2019-07-30

Added · Updated

Provisions on Customer Due Diligence for the Prevention of Money Laundering and Terrorist Financing

The Bank of Italy issues provisions establishing the framework for customer due diligence to prevent money laundering and terrorist financing. The document applies to banks, securities intermediation companies, asset management companies, electronic money institutions, payment institutions, and other specified financial entities. It mandates a risk-based approach for assessing money laundering and terrorist financing risks, defining specific obligations for customer identification, beneficial owner verification, and ongoing monitoring. The text details simplified and enhanced due diligence measures, including specific procedures for remote operations, high-risk third countries, cross-border correspondent relationships, and politically exposed persons.

Banca d'Italia logo

Italy

Banca d'Italia

Click to view thumbnail

This document conforms to the original contained in the archives of the Bank of Italy. Digitally signed by Legal Headquarters: Via Nazionale, 91 - P.O. Box 2484 - 00100 Rome - Paid-in Capital: Euro 156,000.00 Tel. 06/47921 - Telex 630045 BANKIT - VAT No. 00950501007 - www.bancaditalia.it

PROVISIONS ON CUSTOMER DUE DILIGENCE FOR THE PREVENTION OF MONEY LAUNDERING AND TERRORIST FINANCING

INDEX PRELIMINARY PROVISIONS.......................................................................................................1 Legal Sources ................................................................................................................................1 Recipients ........................................................................................................................................1 Definitions .......................................................................................................................................2 PART ONE – ASSESSMENT OF MONEY LAUNDERING AND TERRORIST FINANCING RISK FACTORS........................................................................................7 Section I. The risk-based approach principle..................................................................7 Section II. General criteria and informative sources useful for risk assessment .........................7 Section III. Customer profiling..............................................................................................9 PART TWO – DUE DILIGENCE OBLIGATIONS .................................................11 Section I. Content of customer due diligence obligations.......................................11 Section II. Scope of application................................................................................................11 Section III. Identification of the customer and the executor.............................................................12 Section IV. Identification of the beneficial owner .......................................................................13 Section V. Verification of data relating to the customer, the executor and the beneficial owner...................14 Section VI. Acquisition and assessment of information on the intended purpose and nature of the ongoing relationship and occasional transactions.....................................................................15 Section VII. Ongoing monitoring during the ongoing relationship .........................................16 Section VIII. Specific provisions on remote operations ...................................16 PART THREE – SIMPLIFIED DUE DILIGENCE OBLIGATIONS..........................18 Section I. General principles ............................................................................................................18 Section II. Simplified due diligence measures.....................................................................18 PART FOUR – ENHANCED DUE DILIGENCE OBLIGATIONS .........................20 Section I. General principles ............................................................................................................20 Section II. Enhanced due diligence measures .........................................................................20 Section III. Relationships and occasional transactions involving high-risk third countries..........21 Section IV. Cross-border correspondent relationships with a banking or financial intermediary responsible in a third country.......................................................................................22 Section V. Politically Exposed Persons.....................................................................................23 Section VI. Transactions characterized by unusually high amounts or for which there are doubts about the purpose..........................................................................................................................24 PART FIVE – EXECUTION BY THIRD PARTIES OF DUE DILIGENCE OBLIGATIONS..................................................................................................................26 Section I. Scope of application and responsibility .......................................................................26 Section II. Content and methods of execution of obligations.....................................................27

PART SIX – SPECIFIC PROVISIONS FOR PARTICULAR OPERATIONAL TYPES ....................................................................................................................................29 ANNEX 1 Low-risk factors ...........................................................................................31 ANNEX 2 High-risk factors.........................................................................................33 ANNEX 3 Video-identification procedure .........................................................................37

1 PRELIMINARY PROVISIONS Legal Sources The matter is governed by: – Legislative Decree 21 November 2007, No. 231, as amended by Legislative Decree 25 May 2017, No. 90, and in particular: • Article 7, paragraph 1, letter a), which grants the Bank of Italy the power to issue provisions on customer due diligence; • Article 19, paragraph 1, letter a), No. 5, which assigns the Bank of Italy the task of identifying suitable forms and methods for the remote acquisition of customer identification data for the purpose of fulfilling the identification obligation, taking into account the evolution of remote identification techniques; • Article 23, paragraph 3, which grants the Bank of Italy the power to: i) identify additional low-risk factors beyond those listed in paragraph 2 of the same article, as well as the power to establish simplified due diligence measures to be adopted in low-risk situations; ii) identify the type of simplified due diligence measures that banks and electronic money institutions are authorized to adopt in relation to particular types of electronic money products; • Article 24, paragraph 4, which grants the Bank of Italy the power to identify additional high-risk factors beyond those listed in paragraph 2 of the same article, as well as the power to establish enhanced due diligence measures to be adopted in high-risk situations; • Article 27, paragraph 5, which grants the Bank of Italy the power to identify further operational types beyond consumer credit and leasing in which identification can be carried out by external collaborators linked to the intermediary by specific agreement. Also relevant are: – Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015, as amended by Directive (EU) 2018/843, on the prevention of the use of the financial system for the purpose of money laundering and terrorist financing; – Joint Guidelines of the European Supervisory Authorities, issued pursuant to Article 17 and Article 18, paragraph 4, of Directive (EU) 2015/849 on simplified and enhanced customer due diligence measures and on the factors that credit institutions and financial institutions should take into consideration when assessing the money laundering and terrorist financing risks associated with individual ongoing relationships and occasional transactions.

Recipients These provisions apply to: a) banks; b) securities intermediation companies (SIM); c) asset management companies (SGR); d) variable capital investment companies (SICAV); e) fixed capital investment companies, securities and real estate (SICAF); f) intermediaries registered in the register provided for by Article 106 of the TUB; g) electronic money institutions; h) payment institutions; i) branches established in Italy of banking and financial intermediaries having their legal seat and central administration in another EU country or a third country; j) banks, payment institutions and electronic money institutions having their legal seat and central administration in another EU country required to designate a central contact point in Italy pursuant to Article 43, paragraph 3, of the anti-money laundering decree; k) fiduciary companies registered in the register provided for pursuant to Article 106 of the TUB; l) guarantee funds (confidi) (1); m) micro-credit providers, pursuant to Article 111 of the TUB; n) Poste Italiane S.p.A., for the bancoposta activity; o) Cassa Depositi e Prestiti S.p.A.. In credit securitization transactions governed by Law 30 April 1999, No. 130, the obligations under these Provisions are fulfilled by the subjects referred to in Article 2, paragraph 6, of the same law.

Definitions For the purposes of these provisions, the following terms are understood as:

  1. "financial activity agents": agents registered in the list provided for by Article 128-quater, paragraphs 2 and 6, of the TUB;
  2. "senior executive": a director or the general manager or another employee delegated by the management body or by the general manager to follow up on relationships with high-risk customers; the senior executive has adequate knowledge of the level of money laundering or terrorist financing risk to which the recipient is exposed and possesses a sufficient level of autonomy to make decisions capable of impacting this level of risk;
  3. "institutional activity": the activity for which the recipients have obtained registration or authorization from a Public Authority;
  4. "shell bank": a bank (or a financial intermediary performing functions analogous to a bank) lacking a significant structure in the country where it was incorporated and authorized to conduct business, and not belonging to a financial group subject to effective consolidated supervision;
  5. "customer": the subject that establishes or maintains ongoing relationships or carries out occasional transactions with the subjects indicated in the "recipients" paragraph (2); in the case of ongoing relationships or occasional transactions jointly held by multiple subjects, each co-owner is considered a customer;

(1) The reference is to be understood as referring to the confidi provided for by Article 155 of the TUB, in the text prior to the entry into force of Title III of Legislative Decree 13 August 2010, No. 141.

(2) In credit transfer transactions, when the transferred credits originate from relationships not subject to these Provisions, the assigned debtors are not considered customers, even occasional, of the assignee companies. The assigned debtor acquires the status of customer of the assignee intermediary if a new agreement intervenes between the assignee intermediary and the assigned debtor, even in the form of payment deferral (unless the latter is gratuitous).

(3) Subjects entrusted by a public authority with the administration of the customer's assets and relationships or their representation (such as, for example, bankruptcy trustees) are considered executors.

  1. "pass-through accounts": cross-border correspondent relationships, maintained between banking and financial intermediaries, used to carry out transactions on own account and on behalf of customers;

  2. "identification data": first and last name, place and date of birth, residential address and domicile, if different from the residential address, details of the identification document and, if assigned, the tax code, or, in the case of subjects other than natural persons, the name, legal seat and, if assigned, the tax code;

  3. "anti-money laundering decree": Legislative Decree 21 November 2007, No. 231, as amended by Legislative Decree 25 May 2017, No. 90, implementing Directive (EU) 2015/849;

  4. "cash" or "cash": banknotes and coins, in euros or foreign currencies, having legal tender;

  5. "recipients": the subjects to whom these provisions apply, indicated in the "recipients" paragraph;

  6. "anti-money laundering directive": Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015, on the prevention of the use of the financial system for the purpose of money laundering of proceeds of criminal activity and terrorist financing;

  7. "provisions on internal anti-money laundering controls": "Provisions on organization, procedures and internal controls aimed at preventing the use of intermediaries for money laundering and terrorist financing", adopted by the Bank of Italy on 26 March 2019;

  8. "anti-money laundering policy document": the document defined by the management body and approved by the strategic supervision body pursuant to the Provisions on organization, procedures and internal controls aimed at preventing the use of intermediaries for money laundering and terrorist financing, adopted by the Bank of Italy on 26 March 2019 (see Part One, Sections II and III);

  9. "executor": the subject delegated to act in the name and on behalf of the customer or to whom powers of representation are otherwise conferred allowing them to act in the name and on behalf of the customer (3);

  10. "terrorist financing": in accordance with Article 1, paragraph 1, letter d), of Legislative Decree 22 June 2007, No. 109: "any activity, by any means, direct or indirect, aimed at the provision, collection, raising, intermediation, deposit, custody or disbursement of funds and economic resources, however realized, intended to be, directly or indirectly, in whole or in part, used for the commission of one or more acts with terrorist purposes, as provided for by criminal laws, regardless of the actual use of the funds and economic resources for the commission of the aforementioned acts";

  11. "FATF": Financial Action Task Force, an body established within the OECD specialized in the sector of prevention and combating money laundering, terrorist financing and the proliferation of weapons of mass destruction;

  12. "group": the banking group governed by Article 60 of the TUB and implementing provisions, the financial group governed by Article 109 of the TUB and implementing provisions, the group provided for by Article 11 of the TUF and implementing provisions, as well as, outside these cases and if recipients of these provisions, controlled and controlling companies pursuant to Article 2359 of the Civil Code and their respective controlling companies;

  13. "EU banking and financial intermediaries": the subjects referred to in Article 3, paragraphs 1 and 2, of the "anti-money laundering directive" having their seat in an EU country;

  14. "payment instruments": cash, bank and postal checks, cashier's checks and other checks assimilated or equated thereto such as traveler's checks, postal money orders, credit or payment orders, credit cards and other payment cards, transferable insurance policies, pawn policies and any other instrument that allows the transfer, movement or acquisition of funds, assets or financial resources, also via telematic means;

  15. "MoneyVal": Committee established within the Council of Europe, acting in the capacity of the FATF regional body for the Euro-Asian area;

  16. "transaction": the activity consisting in the movement, transfer or transmission of payment instruments or the performance of contractual acts with a patrimonial content;

  17. "structured transaction": a unitary transaction under an economic perspective with an amount equal to or greater than the limits established by the anti-money laundering decree, carried out through multiple transactions individually of an amount lower than the aforementioned limits, carried out at different times and within a limited period of time fixed at seven days, provided that elements exist to consider it as such;

  18. "occasional transaction": a transaction not attributable to an existing ongoing relationship;

  19. "Joint Guidelines": Joint Guidelines of the European Supervisory Authorities, adopted on 26 June 2017, pursuant to Articles 17 and 18, paragraph 4, of the anti-money laundering directive, on risk factors that intermediaries should take into consideration when assessing the money laundering and terrorist financing risks associated with customers and on due diligence measures to be adopted;

  20. "EU countries": countries belonging to the European Economic Area;

  21. "third countries": countries not belonging to the European Economic Area;

  22. "high-risk third countries": countries not belonging to the European Economic Area with strategic deficiencies in their national regimes for the prevention of money laundering and terrorist financing, as identified by the European Commission in the exercise of the powers governed by Articles 9 and 64 of the anti-money laundering directive;

  23. "politically exposed persons (PEPs)": natural persons indicated in Article 1, paragraph 2, letter dd) of the anti-money laundering decree;

  24. "public administration": the public administrations provided for in Article 1, paragraph 2, of Legislative Decree 30 March 2001, No. 165, and subsequent amendments, national public bodies, companies owned by public administrations and their subsidiaries, pursuant to Article 2359 of the Civil Code, limited to their public interest activity governed by national or European Union law, as well as subjects responsible for tax collection within national or local taxation, regardless of their legal form;

  25. "relationships assimilated to pass-through accounts": relationships however named maintained between banking and financial intermediaries on which the customer of the responsible entity is granted the right to execute directly even only part of the transactions pertaining to them;

  26. "ongoing relationship": a relationship of duration, which does not end in a single transaction, falling within the exercise of the institutional activity of the recipients;

  27. "correspondent relationships": accounts held by banks for the settlement of interbank services (remittance of bills, cashier's and bank checks, deposit orders, fund transfers, documentary remittances and other operations) as well as relationships, however named, maintained between banking and financial intermediaries used for the settlement of transactions on behalf of the customers of the responsible entities (e.g., securities deposit, investment services, foreign exchange operations, document collection services, issuance or management of debit or credit cards);

  28. "money laundering", pursuant to Article 2, paragraph 4, of the anti-money laundering decree: a. the conversion or transfer of assets, carried out knowing that they originate from criminal activity or participation in such activity, with the aim of concealing or disguising the illegal origin of the assets themselves or helping anyone involved in such activity to escape the legal consequences of their actions; b. the concealment or disguise of the true nature, origin, location, disposition, movement, ownership of assets or rights thereto, carried out knowing that such assets originate from criminal activity or participation in such activity; c. the acquisition, possession or use of assets knowing, at the time of their receipt, that such assets originate from criminal activity or participation in such activity; d. participation in one of the acts provided for in the preceding letters, association to commit such an act, attempt to perpetrate it, helping, instigating or advising someone to commit it or facilitating its execution;

  29. "contracted subjects and agents": operators, however named, other than financial activity agents, whom payment service providers and electronic money issuing institutions, including those having their legal seat and central administration in another EU country, avail themselves of for the exercise of their activity on the territory of the Republic;

  30. "beneficial owner": a. the natural person or natural persons on whose behalf the customer establishes an ongoing relationship or carries out an operation (briefly, "beneficial owner sub 1"); b. in the case where the customer or the subject on whose behalf the customer establishes an ongoing relationship or carries out an operation are entities other than a natural person, the natural person or natural persons to whom, ultimately, direct or indirect ownership of the entity or its control is attributable or who are beneficiaries thereof (briefly, "beneficial owner sub 2"). In particular, in the case of capital companies or other private legal persons, even if based abroad, and express trusts, regardless of their place of establishment and the law applicable to them, the beneficial owner sub 2) is identified according to the criteria provided for in Articles 20 and 22, paragraph 5, of the anti-money laundering decree; the same criteria apply, insofar as compatible, in the case of partnerships and other subjects, public or private, even if lacking legal personality;

  31. "TUB": Legislative Decree 1 September 1993, No. 385, containing the Consolidated Law of Banking and Credit;

  32. "TUF": Legislative Decree 24 February 1998, No. 58, containing the Consolidated Law of Provisions on Financial Intermediation;

  33. "UIF": the Financial Intelligence Unit for Italy established at the Bank of Italy pursuant to Article 6 of the anti-money laundering decree.

7

PART ONE ASSESSMENT OF MONEY LAUNDERING AND TERRORIST FINANCING RISK FACTORS

Section I. The principle of the risk-based approach

This Part establishes the general criteria to which recipients adhere to identify and assess money laundering and terrorist financing risks associated with customers and, consequently, to grade the methods for carrying out due diligence.

Based on the principle of the risk-based approach, the intensity and extent of due diligence obligations are modulated according to the degree of money laundering and terrorist financing risk associated with the individual customer (4). Recipients define and formalize, in the anti-money laundering policy document, customer due diligence procedures that are sufficiently detailed; the document must indicate at least the specific measures (among those listed in Section II and Parts Three and Four) of simplified and enhanced due diligence to be adopted in relation to different types of customers or products.

Recipients exercise their autonomy responsibly, considering all relevant risk factors.

The assessment systems and decision-making processes adopted ensure consistent behavior throughout the entire organizational structure and the traceability of checks carried out and assessments made, also to demonstrate to the authorities that the specific measures taken are adequate with respect to the risks identified in concrete terms.

Section II. General criteria and useful information sources for risk assessment

A. General criteria

To assess the risk of money laundering and terrorist financing (5), recipients consider the general criteria provided for in Article 17, paragraph 3, of the anti-money laundering decree, which refer to the characteristics of the customer, their conduct, and the specifics of the transaction or ongoing relationship.

  1. General assessment criteria concerning the customer

In identifying risk factors pertaining to a customer, recipients also consider the beneficial owner and, where relevant, the agent. Recipients assess the scope of activity and the characteristics of the customer, the beneficial owner, and, where relevant, the agent, as well as the country or geographic area in which they have their headquarters or residence or domicile or from which the funds originate (6); they also note the location of the activity carried out and the countries with which the customer, the beneficial owner, and, where relevant, the agent have significant connections.

The importance of risk factors linked to the country or geographic area varies in relation to the type of ongoing relationship or transaction.

Recipients consider the behavior held by the customer or the agent at the time of opening ongoing relationships or carrying out transactions.

In the case of a customer other than a natural person, recipients consider the purposes of its establishment, the goals it pursues, the methods through which it operates to achieve them, as well as the legal form adopted, especially if it presents particular elements of complexity or opacity.

Recipients verify whether the customer and the beneficial owner are included in the "lists" of persons and entities associated with terrorist financing activities adopted by the European Commission.

Recipients also avail themselves, as auxiliary tools, of the anomaly indicators and the Communications on the prevention of terrorist financing published by the UIF.

  1. General assessment criteria concerning the relationship or transaction

Recipients consider the structure of the product or service offered by them, in terms of transparency and complexity, and the channels through which it is distributed. In assessing the risk associated with the complexity of the product, service, or transaction, recipients consider the possible involvement of a plurality of parties or countries.

Recipients pay attention to new or innovative products or services, particularly in the case where, for the offer of these products or services, they avail themselves of new technologies or new payment methods. Recipients also consider whether the product, service, or transaction is normally associated with the use of cash and whether they allow for high-value transactions. Recipients assess the reasonableness of the ongoing relationship or transaction in relation to the activity carried out and the overall economic profile of the customer and the beneficial owner, taking into account all available information (e.g., income and asset capacity) and the nature and purpose of the relationship. In this context, recipients may carry out comparative assessments with the operations of subjects with similar professional or dimensional characteristics, economic sector, or geographic area.

With reference to risk factors linked to distribution channels, reference is made to Part Five for the safeguards to be adopted in the case of due diligence by third parties.

B. Useful information sources for risk assessment

Recipients draw information for the identification of the customer's risk profile from every useful source and document, including: the report adopted by the European Commission pursuant to Article 6 of the anti-money laundering directive (so-called Supranational Risk Assessment Report); the report adopted by the Financial Stability Committee pursuant to Article 14 of the anti-money laundering decree containing the "National Risk Analysis"; reports published by investigative and judicial authorities (7); documents from supervisory authorities (such as communications and

(4) The risk-based approach can be exercised within the limits set by the legal system. In no case can it be invoked by recipients to justify conduct that results in non-compliance with obligations specifically defined by legal provisions or these provisions. Among these are the freezing obligations provided for with regard to subjects included in Community lists, also issued in implementation of Resolutions of the United Nations Organization, to combat terrorist financing and the activities of countries threatening international peace and security. It follows that it will not be possible to establish or maintain a business relationship with subjects included in these lists, except within the limits and under the conditions strictly provided for. (5) The risk factors to be taken into consideration for the fight against terrorist financing often overlap with those related to the fight against money laundering; however, terrorist financing has characteristics distinct from money laundering, both because the sums used are generally of lower amount, and because the origin of the funds may also be lawful. Recipients apply the safeguards provided for in these provisions also in the key of combating the financing of weapons of mass destruction development programs.

8

sanctioning measures) and from the UIF, such as, for example, indicators, anomaly schemes, and cases of money laundering.

Recipients may also take into consideration information coming from statistical institutes and reputable journalistic sources.

In the case of relationships or transactions involving a third country, recipients assess the overall robustness of the existing anti-money laundering safeguards in that country. To this end, they may consult: mutual evaluation reports adopted by the FATF (8) or analogous international bodies (9); the list published by the FATF of high-risk and non-cooperative countries; reports published by the International Monetary Fund within the framework of the Financial Sector Assessment Programme (FSAP). Recipients verify whether the country is subject to financial sanctions, embargoes, or measures related to terrorist financing or the proliferation of weapons of mass destruction.

For the identification of third countries characterized by a low level of fiscal transparency or poor compliance with tax obligations, recipients consult the reports approved by the OECD Global Forum on fiscal transparency and exchange of information, as well as assessments on the commitment to automatic exchange of information based on the so-called "Common Reporting Standard".

Section III. Customer profiling

Recipients define the risk profile attributable to each customer, based on the overall assessment elements and risk factors described in Section II and Annexes 1 and 2. The different risk factors are weighted based on their relative importance. As a result of profiling, each customer is included in one of the predefined risk classes established by the recipients.

The elaboration of the risk profile is based, as far as possible, on algorithms and computer procedures. Recipients ensure that the risk class proposed automatically by computer systems is consistent with their knowledge of the customer, applying, if necessary, higher risk classes. The lowering of the risk level or controls by operators must be restricted to exceptional cases and must be detailed and motivated in writing.

If the computer system is provided by external subjects, recipients adequately know the functioning of the system and the criteria that determine the attribution of the risk class.

For recipients belonging to a group, when customer profiling is not centralized, it is carried out by individual companies also based on the information used by other companies in the group. Each company assumes, for the same customer, the highest risk profile among those assigned by all companies in the group. Where it intends to attribute a lower risk profile than that assigned by other companies in the group, the reasons for the choice are specifically motivated in writing. When a company changes the risk class of a customer, it communicates this to the other interested companies.

(6) For the purpose of defining the customer's risk profile, trust companies take into account, also in the course of the ongoing relationship, the characteristics of the company in which they acquire a fiduciary participation (e.g., headquarters, operational sector, possible submission to bankruptcy proceedings). For the same purposes, in the case of fiduciary ownership of insurance policies, any useful information on the beneficiaries thereof is relevant. (7) For example, with reference to resident customers or those with headquarters in Italy, useful information to know the degree of infiltration of economic crime, socio-economic or institutional weakness factors, and phenomena of underground economy can be drawn from the annual reports made by: various judicial bodies on the occasion of the inauguration of the judicial year; the National Anti-Mafia Directorate; the Ministry of the Interior on the activity of the Anti-Mafia Investigative Directorate and on the activity of the Police Forces, the state of public order and security, and organized crime. (8) The fact that a country is a member of the FATF or of analogous international bodies (e.g., MoneyVal) does not constitute in itself a presumption of adequacy of its money laundering prevention and combating system. (9) In this context, recipients pay particular attention to the information contained in the following parts of the mutual evaluation reports: executive summary; "Key findings"; assessments on compliance with Recommendations no. 10, no. 26, and no. 27 and "Immediate outcomes" no. 3 and no. 4.

9

To each risk class, recipients associate a coherent level of depth and extent of the measures adopted in the different areas of due diligence.

With regard to ongoing relationships, recipients define the ordinary frequency of updating customer profiling in coherence with its risk level. Recipients verify the congruity of the risk class assigned to the occurrence of events or circumstances that are capable of modifying the risk profile (e.g., in the case of acquisition of PEP status, significant changes in the customer's or beneficial owner's operations or shareholding).

10

PART TWO DUE DILIGENCE OBLIGATIONS

Section I. Content of customer due diligence obligations

Customer due diligence consists of the following activities: a) identification of the customer and any agent; b) identification of any beneficial owner; c) verification of the identity of the customer, any agent, and any beneficial owner based on documents, data, or information obtained from a reliable and independent source; d) acquisition and evaluation of information on the purpose and nature of the ongoing relationship and, in the presence of a high risk of money laundering and terrorist financing, of the occasional transaction; e) exercise of constant monitoring during the ongoing relationship.

When recipients are unable to comply with customer due diligence obligations, they do not establish the ongoing relationship nor execute the transaction (see art. 42 of the anti-money laundering decree). If the impossibility occurs for an existing ongoing relationship, they refrain from continuing the relationship. In these cases, recipients also assess whether to send a suspicious transaction report.

Section II. Scope of application

Recipients proceed with customer due diligence in relation to relationships and transactions that fall within their institutional activity, as defined by sector legislation.

Due diligence is not required for activities aimed at or connected to the organization, functioning, and administration of the recipients, given that they do not fall within the institutional activities proper to the recipients and that, in their performance, the recipients' counterparties constitute providers of goods or services on the initiative of the recipients themselves, rather than customers requesting to establish an ongoing relationship or carry out an occasional transaction (e.g., supplies for the acquisition of materials or instrumental goods; acquisition and maintenance of the buildings where the institutional activity is exercised; services acquired from self-employed professionals for consultations) (10).

The due diligence activities provided for in letters a), b), c), d) of Section I are carried out at least at the following times and circumstances: a) when an ongoing relationship is established; b) when an occasional transaction is carried out by the customer that: (i) involves the transmission or movement of payment instruments of an amount equal to or greater than 15,000 euros, regardless of whether it is carried out with a single operation or with more fractional operations; or (ii) consists in a fund transfer (11) exceeding 1,000 euros. The amount limits do not apply, and due diligence is therefore always due, for all occasional transactions carried out as a payment service or for the issuance and distribution of electronic money through agents in financial activity or "conventional subjects and agents".

Occasional transactions also include cases where banks, electronic money institutions, payment institutions, or Poste Italiane S.p.A. act as intermediaries or are otherwise parties in transfers of cash or bearer securities carried out for any reason between different subjects, of a total amount equal to or greater than 15,000 euros; c) when there is suspicion of money laundering or terrorist financing, regardless of any applicable derogation, exemption, or threshold; recipients avail themselves of the anomaly indicators and schemes representing anomalous behaviors issued by the UIF, pursuant to the anti-money laundering decree; d) when doubts arise regarding the completeness, reliability, or truthfulness of the information or documentation previously acquired (e.g., in the case of non-delivery of correspondence to the communicated address or inconsistencies between documents presented by the customer or otherwise acquired by the recipient).

Recipients fulfill due diligence obligations towards new customers. With regard to already acquired customers, recipients carry out due diligence again when appropriate, due to the increase in the level of money laundering and terrorist financing risk associated with the customer.

Section III. Identification of the customer and the agent

Pursuant to Article 19, paragraph 1, letter a), of the anti-money laundering decree, if the customer is a natural person, identification consists of acquiring the identification data provided by the customer themselves, prior to presentation of an identity document or other equivalent recognition document pursuant to current legislation, of which a copy is acquired in paper or electronic format. In the same manner, recipients identify co-holders and the agent. In the case of the agent, information regarding the existence and extent of the power of representation is also acquired.

If the customer is a subject other than a natural person, and therefore operates through natural persons endowed with the power to represent them, identification is carried out with regard to:

  • the customer, through the acquisition of identification data as well as information on type, legal form, goals pursued, and activity carried out, and, if they exist, the details of registration in the business register and in the registers kept by sector supervisory authorities. In the case of non-profit organizations, information regarding the class of beneficiaries to whom the activities carried out are directed (e.g., victims of natural disasters and wars) is also acquired. In the case of trusts, recipients acquire a copy of the latest version of the constitutive deed, in order to collect and continuously monitor information regarding the purposes actually pursued, the identity of the beneficiaries and the trustee, the methods of execution of the trust, and any other characteristic thereof;
  • the agent, who is identified with the same methods provided for the customer-natural person and for whom information regarding the existence of the power of representation is also acquired.

(10) Relationships and transactions, carried out on the initiative of the manager, in the provision of collective investment services provided for in art. 1, paragraph 1), letter n), of the TUF as well as portfolio management pursuant to art. 1, paragraph 5-quinquies, of the TUF are also excluded. Reference is made to relationships and transactions relating to the purchase and sale and administration of assets (movable, immovable, securities) in which customer resources are invested. Instead, the activity of granting financing carried out by managers who establish a so-called "credit fund" falls within the perimeter of institutional activity. In these cases, the financed subject is a customer and towards whom the manager therefore fulfills the obligations provided for by anti-money laundering legislation.

11

(11) As defined by Article 3, paragraph 1, point 9, of Regulation (EU) no. 2015/847 of the European Parliament and of the Council.

12

13 Identification is carried out in the presence of the customer or – when the customer is a subject other than a natural person – of the agent. When the persons to be identified are more than one (in the case of joint account holders or multiple agents), the acquisition of identity documents may take place at different times, provided it occurs before making the joint ownership or delegation or representation powers operational. In compliance with the anti-money laundering decree and subject to what is provided in Sections VI and VII of this Part, the identification obligation is considered fulfilled, even without their physical presence, for customers:

  1. whose identification data appear in public deeds, authenticated private writings, or qualified certificates used for generating a digital signature associated with electronic documents, pursuant to Article 24 of Legislative Decree No. 82 of 7 March 2005;
  2. in possession of a digital identity, at the highest level of security, within the System referred to in Article 64 of Legislative Decree No. 82 of 7 March 2005, and its implementing regulations, or of a digital identity at the highest level of security or a certificate for generating a digital signature, issued within the framework of an electronic identification regime included in the list published by the European Commission pursuant to Article 9 of Regulation (EU) No. 910/2014;
  3. whose identification data result from a declaration by the Italian diplomatic representation and consular authority, as indicated in Article 6 of Legislative Decree No. 153 of 26 May 1997;
  4. who have already been identified by the recipient in relation to another ongoing continuous relationship, provided that the existing information is updated and adequate with respect to the specific risk profile of the customer and the characteristics of the new relationship intended to be established;
  5. whose identification data are acquired according to the methods identified in Section VIII for remote operations.

Section IV. Identification of the Beneficial Owner Recipients identify the beneficial owner, without the need for their physical presence, concurrently with the identification of the customer and based on the identification data provided by the customer. At the time of identification, recipients require the customer, other than a natural person, to provide all information necessary for the identification of the beneficial owner sub 2). The customer must also be reminded to declare whether the continuous relationship is opened or the occasional operation is carried out on behalf of another subject, as well as to provide all indications necessary for the identification of this subject and its eventual beneficial owner sub 2). Subject to the above, operations attributable to a continuous relationship are presumed to be carried out in the interest of the natural person customer who is the holder of the relationship or, in the case of a customer other than a natural person, of the beneficial owner sub 2) of the relationship, unless otherwise indicated by the customer. At the time of establishing the continuous relationship, recipients ensure that the customer commits to reporting, during the future conduct of the relationship, any operations with an amount equal to or greater than those indicated in Section 2, letter b), of this Part, carried out on behalf of third parties (12) and to provide all indications necessary for the identification of the beneficial owner of the operation. Within the framework of ongoing monitoring, recipients evaluate any elements that suggest the customer is acting on behalf of subjects other than those indicated.

(12) These are operations carried out on behalf of subjects other than the natural person customer who is the holder of the relationship or, in the case of a customer other than a natural person, from the beneficial owner sub 2) of the relationship itself.

14 If, in relation to concrete situations, there are multiple beneficial owners, recipients fulfill identification obligations with respect to each of them.

Section V. Verification of data relating to the customer, the agent, and the beneficial owner Verification of data relating to the customer, the agent, and the beneficial owner (13) requires checking the truthfulness of the identification data contained in documents and the information acquired at the time of identification (14).

  1. With reference to the natural person customer and the agent: a) recipients ascertain the authenticity and validity of the identity document or other equivalent identification document acquired and, for the agent, also ascertain the existence and extent of the power of representation under which they act in the name and on behalf of the customer. For minors, identification data are verified, in the absence of an identity or identification document, through the birth certificate or any ruling by the guardianship judge. Verification may also take place by means of an authenticated photo: in this case, the details of the interested party's birth certificate are recorded. For non-EU subjects, recipients ascertain the authenticity and validity of the passport, residence permit, travel document for foreigners issued by the Police Headquarters, or any other document considered equivalent under Italian legislation (15); b) when, from the checks under a), doubts, uncertainties, or inconsistencies emerge, recipients carry out any further checks necessary to verify the identification data and information acquired. By way of example, they may consult the public system for the prevention of identity theft provided for by Legislative Decree No. 64 of 11 April 2011.
  2. In the case where the customer is a subject other than a natural person: a) recipients check the identification data of the customer with information derivable from reliable and independent sources (among those indicated below), of which they acquire
  • autonomously or through the customer – and keep copies in paper or electronic format; b) with reference to the beneficial ownership of the customer, recipients adopt measures proportionate to the risk to reconstruct its ownership and control structure with reasonable reliability. For this purpose, recipients consult any useful information source until they identify, with reasonable certainty, the beneficial owner sub 2) and verify their data, in light of the risk profile of the customer, the relationship, or the operation (16). For example, recipients may consult the special section of the business register provided for by Article 21 of the anti-money laundering decree (17).

(13) Verification of the identification data of the beneficial owner sub 1) takes place by comparison with those derivable from a reliable and independent source of which a copy is acquired and kept, in paper or electronic format. (14) When original documents are in a foreign language, recipients adopt necessary measures to identify their content (also through a sworn translation of the original, when deemed necessary). (15) By way of example, for stateless persons, who do not appear to possess the aforementioned documents, identification data may be verified through the travel document for stateless persons, issued pursuant to the Convention relating to the Status of Stateless Persons signed in New York on 28 September 1954. For holders of the status of "refugee" or the status of "subsidiary protection", pursuant to Legislative Decree No. 251 of 19 November 2007, identification data may also be verified through travel documents provided for in Article 24 of the same Decree.

15 In addition to the Italian business register, the following are included among reliable and independent sources for checking the identification data of the customer other than a natural person and the beneficial owner sub 2): i. registers and lists of authorized subjects, constitutive deeds, statutes, balance sheets, or equivalent documents, communications made to the public in compliance with sector regulations (such as prospectuses, communications of significant shareholdings, or inside information); ii. registers of beneficial owners established in other EU countries in implementation of Articles 30 and 31 of the anti-money laundering directive; iii. information from bodies and public authorities, also from other EU countries; such information may also be acquired through websites. Recipients, according to a risk-based approach, evaluate the extent and depth of the checks to be carried out.

Section VI. Acquisition and Evaluation of Information on the Purpose and Nature of the Continuous Relationship and Occasional Operations Recipients acquire and evaluate information on the purpose and nature of the relationship. The depth and extent of checks are correlated to the risk profile. Recipients acquire and evaluate, in any case, information concerning:

  • the purposes related to the establishment of the relationship;
  • the relationships between the customer and the agent;
  • the relationships between the customer and the beneficial owner of the relationship;
  • the work and economic activity carried out and, in general, the business relationships of the customer. Further information to be acquired according to the risk-based approach may concern, by way of example:
  • the origin of the funds used in the relationship;
  • business relationships and relations with other recipients;
  • the economic (e.g., sources of income) and asset situation (balance sheets, VAT and income tax returns, documents and declarations from employers, financial intermediaries, or other subjects may be acquired by way of example);
  • the work, economic, and asset situation of the beneficial owner, as well as, to the extent known or easily ascertainable, of family members and cohabitants. Information may be derived from the relationship or requested from the customer. Recipients verify the compatibility of the data and information provided by the customer with information acquired autonomously by them, also taking into account the overall operations carried out during the relationship or other previously maintained relationships as well as in the establishment of further relationships. Recipients request and evaluate information on the purpose and nature of occasional operations when they detect, according to a risk-based approach, elements that could constitute a high risk of money laundering and terrorist financing.

Section VII. Ongoing Monitoring During the Continuous Relationship Recipients carry out ongoing monitoring during the continuous relationship to keep the customer profile updated and identify elements of inconsistency that may constitute relevant anomalies for specific obligations (adoption of enhanced due diligence measures, reporting of suspicious transactions, abstention from executing the operation or from continuing the relationship). Ongoing monitoring is exercised through the examination of the customer's overall operations, taking into account both ongoing continuous relationships and specific operations possibly ordered, as well as through the acquisition of information during verification or updating of data for the identification of the customer, the beneficial owner, and the ascertainment and evaluation of the nature and purpose of the relationship or operation. In the anti-money laundering policy document, recipients establish, based on the risk profile, the timing and frequency of updating the data and information acquired, also making use of automatic procedures for reporting the expiration of documents, certifications, powers of representation, mandate relationships, as well as for reporting the acquisition of specific qualities (e.g., that of PEP), or inclusion in lists or registers (e.g., those provided for by EU Regulations or decrees adopted pursuant to Legislative Decree No. 109 of 22 June 2007, to combat international terrorist financing). Updating is nevertheless carried out when the recipient detects that the information previously acquired and used for due diligence is no longer current. Where appropriate, the results of monitoring lead to: updating of data, information, and risk profiles; carrying out broader and more in-depth checks (also application of enhanced due diligence); identification of anomalies and inconsistencies that may lead to reporting suspicious transactions; freezing of funds; abstention from carrying out the operation; closure of the relationship.

Section VIII. Specific Provisions on Remote Operations Remote operations are those carried out without the physical co-presence, at the recipient's premises, of the customer, the recipient's employees, or other personnel entrusted by the recipient (e.g., through telephone or computer communication systems); when the customer is a subject other than a natural person, they are considered present when the agent is present. Recipients pay particular attention to remote operations, given the absence of direct contact with the customer or the agent. Recipients take into account the risk of fraud connected to identity theft. In cases of remote operations, recipients: a) acquire the identification data of the customer and the agent and check them against a copy – obtained via fax, mail, in electronic format, or with analogous methods – of a valid identity document, pursuant to current legislation; b) carry out checks beyond those provided for in Section V on the acquired data, according to the most appropriate methods in relation to the specific risk. By way of example,

16 the following methods are indicated: telephone contact on a landline (welcome call); sending communications to a physical address with return receipt; transfer made by the customer through a banking and financial intermediary with headquarters in Italy or in an EU country; request for sending of signed documentation; verification of residence, domicile, activity carried out, through requests for information to competent offices or through on-site meetings, carried out using own personnel or third parties. In compliance with the risk-based approach, recipients may use verification mechanisms based on innovative and reliable technological solutions (e.g., those involving biometric recognition), provided they are assisted by robust security safeguards; c) identify, in the anti-money laundering policy document, the specific mechanisms they intend to use to carry out the checks under b) and illustrate the assessments conducted by the anti-money laundering function on the risk profiles characterizing each of these tools and their related security safeguards (18). As an alternative to what is provided under a), b), c), the identification of the natural person customer may be carried out by recipients digitally remotely according to the audio/video registration procedure regulated in Annex 3.

(18) In the assessment of the reliability and risks associated with verification mechanisms based on innovative technologies, recipients take into account, among other things, the indications contained in the Opinion on the use of innovative solutions by credit and financial institutions in the customer due diligence process (“Opinion on the use of innovative solutions by credit and financial institutions in the customer due diligence process”) adopted by the European Banking Authority on 23 January 2018, available at the following link: https://esas-joint-committee.europa.eu/Publications/Opinions/Opinion%20on%20the%20use%20of%20innovative%20solutions%20by%20credit%20and%20financial%20institutions%20(JC-2017-81).pdf.

17

PART THREE SIMPLIFIED DUE DILIGENCE OBLIGATIONS

Section I. General Principles In the presence of a low risk of money laundering and terrorist financing, recipients may comply with due diligence obligations in a simplified manner, reducing the scope and frequency of the obligations provided for in Part Two. To facilitate recipients in applying simplified due diligence measures, the low-risk factors provided for by the anti-money laundering decree are reported in the annex (Annex 1) – accompanied, where appropriate, by explanatory examples – and further low-risk factors relevant for the application of simplified measures are indicated, pursuant to Article 23, paragraph 3, of the anti-money laundering decree. Recipients define and formalize, in the anti-money laundering policy document, sufficiently detailed customer due diligence procedures; the document indicates at least the specific simplified due diligence measures (among those indicated in Section II) to be taken in relation to different types of low-risk customers or products. Recipients adequately justify the choice to consider additional factors indicating low risk.

Section II. Simplified Due Diligence Measures Simplified due diligence measures consist of a reduction in the scope or frequency of the obligations provided for in Part Two, taking into account:

  • the modulation of execution times for activities to identify the customer, the agent, or the beneficial owner. For example, recipients may collect the identification data of the customer or the agent before the opening of the continuous relationship and defer the actual acquisition of the copy of the document for up to thirty days; with respect to electronic money instruments, cumulatively meeting the conditions listed in Article 23, paragraph 3, letters a), b), c), d), e), f) of the anti-money laundering decree, recipients may defer the acquisition of a copy of the identity document even beyond the maximum thirty-day term, up to the moment of activation of the instrument or the first operation of loading value onto it;
  • the reduction of information to be collected. For example, recipients may: i) perform verification of data relating to the beneficial owner sub 2) by acquiring a declaration of confirmation of data signed by the customer, under their own responsibility; ii) use presumptions to identify the purpose and nature of the continuous relationship, where the offered product is intended for a specific use (e.g., consumer credit, company pension fund);
  • the reduction of the frequency of updating data collected for due diligence. For example, recipients may update information upon the occurrence of specific circumstances (such as, for example, the opening of a new relationship or the carrying out of an operation with an amount exceeding a predetermined threshold);
  • the reduction of the frequency and depth of functional analyses for monitoring the relationship. For example, ongoing monitoring may concern only operations above a certain threshold, provided the amount is consistent with the purpose and nature of the relationship.

18 Recipients verify the persistence of the prerequisites for applying the simplified procedure, with methods and frequency established according to the risk-based approach. Simplified due diligence measures do not apply when:

  • there are doubts, uncertainties, or inconsistencies regarding the identification data and information acquired during the identification of the customer, the agent, or the beneficial owner;
  • the conditions for applying simplified measures cease to exist, based on the risk indices provided for by the anti-money laundering decree and these Provisions;
  • monitoring activities on the customer's overall operations and information acquired during the relationship lead to excluding the presence of a low-risk scenario;
  • there is nevertheless suspicion of money laundering or terrorist financing.

19

20

PART FOUR ENHANCED CUSTOMER DUE DILIGENCE OBLIGATIONS

Section I. General Principles

Recipients apply enhanced customer due diligence measures when there is a high risk of money laundering and terrorist financing, resulting from specific regulatory provisions or from their own autonomous assessment.

The following are always considered high risk, pursuant to Article 24, paragraphs 3 and 5, of the anti-money laundering decree: a) relationships and occasional transactions involving high-risk third countries in the cases indicated by Article 24, paragraph 5, letter a), of the anti-money laundering decree; b) cross-border correspondent relationships with a responding banking or financial intermediary established in a third country; c) ongoing relationships or occasional transactions with customers and their beneficial owners who hold the status of politically exposed persons; d) customers who carry out transactions characterized by unusually high amounts or regarding which there are doubts about the concrete purpose to which they are directed.

To facilitate recipients in applying enhanced due diligence measures, the high-risk factors provided for in the anti-money laundering decree are reported in Annex 2 (Annex 2), accompanied, where appropriate, by explanatory examples, and further relevant factors for the application of enhanced measures are provided, pursuant to Article 24, paragraph 4, of the anti-money laundering decree.

Recipients define and formalize in their anti-money laundering policy document, sufficiently detailed customer due diligence procedures; the document must indicate at least the specific measures (among those indicated in Section II) of enhanced due diligence to be taken in relation to different types of high-risk customers or products.

Section II. Enhanced Customer Due Diligence Measures

Enhanced customer due diligence measures consist of acquiring more information about the customer and the beneficial owner; a more accurate assessment of the nature and purpose of the relationship; intensifying the frequency of checks and increasing the depth of analyses carried out within the scope of the ongoing monitoring activity of the continuous relationship.

The measures may consist of: a) acquiring a greater quantity of information relating to: i. the identity of the customer and the beneficial owner or the customer's ownership and control structure. This includes the acquisition and evaluation of information on the reputation of the customer and the beneficial owner (indications provided in Annex 2, letter A), no. 3) are relevant in this regard); ii. the ongoing relationship, to fully understand its nature and purpose. This includes acquiring information on:

21

  • the number, amount, and frequency of expected transactions, to identify any deviations that could determine elements of suspicion;
  • the reasons why the customer requests a specific product or service, especially if their financial needs could be best met in another way or in another country;
  • the destination of the funds;
  • the nature of the activity carried out by the customer and the beneficial owner; b) improving the quality of information to be acquired. This includes: i. requiring that, at the time of opening the ongoing relationship and in addition to the checks provided for in Part Two, the customer make a bank transfer from an account held in their name at an Italian, EU, or third-country banking and financial intermediary with anti-money laundering safeguards at a level analogous to those provided for in Chapter II of the anti-money laundering directive; ii. verifying the origin of the customer's wealth and funds used in the ongoing relationship. For this purpose, recipients refer to balance sheets, VAT and income tax returns, documents and declarations from the employer or other intermediaries. In the case of economic activities characterized by a high use of cash, recipients acquire accurate information to assess the consistency of the overall movement carried out on the relationship with the activity carried out and with the company's turnover. In particular, in cases of cash deposits or withdrawals carried out through cash-in-transit companies, recipients verify that the company itself is able to provide, upon request, the identification data on the subjects at whom the cash was withdrawn or delivered, as well as on the location of withdrawal or delivery of the sums, the amount of the sums withdrawn or delivered, and the denomination of the banknotes.

In the case of frequent and unjustified cash transactions, especially if carried out with large-denomination banknotes, recipients conduct in-depth investigations, also with the customer, to verify the reasons underlying this activity.

In the case of services with a high degree of customization, offered to high-risk customers, recipients verify in any case the origin of income and wealth. c) increasing the frequency of updates of the information acquired through: i. more frequent checks on the ongoing relationship aimed at promptly detecting any changes in the customer's risk profile; ii. more frequent or in-depth checks on transactions, to promptly detect any elements of suspicion of money laundering. In this context, recipients verify the destination of the funds and the reasons underlying a specific activity; d) requesting the authorization of a senior manager for the initiation or continuation of the ongoing relationship.

Section III. Relationships and Occasional Transactions Involving High-Risk Third Countries

Recipients apply enhanced customer due diligence measures to relationships and occasional transactions involving high-risk third countries, in the cases indicated by Article 24, paragraph 5, letter a), of the anti-money laundering decree.

Pursuant to Article 42, paragraph 2, of the anti-money laundering decree, recipients refrain from establishing or continuing ongoing relationships or carrying out transactions in which they are parties, directly or indirectly, to fiduciary companies, trusts, anonymous companies (or controlled through bearer shares) established in high-risk third countries.

Section IV. Cross-Border Correspondent Relationships with a Responding Banking or Financial Intermediary of a Third Country

Recipients modulate the enhanced customer due diligence measures applied to the responding intermediary based on risk, pursuant to Article 25, paragraph 2, of the anti-money laundering decree, paying particular attention to the geographic risk factors indicated in Annex 2, letter C.

They ascertain that respondents are not shell banks and do not allow shell banks access to correspondent relationships.

Enhanced customer due diligence measures include at least: a) the acquisition by the recipient of information suitable to clearly identify the ownership structure of the respondent; b) the acquisition, from the respondent, of information suitable to fully understand the nature of the activities carried out by it, also with reference to the services provided to customers for which the account or accounts opened at the intermediary recipient of the enhanced obligations are used; c) that recipients, when customers of the respondent have direct access to pass-through accounts, ensure, also through sample checks, that the respondent: i) fulfills the customer due diligence obligations, including ongoing monitoring; ii) can provide the recipient itself, upon request, all data collected as a result of fulfilling such obligations as well as any other relevant information regarding its customers or specific transactions. Recipients carefully evaluate the completeness of the information and documentation provided in response; any information gaps are taken into account for the purpose of re-evaluating the respondent's risk profile. Recipients acquire an express attestation from the respondent regarding the non-existence of regulatory or contractual impediments regarding the timely transmission of the requested information; d) the acquisition and evaluation of publicly available information on the reputation of the respondent and on the quality of the supervisory and anti-money laundering control regime to which it is subject. For this purpose, recipients may avail themselves of mutual evaluation reports adopted by the FATF or the IMF; e) the authorization, for the opening of each correspondent or pass-through relationship, by a senior manager, preferably not coinciding with the manager who promoted the opening of the business relationship with the respondent. For this purpose, the senior manager verifies the adequacy of the measures adopted to effectively mitigate the risk connected to the correspondent relationship; f) the definition in writing of the terms of the agreement with the respondent and their respective obligations. The recipient is required to identify which subjects (and by what means) can access the correspondent banking service (e.g., whether the correspondent account can be used by other banks having agreements with the respondent) as well as to define the respondent's responsibilities regarding anti-money laundering obligations. The agreement also provides: i) the methods through which the recipient can monitor the correspondent relationship to ascertain whether the respondent fulfills customer due diligence obligations and carries out other checks provided for by anti-money laundering regulations; ii)

23

the obligation for the respondent to provide the recipient, upon request, information on specific transactions or specific customers of the respondent; g) ongoing monitoring of the relationship with the respondent, with frequency and intensity commensurate with the correspondent service performed; in this context, recipients adopt procedures, also IT-based, aimed at automatically detecting anomalous transactions due to the recurrence or amount of operations or due to the destination or origin of flows; h) the evaluation of the respondent's internal anti-money laundering control system, acquiring suitable documentation. For this purpose, documentation solely regarding the respondent's anti-money laundering policies and procedures is not sufficient. If the risk is particularly high and the volume of transactions relevant, the recipient evaluates the appropriateness of carrying out inspections and sample checks to ascertain the effectiveness of the respondent's anti-money laundering policies and procedures.

With reference to accounts opened by the recipient used indirectly by other intermediaries (who, therefore, have a direct relationship with the respondent but not with the recipient, hereinafter referred to as "indirect correspondents"), the recipient:

  • is adequately informed regarding the existence of these relationships as well as regarding transactions carried out by the customers of indirect correspondents;
  • acquires information on the geographic area of operation of indirect correspondents;
  • ascertains that the indirect respondent issues instructions to the respondent in a transparent manner, so that all parties involved in the operations for checks and controls are known;
  • equips itself with suitable tools to identify any relationships with indirect correspondents not declared by the respondent and, in such cases, adopts consequent measures suitable to mitigate the risk of money laundering and terrorist financing;
  • evaluates the control system put in place by the respondent regarding relationships with indirect respondents and operations carried out by the latter (e.g., ascertains that monitoring instruments regarding operations requested by indirect respondents take into account all relevant risk factors; verifies whether the controls put in place by the respondent are manual or automated and, in the latter case, whether they are sufficiently accurate and whether the resources assigned to controls are adequate).

Section V. Politically Exposed Persons

Pursuant to the anti-money laundering decree, politically exposed persons (or PEPs) are considered at higher risk of money laundering as they are more exposed to potential corruption phenomena. The qualification of PEP is relevant for both the customer and the beneficial owner.

Recipients define procedures to verify whether the customer or the beneficial owner falls within the definition of PEP. For this purpose, in addition to obtaining pertinent information from the customer, they avail themselves of other sources, such as official websites of Italian authorities or countries of origin of PEPs, or commercial databases. The intensity and extent of checks are commensurate with the degree of risk associated with the different products and operations requested.

Regarding ongoing relationships already opened, within the scope of ongoing monitoring activity, recipients verify the possible acquisition or subsequent changes in the PEP status of the customer or the beneficial owner of the relationship. For this purpose, recipients, in addition to external information sources, use in an integrated manner all information otherwise in their possession (e.g.,

24

information collected during the investigation phase for the granting of financing operations, MiFID questionnaire where relevant).

When the customer or the beneficial owner falls within the definition of PEP, the recipient ensures that the initiation or continuation of the ongoing relationship or the execution of the occasional transaction is authorized by a senior manager who evaluates the PEP's exposure to money laundering risk and the degree of effectiveness of existing company safeguards to mitigate the risk.

Regarding subjects originally identified as PEPs, who have ceased to hold public office for more than one year, recipients, in the presence of a high risk of money laundering, continue to apply enhanced customer due diligence measures.

Recipients adopt adequate measures and acquire all necessary information to establish the origin of the wealth of PEPs and the funds specifically used in the relationship or in the occasional transaction. For this purpose, in the case of ongoing relationships, recipients acquire an attestation from the customer and, consistent with the risk-based approach, verify the information based on reliable documents, from independent sources, provided by the customer or publicly available as well as based on attestations from other intermediaries, where issued.

The extent of the measures adopted and the information acquired depends on the degree of risk associated with the PEP. Recipients collect information suitable to reasonably exclude that the funds used are the result of corrupt crimes or other criminal offenses.

The acquisition of this information aims to guarantee effective ongoing monitoring, also for the purpose of detecting any elements of suspicion. The customer's reluctance to provide the requested information regarding the origin of wealth or funds is an element that recipients consider for the purpose of fulfilling the obligation to report suspicious transactions.

Recipients subject ongoing relationships attributable to a PEP to reinforced ongoing monitoring. For this purpose, they adopt, among other things, procedures aimed at detecting anomalous operations related to the PEP and promptly examine information useful to evaluate the PEP's risk.

Section VI. Transactions Characterized by Unusually High Amounts or Regarding Which There Are Doubts About the Purpose

Recipients adopt procedures for detecting and evaluating anomalous transactions and operational schemes. This includes:

  • transactions of a higher amount than expected by the recipient based on their knowledge of the customer and the nature and purpose of the ongoing relationship;
  • anomalous operational schemes compared to the customer's ordinary activity or the typical activity of similar customers, products, or services;
  • particularly complex transactions compared to similar transactions associated with similar types of customers, products, or services.

The enhanced customer due diligence measures adopted by recipients allow for the evaluation of the suspicious nature of the transactions and consist at least of:

  • adopting adequate measures to understand the context and purpose of these transactions and determine their consistency with the customer's economic profile, for example by acquiring additional information on the origin and destination of funds and on the customer's activity;

25

  • more frequent ongoing monitoring of the ongoing relationship and further transactions carried out.

26

PART FIVE EXECUTION BY THIRD PARTIES OF CUSTOMER DUE DILIGENCE OBLIGATIONS

Section I. Scope of Application and Responsibility

Within the limits indicated below, recipients may delegate the fulfillment of customer due diligence obligations to third parties, with the full responsibility of the recipient for the observance of said obligations remaining intact.

In particular, the following are distinguished: a) third parties who can carry out all phases of due diligence, except for the ongoing monitoring of activity. They are:

  1. banking and financial intermediaries referred to in Article 3, paragraph 2, of the anti-money laundering decree, as well as their branches established in EU countries or those established in third countries that meet the requirements provided for in Article 26, paragraph 2, letter d), of the anti-money laundering decree;
  2. EU banking and financial intermediaries;
  3. banking and financial intermediaries having their seat in third countries that meet the requirements provided for in Article 26, paragraph 2, letter d), of the anti-money laundering decree. b) third parties who can only carry out the identification of the customer, the executor, and the beneficial owner, including the acquisition of copies of identity documents. They are:
  4. credit brokers and financial activity agents, unless otherwise provided by law;
  5. "contracted subjects and agents", with the methods provided for in Article 44 of the anti-money laundering decree;
  6. external collaborators who, by virtue of a specific agreement, operate in the name and on behalf of recipients in proposing to customers the subscription of contracts, related to their institutional activity, concerning consumer credit, leasing, factoring, microcredit, agricultural and fishing credit.

The agreement specifies the obligations to be fulfilled regarding identification and the methods and times of fulfillment, including the times for transmitting information to the recipient, as well as the responsibility of the collaborator for the incorrect performance of the assigned activity.

With the full responsibility of recipients for the observance of obligations intact, the provisions of this Part do not apply to outsourcing or agency relationships when, pursuant to the contract or agreement however named, the provider of the outsourced service or the agent are comparable to employees (19) or, in any case, to subjects stably integrated into the recipient's organization (20).

(19) For the purposes of these provisions, financial consultants authorized for off-premises offers are comparable to employees of the recipients for whom they perform their activity. (20) In banking or financial groups governed by Articles 60 and 109 of the TUB and Article 11 of the TUF, companies of the group established in Italy to which the fulfillment of due diligence obligations is outsourced are assumed to be stably integrated into the recipient's organization.

27 In no case can the due diligence obligations be delegated to convenience banks or intermediaries established in high-risk third countries.

Section II. Content and methods of execution of obligations

In the event of the use of third parties provided for in letter a) of Section I, the due diligence obligations are considered satisfied through a suitable attestation issued by the third party who has directly complied with them in relation to the establishment of a continuous relationship or the execution of an occasional transaction.

The attestation is clearly attributable to the attesting third party, through appropriate measures (signature by authorized personnel, sending via IT systems, etc.), and is transmitted by the attesting third party and not by the client.

To standardize the information acquisition process, the recipient may prepare specific forms for the issuance of attestations.

The attestation expressly confirms the correct compliance with anti-money laundering obligations by the attester, in relation to the various activities carried out. The content of the attestation varies depending on the specific due diligence obligation to which it is directed; based on this criterion, it contains: a) the identification data of the client, the executor, and the beneficial owner for the purpose of fulfilling the identification obligation; b) the indication of the types of sources used for the verification and checking of identity; c) information on the nature and purpose of the relationship to be opened and of the occasional transaction to be executed for the purpose of fulfilling the related obligation.

The recipient ensures that, in addition to the attestation, third parties are able to promptly transmit copies of the documents and information acquired, when the recipient requests it.

The attestation may be provided in paper or electronic form, independently or in connection with specific transactions.

The recipient remains responsible for due diligence and evaluates whether the elements collected and the checks carried out by third parties are up-to-date, suitable, and sufficient for the fulfillment of the obligations provided by law. In case of failure, the recipient proceeds, depending on the case and circumstances, to:

  • inform the attesting third party of any irregularities, deficiencies, or inconsistencies found in the received documentation;
  • make the necessary corrections or integrations;
  • directly fulfill the due diligence obligations;
  • refrain from establishing the continuous relationship or executing the transaction, evaluating whether to file a report with the UIF if the conditions provided for in Article 35 of the anti-money laundering decree are met (the choice in this paragraph is made, in particular, when the intermediary is unable to comply with the due diligence obligations).

In the event of the use of third parties who can only perform client identification (see Section I, letter b), the recipient ensures that third parties transmit in any case the data and information acquired, so that the recipient itself can complete the due diligence procedure (21).

Within the scope of information collection and exchange methods with third parties, the recipient:

  • defines the phases of due diligence delegated to third parties, identifies the data and information that must be transmitted by third parties and the methods and timing of transmission;
  • prepares tools, in paper or electronic format, for the timely exchange of information flows;
  • verifies the truthfulness of the received documents and the correctness and reliability of the information derived from them;
  • acquires, where necessary, supplementary information from third parties, the client, or other sources.

(21) In the case of "contracted subjects and agents", the acquisition of data takes place according to the methods provided for in Article 44 of the anti-money laundering decree.

28

29 SIXTH PART SPECIFIC PROVISIONS FOR PARTICULAR TYPES OF OPERATIONS

This Part applies when a recipient (hereinafter referred to as the counterparty recipient) offers investment services and activities or collective investment management through another banking or financial intermediary that operates in the interest of its own clients (the commissioning intermediary) (22); for matters not otherwise regulated, reference is made to the other Parts of these provisions.

In these cases, for the purpose of applying due diligence obligations, the counterparty recipient first identifies the role and position assumed by the commissioning intermediary acting on behalf of its client (the investor).

In particular, two cases can be distinguished:

  1. the commissioning intermediary acts on behalf of the client but in its own name, as the direct counterparty of the recipient, having received, for example, from its own client (the investor) a mandate to manage its assets or otherwise to carry out one or more investment transactions (23).

In this hypothesis, the commissioning intermediary - as the direct counterparty of the recipient - becomes the holder of the financial instruments, even though it acts based on specific purchase or sale instructions given by its client; 2) the commissioning intermediary acts not only on behalf of but also in the name of the client, assuming the position of mere intermediation in the relationship between its own client (the investor) and the counterparty recipient. According to this scheme, the commissioning intermediary is therefore not the holder of the financial instruments (ownership of which lies directly with the investor).

Case 1) The commissioning intermediary assumes the position of client of the counterparty recipient. In this case, in low-risk situations, the counterparty recipient may limit itself to acquiring only the identification data of the investor on whose behalf the commissioning intermediary acts (and of its beneficial owner sub 2, where it is not a natural person) if: i. the commissioning intermediary falls among intermediaries potentially at low risk of money laundering and terrorist financing, based on the criteria provided for in Annex 1; ii. the counterparty recipient has adopted graduated risk-based measures to ensure that the risk of money laundering and terrorist financing connected to the continuous relationship with the commissioning intermediary is low, considering, among other things, the activity of the commissioner, the type of clientele served, and the countries in which it offers its services; iii. the counterparty recipient ensures that the commissioning intermediary applies graduated risk-based due diligence measures to its clients; in particular, the recipient, based on publicly available information or acquired directly from the commissioning intermediary, evaluates the suitability of the due diligence procedures adopted by it; iv. the counterparty recipient adopts graduated risk-based measures (24) to ensure that the commissioning intermediary is able to provide, upon request, all data collected regarding investors as well as any other relevant information regarding them or specific transactions. The counterparty recipient carefully evaluates the completeness of the documentation and information received and takes into account any information gaps for the purpose of a re-evaluation of the commissioning intermediary's risk profile.

If the conditions are not all met or if there is suspicion of money laundering or terrorist financing, the application of simplified obligations is excluded.

Case 2) The relationship is established directly between the investor, as client, and the counterparty recipient: the latter therefore subjects the investor to graduated risk-based due diligence measures.

For this purpose, the counterparty recipient may resort to another intermediary (generally, the commissioning intermediary), in compliance with the provisions on the execution of due diligence obligations by third parties (see Sixth Part).

(22) In the case of occasional transactions, the due diligence obligations are fulfilled by the recipient who comes into contact with the client and not by the recipient with whom the occasional transaction occurs. Reference is made, by way of example, to the delivery of cashier's checks by banks other than the one issuing the instrument. (23) This case includes the scenario of an intermediary authorized to provide investment services that participates in a fund (formal participant) in its own name and on behalf of the client (effective participant) and therefore based on a mandate without representation.

30

31 ANNEX 1 Low-risk factors

To facilitate recipients in applying simplified due diligence measures, the low-risk factors provided for in the anti-money laundering decree are reported below, accompanied, where appropriate, by explanatory examples. Furthermore, pursuant to Article 23, paragraph 3, of the anti-money laundering decree, additional low-risk factors relevant for the application of simplified measures are provided (25).

A) Low-risk factors relating to the client, executor, and beneficial owner:

  1. companies admitted to listing on a regulated market and subject to disclosure obligations that include those to ensure adequate transparency of beneficial ownership;
  2. public administrations or institutions or bodies performing public functions, in accordance with European Union law;
  3. clients who are resident or have their seat in low-risk geographic areas. This factor occurs in cases where the client or beneficial owner are resident, have their main place of business, or have significant connections with countries or geographic areas at low risk, based on the criteria of letter C);
  4. banking and financial intermediaries listed in Article 3, paragraph 2, of the anti-money laundering decree - with the exception of those referred to in letters i), o), s), v) - and banking and financial intermediaries from the Community or with their seat in a third country with an effective regime for combating money laundering and terrorist financing. In evaluating the concrete existence of low risk, recipients consider, among other things, the possible adoption, against the intermediary, of supervisory sanctions or intervention measures for non-compliance with anti-money laundering obligations.

B) Low-risk factors relating to products, services, transactions, or distribution channels:

  1. life insurance contracts falling within the branches indicated in Article 2, paragraph 1, of Legislative Decree 7 September 2005, n. 209, when the annual premium does not exceed 1,000 euros or the single premium is not higher than 2,500 euros;
  2. complementary pension schemes regulated by Legislative Decree 5 December 2005, n. 252, if they do not provide for surrender clauses other than those provided for in Article 14 of the same decree and cannot serve as collateral for a loan outside the hypotheses provided by law;
  3. pension schemes or similar systems that pay pension benefits to employees, where contributions are paid through salary deduction and which do not allow beneficiaries to transfer their rights;
  4. financial products or services that offer appropriately defined and limited services to specific types of clientele, aimed at promoting financial inclusion;
  5. products in which the risks of money laundering or terrorist financing are mitigated by factors, such as spending limits or transparency of ownership (26). Reference is made to products and

(24) For example, by including specific clauses to this effect in the contract with the commissioning intermediary or by sampling the ability of the latter to transmit the requested information on customer due diligence.

32 services with low exposure to possible use for illicit purposes. Relevant in this context are products with limited functionality (e.g., with a predetermined operational threshold or subordinate to the purchase of a specific good or service for the consumer) and which do not allow anonymity or concealment of the identity of the client and/or the beneficial owner.

C) Geographic low-risk factors:

  1. Community countries;
  2. third countries equipped with effective anti-money laundering prevention systems. Reference is made to countries with anti-money laundering and counter-terrorist financing controls of a level analogous to those provided for by the anti-money laundering directive and which are associated with low levels of commission of predicate offenses;
  3. third countries that authoritative and independent sources assess as characterized by a low level of corruption or permeability to other criminal activities. Examples of authoritative and independent sources are "National Risk Assessments" (hereinafter referred to as National Risk Assessment); reports published by investigative and judicial authorities; reports adopted by the OECD regarding the implementation of the Convention against Bribery; the World Drug Report published by the United Nations Office on Drugs and Crime;
  4. third countries that, based on authoritative and independent sources (e.g., mutual evaluation reports or public detailed assessment reports), are equipped with an effective system for preventing money laundering and terrorist financing. Examples of authoritative and independent sources are mutual evaluation reports adopted by the FATF or similar international bodies (e.g., MoneyVal); the FATF list of high-risk and non-cooperative countries; reports adopted by the International Monetary Fund within the Financial Sector Assessment Programme (FSAP); information from supervisory authorities, such as those contained in the reasoning of sanctioning measures.

33 ANNEX 2 High-risk factors

To facilitate recipients in applying enhanced due diligence measures, the risk factors provided for in the anti-money laundering decree are reported below, accompanied, where appropriate, by explanatory examples. Furthermore, pursuant to Article 24, paragraph 4, of the anti-money laundering decree, additional risk factors relevant for the application of enhanced measures are provided (27).

A) High-risk factors relating to the client, executor, and beneficial owner:

  1. continuous relationships established under anomalous circumstances. By way of example, circumstances are taken into account where the client or executor are reluctant to provide the requested information, repeatedly change the information provided, give incomplete or erroneous information, or are unable to produce documentation on their identity, except for legitimate cases, such as asylum seekers. Also taken into consideration are any behaviors symptomatic of the client's will to avoid the establishment of a continuous relationship, for example, when the client asks to carry out one or more occasional transactions despite the opening of a continuous relationship appearing economically more reasonable;
  2. clients and beneficial owners resident or having their seat in high-risk geographic areas. This factor occurs when the client or beneficial owner are resident or have their main place of business or significant connections with high-risk countries, according to the criteria provided for in letter C (28). In particular, when the client is resident or has their seat in a high-risk geographic area, it is appropriate to evaluate whether there is a valid economic or legal reason justifying the type of continuous relationship or transaction requested or whether the client's financial needs could be more properly satisfied in the country of residence or where the client has their seat;
  3. negative reputational indices relating to the client, beneficial owner, and executor. Relevant, among other things, is the existence of: criminal proceedings, when this information is notorious or otherwise known to the recipient and not covered by secrecy obligations that prevent its use by the recipient under the code of criminal procedure; proceedings for damage to the treasury; proceedings for administrative liability pursuant to Legislative Decree 8 June 2001, n. 231; administrative sanctions imposed for violation of anti-money laundering provisions against the client or beneficial owner. Recipients also consider the existence of previous suspicious transaction reports filed with the UIF regarding the client or beneficial owner. Recipients also take into account information - publicly accessible - external to the company's information asset. In evaluating negative news from the media or other information sources, recipients consider their validity and reliability based, in particular, on the quality and independence of the information sources and the recurrence of the information. Relevant, among other things, are information relating to the activities exercised, even in the past, by the client and beneficial owner and those concerning subjects notoriously linked to the client or beneficial owner by virtue, for example, of family or business relationships. The need remains

(25) Where relevant in relation to the specific activity carried out, recipients also take into consideration the additional low-risk factors contained in Title III ("Sectoral Guidelines") of the Joint Guidelines of the European Supervisory Authorities on simplified and enhanced customer due diligence measures and on money laundering and terrorist financing risk factors associated with continuous relationships and occasional transactions (see: https://esas-joint-committee.europa.eu/Publications/Guidelines/Guidelines%20on%20Risk%20Factors_IT_04-01-2018.pdf). (26) Trust companies registered in the Register provided for in Article 106 of the TUB may consider low-risk the compensation plans based on financial instruments referred to in Article 114-bis of the TUF.

34

(27) Where relevant in relation to the specific activity carried out, recipients also take into consideration the additional high-risk factors contained in Title III ("Sectoral Guidelines") of the Joint Guidelines of the European Supervisory Authorities on simplified and enhanced customer due diligence measures and on money laundering and terrorist financing risk factors associated with continuous relationships and occasional transactions (see: https://esas-joint-committee.europa.eu/Publications/Guidelines/Guidelines%20on%20Risk%20Factors_IT_04-01-2018.pdf). (28) It remains understood that against high-risk third countries, recipients apply enhanced customer due diligence measures provided for in the Fourth Part.

34 verify the occurrence of names in the lists of persons or entities associated for the purposes of applying the freezing obligations provided for by Community Regulations or by decrees adopted pursuant to Legislative Decree 22 June 2007, n. 109; 4) structures that can be classified as vehicles for asset intermediation. This includes, by way of example, trusts, fiduciary companies, foundations, and further legal subjects that can be structured in such a way as to benefit from anonymity and allow relationships with shell banks or with companies having nominee shareholders. Specific attention is paid to corporate structures and trusts that can be classified as intermediation vehicles having their seat in countries that, following evaluations conducted by the FATF or similar international bodies, present unfavorable ratings regarding Recommendations nos. 24 and 25 and the "Immediate Outcome" no. 5 (29) regarding transparency obligations for corporate structures and trusts. Entities having their seat in countries that present negative evaluations by the OECD Global Forum on transparency and exchange of information for tax purposes are also considered high risk. With reference to fiduciary companies, the supervision by the Bank of Italy constitutes a risk mitigation factor, which may determine the application of standard due diligence measures. In the context of securitization operations, the improper use of special purpose vehicles to shield the beneficial ownership of certain assets, hindering the correct reconstruction of the financial flows generated by them, is relevant; 5) companies that have issued bearer shares or are held by nominees (so-called nominee shareholder). The reference, in the first case, is to companies constituted or capitalized through bearer instruments, especially if issued in foreign countries that, based on evaluations conducted by the FATF or similar international bodies, present unfavorable ratings regarding Recommendation no. 24 and no. 25 and the Immediate Outcome no. 5, regarding transparency obligations for corporate structures and trusts; 6) type of economic activity characterized by high use of cash. The reclassification of economic activities carried out by the customer into types particularly exposed to money laundering risks is relevant, such as the gold buying sector, currency exchange, gambling or betting activities, services provided by financial activity agents and "contracted subjects and agents" in the money remittance service; 7) type of economic activity attributable to sectors particularly exposed to corruption risks. These are, in particular, economic sectors involved in the provision of public funds, including those of Community origin, public contracts, healthcare, construction, arms trade, defense, military industry, mining industry, waste collection and disposal, production of renewable energies; 8) customer or beneficial owner who hold public offices in areas not included in the notion of PEP but for whom there is nevertheless a significant exposure to corruption risk. Reference is made, for example, to local administrators, subjects with senior roles in public administration or public bodies, consortia, and associations of a public nature; 9) anomalous or excessively complex ownership structure given the nature of the activity carried out. The legal form adopted by the customer must be considered, especially where there are particular elements of complexity or opacity that prevent or hinder the identification of the beneficial owner or the real corporate object or any shareholding or financial links with subjects having their seat in high-risk geographic areas. B) High-risk factors related to products, services, operations, or distribution channels:

(29) For this purpose, addressees may consult the consolidated table of ratings relating to the various evaluations conducted within the FATF or by similar international bodies.

35

  1. services with a high degree of personalization, offered to a clientele with significant wealth. Wealth management services provided for a clientele with high economic availability, especially if originating from high-risk economic sectors, are relevant;
  2. products or operations that could favor anonymity or facilitate the concealment of the identity of the customer or the beneficial owner. Examples include anonymous prepaid cards issued by foreign intermediaries, bearer shares, and operations related to services connected to the conversion of legal currency into virtual currency and vice versa;
  3. frequent and unjustified cash operations, characterized by the use of large-denomination euro banknotes or the presence of damaged or counterfeit bills;
  4. cash or value deposit operations originating from abroad with a total amount equal to or greater than the equivalent of 10,000 euros. In this context, addressees request the customer to provide a copy of the cash transfer declaration provided for by Article 3 of Legislative Decree 19 November 2008, n. 195, and investigate any behaviors of refusal or reluctance to provide documentation;
  5. ongoing relationships or occasional remote operations not assisted by adequate recognition mechanisms and procedures. The mechanisms and procedures identified by Article 19, paragraph 1, letter a), of the anti-money laundering decree and by Annex 3 of these provisions are considered adequate;
  6. payments received from third parties lacking an obvious link with the customer or their activity. By way of example, this includes the payment of invoices by third parties unrelated to the contractual relationship (30) or commercial triangulations not supported by suitable justificatory documentation, characterized by payments made by foreign companies lacking links with the invoice holder, especially if seated in high-risk geographic areas. This scope also includes the receipt of guarantees, especially if originating from abroad and for significant amounts, by third parties lacking a link with the customer;
  7. products and commercial practices of new generation, which include the use of distribution mechanisms or innovative technologies for new or existing products. The addressee must be able to identify and assess the risks associated with the innovative product or service offered. C) High-risk geographic factors:
  8. third countries that authoritative and independent sources consider lacking effective anti-money laundering safeguards. Authoritative and independent sources include: mutual evaluation reports prepared by the FATF or similar international bodies (e.g., MoneyVal); the list published by the FATF of high-risk and non-cooperative countries; reports published by the International Monetary Fund within the framework of the Financial Sector Assessment Programme (FSAP); information from supervisory authorities, such as those contained in the reasoning of sanctioning measures;
  9. countries and geographic areas evaluated as having a high level of corruption or permeability to other criminal activities by authoritative and independent sources. Authoritative and independent sources may include "National Risk Assessments" (cd. National Risk Assessment); reports published by investigative and judicial authorities; reports adopted by the OECD regarding the implementation of the OECD Convention against Bribery as well as the

(30) See the schematic representation of anomalous behaviors "Operationality related to international tax fraud and invoicing fraud" published by the UIF on April 23, 2012.

36 World Drug Reports published by the United Nations Office on Drugs and Crime; 3) countries subject to sanctions, embargoes, or similar measures adopted by competent national and international bodies. In this regard, addressees observe the measures issued by the European Union and other restrictive measures adopted pursuant to Article 4 of Legislative Decree 22 June 2007, n. 109, implementing Resolutions of the United Nations Security Council, for the fight against terrorist financing and the financing of weapons of mass destruction proliferation programs and against the activity of countries threatening international peace and security; 4) countries and geographic areas that finance or support terrorist activities or in which terrorist organizations operate. Reports on terrorism published by the FATF or other international organizations and agencies, such as Europol, are helpful in identifying such countries; 5) countries evaluated by authoritative and independent sources as lacking in compliance with international standards on transparency and exchange of information for tax purposes. Authoritative and independent sources include reports adopted by the OECD on tax transparency and information exchange; evaluations on the country's commitment to the automatic exchange of financial information for tax purposes under the so-called Common Reporting Standard; ratings assigned to FATF Recommendations nos. 9, 24, and 25 and to "Immediate Outcomes" nos. 2 and 5 in international mutual evaluation reports are also relevant. In the anti-money laundering policy document, addressees establish the importance to be attributed to each risk factor relating to the country or geographic area, in light of the nature and purpose of the ongoing relationship. For example, when:

  • the funds used in the ongoing relationship were produced in a third country, the crime rate of that country and the effectiveness of its investigative and judicial system assume particular relevance;
  • the funds are received from or sent to third countries associated with terrorist activities, addressees evaluate any elements of suspicion, also in light of the purpose and nature of the relationship;
  • the customer is a banking or financial intermediary, addressees pay particular attention to the adequacy of its anti-money laundering and terrorist financing safeguards and the effectiveness of supervisory controls.

37 ANNEX 3 Video-identification Procedure Addressees implement a system that guarantees, prior to the establishment of the audio/video session, the encryption of the communication channel through the adoption of standard mechanisms, updated applications, and protocols. They also guarantee the use of applications oriented towards usability and accessibility for the customer. Addressees ensure that the remote identification performed by the operator in charge of video-identification (hereinafter, "operator") respects the following conditions: a) video images are in color and allow clear visualization of the interlocutor in terms of brightness, sharpness, contrast, and image fluidity; b) audio is clearly audible, free from distortions or obvious disturbances; c) the audio/video session, which concerns the video images and audio of the customer and the operator, is conducted in environments free from particular disturbing elements. Addressees ensure that the operator in charge of the activity refrains from initiating the identification process or suspends it when the audio/video quality is poor or deemed inadequate to allow customer identification. The operator performing the identification: i) acquires the identification data provided by the customer; ii) requests the presentation of a valid identity document, bearing a recent and recognizable photograph and the applicant's handwritten signature, issued by a public administration; and iii) verifies the tax code via the valid health card in force. A copy of the document is acquired in electronic format. The operator performing the identification may exclude the admissibility of the audio/video session for any reason, including the possible inadequacy of the document presented by the customer. The audio/video session is entirely recorded and preserved. Addressees request consent for the processing of personal data contained in the audio-video recordings, specifying this aspect in the information to be provided to the interested party pursuant to provisions on personal data protection. The audio/video session is conducted following a written procedure formalized by the addressees, which provides for at least the following activities: a) the operator acquires consent to video recording and its preservation and informs that the video recording will be preserved in a protected manner; b) the operator declares their personal details; c) the customer confirms their identification data; d) the customer confirms the date and time of the recording; e) the customer confirms their intention to establish the ongoing relationship and confirms the identification data and other data entered in the online forms during pre-registration; f) the customer confirms their mobile phone number and email address; g) the operator sends a message that the customer displays to the recording device or whose content is communicated to the operator, and an email to the email address declared by the customer, with a link to a URL specifically set up for verification;

38 h) the operator asks the customer to frame, front and back, the identification document used, and ensures that it is possible to clearly view the photograph and read all the information contained therein (personal data, document number, issue and expiry dates, issuing authority). An electronic copy of the document is acquired; i) the operator asks to show, front and back, the health card on which the customer's tax code is reported; j) the operator asks the customer to perform one or more random actions to strengthen the authenticity of the interaction; k) the operator briefly summarizes the customer's expressed intention to establish the ongoing relationship and collects confirmation. When doubts, uncertainties, or inconsistencies emerge in the customer's identification, addressees carry out further checks. By way of example, they may consult the public system for the prevention of identity theft provided for by Legislative Decree 11 April 2011, n. 64. The documentation to be preserved includes the information and documents that were collected during the registration activity. Addressees preserve, in a manner compliant with the provisions on preservation of the anti-money laundering decree, the registration data as well as the customer's explicit intention to establish the ongoing relationship, stored in audio-video files, images, and metadata structured in electronic format.

More like this from BOI

We email you every new BOI publication the day it's published.

Topics
Share