or information forms with illegible or "deceptive" handwriting, difficult to verify. 24.- Persons who show reluctance or annoyance when asked for adequate identification or the mandatory completion of certain information forms. 25.- Persons who appear nervous, doubt in their answers, and/or consult data they have written down, when asked for information required to initiate the commercial relationship. 26.- Natural or legal persons, who act as agents or licensees of money remitting entities, who demonstrate great economic solvency and yet find it difficult to obtain or provide information about commercial or financial references when filling out the linkage forms. 27.- Any transaction in which a third party participates whose name is not revealed or that involves anonymous participants. 28.- Operations in which the client does not reveal possessing financial conditions for the operation to be carried out, configuring the possibility of not operating in their own name, but as an agent for a hidden principal, being reluctant to provide information regarding said person or entity. 29.- Client who refuses or suspends a transaction when asked for information regarding the origin of the funds or the goods or merchandise involved. 30.- Any individual who pressures or attempts to pressure to not present the background required to carry out a transaction. 31.- Companies that request payroll payment services through accounts or in cash in the name of their employees, and who refuse or do not accredit their registration as an employer before the corresponding Social Security authority nor data on billing for the retention of their employees' contributions and paid to Social Security.

C) Regarding transactions linked to risky, non-cooperative, or cause-for-concern jurisdictions:

1.- Sending and receiving international transactions to or from risky jurisdictions. 2.- Clients who acquire financial products of significant amounts, whose residence or business domicile is located in tax havens or whose corporate purpose is "offshore" operations. 3.- Successive transactions within a brief period of time, by electronic transfers to places that generate specific concerns, for example, countries, jurisdictions, or territories designated or qualified by national authorities or by the FATF as non-cooperative, of concern, or High Risk. 4.- Commercial relationships with persons from countries where the FATF Recommendations are not applied or are not applied sufficiently.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 115 5.- The Client obtains a credit instrument or commits to commercial transactions involving the movement of funds to and from risky jurisdictions when there are illogical business reasons to deal with those jurisdictions. 6.- A business account through which a large number of cable and electronic transfer receipts and sendings occur, and through which they appear incompatible with the business or other economic purposes. 7.- The use of multiple accounts to collect and then channel funds to a small number of foreign beneficiaries, both individuals and businesses, particularly when these are in places of concern or risk. 8.- The opening of accounts or the initiation of commercial relationships with institutions belonging to risky or non-cooperative jurisdictions. 9.- Successive deposits, in a short time, followed by a transfer of funds, particularly to, or through, a risky or non-cooperative place. 10.- Sending or receiving funds by international transactions to risky jurisdictions. 11.- Funds generated by a business that belongs to individuals of the same origin or linkage of several individuals of the same origin, from countries that generate specific concern, acting in the name of similar types of businesses. 12.- Transactions involving currencies, followed within a brief period of time, by electronic transfers to places that generate specific concerns. 13.- A commercial account through which a large number of electronic transfers are made from and to the outside, and for which there does not seem to exist a logical commercial or other economic purpose, particularly when this activity is carried out through or from, places that generate concern. 14.- Use of multiple accounts to collect and then channel funds to a small number of foreign beneficiaries, both individuals and businesses, particularly when these are located in places that generate concern. 15.- Opening of accounts of financial institutions from places that generate concern. 16.- Sending or receiving funds via international transfers from or to places that generate concern. 17.- Funds generated by a business that belongs to individuals of the same origin or linkage of several individuals of the same origin, from countries that generate specific concern, acting in the name of similar types of businesses. 18.- The presence of foreign directors of a non-profit organization, particularly in combination with the sending of large sums of money to the country of origin of said directors, and especially if the destination is a high-risk jurisdiction. 19.- Clients presented by a branch, subsidiary, or Foreign Entity, based in countries or territories considered "tax havens" or non-cooperative by the FATF.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 116 D) Regarding strange situations or behaviors of executives, officials, employees, representatives, agents, and intermediaries of Financial Entities:

1.- Executives, officials, or employees who repeatedly omit the preventive or due diligence acts to which they are obligated. 2.- Executives, officials, or employees who use or lend their own home address to receive client documentation. 3.- Executives, officials, or employees who, without reasonable justification or relation to the nature of their functions, personally carry out, in their name or through their accounts, transactions or operations of clients. 4.- Executives, officials, or employees who have a lifestyle or carry out financial and investment transactions that do not correspond to the amount of their known income. 5.- Executives and officials who refuse or in any way prevent the general staff of the entity or some particular positions from taking their restful vacations. 6.- Officials or employees who repeatedly refuse to take vacations. 7.- Officials or employees who show a sudden favorable and expensive change in their economic lifestyle, without a clear and reasonable justification. 8.- Officials or employees reluctant to accept changes, promotions, or advancements in their work activity, without a clear and reasonable justification. 9.- Officials or employees who present a broad, unexpected, sudden, and/or unusual growth in their operations or sales. 10.- Officials or employees who frequently process operations with exceptions for certain clients or users. 11.- Officials or employees who avoid certain internal controls or approvals established for certain transactions, financial products, or services. 12.- Officials or employees who frequently incur errors, discrepancies, or inconsistencies, and their explanations are insufficient or inadequate. 13.- Officials or employees who omit the verification of the identity of a person or do not confront the data with the records supplied in the forms or databases of the entity, as they have assigned such functions. 14.- Officials or employees who prevent other colleagues from attending to certain clients or users without an apparent justification. 15.- Officials or employees, mainly commercial advisors, who are repeat offenders in partially documenting or supporting the information or transactions of a client or user, without a clear and reasonable justification. 16.- Officials or employees, mainly commercial advisors, who frequently attend to the same client or user to whom they appear not to know.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 117

17.- Officials or employees, primarily commercial advisors, who attend to certain customers in a preferential, exclusive, and permanent manner, or exempt them from certain controls, with arguments such as: "he is quite well known", "he is referred by another entity", "he only trusts me", "I advise him on all his business" or similar.

18.- Officials or employees who frequently receive gifts, invitations, favors, or other presents from certain customers or users, without clear and reasonable justification, or without being authorized by the entity's policies or codes of conduct.

19.- Officials or employees who frequently and without clear and reasonable justification, absent themselves from their workplace, remain in the office after normal hours, or attend outside normal working hours.

20.- Repeated non-compliance with internal LD/FT (Money Laundering/Terrorism Financing) prevention rules.

II.- Specific to the Banking and Financial Market

A) Regarding Liabilities and Deposits:

1.- An account whose expected activity, according to the Customer's Comprehensive Profile, is not congruent with its actual activity.

2.- An account whose volume and frequency of transactions, such as withdrawals, check deposits, payment orders, or other instruments, do not relate to the nature and size of the business.

3.- An account with a manifest incongruence between the apparent source of funds and the amount thereof. For example, funds raised or transferred by a non-profit organization in the case where large sums of money apparently come from communities with a very modest standard of living, or the case of lack of donor contributions.

4.- The opening of multiple Accounts by the same person, in which numerous small deposits are made, which, collectively, do not correspond to the client's expected income.

5.- Deposit of cash, checks, or monetary instruments that are atypical or incongruent with the income or activities normally carried out by the depositor.

6.- An account that has frequent transactions with high amounts or large volume of deposits in cash and in checks, payment orders, transfers, and other negotiable instruments; but which do not relate to the real income and/or the type of business of the client.

7.- Accounts of the same person in which deposits are made in small amounts, but which, when added up, are disproportionate to the expected and/or declared income of said account holder.

8.- An account of a recently constituted entity, in which a higher level of expected deposits is made compared to the income of the entity's founders and/or compared to entities whose businesses or activities are similar.

9.- Accounts that receive funds from activities or businesses, but whose movements and speed of rotation are unusual, are outside the parameters of normality, or do not relate to the current situation the business is going through in the market in which the account holder operates.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 118

account holder. For example, individuals who claim that the large sums moved in the Account come from certain crops, when in reality the product is depressed in the national or international market; or conversely, claim a lack of movement in the Account due to a bad market situation when in reality it is not so.

10.- Companies whose Accounts have movements at a level of sales that does not relate to the economic capacity and consumption of the population in the area.

11.- Resident foreigner, opens an account with a cash deposit from another local bank, however the local bank informs that this person has not been their client.

12.- An inactive account containing a minimum sum, which suddenly receives a deposit or a series of deposits followed by daily cash withdrawals, which continue until the transferred sums have been withdrawn or removed completely.

13.- An inactive business account, notwithstanding the account holder carries out frequent exchange counter operations and purchase of consignment instruments in foreign currency, a situation that is not adequately justified.

14.- A regional account in a personal name with little or no activity during certain periods of time but which occasionally receives deposits from abroad from natural persons for high sums of money without a reason congruent with the purpose of the Account.

15.- An account that receives relevant periodic deposits and remains inactive during other periods, then is used in the creation of a financial history through which fraudulent activities can be carried out.

16.- Deposits of high volumes of checks for smaller amounts, drawn abroad that do not relate to the declared purpose for the management of the Account.

17.- Opening of an Account in a branch different from the domicile despite having a closer branch, in which a transfer from abroad is received for the sale of shares abroad, and the economic activity is not compatible with the amount of the international transfer received.

18.- Deposits of funds in several Accounts, generally in amounts below the reporting limit, which are then consolidated in another Account and transferred out of the country.

19.- An Account from which telegraphic transfers are sent and received without apparent commercial reason or consistency with the client's business history.

20.- Use of multiple personal and commercial accounts or accounts of non-profit or charitable organizations, to collect funds and then channel them, immediately or after a brief period of time, to a small number of foreign beneficiaries.

21.- Accounts where payment orders are deposited by mail with strange signs or symbols.

22.- Significant cash deposits in low-denomination bills and without clarification of their origin.

23.- An account that reflects frequent and large deposits of low-denomination cash, for a business that generally does not handle significant sums of cash.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 119

24.- An account where funds from casino and slot machine businesses are handled, from which it is not possible to obtain evidence that they operate within the established legal regulations or of the volumes of funds handled.

25.- Fiduciary accounts that show substantial deposits of cash.

26.- Significant cash deposits to the Account of an individual or entity, when normally made by means of checks or other payment instruments.

27.- Large cash withdrawals from a commercial Account not normally associated with cash transactions.

28.- Frequent deposits of large sums of cash wrapped in paper bands from another Bank.

29.- Frequent deposits of large amounts of cash outside of customer service hours, thereby avoiding direct contact with the entity's financial staff.

30.- Deposits and withdrawals of funds from Corporate Accounts that are commonly made in cash, instead of checks.

31.- Rapid increases in the size and frequency of cash deposits, without the corresponding decrease in non-cash deposits.

32.- A reduced number of deposits using considerable amounts of checks, in which, however, withdrawals for daily operations are rarely made.

33.- Non-commercial personal accounts, used for the deposit and management of funds from commercial and/or industrial activities.

34.- Mix of cash deposits and monetary instruments in an Account in which this type of transaction does not seem to have any relation with the normal use of the Account.

35.- An Account opened supposedly for personal expenses that receives transfers from abroad for high sums remitted by companies domiciled abroad, followed by the issuance of checks to a single beneficiary who cashes them in cash.

36.- Frequent and significant deposits with dirty, mutilated, moldy bills, or marked with strange symbols.

37.- Frequent deposits or withdrawals from an Account, which fall just below the amount indicated by law to be reported.

38.- Accounts that show several deposits under the cap amount made at an ATM.

39.- The deposit or withdrawal of multiple monetary instruments in amounts that systematically fall below the identification or reporting limits, particularly if the instruments are numbered in sequence.

40.- Deposits made on the same day in different branches of the same Bank or of several Banks.

41.- Multiple transactions carried out on the same day, in the same branch of a Financial Entity, but in an apparent attempt to use different Accounts.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 120

42.- Deposits to a legal entity combining monetary instruments that are atypical for the activity normally associated with said business. For example, deposits that include a mix of commercial deposits, salary checks, and social security checks.

43.- A company acting as an agent for remittance business of foreign owners residing in the country, which mixed funds from Accounts in the name of the business with Accounts in the personal name of the principal shareholder without a logical business justification.

44.- Structuring of deposits through multiple branches of the same Financial Entity or through groups of individuals who enter a branch at the same time.

45.- An Account over which several people have authorized signature, but among them there does not seem to be any relationship, neither familial nor commercial.

46.- Accounts whose authorized signature is or are the same persons, but among them there is no apparent economic or legal reason for that type of agreement. For example, individuals who act as directors of a company for multiple companies whose headquarters are located in the same place.

47.- Accounts of state institutions that do not comply with internal control policies as such, which they are obliged to conform to according to the technical standards issued by the entity controlling state accounts, mainly on issues of Account Management, Drawer Signatures, Check Disbursement, and Electronic Funds Transfer.

48.- Frequent deposit of checks drawn from Accounts of public entities that are deposited in Accounts of individuals and that are immediately withdrawn or transferred.

49.- An Account opened by a legal entity or organization that has the same residential address as other legal entities or organizations without any reasonable explanation.

50.- An Account for clients whose addresses are outside the service area of the Financial Entity.

51.- An Account opened in the name of a legal entity that is involved in the activities of an association or foundation whose objectives are related to the claims or demands of a terrorist organization.

52.- An Account opened in the name of a legal entity, a foundation, or an association, which may be linked to a terrorist organization and that shows fund movements above the expected income level.

53.- Money is withdrawn from local bank Accounts by means of checks drawn in favor of several beneficiaries, who generally endorse them irregularly.

54.- The infrastructure of the companies is generally limited to an office or a place of residence that does not seem to relate to the amounts moved in Accounts and the activity the company carries out.

55.- An Account with an exaggerated increase in the volume of funds moved after going through financial difficulties, without an apparent justification.

56.- Frequent transfer of money by bank transfers to border areas of the country, without any justification.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 121

57.- Accounts where cash deposits are frequently made by third parties (sometimes foreigners) who are not the account holders, without any justification.

58.- Companies that record consignments in their Accounts with signs of fragmentation, carried out in cities different from the zone in which they carry out their commercial activity.

59.- Companies that do not make purchases or expenses, only cash withdrawals from their Accounts.

60.- Opening of several Checking Accounts under one or more names, in all of them with the same person authorized to draw or issue checks.

61.- Persons who carry out the opening of a Checking Account in a bank office whose location is different, distant, and without apparent justification to the locality where the client carries out their business or economic activity. For example, if it is a salaried natural person, when there is no adequate relationship with the location of their employer or with the place of their residence.

62.- Checking Account applicants who, due to their age, experience, or economic activity, do not have a history of financial products with the sector when they should have accredited it.

63.- Checking Account applicants who demand to be attended or manifest marked preference for a specific commercial advisor, manager, or bank official.

64.- Persons authorized for signature and financial management of the Checking Account when they do not have a direct link or apparent justification regarding the relationship with the holder, or said link is incoherent or inconvenient. For example, that an external auditor is authorized for the management of the Account of their auditee.

65.- Person who appears as an authorized signature for the management of numerous Checking Accounts of different persons or companies, without any apparent justification.

66.- Persons considered as Politically Exposed Persons (PEPs) who appear or attempt to be registered as authorized for the management of one or several checking accounts of third parties, without a clear and justified link.

67.- Checking Accounts that record only deposits for a period of time, manage to accumulate a considerable balance, and then the money is withdrawn in a single day or in a very short period.

68.- Consignments of high sums of money for Checking Accounts that are or have been inactive.

69.- Consecutive opening of several Savings Accounts in the name of different persons, to which the financial entity assigns debit cards for their management, and in turn are delivered to the same person or are used to carry out simultaneous operations.

70.- Persons or entities that frequently close and open new Savings Accounts in the same bank or in others in the locality, without justification.

71.- Certificates of Deposit cancelled in advance, without reasonable justification of the origin of funds for this purpose.

72.- Applicant for a Certificate of Deposit whose amount is high and who is identified with a document that cannot be easily verified or is expired and which correspond, for example, to foreigners, tourists, non-residents, minors.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 122

73.- Constitution of Certificates of Deposit for high sums of money, with one or multiple transfers from accounts of the same holder and/or third parties, from the same or different financial entity, without apparent justification.

74.- Applicant for a Certificate of Deposit who does not define a specific economic activity or defines it as "independent" and the value of their investment is high.

75.- Companies applying for a Certificate of Deposit whose high amount is not in line with the low capital, operating income, or average available resources of their treasury and/or have also been created very recently.

76.- Applicants for a Certificate of Deposit who invest high sums of money without caring or asking about profitability and feign ignorance regarding the market.

77.- Constitution of Certificates of Deposit frequently and for high sums of money, in cash, in favor of a company that, due to its commercial activity, normally does not receive or is not associated with this type of operation.

78.- Constitution of Certificates of Deposit for high sums of money, with one or multiple checks that, due to the information of their drawers, do not correspond to the economic activity of the holder or the justification is not satisfactory for the issuing entity.

79.- Opening of Accounts and/or constitution of Certificates of Deposit of different companies that have in common partners, managers, administrators, or legal representatives.

80.- Consecutive opening of several Accounts and/or constitution of Certificates of Deposit in the name of different persons with similar characteristics (age, economic activity, location, kinships) that apparently do not know each other.

81.- Opening of several Certificates of Deposit in the name of one or more persons, in all of them with the same person registered as co-holder.

82.- Certificates of Deposit that are frequently cancelled shortly after being issued or are endorsed to third parties, who also cancel them, in order to recover the invested capital.

83.- Constitution of a Certificate of Deposit with cash by a natural person in favor of a legal person that has no commercial relations with said holder nor apparent justification.

84.- Addition or change of one or more persons, designated as beneficiaries, at the time of issuance of a Certificate of Deposit, different from the purchaser of the title.

85.- Titles that are initially issued for small amounts in favor of the same beneficiary but that shortly after, or at the time of their maturity, are added with large sums of money.

86.- Realization of multiple endorsements, especially of Certificates of Deposit whose amount is considerable, by several beneficiaries with similar characteristics (for example: companies of the same "financial group", persons related by family, persons linked commercially), which are registered with the issuer of the title.

87.- Request by a holder to carry out the fragmentation of a Certificate of Deposit into several titles in favor of different natural or legal persons without apparent or justified relationship with the initial beneficiary.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 123

88.- Issuance, renewal, endorsement, or fragmentation of a Certificate of Deposit for a high amount, in which one or more persons considered as Politically Exposed Persons (PEPs) participate.

89.- Multiple endorsements of a Certificate of Deposit, for a high amount, that were not registered in a timely manner with the issuer of the title and are only known at the time of its renewal or cancellation.

90.- Endorsement of nominative Certificates of Time Deposits without notification or registration with the depositary-issuing bank and whose new owner (new bank client) is or cannot be known by said bank.

91.- Cancellation of a Certificate of Deposit in cash or by check, carried out by the beneficiary of the title, when the amount is lower and very close to the limit established for the control of cash transactions.

92.- Cancellation of several Certificates of Deposit in cash, on the same day or in a very short period of time, initially issued to different beneficiaries, which are cashed by the same person.

93.- Cancellation of multiple Certificates of Deposit in cash, issued in favor of different companies, which are cashed by the same person in the capacity of legal representative, attorney, or legitimate beneficiary.

94.- Cancellation of several Certificates of Deposit in cash, issued in favor of different persons who present themselves in a group to cash the titles.

95.- Cancellation of a Certificate of Deposit, whose holder and beneficiary is a company, which requests payment in several checks for amounts lower and very close to the limit established for the control of cash transactions, drawn in favor of the same holder or in favor of different persons.

96.- Cancellation of several Certificates of Deposit in checks, issued in favor of different beneficiaries, which after being endorsed (sometimes with similar graphological traits) are cashed by the same person.

97.- Cancellation of a Certificate of Deposit for a high amount, whose holder is a company, which requests payment by means of a check that is subsequently cashed in cash by the same manager or another official of the same.

98.- Cancellation of one or several Certificates of Deposit by means of local (or international if possible) transfers, to different cities (or countries), when the holder does not have clients or businesses in those localities that justify such operations.

99.- Cancellation of one or several Certificates of Deposit by means of local (or international if possible) transfers to localities different and distant from the headquarters of the beneficiary's business without apparent justification.

100.- Cancellation of one or several Certificates of Deposit by means of transfers, with instructions to pay them only in cash.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 124 101.- Cancellation of one or more Certificates of Deposit via local transfers, in favor of the same person or on behalf of several third parties, in amounts lower and very close to the limit established as control for cash transactions. 102.- Cancellation of one or more Certificates of Deposit via transfers to checking, savings, or other financial instruments, whose money is withdrawn immediately or in a very short time through ATMs. 103.- Accounts opened in the name of Exchange Houses where telegraphic transfers and/or structured deposits are received. 104.- The use of multiple personnel and Business Accounts or Accounts of Associations without Profit Motive, of charity or benevolence, to collect and concentrate funds, immediately or in short times, in favor of a small number of foreign beneficiaries. 105.- Account holders who have businesses whose projection, organization, number of employees, infrastructure construction, and rental of premises are disproportionate and do not show congruence with the current market situation in which they operate. 106.- Client dedicated to export, whose account movements, payments, or drafts come from countries different from that of the exports being made. 107.- Use of Accounts for payments to suppliers of a company, made on behalf of third parties who apparently have no link with it. 108.- Deposits made in different offices in the city or country, on the same day, in which the depositor (apparent client of the checking account holder) does not have businesses or agencies. 109.- Deposits made by natural persons in favor of a Checking Account whose holder is a legal entity that has no commercial relations with said depositors. 110.- Simultaneous deposits by the same person to several Checking Accounts of different companies of the same "financial group". 111.- Frequent deposits and large sums of cash in the Checking Account of a company that, due to its commercial activity, normally does not receive or is not associated with this type of operations. 112.- Client who makes a deposit of money with the purpose of carrying out a long-term operation, followed immediately by a request to liquidate the position and transfer the benefits outside the account. 113.- Client who, without apparent justification, maintains multiple accounts under a single name or on behalf of family members or companies, with a large number of transfers in favor of third parties. 114.- Deposit accounts used, without apparent reason, to consolidate funds managed in other accounts of the same client within the entity or linked directly or indirectly to him to then transfer them and/or buy monetary instruments. 115.- Accounts that receive deposits for various concepts that are not regularized and are later returned to the client or applied to other accounts.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 125 116.- Use of unauthorized accounts in the MUC to use them as generic or operational accounts for the recording of transactions related to exchange desks, sale of deposit instruments and related, which hinder their identification and monitoring. B) Regarding Active Accounts and Credits: 1.- Clients who suddenly pay off a problematic loan, without any explanation regarding the origin of the money. 2.- Early cancellation of large loans (pre-payments) without apparent justification for the reason for the sudden payment or the origin of the funds. 3.- Loans with liquid collateral cancelled in advance, without reasonable justification for the origin of funds for this purpose. 4.- Credit with liquid collateral that do not receive deposits during the term of said credit and contact with the debtor is difficult, being finally cancelled through the internal application of the guarantee. 5.- Large loans that have Certificates of Deposit or other investment vehicles as guarantees, after these were constituted with cash. 6.- Clients who request a credit and the analysis of their financial situation does not reflect any credit need. 7.- Credit lines for significant amounts in favor of clients for whom sufficient sources of funds with which they are paying the credit are not known. 8.- Credit lines for significant amounts in favor of businesses that do not bear proportion to their modest size and presence in the market. 9.- Loans that are suddenly cancelled on behalf of third parties, in cash or by transfers, both in the country and abroad. 10.- Companies with economic problems that suddenly pay off all their debts in advance. 11.- Credit Cards with high monthly consumption volumes and immediate full payment, which do not adjust to the cardholder's economic and income profile. 12.- Credit Cards with high available limits that present frequent pre-payments without reasonable justification. 13.- Loans paid via automatic debits to deposit or investment accounts that do not correspond to the client's profile. 14.- Loans cancelled via voluntary conveyances or judicial adjudications with little or no opposition. 15.- Loans used for the immediate opening of Time Deposit Certificates, which are then used as guarantees.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 126 16.- Clients who request Letters of Credit in order to guarantee loans granted to them or international operations with other financial institutions abroad that do not relate to the client's profile. 17.- Accounting debtor and/or creditor accounts, in which operations such as disbursed and unformalized loans that are cancelled by the client or debits for applications to loans when the funds that are later received from the client to close the accounting record have not yet been received. C) Regarding Neutral Operations, Services, Transfers, and Drafts: 1.- Collection of checks against an Account on the same day and in different branches, with short time intervals and below the limit indicated in the law to be reported. 2.- Issuance of checks solely in favor of the signatories and officials of the company. 3.- Large amounts of money withdrawn by majority shareholders, via checks in their names. 4.- Checks drawn by the company that present irregular endorsements and are generally collected in cash. 5.- Purchase of a large number of payment orders, checks, or other negotiable instruments in large quantities, using cash. 6.- Frequent exchange of low-denomination bills for high-denomination bills and vice versa. 7.- Clients who, without apparent reason, buy deposit instruments with large sums of cash and/or just below the limit indicated in the law to be reported. 8.- Purchase of bank drafts in a short time in favor of the same beneficiary, where the orderer and beneficiary are foreign residents. 9.- Multiple transactions carried out on the same day in the same branch, but through different ATMs. 10.- A safety deposit box is opened in the name of a commercial entity when the commercial activity of the client is unknown or said activity does not seem to justify the use of said service. 11.- Exchange of large amounts of low-denomination bills for others of higher denomination, without a lawful business to justify it. 12.- Daily withdrawals via ATM in a country different from that of the account opening. 13.- Instructions to the bank to transfer funds abroad and then wait for the same amount to be transferred from other sources. 14.- International transfers from or to an Account, of large sums of money, with instructions to pay them only in cash. 15.- Transfers, drafts, and checks for significant amounts in favor of supposed suppliers of the account holder, without supporting evidence of commercial links between them.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 127 16.- Account in which many small money transfers are received, or deposits of checks and payment orders, and immediately almost all funds are transferred to another city or country, when the activity is not consistent with the client's history or business. 17.- Deposits and withdrawals of large sums of money via transfers, through countries whose level of economic activity, in the opinion of the intermediary bank, do not justify amounts and frequencies of such transactions. 18.- Transfer of funds or deposit earnings to another country, without changing the currency type. 19.- Receipt of transfers and immediate purchase of monetary instruments to make payments to third parties. 20.- Electronic or telegraphic transfers of funds carried out in small amounts, in an apparent effort to avoid triggering identification or reporting requirements. 21.- Electronic or telegraphic transfers where the information of the originator, or the person on whose behalf the transaction was made, was not provided in or with the transfer, when the inclusion of said data was expected and would allow clearly identifying said transactions. 22.- Foreign currency exchange transactions that are executed on behalf of a client or by a third party followed by electronic transfer of funds to places where there is no business connection with the client. 23.- Client of few resources who receives a significant transfer from abroad in the concept of profit distributions from a company. 24.- Transactions in foreign currency that are carried out on behalf of a client by a third party, followed by electronic transfers of funds to places that apparently have no commercial connection with the client or to countries that generate specific concern. 25.- International transfers received supposedly for the purchase of real estate but that are returned to the sender a few days after being received. 26.- Transfer of money from a person who apparently won a contest, prize, event, lottery, or bet abroad, to third parties of whom no clear relationship or formal commercial transaction is evidenced. 27.- Checking Account that records multiple local or international transfers, for high amounts of money, to different cities or countries, when the holder does not have clients or businesses in those localities that justify said operations. 28.- Local transfers in favor of the same person or on behalf of third parties in amounts with signs of fragmentation; that is, amounts lower and very close to the limit established for their reporting. 29.- Electronic transfers received in favor or ordered from a Checking Account, whose money is withdrawn immediately or in a very short time via checks drawn in favor of third parties, ATMs, or transfers to other beneficiaries. 30.- Checking Account that receives many local transfers, for small amounts of money, which is immediately transferred to another Account in another city where the economic activity of the holder has no apparent justification.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 128 31.- Local or international transfers in favor of beneficiaries considered Politically Exposed Persons (PEPs), or checks drawn in favor of them, without a clear and justified link. 32.- Funds from internet betting received as family remittances, subsequently forwarded via international transfers to banks located in tax havens. 33.- Accumulation of large balances that are not consistent with the client's business sales or invoicing, and subsequent transfers to Accounts abroad. 34.- Electronic transfers of funds carried out by clients, with immediate entry and exit from the Account, or without passing through an Account of the same. 35.- Requests information on the possibility of receiving transfers for significant sums without clarifying the origin, data, and relationship with the orderer. 36.- Checking account holders who suddenly change the type of transactions and the way they receive or transfer money. 37.- Purchase and sale of Adjudicated Goods without the Supervised Entity knowing the origin of the buyer's funds nor the true beneficiaries of said operation. 38.- Money is withdrawn from local bank accounts via checks drawn in favor of several beneficiaries, who generally endorse them irregularly. 39.- Structured remittances to unrelated persons, sent by the same beneficiary. 40.- There are no checks drawn in the name of suppliers or service providers in favor of the client dedicated to export or import. 41.- Checks drawn for similar amounts in favor of different persons that are finally collected by one person. 42.- Checks drawn and collected in cash whose amounts are just below the limit indicated in the law to be reported. 43.- Checks drawn by a company, for large sums of money, that are collected in cash by the manager or officials of the same company. 44.- Checks drawn in favor of different persons that are collected in cash by others who show similar graphological traits in the endorsement. 45.- Checks drawn in favor of one person but collected or credited to the Account of another with a similar or apparent name. 46.- Paid checks that present symbols, stamps, or annotations (such as initials) written on the front or back of said checks. 47.- Counter check exchange for large sums of money that affect State Entity Accounts.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 129 48.- Consecutive opening of several "Draft Accounts" or sending of international drafts on behalf of different persons with similar characteristics (age, economic activity, location, kinships), who apparently do not know each other, in order to carry out international drafts to the same or different countries. 49.- Receipt of drafts from several senders, in different countries, and in favor of the same beneficiary. 50.- The same sender sending drafts to several beneficiaries without an apparent relationship. 51.- The drafts are sent in favor of a group of persons, without apparent relationship or who do not know each other, with the same phone number or address to contact them. 52.- Sending of international drafts by different senders in favor of a common beneficiary. 53.- Sending of consecutive international drafts for equal or similar sums of money, destined to the same country. 54.- Sending of international drafts for the same amount, on the same date, to the same city or country, in the name of different persons who apparently do not know each other. 55.- Sending of multiple international drafts, to the same country, on behalf of one or several senders, when the amount is lower and very close to the limit established for the control of cash transactions. 56.- Multiple international drafts, coming from different places and/or different senders, collected by the same beneficiary and/or in different cities of the country without an apparent justification. 57.- International drafts for the same amount, generally consecutive, which are collected simultaneously on the same date and city, in the name of different persons who apparently do not know each other. 58.- International drafts paid by checks, in favor of different beneficiaries, which after being endorsed (sometimes with similar graphological traits) are collected by the same person, or are endorsed illegibly and collected in cash in such a way that the identity of the final beneficiary cannot be verified. 59.- International drafts in which the beneficiary wants to collect them in cash and initially refuses to accept payment by check, due to the amount of the operation or the policies of the Entity. 60.- International drafts paid via credit to a bank Account different from that of the beneficiary, without an apparent justification or relationship. 61.- International drafts paid via transfers to checking, savings, or other financial instruments, whose money is withdrawn immediately or in a very short time through ATMs. 62.- International drafts to pay beneficiaries who have been contacted by telephone and who at the time of collection state that they do not know the sender or that they do not have persons or relatives abroad.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 130 63.- Beneficiaries who present themselves periodically (in a weekly or lower frequency) to collect international drafts without the Entity having contacted them and even without the financial entity having received the transfer. 64.- Draft beneficiaries who do not know the name of the sender, the origin, the amount, and the purpose of the money. 65.- Lack of withdrawal of funds against checks deposited, by a client who operates a retail business and provides the service of buying checks. This suggests that such a client has another source of funds. 66.- Clients who often visit the safety deposit box area immediately before making a cash deposit whose amount is just under the limit required to generate a report. 67.- Significant changes in the patterns of sending cash between correspondent banks. 68.- Persons carrying out numerous and frequent transactions in electronic ATMs charged to Accounts of banks abroad. 69.- Purchase and sale of cash foreign currency carried out frequently by persons or businesses that are not legitimized to exercise this activity. 70.- Purchase and sale of cash foreign currency that present signs of fragmentation just below the limit indicated in the law to be reported. 71.- An entrepreneur receives money from a "third party" to put on his Payroll non-existent persons or straw men that he designates, with the purpose that through the Payroll Bank Accounts service he pays or returns said money under the justification of salaries. 72.- Unusual or suspicious flows or activities in the movement of physical money internally or externally, from or to the Supervised Entity. 73.- Branches that reflect atypical behavior in the composition of their cash in box regarding amounts or types of denominations and currencies that do not relate to their profile whether this is of net cash captor or net cash placer, in relation to the characteristics of the market in which it operates or economic seasonality. III.- Specific to the Insurance Market 1.- Request for transactions that do not correspond to the normal operations profile of the policyholder or are outside the ordinary pattern of the insured. 2.- Insurance Policies with premiums that exceed the apparent means or possibilities of the client. 3.- Payment of premium via international transfer in which the identity of the orderer or the number of the source account is not contained.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 131 4.- Insurance Policies with values that seem incompatible with the client's Insurance needs. 5.- The client requests an Insurance product that does not have a discernible purpose and shows reluctance to reveal the reason for the investment. 6.- The short period between the constitution of a considerable value policy and the moment of its redemption, especially when it is requested that the surrender value be returned in favor of a third party. 7.- Clients who suspiciously seek that the insured value be higher than initially established, including costly accessories within the policy. 8.- Dubious origin of the insured goods due to the lack of apparent reason for the client to possess or hold them. 9.- Policies in which the interveners are crossed (for example, the policyholder of one policy is the insured of another policy in which the insured of the first policy appears as the policyholder) and no reasons justifying it are appreciated. 10.- Plurality of policies with a single beneficiary. 11.- Insurance in multiple policies by the same person for very significant amounts, whether with one or different insurers. 12.- Collective insurance of companies with high employee turnover. 13.- Early redemption of life insurance in a relatively short interval of time from contracting. 14.- The same beneficiary of life or retirement insurance policies for very significant amounts, contracted by different persons. 15.- Policies that cover death, and this occurs abroad. 16.- Early cancellation of life insurance without penalty or indication of the reasons. 17.- Life insurance contracted with conditions outside the market. 18.- An atypical incidence of early payment of insurance premiums. 19.- Early conclusion of an insurance product, especially with loss, or transaction in which cash is delivered and/or the refund check is issued to a third party. 20.- The client does not seem to be concerned about the price of the policy, or the convenience of the product for their needs. 21.- The applicant for an insurance product shows no interest in the performance of the policy, but does show much interest in knowing the procedure for early cancellation of the contract. 22.- The client concretizes or seeks the way to cancel, before its maturity, a costly life insurance policy, with single premium, without worrying about the additional costs or charges that this represents.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 132 23.- The client contracts a policy for a very significant amount and, after a short period of time, requests a refund of the funds, asking that they be paid to a third party, regardless of the discount for early cancellation. 24.- The client accepts very unfavorable conditions in the policy that have no relation to their health or age. 25.- The client seeks the purchase of a single-premium policy, or prepay premiums to borrow the maximum cash value, or use said policy as collateral for a loan. 26.- Request for a policy by a potential client from a distant geographic location, when a contract with similar characteristics could be obtained near their home. 27.- Intervention of an Insurance Agent, Intermediary, or Broker from a jurisdiction or geographic area that is unregulated, or whose regulation is very lax, or where organized crime activities are frequent. 28.- Large flows of funds through Insurance Brokers for non-resident accounts. 29.- Transfer of the benefit of an insurance product to a third party who apparently has no relation to the client. 30.- Change of designated beneficiaries, apparent reason, especially if this can be done without the knowledge or consent of the insurer and/or the right to receive payment can be transferred simply by endorsing the policy. 31.- Policies in which, shortly before the claim is paid, the beneficiary is changed. 32.- Substitution, during the term of an insurance contract, of the ultimate beneficiary by a person who apparently has no connection with the policyholder. 33.- Attempt to use a third-party check to purchase a policy. 34.- The applicant for an insurance product attempts to use cash to complete a transaction that is normally settled by checks or other payment instruments. 35.- The applicant for an insurance product appears to have policies with several institutions. 36.- The Insurer receives instructions to accelerate the maturity of a life insurance policy just at the moment the client is mentioned in news or trials linked to organized crime. 37.- Purchase of insurance covering risks to which the client is not effectively exposed, for example, maritime civil liability insurance for a "ghost" ship. 38.- Payment of very high premiums for the policy, and frequent claims for smaller amounts, in order to receive the amounts related to them via checks, leaving the respective and reasonable profit margin to the Insurer. 39.- Agreement for the assignment and payment of claims, through which persons or legal businesses authorize and request that the payment of claims or indemnification for loss be made to a third party, who has previously promised to pay them in cash, traveler's checks, or payment orders for the amount of said claim plus a commission, all in exchange for the Insurer's check.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 133 40.- Claim for "ghost" accidents or alleged loss (e.g., auto theft) of valuable insured goods. 41.- Insurance of "ghost" or non-existent goods, or supported by false documentation; and subsequent claim for alleged accidents on them. 42.- Issuing checks for claim payments and in the respective receipt, the beneficiary is not identified with an official document. 43.- False phone numbers and addresses of policy beneficiaries. 44.- Premiums that are commonly paid in one type of currency and claims are requested in another currency; or the unearned premium is requested to be collected in a currency different from that in which the insurance was originally contracted. 45.- A number of low-denomination policies are contracted and immediately cancelled by the same agent. 46.- The crediting of the unearned premium is made to an account different from that from which the funds originally came. 47.- Insurance of goods and businesses that represent excessively large sums, and in an "accidental" but recurrent manner, the client makes overpayments of premiums and consequently requests the respective refund via checks or electronic transfers. 48.- When the overpayment of premiums is made through an agent and has the following characteristics: it is of considerable or significant magnitude and the request for reimbursement or refund of the funds is made to a third party and the insured is located in a jurisdiction with frequent cases associated with money laundering. 49.- An Insurance Broker receives premium payment in cash and deposits the funds in their bank but does not notify it. 50.- Insurers that are willing to pay a value much higher than the average market rate in reinsurance, in favor of companies whose owners are not clearly identified nor can any public domain information be verified. 51.- Official or employee of an Insurer or Agent, Intermediary, or Insurance Broker who, suddenly and without reasonable explanation, has an exaggerated level in their portfolio of single-premium insurance policy sales. 52.- Notable and unexpected increase in sales or results by Insurance intermediaries.

IV.- Specific to the Securities Market 1.- Investment operations in negotiable securities for unusually large amounts that do not correspond to the declared activity and/or the client's financial/net worth situation. 2.- Operations arranged at prices that do not correspond to market conditions.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 134 3.- Payment/collection of premiums excessively higher/lower than those negotiated in the options market. 4.- Purchase/Sale of negotiable securities in the spot market at prices notably higher/lower than the quotes being negotiated. 5.- Purchase/sale of the underlying asset — by exercise of the option — at prices that do not correspond conveniently to the exercise price. 6.- Purchase/Sale of futures contracts at prices considerably higher/lower than the quotes being negotiated. 7.- Purchase of negotiable securities for very notable amounts. 8.- Very relevant amounts in guarantee margins paid for open positions in the futures and options markets. 9.- Very high investment in premiums in the options market. 10.- Very relevant investment in stock transfer or margin operations. 11.- Client requests for investment portfolio management services, where the origin of the funds is not clear or is not consistent with the type of business or declared activity. 12.- Investment operations in negotiable securities for very high nominal volumes, which do not correspond to the volumes traditionally operated in the species for the type of client. 13.- Operations carried out repeatedly between the same parties, in which there are continuous gains or losses for any of them. 14.- Client who carries out succession of transactions and/or transfers to other principal accounts without apparent justification. 15.- Client who carries out complex financial operations (financial engineering) without a concrete purpose. 16.- Purchase of participation quotas in investment funds, without respecting the stipulated terms, redeeming the investment early, despite the penalties. 17.- Purchases of high-risk securities on successive occasions and early resale for values lower than initially agreed. 18.- Investments in negotiable banking securities from sensitive regions (tax havens or countries related to terrorism). 19.- Frequent investments in uninteresting securities by companies that do not dedicate themselves to the investment sector. 20.- Frequent investments by Non-Profit Organizations, with request for early termination in the name of third parties via management checks. 21.- Requests for "interesting" investments from tax haven intermediaries.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 135 22.- Early terminations of investments, with request by the intermediary, for the transfer of resources to a tax haven. 23.- Significant investments by companies with low liquidity rating.

V.- Specific to the General Warehouse Receipt Market 1.- Goods in the process of nationalization whose weight, size, or general physical characteristics do not seem consistent with the data recorded in the documentation supporting the operation. 2.- Differences between the different boxes, bundles, or packages of a good that is exported/imported in bulk. 3.- Transport of foreign-origin goods from ports or border places to the interior of the country without the transporter presenting the documentation that accredits the legal importation of goods. 4.- Natural or legal persons who carry out a considerable volume of exports/imports without having sufficient infrastructure and economic capacity. 5.- Importers/exporters mentioned in the media for belonging to or having links with criminal activities or organizations. 6.- Atypical exports/imports not in accordance with the country of origin and/or destination. 7.- Companies that, shortly after being created, carry out very significant foreign trade operations and then become inactive or are liquidated. 8.- Exports/imports of products sensitive to smuggling carried out to countries with lax foreign trade regulation and with free zones. 9.- Exports/imports of goods or merchandise in bad condition, expired, or with short expiration and/or request for issuance of deposit certificates and pledge bonds on this type of merchandise. 10.- Request for issuance of deposit certificates and pledge bonds on agricultural products or merchandise destined for export carried out by natural or legal persons without antecedents in this type of activities and/or who buy directly from the producer in cash and whose banking references are not in accordance with the sums of money handled. 11.- Goods or merchandise abandoned without justification on which financing has been granted. 12.- Overvaluation of goods or merchandise on which the issuance of deposit certificates and pledge bonds is requested. 13.- Export/import of overvalued and undervalued goods or merchandise. 14.- Change of owners of the merchandise and the history of the new owners that is not consistent with the nature of the client's business or the new owners are reluctant to provide personal or financial information.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 136 15.- Changes of ownership of deposit certificates and/or pledge bonds without coherence between the type of business and the history of the new owner(s) and/or the latter evade the delivery of their financial antecedents. 16.- Carrying out consecutive and/or simultaneous purchases and sales of deposit certificates and/or pledge bonds, with the object of generating an artificial volume of investments. 17.- Non-payment of credits intentionally so that the pledged goods or merchandise are auctioned. 18.- Transactions with deposit certificates and pledge bonds, which repeat in short intervals of time and involve cash, especially if the counterparties are located in vulnerable geographic areas.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 137 Annex 4: Instruction and Format for the Presentation of the Suspicious Operations Report (ROS). I.- Instruction for the presentation and submission of the Suspicious Operations Report (ROS): i. The ROS must be sent by the entity to the competent authority in a single copy within a hermetically closed envelope, sealed and stamped by the entity, accompanied by an original submission letter attached to the envelope, having as the sole recipient the representative of the competent authority. ii. The entity must not send a copy of the ROS or the submission letter to any person or other authority. iii. On the cover of both documents (the envelope containing the ROS and the submission letter), the indicative note CONFIDENTIAL will be placed. iv. Both documents (the envelope containing the ROS and the submission letter) must be delivered directly to the offices of the competent authority, who will stamp the respective Acknowledgment of Receipt on the submission letter and its copy. The copy of the submission letter will be returned to the reporting entity as support for the delivery of the closed envelope containing the ROS. v. Each ROS will be identified with a Numerical Code that will be configured by the union of four aspects or sections, in the following way:

  1. The letter "R" (which indicates ROS).
  2. The numeric number of each entity composed of four digits.
  3. The consecutive number of the ROS in the year composed of three digits.
  4. The year. Example: R-XXXX-017-2008. This indicates that we are facing ROS number 17 issued in the year 2008 by entity XXXX. vi. The Numerical Code that identifies each ROS, will be inscribed on the cover of the envelope, on the submission letter, and on each page of the Report itself. vii. For each ROS there will be an exclusive envelope, therefore, if two or more ROS are presented at the same time, each will come in its own envelope, and the submission letter will specify the Numerical Codes that identify each of the envelopes with the ROS. viii. In the submission letter and in the envelope containing the ROS, no type of explanation or narration about the content of the envelope or the ROS itself, nor about the reported suspicious activity, nor about the documents attached, nor about the name(s) mentioned in the ROS, should be made. ix. In corrections, additions, supplements, expansions, or complements to a previous ROS, these same quality, confidentiality, and security measures will apply.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 138 x. Each ROS will always conserve its Numerical Code that identifies it, therefore, that same Numerical Code will be applied to those corrections, additions, supplements, expansions, or complements made on said ROS subsequently, indicating this circumstance in the envelope and in the submission letter, in the following manner. Example: EXPANSION: R-XXXX-017-2008 / A-1 This indicates that we are facing expansion information (the first) of Report number 17 issued in the year 2008 by entity XXXX. Example: CORRECTION: R-XXXX-017-2008 / C-1 This indicates that we are facing correction information (the first) of Report number 17 issued in the year 2008 by entity XXXX. Example: CORRECTION: R-XXXX-017-2008 / C-2 This indicates that we are facing correction information (the second) of Report number 17 issued in the year 2008 by entity XXXX. xi. When a ROS, even having direct or indirect linkage with a previous ROS, is referred to different clients and operations, it will be considered as a new ROS, and consequently will have its own Numerical Code. However, within the information, it must be mentioned that the linkage exists with other ROS. xii. The ROS (within the envelope) must contain the Numerically Coded Signature of the ML/TF Prevention Administrator (or their Substitute, as the case may be) of the Supervised Entity. The ROS will not contain the name of said official nor their autograph signature. Said Coded Signature will be permanent and will be configured by the union of four aspects or sections, in the following way:

  1. The letter "F" (which indicates Signature).
  2. The four numeric digits that identify each entity.
  3. Two alphabetic digits.
  4. Six numeric digits. Example: F-XXXX-AB-XXXXXX xiii. Each page of the ROS will contain the Coded Signature of the ML/TF Risk Administrator and the seal of the Reporting Supervised Entity. xiv. The submission letter of the ROS must be autographically signed by the ML/TF Risk Administrator of the Supervised Entity, in addition to containing the entity's seal. xv. ROS that are presented without meeting these requirements will be returned by the competent authority. xvi. Each time a ROS is generated, the entity must update the respective Comprehensive Client Profile.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 139 II.- Format for the Presentation of the Suspicious Operations Report (ROS) FORMAT SUSPICIOUS OPERATION REPORT (ROS)

Initial Report Correction Expansion

I.- Reporting Supervised Entity 1 Name 2 Head Office Address

II Person(s) linked to the Suspicious Operation (Note: For each person who links directly or indirectly, as client, beneficiary, or manager, the following table must be completed with all pertinent information) A. Full Name: B. Sex: C. Nationality of Origin and Acquired: D. Marital Status: E. Profession or Trade: F. Date of Birth: G. Spouse's Name: H. Address (Residential and Work): I. Identification Document for Natural Person: Passport Nicaraguan ID Residence Card Other Document Number:_______________________________ Document Registration Number:_____________________ J. Identification Document for Legal Person: RUC Number:_____________________________________ Commercial Registry Number:_____________________ Number of Other Registers: _______________________ K. Contact Data: Conventional Phone:_________________ ROS Code:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 140 Cell Phone:_______________________ Fax:__________________________________ Email:_____________________ Postal Code:_________________________ L. Economic Activity: M. Type of Relationship with the Supervised Entity: Client Potential Client Manager Employee Legal Representative Official Director Shareholder Other____________________________________

III Information Regarding the Suspicious Operation A. Date of Detection of the Operation: B. Indicate if the transaction was carried out, attempted, or rejected; and also if it was decided to terminate or continue the relationship with the client. C. Type(s) of Financial Means and Instruments Used: Currency Cash Fund Transfer Personal Check Cashier's Check Management Check Traveler's Check Bonds Securities Credit Card Credit Line Other D. Description of the Financial Means and Instruments Used (Describe the instrument including type, issuer, serial number, amount) E. Amount of the Operation (Indicate the value in dollars and in national currency. Indicate added values if the activity involves more than one transaction related to the same person during the same period. Leave blank, if exact knowledge of the total value is not available) F. Description of the Operation (Provide a complete chronological narration of the unusual or irregular facts that may constitute a violation of the Law and its norms. The narration must be explicit and clear. The narration must include, without limitation, the following: Details about the supporting documentation and retain the documentation in the Supervised Entity for a period of five years; Indicate the person(s) who benefited through the transaction, the amount, and the circumstances of how they benefited; Indicate the Branch where the operation took place. Indicate the Start Date of the Relationship. Describe and retain explanations supplied by the actor of the unusual activity; Provide detail on the instruments used and accounts involved in the activity)

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 141 G. Accounts related to the Suspicious Operation No. Account Type Status

H. Observations: Encoded Number of the ML/TF Risk Administrator Seal of the Supervised Entity

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 142 ANNEX 5: Manual and Format for the Automated Presentation of Cash Transaction Reports (RTE) i.- Conceptual Aspects (Data Flow) :: General data sending process Generates data files from proprietary systems Compresses files with ZIP format Loads compressed file to SIBOIF server Validates user and key on SIBOIF server Validates file format Validates form, congruence, background, and balancing Unifies data Encrypts (ciphers) file (GNUPG) Data okay? Yes Generates incident file No Data okay? Yes No Yes Notification via email Note: If there are incidents, the files will be compressed with Zip format and then encrypted with GNUPG only and exclusively for the corresponding Financial Institution. The files will be located in the corresponding folder of the Financial Institution to be downloaded via SSH of FTP. Figure 1 General process of data sending and reception The main data sending flow is shown in "Figure 2: General process of data sending and reception.":

  1. The Supervised Entity must generate the pertinent files from its proprietary systems.
  2. The generated files must be compressed in Zip format.
  3. Once the file is compressed, it must be encrypted (ciphertext) using the SIBOIF public key.
  4. Subsequently, one must connect to the SIBOIF main page where one must authenticate with user and key.
  5. Once connected, one must load the encrypted file.
  6. The first validation consists of verifying the sent files, checking that the quantity of files and the format accord with the type of sending. If not in accordance with the standard, notification is sent automatically via email.
  7. If the format is correct, the content of the files is validated. If any inconsistency is found, a file is generated where it is subsequently compressed (zip) and encrypted (GNUPG). An automatic email notification is sent so that the Supervised Entity downloads said file through FTP.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 143

  1. If there are no relevant problems in the validation, the data is unified in the history.

ii.- Types of submissions

ii.1 Submissions from Financial Institutions to SIBOIF

Table 1 Types of submissions from Financial Institutions to SIBOIF

Type of submissionFilesDescription
PLdDPLdD_DatosGeneral data on transactions
PLdDPLdD_PersonasGeneral information on persons (Beneficiaries and/or Managers)
PLdDPLdD_Datos_Persona RelacionData vs. Persons

PLdD_Datos id_transaccion: int fecha: datetime id_sucursal: int id_tipo_reporte: int id_tipo_transaccion: char(1) id_numero_cuenta: varchar(20) id_tipo_operacion: int monto: numeric(20,2)

PLdD_Datos_Persona id_persona: varchar(20) id_tipo_documento: int id_transaccion: int id_tipo_relacion: char(1)

PLdD_Personas id_persona: varchar(20) id_tipo_documento: int id_cedula_residencia: varchar(20) direccion: varchar(250) id_pais: int nombre: varchar(100) numero_de_registro: varchar(20)

ii.2 Format of the files

The format of the files to be used for data submission to SIBOIF is a text file (ASCII). The fields must be separated by the character "|" (vertical bar) and the fields/variables that are characters (varchar) must be delimited by double quotes. For example, the Anti-Money Laundering Prevention file is composed of a series of fields (see Annex A.1: Type of submission: Anti-Money Laundering Prevention). An example of the content of said file for the first five fields is shown below:

"20060301"|999|"0071"|"VALERIA"|"LISSETH"|"CARCAMO"|"PRADO"|"BO. J. GONZALEZ, CENTRO COMUNITARIO 620VRS.E."|9|"0060105930006H"|"NI"|""|""|""|""|"EMPRESA NICARAGUENSE AGUA, S.A"|"EDIFICIO VILLA FONTANA 4TO PISO"|4|"301F195D9520"|"--"|"I"|54547.873|91|"" "20060301"|999|"0071"|"SALVADOR"|"AUGUSTO"|"BALDIZON"|""|"REPARTO J.R. PADILLA, 6TA. CALLE"|1|"0021302360000X"|"NI"|""|""|""|""|"ACME S.A"|"KM. 5 1/2 C. NORTE COMPLEJO INDUSTRIAL"|7|"2107909551"|"--"|"X"|27636.860000000001|91|"" "20060301"|999|"0071"|"ALVARO"|"JOSE"|"FLORES"|"GARCIA"|"VILLA DON BOSCO, FTE. A LA CRUZ ROJA"|1|"0042810790006L"|"NI"|""|""|""|""|"ACME #2 S. A."|"DE LA ROTONDA EL GUEGUENSE 175VRS AL SUR"|4|"180883759502"|"--"|"I"|13239.440000000001|11|"" "20060301"|999|"0071"|"DAE"|"KYU"|"JOHN"|"CC"|"VILLA FONTANA ENITEL 250MTS AL SUR 4C ABAJO"|1|"40348515"|"NI"|"KANG AE"|""|"LEE"|""|""|"CONDOMINIO LOMA,DEL PARQUE 150 MTS AL SUR"|2|"2036679D65"|"KR"|"I"|20941.43|11|""

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 144

The names of the files to be sent must have the name found in parentheses in “Table 1 Types of submissions from Financial Institutions to SIBOIF” with the .txt extension with the format previously stated.

The submissions must be compressed with the Zip format. Then they must be encrypted with GNUPG with the .dat extension.

The name of the encrypted file must contain at the end of it the underscore symbol (“_”) followed by the code generated by the Sha-1 cryptographic function. This code serves to guarantee that the submitted file has not been altered during transmission.

Example: ACME200510_c477cd741fe913af75dc92ffd27ece78a7348760.dat

ii.3 Submissions from SIBOIF to Supervised Entities

SIBOIF will make available to Supervised Entities a private folder on an FTP (File Transfer Protocol) server to locate files on incidents, credit references, consolidations, among others. Access to this site is through SSH (Secure Shell). Each Supervised Entity will have unique and exclusive access to its folder; additionally, the files located in said folders will be encrypted exclusively for the respective Supervised Entity. Figure 2 shows an example of the site structure.

FTP Server Institutions B1 Bn F1 Fn

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 145

Figure 2 FTP Server

SIBOIF has one type of submission to Financial Institutions: • Incidences (errors): When an incidence (validation error) is identified in the files submitted in the corresponding batches, a file with the same name containing the records with problems will be created. At the end of the record, the record number will be added, as well as a field containing all validation errors. The errors will be encoded according to the Validation Catalog (Annex C.3: Validation Catalog). Likewise, a general incidence file will be generated which will contain all incidences found in the validation of each of the files sent.

The format of these files will be text (ASCII) as stated in section (1.3.2 Format of the files).

The names of the files will be compressed (Zip) and in turn encrypted (GNUPG):

File NameNomenclature
Incidences (errors)yyyymmdd_hh_mi_ss_mmm_[id_carga]_SiglasInstFin_PLdD_Errores_SHA1.dat

Example: 20051104_16_41_14_030_[635]_ACME_PLdD_Errores_4a578ecd09a5d0c8431bdd8cf3d5c5f3ddcddfc9.dat

yyyy Year mm Month dd Day hh Hour mm Minutes ss Seconds mmm Milliseconds id_carga Load ID SiglasInstFin Supervised Entity Acronym PLdD Anti-Money Laundering Prevention SHA1 Code generated by the Sha-1 cryptographic function

Table 2 Nomenclature of the names of files to be sent by SIBOIF

iii.- File formats according to type of submission

iii.1: General Data Anti-Money Laundering Prevention (PLdD_Datos)

OrderFieldData TypeDescriptionRequiredRelated Table
1id_transaccionintUnique transaction number defined by the EntityYes
2fechayyyymmddDate of realization of the transaction or transactionsYes
3id_sucursalintCode assigned by the Supervised EntityYes
4id_tipo_reporteintid_tipo_reporte
5id_tipo_transaccionchar(1)Type of transactionYesid_tipo_transaccion
6id_numero_cuentavarchar(20)Account numberYes
7id_tipo_operacionintOperation TypeYesid_tipo_operacion
8montonumeric(20,2)Transaction amountYes

iii.2: Persons (PLdD_Persona)

OrderFieldData TypeDescriptionRequiredRelated Table
1id_personavarchar(20)Identification of the Person. Number of the identification of the natural or legal person, national or foreign, that maintains some type of relationship (debtor, guarantor, surety, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) of the Supervised Entity, according to the type of document established in this Manual.Yes
2id_tipo_documentointType of Document. Indicates the code of the type of document that corresponds to the identification used by the natural or legal person, national or foreign, that maintains some type of relationship (debtor, guarantor, surety, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) with the financial institution, according to the corresponding catalog established in this Manual.Yesid_tipo_documento

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 146

OrderFieldData TypeDescriptionRequiredRelated Table
3id_cedula_residenciavarchar(20)Residence cardYes
4direccionvarchar(250)Address of the personYes
5id_paisintCountry IDYesid_pais
6nombrevarchar(100)Name. Indicates the name or trade name of the natural or legal person, national or foreign, which must be in correspondence with the identification document presented by the same. In the case of natural persons, first names must be reported and then surnames.Yes
7numero_de_registrovarchar(20)Registration numberYes

iii.3: Data versus Persons Relationship (PLdD_Datos_Persona)

OrderFieldData TypeDescriptionRequiredRelated Table
1id_personavarchar(20)Identification of the Person. Number of the identification of the natural or legal person, national or foreign, that maintains some type of relationship (debtor, guarantor, surety, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) of the Supervised Entity, according to the type of document established in this Manual.Yes
2id_tipo_documentointType of Document. Indicates the code of the type of document that corresponds to the identification used by the natural or legal person, national or foreign, that maintains some type of relationship (debtor, guarantor, surety, acquirer of adjudicated goods, related party, linked to the related party, shareholder, employee) with the Supervised Entity, according to the corresponding catalog established in this Manual.Yesid_tipo_documento

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 147

OrderFieldData TypeDescriptionRequiredRelated Table
3id_transaccionintTransaction numberYes
4id_tipo_relacionchar(1)Type of relationshipYesid_tipo_relacion

iv.- SIBOIF response files

iv.1: Incidences

OrderFieldData TypeDescriptionRelated Table
1LineaIntOriginal line of submission of the file where the incidence is found
2
7
8
9Id_validacionvarchar(500)Validation codes separated by commas if more than one error is found in the indicated line.

Example: "20060301"|999|"0071"|"VALERIA"|"LISSETH"|"CARCAMO"|"PRADO"|"BO. J. GONZALEZ, CENTRO COMUNITARIO 620VRS.E."|9|"0060105930006H"|"NI"|""|""|""|""|"EMPRESA NICARAGUENSE AGUA, S.A"|"EDIFICIO VILLA FONTANA 4TO PISO"|4|"301F195D9520"|"--"|"I"|54547.873|91|""|1|"50.001.0005, 50.001.0008" "20060301"|999|"0071"|"SALVADOR"|"AUGUSTO"|"BALDIZON"|""|"REPARTO J.R. PADILLA, 6TA. CALLE"|1|"0021302360000X"|"NI"|""|""|""|""|"ACME S.A"|"KM. 5 1/2 C. NORTE COMPLEJO INDUSTRIAL"|7|"2107909551"|"--"|"X"|27636.860000000001|91|""|2|"50.001.0001, 50.001.0002, 50.001.0008, 50.001.0003"

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 148

iv.2: Statistics

OrderFieldData TypeDescriptionRelated Table
1Id_consecutivointConsecutive
2Id_validacionVarchar(20)Validation code.
3Descripciónvarchar(500)Description of the validation that was violated

Example 1|"50.001.0002"|"0060105930006H: The type of identification of the Beneficiary/Manager is not found in {1, 2, 3, 4, 5, 6, 7, 9}." 2|"50.001.0005"|"0060105930006H: Transaction Type is not found in {11, 12, …, 27}." 3|"50.001.0001"|"0021302360000C: The identifier 'Individual Fractional' is not … in {I, F}." 4|"50.001.0002"|"0021302360000C: The type of identification of the Beneficiary/Manager is not … {1, 2, 3, 4, 5}." 5|"50.001.0005"|"0021302360000C: Transaction Type is not found in {11, 12, …, 27}." 6|"50.001.0003"|"0021302360000C: The Beneficiary/Manager's ID does not comply with the algorithm ...."

Note: In order to save space, the last two messages were cut. In practice, the description corresponding to the Validation Catalog (Annex C.3) will appear.

v.- Annex catalogs

v.1: General catalogs

id_tipo_documentoDescription
1Foreign Natural Residents (Residence Card).
2Legal Persons (RUC -Nicaragua).
3Foreign Natural Non-Residents (Passport).
4Nicaraguan (Citizen Identity Card)
5Nicaraguan Residents Abroad (Passport).
6Foreign Natural Diplomatic, Consular, International Organizations and Special Guests Officials (Card of the Ministry of Foreign Affairs of the Republic).
7Non-Profit Legal Persons (Card of MIGOB)
9Generic Identification / Identification Unknown by the Supervised Entity.
id_tipo_reporteDescription
1Report of Cash Transactions above determined threshold (RTE)
2Financial Transfers Report (RTF)
3Report of Purchase and Sale of Consignment Instruments (RCIC)
id_tipo_transaccionDescription
IIndividual
FFractional
id_tipo_operacionDescription
11Deposits
12National transfers sent
13International transfers sent
14Purchase of consignment instruments
15Exchange desk (Income)
16Credit payments
17Service payments
18Various Income
21Account withdrawal
22National transfers received
23International transfers received
24Payment of consignment instruments
25Exchange desk (Expenses)
26Credit disbursements
27Various Expenses
id_tipo_relacionDescription
GManager
BBeneficiary
ABoth (Beneficiary and Manager)
Id_nacionalidad, id_paisCountry
[1, 80 ]
4AFGHANISTAN
8ALBANIA
10ANTARCTICA
12ALGERIA
16AMERICAN SAMOA
20ANDORRA
24ANGOLA
28ANTIGUA AND BARBUDA
31AZERBAIJAN
32ARGENTINA
36AUSTRALIA
40AUSTRIA
44BAHAMAS
48BAHRAIN
50BANGLADESH
51ARMENIA
52BARBADOS ISLAND
56BELGIUM

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 149

Id_nacionalidad, id_paisCountry
60BERMUDA
64BHUTAN
68BOLIVIA
70BOSNIA AND HERZEGOVINA
72BOTSWANA
74BOUVET ISLAND
76BRAZIL
84BELIZE
86BRITISH TERRITORY IN THE INDIAN OCEAN
90SOLOMON ISLANDS
92VIRGIN ISLANDS (BRITISH)
96BRUNEI DARUSSALAM
100BULGARIA
104MYANMAR
108BURUNDI
112BELARUS
116CAMBODIA
120CAMEROON
124CANADA
132CAPE VERDE
136CAYMAN ISLANDS
140REPUBLIC OF AFRICA CENTRAL
144SRI LANKA
148CHAD
152CHILE
156CHINA
158TAIWAN
162CHRISTMAS ISLAND
166COCOS (KEELING) ISLANDS
170COLOMBIA
174COMORAS
175MAYOTTE
178REPUBLIC OF CONGO
180DEMOCRATIC REPUBLIC OF CONGO, (FORMER ZAIRE)
184COOK ISLANDS
188COSTA RICA
191CROATIA
192CUBA
196CYPRUS
203CZECH REPUBLIC
204BENIN
208DENMARK

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 150

Id_nacionalidad, id_paisCountry
212DOMINICA
214DOMINICAN REPUBLIC
218ECUADOR
222EL SALVADOR
226EQUATORIAL GUINEA
231ETHIOPIA
232ERITREA
233ESTONIA
234FAROE ISLANDS
238FALKLAND ISLANDS (MALVINAS)
239SOUTH GEORGIA AND THE SOUTH SANDWICH ISLANDS
242FIJI
246FINLAND
248ALAND ISLANDS
250FRANCE
254FRENCH GUIANA
258POLYNESIA (FRENCH)
260FRENCH SOUTHERN TERRITORIES
262DJIBOUTI
266GABON
268GEORGIA
270GAMBIA
275PALESTINIAN TERRITORY (OCCUPIED)
276GERMANY
288GHANA
292GIBRALTAR
296KIRIBATI
300GREECE
304GREENLAND (GREENLANDIA)
308GRENADA
312GUADELOUPE (FRENCH)
316AMERICAN GUAM
320GUATEMALA
324GUINEA
328GUYANA
332HAITI
334HEARD ISLAND AND MCDONALD ISLANDS
336THE VATICAN
340HONDURAS
344HONG KONG
348HUNGARY
352ICELAND

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 151

Id_nacionalidad, id_paisCountry
356INDIA
360INDONESIA
364IRAN (ISLAMIC REPUBLIC)
368IRAQ
372IRELAND
376ISRAEL
380ITALY
384COTE D'IVOIRE (COTE D´IVOIRE)
388JAMAICA
392JAPAN
398KAZAKHSTAN
400JORDANIA
404KENYA
408DEMOCRATIC PEOPLE'S REPUBLIC OF KOREA
410REPUBLIC OF KOREA
414KUWAIT
417KYRGYZSTAN
418DEMOCRATIC PEOPLE'S REPUBLIC OF LAOS
422LEBANON
426LESOTHO
428LATVIA
430LIBERIA
434POPULAR AND SOCIALIST JAMAHIRIYA ARAB LIBYA (LIBYA)
438PRINCIPALITY OF LIECHTENSTEIN
440LITHUANIA
442LUXEMBOURG
446MACAO
450MADAGASCAR
454MALAWI
458MALAYSIA
462MALDIVES
466MALI
470MALTA
474MARTINIQUE
478MAURITANIA
480MAURITIUS ISLAND
484MEXICO
492MONACO
496MONGOLIA
498REPUBLIC OF MOLDOVA
500MONTSERRAT
504MOROCCO

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 152

Id_nacionalidad, id_paisCountry
508MOZAMBIQUE
512OMAN
516NAMIBIA
520NAURU
524NEPAL
528HOLLAND
530DUTCH ANTILLES
533ARUBA
540NEW CALEDONIA
548VANUATU
554NEW ZEALAND
558NICARAGUA
562NIGER
566NIGERIA
570NIUE
574NORFOLK ISLANDS
578NORWAY
580NORTHERN MARIANA ISLANDS
581MINOR OUTLYING ISLANDS OF THE UNITED STATES
583FEDERATED STATES OF MICRONESIA
584MARSHALL ISLANDS
585PALAU
586PAKISTAN
591PANAMA
598PAPUA NEW GUINEA
600PARAGUAY
604PERU
608PHILIPPINES
612PITCAIRN (PITCAIRN ISLANDS)
616POLAND
620PORTUGAL
624GUINEA-BISSAU
626EAST TIMOR
630PUERTO RICO
634QATAR
638REUNION
642ROMANIA
643RUSSIAN FEDERATION
646RWANDA
654SAINT HELENA
659SAINT KITTS AND NEVIS
660ANGUILLA

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 153

Id_nacionalidad, id_paisCountry
662SAINT LUCIA
666SAINT PIERRE AND MIQUELON
670SAINT VINCENT AND THE GRENADINES
674SAN MARINO
678SAO TOME AND PRINCIPE
682SAUDI ARABIA
686SENEGAL
690SEYCHELLES
694SIERRA LEONE
702SINGAPORE
703SLOVAKIA
704VIETNAM
705SLOVENIA
706SOMALIA
710SOUTH AFRICA
716ZIMBABWE
724SPAIN
732WESTERN SAHARA
736SUDAN
740SURINAME
744SVALBARD AND JAN MAYEN
748SWAZILAND
752SWEDEN
756SWITZERLAND
760SYRIAN ARAB REPUBLIC
762TAJIKISTAN
764THAILAND
768TOGO
772TOKELAU
776TONGA
780TRINIDAD AND TOBAGO
784UNITED ARAB EMIRATES
788TUNISIA
792TURKEY
795TURKMENISTAN
796TURKS AND CAICOS ISLANDS
798TUVALU
800UGANDA
804UKRAINE
807REPUBLIC OF MACEDONIA (FORMER YUGOSLAV REPUBLIC)
818EGYPT
826UNITED KINGDOM

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 154

Id_nacionalidad, id_paisCountry
834UNITED REPUBLIC OF TANZANIA
840UNITED STATES OF AMERICA
850VIRGIN ISLANDS (U.S.A)
854BURKINA FASO
858URUGUAY
860UZBEKISTAN
862VENEZUELA
876WALLIS AND FUTUNA ISLANDS
882SAMOA
887YEMEN
891SERBIA AND MONTENEGRO
894ZAMBIA
Id_ entidad_reportanteEntity
1105BANCO DE LA PRODUCCION, S.A.
1106BANCO DE CREDITO CENTROAMERICANO, S.A.
1107BANCO DE AMERICA CENTRAL, S.A.
1108BANCO DE FINANZAS, S.A.
1109BANCO UNO, S.A.
1113BANCO PROCREDIT, S.A.
1119FINANCIERA ARREDADORA CENTROAMERICANA, S.A.
1120FINANCIERA NICARAGUENSE DE DESARROLLO, S.A.
1125BANCO HSBC NICARAGUA, S.A.
1132FINANCIERA FAMA, S.A
1133FINANCIERA NICARAGUENSE DE INVERSIONES, S.A.
2101INVERSIONES DE CENTROAMÉRICA, S.A.
2103LAFISE VALORES, S.A.
2105BAC VALORES, S.A.
2107INVERSIONES BURSÁTILES EXPO, S.A.
2109INVERSIONES DE NICARAGUA, S.A.
2110PROVALORES S.A.
2120CENTRAL NICARAGUENSE DE VALORES
2121BOLSA DE VALORES DE NICARAGUA
3101INSTITUTO NICARAGUENSE DE SEGUROS Y REASEGUROS
3102METROPOLITANA COMPAÑÍA DE SEGUROS, S.A.
3103SEGUROS AMÉRICA, S.A.
3104SEGUROS LAFISE, S.A.
3105ASEGURADORA MUNDIAL, S.A.
4101ALMACENADORA FINANCIERA DE NICARAGUA S.A
4102ALMACENADORA LAFISE, S.A
4103ALMACENADORA DE EXPORTACIONES, S.A

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 155

Id_ entidad_reportanteEntity
4104ALMACEN FINANCIERO BAC, S.A

v.2: Validation Catalog

ValidationTableDescription
50.001.0001PLdD_DatosThe id_transaccion is not unique
50.001.0002PLdD_DatosThe id_tipo_reporte is not found in the catalog {1, 2, 3)
50.001.0003PLdD_DatosThe id_tipo_transaccion is not found in the catalog {I, F}.
50.001.0004PLdD_DatosThe id_tipo_operacion is not found in the catalog {11, 12, 13, 14, 15, 16, 17, 18, 21, 22, 23, 24, 25, 26, 27}
50.001.0005PLdD_DatosThe amount cannot be zero or negative
50.002.0001PLdD_PersonasThe type of identification of the Beneficiary/Manager is not found in {1, 2, 3, 4, 5, 6, 7, 9}
50.002.0002PLdD_PersonasThe nationality code (id_pais) of the beneficiary/manager is not valid.
50.002.0003PLdD_PersonasBeneficiaries/Managers with different names.
50.002.0004PLdD_PersonasThe name cannot be empty or with non-significant names {}
50.002.0005PLdD_PersonasThe Beneficiary/Manager's ID does not comply with the check digit algorithm.
50.002.0006PLdD_PersonasThe Beneficiary/Manager's RUC does not comply with the check digit algorithm.
50.003.0001PLdD_Datos_PersonaThe {id_tipo_relacion} was not reported in PLdD_Datos
50.003.0002PLdD_Datos_PersonaThe {id_persona, id_tipo_documento} was not reported in PLdD_Personas
50.003.0003PLdD_Datos_PersonaThe id_tipo_relacion is not found in the catalog {G, B, A}

vi- User Manual for the upload of the Cash Transactions Report (RTE)

vi.1 Introduction

The manual presents a general description of the system, as well as the characteristics of each of the process blocks. For each screen, a brief description of the characteristics and functionality is provided, the data fields are described, values of the lists in case the field has an associated one, and usage instructions.

vi.2 General Description of the System

The data submission system for the different applications and/or systems in a simplified mode can be seen as a tool that allows uploading files from Financial Institutions and then consulting their progress, complying with the validations established by the Superintendence of Banks and Other Financial Institutions (SIBOIF).

vi.2.1 System Structuring

The System is structured in the following function blocks: File Management and Security.

• File Management: This function block contains the processes necessary for file uploading and its status during the system validations, such as: Submissions and Submission Consultation. • Security: This function block contains the process related to the change of user password.

vi.2.1.1 Login

Figure 3 Login Screen

General Description

This option must be the first step the user takes to start using the File Submission System.

The screen contains the following fields:

FieldsDescription
LoginUser ID to enter
PasswordUser password.
EnterWhen pressing the enter button, it validates that the key exists and the password is valid.

Usage Instructions

  1. Enter the user login.
  2. Enter the corresponding password.
  3. Press the Enter button to access the system.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 156

vi.2.1.2 File Management

Figure 4 Menu Options

The File Management function block presents the following options: • Submissions • Submission Consultation

The options presented above are detailed below.

vi.2.1.3 Submissions

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 160 Figure 5 Information Submission Screen General Description Through this screen, the user uploads files corresponding to their Supervised Entity. The screen contains the following fields: Field Description Submission Type List of values that allows specifying the type of submission to be performed. In this case, as the submission type is for uploading accounting balances, the user must select the submission type "" Data Date List of dates that allows the user to specify the cut-off date of the data being sent. File Allows specifying the file to be uploaded via the local path; the file field has a Browse button for uploading information. When clicking on Browse, the file explorer is accessed:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 161 Figure 6 Choose File Window In this file exploration, the file to be loaded into the system is specified; the file extension must be .dat. Once the file is selected, the Open button is pressed. If the Cancel button is pressed, the file selection operation is cancelled. Usage Instructions

  1. Specify the Submission Type
  2. Select the file to be loaded into the system; files to be loaded must be of .dat extension.
  3. Press the upload button, and wait for the generation of the Submission number and the encrypted value of the file.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 162 vi.2.1.4 Submission Query Figure 7 Submission Query Screen General Description Through this screen, the user queries files previously loaded into the System. The Submission Query screen has a Date Range to show the desired loads, at the same time limiting the results to the selected Submission Type. The screen contains the following fields: Field Description Submission Type It is a list of values that allows specifying if the file is of CDR, MUC, Credit Reference Requests and/or Equivalencies of Persons or of the Annexes of the Bank Superintendence, Anti-Money Laundering, etc. Initial Date Starting point where the query is to begin Final Date End point where the query is to finish Query Manages the loads performed within the previously established date range. When clicking on the Initial Date or Final Date field, the following Calendar is shown:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 163 Figure 8 Submission Query - Calendar With which the user will have the flexibility to select the date in an exact and precise way, thereby avoiding typing it. When clicking on the Query button, the following results are shown on screen:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 164 Figure 9 Submission Query Detail Usage Instructions

  1. Specify the Submission Type
  2. Set the initial date
  3. Set the final date
  4. Press the Query button and the loads performed in the selected period will be shown, if any exist. vi.2.1.5 Security Figure 10 Password Change Option The Security Functions Block presents the following options:

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 165 • Password Change The option listed above is detailed below. vi.2.1.6 Password Change Figure 11 Password Change Screen General Description: The Web form for password changes has the purpose of changing the password of the user who is currently online. The password change will take effect upon the next Login. The screen contains the following fields: Field Description Current Password Current password of the online user. New Password New password to be entered. Password Confirmation Confirms the password entered in the previous field Accept Button Replaces the previous password with the new one. Usage Instructions

  1. Type the current password
  2. Type the new password
  3. Confirm the new password specified in the previous field.
  4. Press the Accept button for the changes to take effect.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 166 vii.- Formats with their Instructions vii.1: GNUPG Public Key Exchange This procedure serves as a guide for activities related to the exchange of public keys between Financial Institutions and SIBOIF, with the objective of protecting the information transmitted between them. For this, the data files to be exchanged will be encrypted using the GNUPG encryption tool. Public key exchange requests in financial institutions will be prepared by the security officer or similar position, authorized by their operations manager or similar, and sent to SIBOIF so that the system-owning superintendence and the IT director approve them. And these will be exchanged directly with the SIBOIF Database Administrator (DBA). This procedure will be carried out taking into consideration that the validity of the public keys will have a duration of one year and must be regenerated by each of the involved parties and exchanged again. The exchange will be carried out on a physical storage medium at the SIBOIF facilities. Figure 12 Public Key Exchange Process between SIBOIF and Financial Institutions This procedure will be executed whenever the involved parties need to update keyrings due to the expiration period of public keys established by SIBOIF or well due to early changes in keys by any of the involved parties. In case of expiration

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 167 it must be done one week before the expiration date established by SIBOIF. For changes in public keys, it will be done at the time it is necessary. • The Security Officer of the Supervised Entity together with the operations manager or similar issue a "GNUPG Public Key Exchange Request" (Annex F.1.1) and send it to the system-owning superintendence at SIBOIF. • The system-owning superintendence receives the "GNUPG Public Key Exchange Request" • The system-owning superintendence together with the IT director authorize the request. • The IT director guides the Database and Systems Administrator to attend to said request. • The Database and Systems Administrator receives the request, evaluates it, and assigns to the request a consecutive reference number per institution. This number must be generated as follows: InstitutionAcronyms_yyyy_999

InstitutionAcronyms Acronyms of the Supervised Entity yyyy Current Year 999 Three-digit Consecutive • The Security Officer of the Supervised Entity proceeds to generate the exchange public key and copies it to a floppy disk. • The Database and Systems Administrator of SIBOIF proceeds to generate the exchange public key and copies it to a floppy disk. • The Database and Systems Administrator of SIBOIF exchanges the public key floppies with the Security Officer of the Supervised Entity at the SIBOIF facilities. • The Database and Systems Administrator of SIBOIF performs tests with the Supervised Entity's public key file before passing it to production. • If the tests were satisfactory, the Database and Systems Administrator of SIBOIF guides the Security Officer of the Supervised Entity to fill out the "GNUPG Public Key Exchange Acceptance Act" (Annex F.1.2). • The Security Officer of the Supervised Entity fills out said act accepting the transaction performed and delivers it to the Database and Systems Administrator of SIBOIF • Both parties, once the copies are exchanged and tested, proceed to incorporate them into their respective keyrings. The Database and Systems Administrator of SIBOIF performs a historical backup of expired public keys (Financial Institutions and SIBOIF). vii.1.1: GNUPG Public Key Exchange Request This format is for use by the IT area of financial institutions and for consumption by SIBOIF IT specialists.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 168 vii.1.1.1: GNUPG Public Key Exchange Request Format Bank and Other Financial Institutions Superintendence (SIBOIF) Information Technology Direction (DTI) Technical Support Area GNUPG Public Key Exchange Request Reference No.: General Data To: Name and Surname Position Signature From: Authorizes: Institution: Date: Request Data Description: Observations: Authorizing Signatures Status Name Position Date Time Signature Received Intendence Authorization

DTI Authorization Received Prepared Figure 13 Public Key Exchange Request Format

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 169 vii.1.1.2: GNUPG Public Key Exchange Request Instruction Instruction for the GNUPG Public Key Exchange Request Format To Direct the request to the system coordinator of the owning superintendence at SIBOIF. From / Authorizes Write who is requesting and authorizing the changes (Security Officer or similar position of the Supervised Entity and Operations Manager or similar position). Institution Write the name of the institution which is requesting the update of the new set of keys Preparation Date Write the date on which the request is prepared at the Supervised Entity with the dd/mm/yyyy format. Reference No. This number will be filled by the DBA. • InstitutionAcronyms_yyyy_999 InstitutionAcronyms Acronyms of the Supervised Entity yyyy Year 999 Three-position Consecutive Request Description Explain clearly and concisely to help explain the change, what the required service consists of. If it is due to expiration of public keys, unexpected change in keyring or for a new requirement, etc. Observations Observations noted by the system coordinator, IT director or DBA of SIBOIF if these are necessary Signatures This section is used exclusively by SIBOIF to track the status of the request regarding its attention through the signature of the different people involved in this process: Received Intendence Authorization

DTI Authorization Received Prepared Table 3 GNUPG Public Key Exchange Request Instruction vii.1.2: GNUPG Public Key Exchange Acceptance Act This format is for use and consumption by the DTI technical support area at the Bank Superintendence and is the proof of transaction in the public key exchange between the security officer and the database administrator (DBA).

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 170 vii.1.2.1: GNUPG Public Key Exchange Acceptance Act Format Bank and Other Financial Institutions Superintendence (SIBOIF) Information Technology Direction (DTI) Technical Support Area GNUPG Public Key Exchange Acceptance Act Reference No. To From Institution Exchange Date Exchange Time Current Situation Process Result Expired Keys Keys About to Expire New Requirements Keyring Modifications Others Regenerated Keys Modified Keys Exchanged Keys Others Pass to Production Yes No

Signature Security Officer or Similar Signature of DBA Name Specialist Observations

Figure 14 GNUPG Public Key Exchange Acceptance Act Format vii.1.2.2: GNUPG Public Key Exchange Acceptance Act Instruction Instruction for the GNUPG Public Key Exchange Acceptance Act Format To Write the Name of the Official and the position they hold. This request must be directed to the DBA of SIBOIF. From Write the Name of the Official and the position they hold. For this particular format, the sender is the Security Officer of the Supervised Entity or similar position, as the authority that approves the exchange.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 171 Exchange Date Write the date on which the exchange is accepted with the dd/mm/yyyy format. Exchange Time Write the time at which the exchange is accepted with the HH:MM; a.m. or p.m. format. Institution Write the name of the institution which requested the update of the new set of keys Reference No. Corresponds to the Reference No. of the exchange request corresponding to the institution. Current Situation Indicate which of the indicated options represents the current situation in the Supervised Entity's system. Expired Keys Keys About to Expire New Requirements Keyring Modifications Others Process Results Indicate what was the result of the processes elaborated Regenerated Keys Modified Keys Exchanged Keys Others Pass to Production The DBA indicates if the key exchange procedure ended successfully. Write if you accept to pass to production or not, this will depend on the tests performed by the DBA. If everything is as requested, you must accept to see the change reflected in the systems. Observations If you consider including any observation, or in case the category is Others. Specialist Name Name of the systems and database administrator or person in charge of making changes at SIBOIF. Signature Any exchange act must be signed by both parties, both by the security officer or similar position who requests the exchange as well as by the systems and database administrator who manages the SIBOIF keyrings. Table 4 GNUPG Public Key Exchange Acceptance Act Instruction vii.2 Request for Creation, Deletion, and Changes of Access Accounts. This procedure is the basic guide to be used in activities related to the creation, elimination, and/or modification of access accounts (users) to SIBOIF systems. Through this, each action performed in the global security module of systems regarding user administration and access to specific modules through role assignment is documented and controlled.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 172 These requests are used both in the creation and in the administration of internal or external users and are prepared depending on the type and location of the user, whether for a Supervised Entity or by a specific superintendence within SIBOIF. vii.2.1: Request for Creation, Deletion, and Changes of Access Accounts for External User :: Creation, Deletion, and Changes of Access Accounts to SISBANF - External User - IT Direction DBA SIBOIF System-owning Superintendence Financial Institution Fills the access account format according to their needs Sends the format Receives Notification Notifies to involved users Receives Notification End Reviews Notification Performs actions Receives Notification and/or Privileges Receives, Evaluates and Authorizes Request Receives request, authorizes and guides the attention of the request Figure 15 Request Process for Creation, Deletion, and Changes of Access Accounts This process occurs when a Supervised Entity to which access to use one or more SIBOIF systems has been granted, wishes to create or modify an existing access account. Requests for creation or change in access accounts are prepared by the area head of the Supervised Entity which has access to the system and authorized by the operations manager or similar of the Supervised Entity, sent to SIBOIF for review and approval by the system-owning superintendence and the IT director, and executed directly by the Database Administrator (DBA). • The Supervised Entity creates a "Request for Creation, Deletion, and Changes of Access Accounts for External User" (Annex F.2) and sends it to the system owner at SIBOIF facilities. • The system-owning superintendence together with the IT director receive the request, evaluate feasibility, and approve it. • The IT director sends the request to the DBA, so that he executes it.

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 173 • The DBA receives the request and assigns a consecutive reference number per system. This number must be generated as follows: • SystemAcronyms_yyyy_999 SystemAcronyms CdR Risk Central (CdR) MUC Unique Manual of Accounts (MUC) LdD Money Laundering (LdD) MAR Risk Analysis Model (MAR) ANXBCO Annexes of the Bank Superintendence yyyy Current Year 999 Three-digit Consecutive per system • The DBA proceeds to execute the request, as indicated in it. • In the case of user creation when they are created, the following nomenclature must be followed. InstitutionName_UserName_999 InstitutionName The short name or acronyms of the Financial Institution UserName The name of the user to whom access is granted, this will be composed of: First letter of first name + Last Name Pedro Pérez = pperez 999 Three-position Consecutive per user with the same name and surname • The DBA notifies via email the conclusion of the process. • End of procedure. vii.2.1.1: Format for Request for Creation, Deletion, and Changes of Access Accounts for External User Bank and Other Financial Institutions Superintendence (SIBOIF) Information Technology Direction (DTI) Technical Support Area Request for Creation, Deletion, and Changes of Access Accounts Reference No.: General Data To: Name and Surnames Positions Signatures

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 174 From: Authorizes: Institution: Date: Request Data Actions to Perform User Information • Creation of New User • Modify Existing Profile • Delete Existing User User Names and Surnames: Username: Profile Information 1 Risk Central 1.1 Data Upload 1.1.1 Risk Central 1.1.2 Person Equivalencies 1.2 Credit References 1.2.1 By Batch 1.2.2 Web Services 2 Unique Manual of Accounts 2.1 Data Upload 2.1.1 MUC 2.1.2 Stratifications 2.1.3 Annexes 3 Anti-Money Laundering/FT - RTE 3.1 Data Upload 4. Others 4.1 Information Download Observations: Authorizing Signatures Status Name Position Date Time Signature Received Intendence Authorization

DTI Authorization Received Prepared Figure 16 Format for Request for Creation, Deletion, and Changes of Access Accounts vii.2.1.2: Instruction for Request for Creation, Deletion, and Changes of Access Accounts for External User Instruction for the Request for Creation, Deletion, and Changes of Access Accounts Format To Direct the request to the coordinator of the system-owning superintendence Senders Write who is requesting and authorizing the changes (Area Head of the Supervised Entity and Operations Manager or similar position).

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 175 Institution Write the name of the institution which is making the request Preparation Date Write the date on which the request is prepared at the Supervised Entity with the dd/mm/yyyy format. Reference No. This number will be filled by the DBA. • InstitutionAcronyms_yyyy_999 InstitutionAcronyms Acronyms of the Supervised Entity yyyy Year 999 Consecutive Actions to Perform Indicate which of the indicated options represents the action or actions to be performed in your request according to your needs: Creation of New User Modify an Existing Profile Delete Existing User User Data Write the full name of the user on which the action will be performed, as well as their username for the system Profile Information Indicate which of the indicated options represents the functions or profiles that the user must possess within the system: Risk Central Online Credit Ref. Credit Ref. By Batch Annexes Information Download (Consolidated, Errors, etc.) Unique Manual of Accounts Anti-Money Laundering Signatures This section is used exclusively by SIBOIF to track the status of the request regarding its attention through the signature of the different people involved in this process: Received Intendence Authorization

DTI Authorization Received Prepared Observations Observations noted by the system coordinator, IT director or DBA of SIBOIF if these are necessary. Table 5 Instruction for Request for Creation, Deletion, and Changes of Access Accounts viii.- GNUPG Manual viii.1 Introduction GNUpg is the free software world implementation of PGP, this is an asymmetric encryption system, that is, it consists of a public key and a private key, with this system one can perform both data encryption (with the public key), as well as file signing to ensure the

RESOLUCIÓN No. CD-SIBOIF-524-1-MAR5-2008 176 integrity and authenticity of the information. The following steps describe how to generate keys, export them, and import them into the system.

viii.2 Generating Keys To generate keys, the following command is used: gpg --gen-key

The system will ask for the type of key, the key size, and the expiration date. It is recommended to use RSA and RSA keys with a size of 2048 bits or higher. The expiration date should be set according to the policy established by SIBOIF, which is one year.

viii.3 Exporting Keys Once the keys are generated, they must be exported to be shared with SIBOIF. The public key is exported using the following command: gpg --export --armor [Key ID] > public_key.asc

The private key is exported using the following command: gpg --export-secret-keys --armor [Key ID] > private_key.asc

It is important to keep the private key secure and not share it with anyone.

viii.4 Importing Keys To import the public key received from SIBOIF, the following command is used: gpg --import public_key.asc

To import the private key, the following command is used: gpg --import private_key.asc

After importing the keys, they must be verified to ensure they are correct.

viii.5 Encrypting Files To encrypt a file using the public key, the following command is used: gpg --encrypt --recipient [Recipient Key ID] [File Name]

This will create an encrypted file with the .gpg extension.

viii.6 Decrypting Files To decrypt a file using the private key, the following command is used: gpg --decrypt [File Name]

The system will ask for the passphrase of the private key.

viii.7 Signing Files To sign a file, the following command is used: gpg --sign [File Name]

This will create a signed file with the .sig extension.

viii.8 Verifying Signatures To verify a signature, the following command is used: gpg --verify [File Name] [Signature File]

This will verify if the signature is valid.

viii.9 Key Management To list the keys in the keyring, the following command is used: gpg --list-keys

To list the secret keys, the following command is used: gpg --list-secret-keys

To delete a key, the following command is used: gpg --delete-keys [Key ID]

gpg --delete-secret-keys [Key ID]

It is important to be careful when deleting keys, as this action cannot be undone.

viii.10 Troubleshooting If there are problems with key generation, encryption, or decryption, the following steps should be taken:

  1. Verify that the GNUPG software is installed correctly.
  2. Verify that the key IDs are correct.
  3. Verify that the file paths are correct.
  4. Check the error messages for more information.

If the problem persists, contact the SIBOIT technical support team.

viii.11 Security Recommendations

  1. Always use strong passphrases for private keys.
  2. Never share private keys with anyone.
  3. Keep the GNUPG software updated.
  4. Regularly backup the keyrings.
  5. Use secure channels to exchange keys.
  6. Verify the identity of the other party before exchanging keys.
  7. Do not use keys that have expired.
  8. Report any suspicious activity to the SIBOIF security team.

viii.12 Glossary • GNUPG: GNU Privacy Guard, a free implementation of the OpenPGP standard. • PGP: Pretty Good Privacy, a data encryption and decryption computer program. • Public Key: A key that can be shared with anyone and is used to encrypt data. • Private Key: A key that must be kept secret and is used to decrypt data. • Keyring: A file that stores the keys. • Passphrase: A password used to protect the private key. • Encryption: The process of converting data into a code to prevent unauthorized access. • Decryption: The process of converting coded data back into its original form. • Signature: A digital signature that verifies the authenticity and integrity of a file. • Key ID: An identifier for a key. • DBA: Database Administrator. • SIBOIF: Superintendencia de Bancos y Otras Instituciones Financieras. • DTI: Dirección de Tecnología de la Información. • CDR: Central de Riesgo. • MUC: Manual Único de Cuentas. • LdD: Lavado de Dólares. • MAR: Modelo de Análisis de Riesgo. • ANXBCO: Anexos de la Intendencia de Bancos. • RTE: Reporte de Transacciones Extranormales.

viii.13 References • GNUPG Manual: https://www.gnupg.org/gph/en/manual.html • OpenPGP Standard: https://www.ietf.org/rfc/rfc4880.txt • SIBOIF Security Policy: [Internal Document]

viii.14 Revision History • Version 1.0: Initial release. • Version 1.1: Updated key exchange procedures. • Version 1.2: Added troubleshooting section.

viii.15 Contact Information For questions or support, please contact: SIBOIF IT Support Team Email: soporte@siiboif.gob.ve Phone: +58-212-555-1234

End of Document

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 176 authenticity (using the private key and the recipient to sign). This document is intended only as a brief guide for encrypting and decrypting files; for comprehensive inquiries: http://www.gnupg.org/gph/es/manual/book1.html http://www.gnupg.org/gph/es/manual/book1.html

viii.2 Generation of Keys First of all, we need a computer that has the GNUpg package installed. The installation program is located on the GnuPG main page. http://www.gnupg.org/ http://www.gnupg.org/download/ The installation file for Windows can be located directly at the following link: ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.1.exe Once the program has been downloaded, you must double-click it, and it will install itself (gnupg-w32cli-1.4.1.exe). Modify the c:\autoexec.bat with the following instruction: SET PATH=%PATH%;C:\Archivos de programa\GNU\GnuPG Once this is done, we generate the key pair, the public and private keys, with the command: gpg --gen-key If this is the first time we run it, it will create the file “C:/Documents and Settings/jperez/Application Data/gnupg\pubring.gpg” where the configurations and keys are saved, and it must be run again to launch the creation process, which is a menu system shown and commented on below. gpg --gen-key gpg (GnuPG) 1.4.1; Copyright (C) 2005 Free Software Foundation, Inc. This program comes with ABSOLUTELY NO WARRANTY. This is free software, and you are welcome to redistribute it under certain conditions. See the file COPYING for details. gpg: keyring C:/Documents and Settings/pparamo/Application data/gnupg\secring.gpg' created gpg: keyring C:/Documents and Settings/pparamo/Application data/gnupg\pubring.gpg' created Please select what kind of key you want: (1) DSA and Elgamal (default) (2) DSA (sign only) (5) RSA (sign only)

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 177 Your selection? 1 We select the default key type, ElGamal. DSA keypair will have 1024 bits. ELG-E keys may be between 1024 and 4096 bits long. What keysize do you want? (2048) 2048 With this we select the length of the key. The key length required by SIBOIF for this process is 2048 bits. Requested keysize is 2048 bits Please specify how long the key should be valid. 0 = key does not expire <n> = key expires in n days <n>w = key expires in n weeks <n>m = key expires in n months <n>y = key expires in n years Key is valid for? (0) 1y Key expires at 06/06/06 10:35:53 Is this correct? (y/N) y Next, we are asked for the time for which the public key will be valid. For our example, we consider one year sufficient. We answer yes and continue. You need a user ID to identify your key; the software constructs the user ID from the Real Name, Comment and Email Address in this form: "Heinrich Heine (Der Dichter) heinrichh@duesseldorf.de" Real name: Pedro Páramo Email address: pparamo@siboif.gob.ni Comment: SIBOIF_DTI_Technical Support. The fields are filled with the identifiers we are going to use. You are using the `CP850' character set. You selected this USER-ID: "Pedro Páramo (SIBOIF_DTI_Technical Support.) pparamo@siboif.gob.ni" Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? o You need a Passphrase to protect your secret key. If it is correct, we press O and continue. You need a Passphrase to protect your private key.

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 178 Enter passphrase: We need a key to protect our private key; it is advisable to choose one that is as long and complex as possible, since the weak point of asymmetric encryption is the protection of this key. Repeat passphrase: We repeat the key. With this process, we already have the keys generated and we can sign and encrypt documents. To check that everything is correct, we look to see if the keys have been generated. gpg --list-keys

viii.3 Encrypting Files To encrypt documents, we proceed as follows: we look for the file we want to encrypt and execute the following command: gpg -o encrypted_file -e original_file You did not specify a user ID. (you may use "-r") Current recipients: Enter the user ID. End with an empty line: jperez@siboif.gob.ni Current recipients: 2048g/2B993C22 2005-06-02 "Pedro Páramo pparamo@siboif.gob.ni" Enter the user ID. End with an empty line: It is advisable to delete the unencrypted file once we are sure that the encrypted file has been created.

viii.4 Decrypting Files To decrypt the file we had previously encrypted: gpg -o file -d encrypted_file You need a passphrase to unlock the secret key for user: "José Pérez jperez@siboif.gob.ni" 2048-bit ELG-E key, ID 7C4D8652, created 2005-06-03 (main key ID A216DAED) gpg: encrypted with 2048-bit ELG-E key, ID 7C4D8652, created 2005-06-03 "José Pérez jperez@siboif.gob.ni"

RESOLUTION No. CD-SIBOIF-524-1-MAR5-2008 179 It will ask for the key we set when we created the keys; with this, we ensure that only someone who knows it can decrypt it. With this brief document, we have intended to give a quick description of how to encrypt and decrypt files simply and quickly.

viii.5 Generating the Public Key To send the public key to a third party, you must give the following command: gpg --armor --export pparamo@siboif.gob.ni > pparamo_pk To view the content of the public key: type pparamo_pk

viii.6 Importing a Public Key to Your Keyring To import a public key, you must give the following command: gpg --import jperez_pk gpg: key 9104CDDA: public key "Josè jperez@siboif.gob.ni" imported gpg: Total number processed: 1 gpg: imported: 1

More like this from SIBOIF

We email you every new SIBOIF publication the day it's published.

Topics
Share