2019-07-30
Added · Updated
The Bank of Italy issues provisions establishing the framework for customer due diligence to prevent money laundering and terrorist financing. The document applies to banks, securities intermediation companies, asset management companies, electronic money institutions, payment institutions, and other specified financial entities. It mandates a risk-based approach for assessing money laundering and terrorist financing risks, defining specific obligations for customer identification, beneficial owner verification, and ongoing monitoring. The text details simplified and enhanced due diligence measures, including specific procedures for remote operations, high-risk third countries, cross-border correspondent relationships, and politically exposed persons.
This document conforms to the original contained in the archives of the Bank of Italy. Digitally signed by Legal Headquarters: Via Nazionale, 91 - P.O. Box 2484 - 00100 Rome - Paid-in Capital: Euro 156,000.00 Tel. 06/47921 - Telex 630045 BANKIT - VAT No. 00950501007 - www.bancaditalia.it
PROVISIONS ON CUSTOMER DUE DILIGENCE FOR THE PREVENTION OF MONEY LAUNDERING AND TERRORIST FINANCING
INDEX PRELIMINARY PROVISIONS.......................................................................................................1 Legal Sources ................................................................................................................................1 Recipients ........................................................................................................................................1 Definitions .......................................................................................................................................2 PART ONE – ASSESSMENT OF MONEY LAUNDERING AND TERRORIST FINANCING RISK FACTORS........................................................................................7 Section I. The risk-based approach principle..................................................................7 Section II. General criteria and informative sources useful for risk assessment .........................7 Section III. Customer profiling..............................................................................................9 PART TWO – DUE DILIGENCE OBLIGATIONS .................................................11 Section I. Content of customer due diligence obligations.......................................11 Section II. Scope of application................................................................................................11 Section III. Identification of the customer and the executor.............................................................12 Section IV. Identification of the beneficial owner .......................................................................13 Section V. Verification of data relating to the customer, the executor and the beneficial owner...................14 Section VI. Acquisition and assessment of information on the intended purpose and nature of the ongoing relationship and occasional transactions.....................................................................15 Section VII. Ongoing monitoring during the ongoing relationship .........................................16 Section VIII. Specific provisions on remote operations ...................................16 PART THREE – SIMPLIFIED DUE DILIGENCE OBLIGATIONS..........................18 Section I. General principles ............................................................................................................18 Section II. Simplified due diligence measures.....................................................................18 PART FOUR – ENHANCED DUE DILIGENCE OBLIGATIONS .........................20 Section I. General principles ............................................................................................................20 Section II. Enhanced due diligence measures .........................................................................20 Section III. Relationships and occasional transactions involving high-risk third countries..........21 Section IV. Cross-border correspondent relationships with a banking or financial intermediary responsible in a third country.......................................................................................22 Section V. Politically Exposed Persons.....................................................................................23 Section VI. Transactions characterized by unusually high amounts or for which there are doubts about the purpose..........................................................................................................................24 PART FIVE – EXECUTION BY THIRD PARTIES OF DUE DILIGENCE OBLIGATIONS..................................................................................................................26 Section I. Scope of application and responsibility .......................................................................26 Section II. Content and methods of execution of obligations.....................................................27
PART SIX – SPECIFIC PROVISIONS FOR PARTICULAR OPERATIONAL TYPES ....................................................................................................................................29 ANNEX 1 Low-risk factors ...........................................................................................31 ANNEX 2 High-risk factors.........................................................................................33 ANNEX 3 Video-identification procedure .........................................................................37
1 PRELIMINARY PROVISIONS Legal Sources The matter is governed by: – Legislative Decree 21 November 2007, No. 231, as amended by Legislative Decree 25 May 2017, No. 90, and in particular: • Article 7, paragraph 1, letter a), which grants the Bank of Italy the power to issue provisions on customer due diligence; • Article 19, paragraph 1, letter a), No. 5, which assigns the Bank of Italy the task of identifying suitable forms and methods for the remote acquisition of customer identification data for the purpose of fulfilling the identification obligation, taking into account the evolution of remote identification techniques; • Article 23, paragraph 3, which grants the Bank of Italy the power to: i) identify additional low-risk factors beyond those listed in paragraph 2 of the same article, as well as the power to establish simplified due diligence measures to be adopted in low-risk situations; ii) identify the type of simplified due diligence measures that banks and electronic money institutions are authorized to adopt in relation to particular types of electronic money products; • Article 24, paragraph 4, which grants the Bank of Italy the power to identify additional high-risk factors beyond those listed in paragraph 2 of the same article, as well as the power to establish enhanced due diligence measures to be adopted in high-risk situations; • Article 27, paragraph 5, which grants the Bank of Italy the power to identify further operational types beyond consumer credit and leasing in which identification can be carried out by external collaborators linked to the intermediary by specific agreement. Also relevant are: – Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015, as amended by Directive (EU) 2018/843, on the prevention of the use of the financial system for the purpose of money laundering and terrorist financing; – Joint Guidelines of the European Supervisory Authorities, issued pursuant to Article 17 and Article 18, paragraph 4, of Directive (EU) 2015/849 on simplified and enhanced customer due diligence measures and on the factors that credit institutions and financial institutions should take into consideration when assessing the money laundering and terrorist financing risks associated with individual ongoing relationships and occasional transactions.
Recipients These provisions apply to: a) banks; b) securities intermediation companies (SIM); c) asset management companies (SGR); d) variable capital investment companies (SICAV); e) fixed capital investment companies, securities and real estate (SICAF); f) intermediaries registered in the register provided for by Article 106 of the TUB; g) electronic money institutions; h) payment institutions; i) branches established in Italy of banking and financial intermediaries having their legal seat and central administration in another EU country or a third country; j) banks, payment institutions and electronic money institutions having their legal seat and central administration in another EU country required to designate a central contact point in Italy pursuant to Article 43, paragraph 3, of the anti-money laundering decree; k) fiduciary companies registered in the register provided for pursuant to Article 106 of the TUB; l) guarantee funds (confidi) (1); m) micro-credit providers, pursuant to Article 111 of the TUB; n) Poste Italiane S.p.A., for the bancoposta activity; o) Cassa Depositi e Prestiti S.p.A.. In credit securitization transactions governed by Law 30 April 1999, No. 130, the obligations under these Provisions are fulfilled by the subjects referred to in Article 2, paragraph 6, of the same law.
Definitions For the purposes of these provisions, the following terms are understood as:
(1) The reference is to be understood as referring to the confidi provided for by Article 155 of the TUB, in the text prior to the entry into force of Title III of Legislative Decree 13 August 2010, No. 141.
(2) In credit transfer transactions, when the transferred credits originate from relationships not subject to these Provisions, the assigned debtors are not considered customers, even occasional, of the assignee companies. The assigned debtor acquires the status of customer of the assignee intermediary if a new agreement intervenes between the assignee intermediary and the assigned debtor, even in the form of payment deferral (unless the latter is gratuitous).
(3) Subjects entrusted by a public authority with the administration of the customer's assets and relationships or their representation (such as, for example, bankruptcy trustees) are considered executors.
"pass-through accounts": cross-border correspondent relationships, maintained between banking and financial intermediaries, used to carry out transactions on own account and on behalf of customers;
"identification data": first and last name, place and date of birth, residential address and domicile, if different from the residential address, details of the identification document and, if assigned, the tax code, or, in the case of subjects other than natural persons, the name, legal seat and, if assigned, the tax code;
"anti-money laundering decree": Legislative Decree 21 November 2007, No. 231, as amended by Legislative Decree 25 May 2017, No. 90, implementing Directive (EU) 2015/849;
"cash" or "cash": banknotes and coins, in euros or foreign currencies, having legal tender;
"recipients": the subjects to whom these provisions apply, indicated in the "recipients" paragraph;
"anti-money laundering directive": Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015, on the prevention of the use of the financial system for the purpose of money laundering of proceeds of criminal activity and terrorist financing;
"provisions on internal anti-money laundering controls": "Provisions on organization, procedures and internal controls aimed at preventing the use of intermediaries for money laundering and terrorist financing", adopted by the Bank of Italy on 26 March 2019;
"anti-money laundering policy document": the document defined by the management body and approved by the strategic supervision body pursuant to the Provisions on organization, procedures and internal controls aimed at preventing the use of intermediaries for money laundering and terrorist financing, adopted by the Bank of Italy on 26 March 2019 (see Part One, Sections II and III);
"executor": the subject delegated to act in the name and on behalf of the customer or to whom powers of representation are otherwise conferred allowing them to act in the name and on behalf of the customer (3);
"terrorist financing": in accordance with Article 1, paragraph 1, letter d), of Legislative Decree 22 June 2007, No. 109: "any activity, by any means, direct or indirect, aimed at the provision, collection, raising, intermediation, deposit, custody or disbursement of funds and economic resources, however realized, intended to be, directly or indirectly, in whole or in part, used for the commission of one or more acts with terrorist purposes, as provided for by criminal laws, regardless of the actual use of the funds and economic resources for the commission of the aforementioned acts";
"FATF": Financial Action Task Force, an body established within the OECD specialized in the sector of prevention and combating money laundering, terrorist financing and the proliferation of weapons of mass destruction;
"group": the banking group governed by Article 60 of the TUB and implementing provisions, the financial group governed by Article 109 of the TUB and implementing provisions, the group provided for by Article 11 of the TUF and implementing provisions, as well as, outside these cases and if recipients of these provisions, controlled and controlling companies pursuant to Article 2359 of the Civil Code and their respective controlling companies;
"EU banking and financial intermediaries": the subjects referred to in Article 3, paragraphs 1 and 2, of the "anti-money laundering directive" having their seat in an EU country;
"payment instruments": cash, bank and postal checks, cashier's checks and other checks assimilated or equated thereto such as traveler's checks, postal money orders, credit or payment orders, credit cards and other payment cards, transferable insurance policies, pawn policies and any other instrument that allows the transfer, movement or acquisition of funds, assets or financial resources, also via telematic means;
"MoneyVal": Committee established within the Council of Europe, acting in the capacity of the FATF regional body for the Euro-Asian area;
"transaction": the activity consisting in the movement, transfer or transmission of payment instruments or the performance of contractual acts with a patrimonial content;
"structured transaction": a unitary transaction under an economic perspective with an amount equal to or greater than the limits established by the anti-money laundering decree, carried out through multiple transactions individually of an amount lower than the aforementioned limits, carried out at different times and within a limited period of time fixed at seven days, provided that elements exist to consider it as such;
"occasional transaction": a transaction not attributable to an existing ongoing relationship;
"Joint Guidelines": Joint Guidelines of the European Supervisory Authorities, adopted on 26 June 2017, pursuant to Articles 17 and 18, paragraph 4, of the anti-money laundering directive, on risk factors that intermediaries should take into consideration when assessing the money laundering and terrorist financing risks associated with customers and on due diligence measures to be adopted;
"EU countries": countries belonging to the European Economic Area;
"third countries": countries not belonging to the European Economic Area;
"high-risk third countries": countries not belonging to the European Economic Area with strategic deficiencies in their national regimes for the prevention of money laundering and terrorist financing, as identified by the European Commission in the exercise of the powers governed by Articles 9 and 64 of the anti-money laundering directive;
"politically exposed persons (PEPs)": natural persons indicated in Article 1, paragraph 2, letter dd) of the anti-money laundering decree;
"public administration": the public administrations provided for in Article 1, paragraph 2, of Legislative Decree 30 March 2001, No. 165, and subsequent amendments, national public bodies, companies owned by public administrations and their subsidiaries, pursuant to Article 2359 of the Civil Code, limited to their public interest activity governed by national or European Union law, as well as subjects responsible for tax collection within national or local taxation, regardless of their legal form;
"relationships assimilated to pass-through accounts": relationships however named maintained between banking and financial intermediaries on which the customer of the responsible entity is granted the right to execute directly even only part of the transactions pertaining to them;
"ongoing relationship": a relationship of duration, which does not end in a single transaction, falling within the exercise of the institutional activity of the recipients;
"correspondent relationships": accounts held by banks for the settlement of interbank services (remittance of bills, cashier's and bank checks, deposit orders, fund transfers, documentary remittances and other operations) as well as relationships, however named, maintained between banking and financial intermediaries used for the settlement of transactions on behalf of the customers of the responsible entities (e.g., securities deposit, investment services, foreign exchange operations, document collection services, issuance or management of debit or credit cards);
"money laundering", pursuant to Article 2, paragraph 4, of the anti-money laundering decree: a. the conversion or transfer of assets, carried out knowing that they originate from criminal activity or participation in such activity, with the aim of concealing or disguising the illegal origin of the assets themselves or helping anyone involved in such activity to escape the legal consequences of their actions; b. the concealment or disguise of the true nature, origin, location, disposition, movement, ownership of assets or rights thereto, carried out knowing that such assets originate from criminal activity or participation in such activity; c. the acquisition, possession or use of assets knowing, at the time of their receipt, that such assets originate from criminal activity or participation in such activity; d. participation in one of the acts provided for in the preceding letters, association to commit such an act, attempt to perpetrate it, helping, instigating or advising someone to commit it or facilitating its execution;
"contracted subjects and agents": operators, however named, other than financial activity agents, whom payment service providers and electronic money issuing institutions, including those having their legal seat and central administration in another EU country, avail themselves of for the exercise of their activity on the territory of the Republic;
"beneficial owner": a. the natural person or natural persons on whose behalf the customer establishes an ongoing relationship or carries out an operation (briefly, "beneficial owner sub 1"); b. in the case where the customer or the subject on whose behalf the customer establishes an ongoing relationship or carries out an operation are entities other than a natural person, the natural person or natural persons to whom, ultimately, direct or indirect ownership of the entity or its control is attributable or who are beneficiaries thereof (briefly, "beneficial owner sub 2"). In particular, in the case of capital companies or other private legal persons, even if based abroad, and express trusts, regardless of their place of establishment and the law applicable to them, the beneficial owner sub 2) is identified according to the criteria provided for in Articles 20 and 22, paragraph 5, of the anti-money laundering decree; the same criteria apply, insofar as compatible, in the case of partnerships and other subjects, public or private, even if lacking legal personality;
"TUB": Legislative Decree 1 September 1993, No. 385, containing the Consolidated Law of Banking and Credit;
"TUF": Legislative Decree 24 February 1998, No. 58, containing the Consolidated Law of Provisions on Financial Intermediation;
"UIF": the Financial Intelligence Unit for Italy established at the Bank of Italy pursuant to Article 6 of the anti-money laundering decree.
7
PART ONE ASSESSMENT OF MONEY LAUNDERING AND TERRORIST FINANCING RISK FACTORS
Section I. The principle of the risk-based approach
This Part establishes the general criteria to which recipients adhere to identify and assess money laundering and terrorist financing risks associated with customers and, consequently, to grade the methods for carrying out due diligence.
Based on the principle of the risk-based approach, the intensity and extent of due diligence obligations are modulated according to the degree of money laundering and terrorist financing risk associated with the individual customer (4). Recipients define and formalize, in the anti-money laundering policy document, customer due diligence procedures that are sufficiently detailed; the document must indicate at least the specific measures (among those listed in Section II and Parts Three and Four) of simplified and enhanced due diligence to be adopted in relation to different types of customers or products.
Recipients exercise their autonomy responsibly, considering all relevant risk factors.
The assessment systems and decision-making processes adopted ensure consistent behavior throughout the entire organizational structure and the traceability of checks carried out and assessments made, also to demonstrate to the authorities that the specific measures taken are adequate with respect to the risks identified in concrete terms.
Section II. General criteria and useful information sources for risk assessment
A. General criteria
To assess the risk of money laundering and terrorist financing (5), recipients consider the general criteria provided for in Article 17, paragraph 3, of the anti-money laundering decree, which refer to the characteristics of the customer, their conduct, and the specifics of the transaction or ongoing relationship.
In identifying risk factors pertaining to a customer, recipients also consider the beneficial owner and, where relevant, the agent. Recipients assess the scope of activity and the characteristics of the customer, the beneficial owner, and, where relevant, the agent, as well as the country or geographic area in which they have their headquarters or residence or domicile or from which the funds originate (6); they also note the location of the activity carried out and the countries with which the customer, the beneficial owner, and, where relevant, the agent have significant connections.
The importance of risk factors linked to the country or geographic area varies in relation to the type of ongoing relationship or transaction.
Recipients consider the behavior held by the customer or the agent at the time of opening ongoing relationships or carrying out transactions.
In the case of a customer other than a natural person, recipients consider the purposes of its establishment, the goals it pursues, the methods through which it operates to achieve them, as well as the legal form adopted, especially if it presents particular elements of complexity or opacity.
Recipients verify whether the customer and the beneficial owner are included in the "lists" of persons and entities associated with terrorist financing activities adopted by the European Commission.
Recipients also avail themselves, as auxiliary tools, of the anomaly indicators and the Communications on the prevention of terrorist financing published by the UIF.
Recipients consider the structure of the product or service offered by them, in terms of transparency and complexity, and the channels through which it is distributed. In assessing the risk associated with the complexity of the product, service, or transaction, recipients consider the possible involvement of a plurality of parties or countries.
Recipients pay attention to new or innovative products or services, particularly in the case where, for the offer of these products or services, they avail themselves of new technologies or new payment methods. Recipients also consider whether the product, service, or transaction is normally associated with the use of cash and whether they allow for high-value transactions. Recipients assess the reasonableness of the ongoing relationship or transaction in relation to the activity carried out and the overall economic profile of the customer and the beneficial owner, taking into account all available information (e.g., income and asset capacity) and the nature and purpose of the relationship. In this context, recipients may carry out comparative assessments with the operations of subjects with similar professional or dimensional characteristics, economic sector, or geographic area.
With reference to risk factors linked to distribution channels, reference is made to Part Five for the safeguards to be adopted in the case of due diligence by third parties.
B. Useful information sources for risk assessment
Recipients draw information for the identification of the customer's risk profile from every useful source and document, including: the report adopted by the European Commission pursuant to Article 6 of the anti-money laundering directive (so-called Supranational Risk Assessment Report); the report adopted by the Financial Stability Committee pursuant to Article 14 of the anti-money laundering decree containing the "National Risk Analysis"; reports published by investigative and judicial authorities (7); documents from supervisory authorities (such as communications and
(4) The risk-based approach can be exercised within the limits set by the legal system. In no case can it be invoked by recipients to justify conduct that results in non-compliance with obligations specifically defined by legal provisions or these provisions. Among these are the freezing obligations provided for with regard to subjects included in Community lists, also issued in implementation of Resolutions of the United Nations Organization, to combat terrorist financing and the activities of countries threatening international peace and security. It follows that it will not be possible to establish or maintain a business relationship with subjects included in these lists, except within the limits and under the conditions strictly provided for. (5) The risk factors to be taken into consideration for the fight against terrorist financing often overlap with those related to the fight against money laundering; however, terrorist financing has characteristics distinct from money laundering, both because the sums used are generally of lower amount, and because the origin of the funds may also be lawful. Recipients apply the safeguards provided for in these provisions also in the key of combating the financing of weapons of mass destruction development programs.
8
sanctioning measures) and from the UIF, such as, for example, indicators, anomaly schemes, and cases of money laundering.
Recipients may also take into consideration information coming from statistical institutes and reputable journalistic sources.
In the case of relationships or transactions involving a third country, recipients assess the overall robustness of the existing anti-money laundering safeguards in that country. To this end, they may consult: mutual evaluation reports adopted by the FATF (8) or analogous international bodies (9); the list published by the FATF of high-risk and non-cooperative countries; reports published by the International Monetary Fund within the framework of the Financial Sector Assessment Programme (FSAP). Recipients verify whether the country is subject to financial sanctions, embargoes, or measures related to terrorist financing or the proliferation of weapons of mass destruction.
For the identification of third countries characterized by a low level of fiscal transparency or poor compliance with tax obligations, recipients consult the reports approved by the OECD Global Forum on fiscal transparency and exchange of information, as well as assessments on the commitment to automatic exchange of information based on the so-called "Common Reporting Standard".
Section III. Customer profiling
Recipients define the risk profile attributable to each customer, based on the overall assessment elements and risk factors described in Section II and Annexes 1 and 2. The different risk factors are weighted based on their relative importance. As a result of profiling, each customer is included in one of the predefined risk classes established by the recipients.
The elaboration of the risk profile is based, as far as possible, on algorithms and computer procedures. Recipients ensure that the risk class proposed automatically by computer systems is consistent with their knowledge of the customer, applying, if necessary, higher risk classes. The lowering of the risk level or controls by operators must be restricted to exceptional cases and must be detailed and motivated in writing.
If the computer system is provided by external subjects, recipients adequately know the functioning of the system and the criteria that determine the attribution of the risk class.
For recipients belonging to a group, when customer profiling is not centralized, it is carried out by individual companies also based on the information used by other companies in the group. Each company assumes, for the same customer, the highest risk profile among those assigned by all companies in the group. Where it intends to attribute a lower risk profile than that assigned by other companies in the group, the reasons for the choice are specifically motivated in writing. When a company changes the risk class of a customer, it communicates this to the other interested companies.
(6) For the purpose of defining the customer's risk profile, trust companies take into account, also in the course of the ongoing relationship, the characteristics of the company in which they acquire a fiduciary participation (e.g., headquarters, operational sector, possible submission to bankruptcy proceedings). For the same purposes, in the case of fiduciary ownership of insurance policies, any useful information on the beneficiaries thereof is relevant. (7) For example, with reference to resident customers or those with headquarters in Italy, useful information to know the degree of infiltration of economic crime, socio-economic or institutional weakness factors, and phenomena of underground economy can be drawn from the annual reports made by: various judicial bodies on the occasion of the inauguration of the judicial year; the National Anti-Mafia Directorate; the Ministry of the Interior on the activity of the Anti-Mafia Investigative Directorate and on the activity of the Police Forces, the state of public order and security, and organized crime. (8) The fact that a country is a member of the FATF or of analogous international bodies (e.g., MoneyVal) does not constitute in itself a presumption of adequacy of its money laundering prevention and combating system. (9) In this context, recipients pay particular attention to the information contained in the following parts of the mutual evaluation reports: executive summary; "Key findings"; assessments on compliance with Recommendations no. 10, no. 26, and no. 27 and "Immediate outcomes" no. 3 and no. 4.
9
To each risk class, recipients associate a coherent level of depth and extent of the measures adopted in the different areas of due diligence.
With regard to ongoing relationships, recipients define the ordinary frequency of updating customer profiling in coherence with its risk level. Recipients verify the congruity of the risk class assigned to the occurrence of events or circumstances that are capable of modifying the risk profile (e.g., in the case of acquisition of PEP status, significant changes in the customer's or beneficial owner's operations or shareholding).
10
PART TWO DUE DILIGENCE OBLIGATIONS
Section I. Content of customer due diligence obligations
Customer due diligence consists of the following activities: a) identification of the customer and any agent; b) identification of any beneficial owner; c) verification of the identity of the customer, any agent, and any beneficial owner based on documents, data, or information obtained from a reliable and independent source; d) acquisition and evaluation of information on the purpose and nature of the ongoing relationship and, in the presence of a high risk of money laundering and terrorist financing, of the occasional transaction; e) exercise of constant monitoring during the ongoing relationship.
When recipients are unable to comply with customer due diligence obligations, they do not establish the ongoing relationship nor execute the transaction (see art. 42 of the anti-money laundering decree). If the impossibility occurs for an existing ongoing relationship, they refrain from continuing the relationship. In these cases, recipients also assess whether to send a suspicious transaction report.
Section II. Scope of application
Recipients proceed with customer due diligence in relation to relationships and transactions that fall within their institutional activity, as defined by sector legislation.
Due diligence is not required for activities aimed at or connected to the organization, functioning, and administration of the recipients, given that they do not fall within the institutional activities proper to the recipients and that, in their performance, the recipients' counterparties constitute providers of goods or services on the initiative of the recipients themselves, rather than customers requesting to establish an ongoing relationship or carry out an occasional transaction (e.g., supplies for the acquisition of materials or instrumental goods; acquisition and maintenance of the buildings where the institutional activity is exercised; services acquired from self-employed professionals for consultations) (10).
The due diligence activities provided for in letters a), b), c), d) of Section I are carried out at least at the following times and circumstances: a) when an ongoing relationship is established; b) when an occasional transaction is carried out by the customer that: (i) involves the transmission or movement of payment instruments of an amount equal to or greater than 15,000 euros, regardless of whether it is carried out with a single operation or with more fractional operations; or (ii) consists in a fund transfer (11) exceeding 1,000 euros. The amount limits do not apply, and due diligence is therefore always due, for all occasional transactions carried out as a payment service or for the issuance and distribution of electronic money through agents in financial activity or "conventional subjects and agents".
Occasional transactions also include cases where banks, electronic money institutions, payment institutions, or Poste Italiane S.p.A. act as intermediaries or are otherwise parties in transfers of cash or bearer securities carried out for any reason between different subjects, of a total amount equal to or greater than 15,000 euros; c) when there is suspicion of money laundering or terrorist financing, regardless of any applicable derogation, exemption, or threshold; recipients avail themselves of the anomaly indicators and schemes representing anomalous behaviors issued by the UIF, pursuant to the anti-money laundering decree; d) when doubts arise regarding the completeness, reliability, or truthfulness of the information or documentation previously acquired (e.g., in the case of non-delivery of correspondence to the communicated address or inconsistencies between documents presented by the customer or otherwise acquired by the recipient).
Recipients fulfill due diligence obligations towards new customers. With regard to already acquired customers, recipients carry out due diligence again when appropriate, due to the increase in the level of money laundering and terrorist financing risk associated with the customer.
Section III. Identification of the customer and the agent
Pursuant to Article 19, paragraph 1, letter a), of the anti-money laundering decree, if the customer is a natural person, identification consists of acquiring the identification data provided by the customer themselves, prior to presentation of an identity document or other equivalent recognition document pursuant to current legislation, of which a copy is acquired in paper or electronic format. In the same manner, recipients identify co-holders and the agent. In the case of the agent, information regarding the existence and extent of the power of representation is also acquired.
If the customer is a subject other than a natural person, and therefore operates through natural persons endowed with the power to represent them, identification is carried out with regard to:
(10) Relationships and transactions, carried out on the initiative of the manager, in the provision of collective investment services provided for in art. 1, paragraph 1), letter n), of the TUF as well as portfolio management pursuant to art. 1, paragraph 5-quinquies, of the TUF are also excluded. Reference is made to relationships and transactions relating to the purchase and sale and administration of assets (movable, immovable, securities) in which customer resources are invested. Instead, the activity of granting financing carried out by managers who establish a so-called "credit fund" falls within the perimeter of institutional activity. In these cases, the financed subject is a customer and towards whom the manager therefore fulfills the obligations provided for by anti-money laundering legislation.
11
(11) As defined by Article 3, paragraph 1, point 9, of Regulation (EU) no. 2015/847 of the European Parliament and of the Council.
12
13 Identification is carried out in the presence of the customer or – when the customer is a subject other than a natural person – of the agent. When the persons to be identified are more than one (in the case of joint account holders or multiple agents), the acquisition of identity documents may take place at different times, provided it occurs before making the joint ownership or delegation or representation powers operational. In compliance with the anti-money laundering decree and subject to what is provided in Sections VI and VII of this Part, the identification obligation is considered fulfilled, even without their physical presence, for customers:
Section IV. Identification of the Beneficial Owner Recipients identify the beneficial owner, without the need for their physical presence, concurrently with the identification of the customer and based on the identification data provided by the customer. At the time of identification, recipients require the customer, other than a natural person, to provide all information necessary for the identification of the beneficial owner sub 2). The customer must also be reminded to declare whether the continuous relationship is opened or the occasional operation is carried out on behalf of another subject, as well as to provide all indications necessary for the identification of this subject and its eventual beneficial owner sub 2). Subject to the above, operations attributable to a continuous relationship are presumed to be carried out in the interest of the natural person customer who is the holder of the relationship or, in the case of a customer other than a natural person, of the beneficial owner sub 2) of the relationship, unless otherwise indicated by the customer. At the time of establishing the continuous relationship, recipients ensure that the customer commits to reporting, during the future conduct of the relationship, any operations with an amount equal to or greater than those indicated in Section 2, letter b), of this Part, carried out on behalf of third parties (12) and to provide all indications necessary for the identification of the beneficial owner of the operation. Within the framework of ongoing monitoring, recipients evaluate any elements that suggest the customer is acting on behalf of subjects other than those indicated.
(12) These are operations carried out on behalf of subjects other than the natural person customer who is the holder of the relationship or, in the case of a customer other than a natural person, from the beneficial owner sub 2) of the relationship itself.
14 If, in relation to concrete situations, there are multiple beneficial owners, recipients fulfill identification obligations with respect to each of them.
Section V. Verification of data relating to the customer, the agent, and the beneficial owner Verification of data relating to the customer, the agent, and the beneficial owner (13) requires checking the truthfulness of the identification data contained in documents and the information acquired at the time of identification (14).
(13) Verification of the identification data of the beneficial owner sub 1) takes place by comparison with those derivable from a reliable and independent source of which a copy is acquired and kept, in paper or electronic format. (14) When original documents are in a foreign language, recipients adopt necessary measures to identify their content (also through a sworn translation of the original, when deemed necessary). (15) By way of example, for stateless persons, who do not appear to possess the aforementioned documents, identification data may be verified through the travel document for stateless persons, issued pursuant to the Convention relating to the Status of Stateless Persons signed in New York on 28 September 1954. For holders of the status of "refugee" or the status of "subsidiary protection", pursuant to Legislative Decree No. 251 of 19 November 2007, identification data may also be verified through travel documents provided for in Article 24 of the same Decree.
15 In addition to the Italian business register, the following are included among reliable and independent sources for checking the identification data of the customer other than a natural person and the beneficial owner sub 2): i. registers and lists of authorized subjects, constitutive deeds, statutes, balance sheets, or equivalent documents, communications made to the public in compliance with sector regulations (such as prospectuses, communications of significant shareholdings, or inside information); ii. registers of beneficial owners established in other EU countries in implementation of Articles 30 and 31 of the anti-money laundering directive; iii. information from bodies and public authorities, also from other EU countries; such information may also be acquired through websites. Recipients, according to a risk-based approach, evaluate the extent and depth of the checks to be carried out.
Section VI. Acquisition and Evaluation of Information on the Purpose and Nature of the Continuous Relationship and Occasional Operations Recipients acquire and evaluate information on the purpose and nature of the relationship. The depth and extent of checks are correlated to the risk profile. Recipients acquire and evaluate, in any case, information concerning:
Section VII. Ongoing Monitoring During the Continuous Relationship Recipients carry out ongoing monitoring during the continuous relationship to keep the customer profile updated and identify elements of inconsistency that may constitute relevant anomalies for specific obligations (adoption of enhanced due diligence measures, reporting of suspicious transactions, abstention from executing the operation or from continuing the relationship). Ongoing monitoring is exercised through the examination of the customer's overall operations, taking into account both ongoing continuous relationships and specific operations possibly ordered, as well as through the acquisition of information during verification or updating of data for the identification of the customer, the beneficial owner, and the ascertainment and evaluation of the nature and purpose of the relationship or operation. In the anti-money laundering policy document, recipients establish, based on the risk profile, the timing and frequency of updating the data and information acquired, also making use of automatic procedures for reporting the expiration of documents, certifications, powers of representation, mandate relationships, as well as for reporting the acquisition of specific qualities (e.g., that of PEP), or inclusion in lists or registers (e.g., those provided for by EU Regulations or decrees adopted pursuant to Legislative Decree No. 109 of 22 June 2007, to combat international terrorist financing). Updating is nevertheless carried out when the recipient detects that the information previously acquired and used for due diligence is no longer current. Where appropriate, the results of monitoring lead to: updating of data, information, and risk profiles; carrying out broader and more in-depth checks (also application of enhanced due diligence); identification of anomalies and inconsistencies that may lead to reporting suspicious transactions; freezing of funds; abstention from carrying out the operation; closure of the relationship.
Section VIII. Specific Provisions on Remote Operations Remote operations are those carried out without the physical co-presence, at the recipient's premises, of the customer, the recipient's employees, or other personnel entrusted by the recipient (e.g., through telephone or computer communication systems); when the customer is a subject other than a natural person, they are considered present when the agent is present. Recipients pay particular attention to remote operations, given the absence of direct contact with the customer or the agent. Recipients take into account the risk of fraud connected to identity theft. In cases of remote operations, recipients: a) acquire the identification data of the customer and the agent and check them against a copy – obtained via fax, mail, in electronic format, or with analogous methods – of a valid identity document, pursuant to current legislation; b) carry out checks beyond those provided for in Section V on the acquired data, according to the most appropriate methods in relation to the specific risk. By way of example,
16 the following methods are indicated: telephone contact on a landline (welcome call); sending communications to a physical address with return receipt; transfer made by the customer through a banking and financial intermediary with headquarters in Italy or in an EU country; request for sending of signed documentation; verification of residence, domicile, activity carried out, through requests for information to competent offices or through on-site meetings, carried out using own personnel or third parties. In compliance with the risk-based approach, recipients may use verification mechanisms based on innovative and reliable technological solutions (e.g., those involving biometric recognition), provided they are assisted by robust security safeguards; c) identify, in the anti-money laundering policy document, the specific mechanisms they intend to use to carry out the checks under b) and illustrate the assessments conducted by the anti-money laundering function on the risk profiles characterizing each of these tools and their related security safeguards (18). As an alternative to what is provided under a), b), c), the identification of the natural person customer may be carried out by recipients digitally remotely according to the audio/video registration procedure regulated in Annex 3.
(18) In the assessment of the reliability and risks associated with verification mechanisms based on innovative technologies, recipients take into account, among other things, the indications contained in the Opinion on the use of innovative solutions by credit and financial institutions in the customer due diligence process (“Opinion on the use of innovative solutions by credit and financial institutions in the customer due diligence process”) adopted by the European Banking Authority on 23 January 2018, available at the following link: https://esas-joint-committee.europa.eu/Publications/Opinions/Opinion%20on%20the%20use%20of%20innovative%20solutions%20by%20credit%20and%20financial%20institutions%20(JC-2017-81).pdf.
17
PART THREE SIMPLIFIED DUE DILIGENCE OBLIGATIONS
Section I. General Principles In the presence of a low risk of money laundering and terrorist financing, recipients may comply with due diligence obligations in a simplified manner, reducing the scope and frequency of the obligations provided for in Part Two. To facilitate recipients in applying simplified due diligence measures, the low-risk factors provided for by the anti-money laundering decree are reported in the annex (Annex 1) – accompanied, where appropriate, by explanatory examples – and further low-risk factors relevant for the application of simplified measures are indicated, pursuant to Article 23, paragraph 3, of the anti-money laundering decree. Recipients define and formalize, in the anti-money laundering policy document, sufficiently detailed customer due diligence procedures; the document indicates at least the specific simplified due diligence measures (among those indicated in Section II) to be taken in relation to different types of low-risk customers or products. Recipients adequately justify the choice to consider additional factors indicating low risk.
Section II. Simplified Due Diligence Measures Simplified due diligence measures consist of a reduction in the scope or frequency of the obligations provided for in Part Two, taking into account:
18 Recipients verify the persistence of the prerequisites for applying the simplified procedure, with methods and frequency established according to the risk-based approach. Simplified due diligence measures do not apply when:
19
20
PART FOUR ENHANCED CUSTOMER DUE DILIGENCE OBLIGATIONS
Section I. General Principles
Recipients apply enhanced customer due diligence measures when there is a high risk of money laundering and terrorist financing, resulting from specific regulatory provisions or from their own autonomous assessment.
The following are always considered high risk, pursuant to Article 24, paragraphs 3 and 5, of the anti-money laundering decree: a) relationships and occasional transactions involving high-risk third countries in the cases indicated by Article 24, paragraph 5, letter a), of the anti-money laundering decree; b) cross-border correspondent relationships with a responding banking or financial intermediary established in a third country; c) ongoing relationships or occasional transactions with customers and their beneficial owners who hold the status of politically exposed persons; d) customers who carry out transactions characterized by unusually high amounts or regarding which there are doubts about the concrete purpose to which they are directed.
To facilitate recipients in applying enhanced due diligence measures, the high-risk factors provided for in the anti-money laundering decree are reported in Annex 2 (Annex 2), accompanied, where appropriate, by explanatory examples, and further relevant factors for the application of enhanced measures are provided, pursuant to Article 24, paragraph 4, of the anti-money laundering decree.
Recipients define and formalize in their anti-money laundering policy document, sufficiently detailed customer due diligence procedures; the document must indicate at least the specific measures (among those indicated in Section II) of enhanced due diligence to be taken in relation to different types of high-risk customers or products.
Section II. Enhanced Customer Due Diligence Measures
Enhanced customer due diligence measures consist of acquiring more information about the customer and the beneficial owner; a more accurate assessment of the nature and purpose of the relationship; intensifying the frequency of checks and increasing the depth of analyses carried out within the scope of the ongoing monitoring activity of the continuous relationship.
The measures may consist of: a) acquiring a greater quantity of information relating to: i. the identity of the customer and the beneficial owner or the customer's ownership and control structure. This includes the acquisition and evaluation of information on the reputation of the customer and the beneficial owner (indications provided in Annex 2, letter A), no. 3) are relevant in this regard); ii. the ongoing relationship, to fully understand its nature and purpose. This includes acquiring information on:
21
In the case of frequent and unjustified cash transactions, especially if carried out with large-denomination banknotes, recipients conduct in-depth investigations, also with the customer, to verify the reasons underlying this activity.
In the case of services with a high degree of customization, offered to high-risk customers, recipients verify in any case the origin of income and wealth. c) increasing the frequency of updates of the information acquired through: i. more frequent checks on the ongoing relationship aimed at promptly detecting any changes in the customer's risk profile; ii. more frequent or in-depth checks on transactions, to promptly detect any elements of suspicion of money laundering. In this context, recipients verify the destination of the funds and the reasons underlying a specific activity; d) requesting the authorization of a senior manager for the initiation or continuation of the ongoing relationship.
Section III. Relationships and Occasional Transactions Involving High-Risk Third Countries
Recipients apply enhanced customer due diligence measures to relationships and occasional transactions involving high-risk third countries, in the cases indicated by Article 24, paragraph 5, letter a), of the anti-money laundering decree.
Pursuant to Article 42, paragraph 2, of the anti-money laundering decree, recipients refrain from establishing or continuing ongoing relationships or carrying out transactions in which they are parties, directly or indirectly, to fiduciary companies, trusts, anonymous companies (or controlled through bearer shares) established in high-risk third countries.
Section IV. Cross-Border Correspondent Relationships with a Responding Banking or Financial Intermediary of a Third Country
Recipients modulate the enhanced customer due diligence measures applied to the responding intermediary based on risk, pursuant to Article 25, paragraph 2, of the anti-money laundering decree, paying particular attention to the geographic risk factors indicated in Annex 2, letter C.
They ascertain that respondents are not shell banks and do not allow shell banks access to correspondent relationships.
Enhanced customer due diligence measures include at least: a) the acquisition by the recipient of information suitable to clearly identify the ownership structure of the respondent; b) the acquisition, from the respondent, of information suitable to fully understand the nature of the activities carried out by it, also with reference to the services provided to customers for which the account or accounts opened at the intermediary recipient of the enhanced obligations are used; c) that recipients, when customers of the respondent have direct access to pass-through accounts, ensure, also through sample checks, that the respondent: i) fulfills the customer due diligence obligations, including ongoing monitoring; ii) can provide the recipient itself, upon request, all data collected as a result of fulfilling such obligations as well as any other relevant information regarding its customers or specific transactions. Recipients carefully evaluate the completeness of the information and documentation provided in response; any information gaps are taken into account for the purpose of re-evaluating the respondent's risk profile. Recipients acquire an express attestation from the respondent regarding the non-existence of regulatory or contractual impediments regarding the timely transmission of the requested information; d) the acquisition and evaluation of publicly available information on the reputation of the respondent and on the quality of the supervisory and anti-money laundering control regime to which it is subject. For this purpose, recipients may avail themselves of mutual evaluation reports adopted by the FATF or the IMF; e) the authorization, for the opening of each correspondent or pass-through relationship, by a senior manager, preferably not coinciding with the manager who promoted the opening of the business relationship with the respondent. For this purpose, the senior manager verifies the adequacy of the measures adopted to effectively mitigate the risk connected to the correspondent relationship; f) the definition in writing of the terms of the agreement with the respondent and their respective obligations. The recipient is required to identify which subjects (and by what means) can access the correspondent banking service (e.g., whether the correspondent account can be used by other banks having agreements with the respondent) as well as to define the respondent's responsibilities regarding anti-money laundering obligations. The agreement also provides: i) the methods through which the recipient can monitor the correspondent relationship to ascertain whether the respondent fulfills customer due diligence obligations and carries out other checks provided for by anti-money laundering regulations; ii)
23
the obligation for the respondent to provide the recipient, upon request, information on specific transactions or specific customers of the respondent; g) ongoing monitoring of the relationship with the respondent, with frequency and intensity commensurate with the correspondent service performed; in this context, recipients adopt procedures, also IT-based, aimed at automatically detecting anomalous transactions due to the recurrence or amount of operations or due to the destination or origin of flows; h) the evaluation of the respondent's internal anti-money laundering control system, acquiring suitable documentation. For this purpose, documentation solely regarding the respondent's anti-money laundering policies and procedures is not sufficient. If the risk is particularly high and the volume of transactions relevant, the recipient evaluates the appropriateness of carrying out inspections and sample checks to ascertain the effectiveness of the respondent's anti-money laundering policies and procedures.
With reference to accounts opened by the recipient used indirectly by other intermediaries (who, therefore, have a direct relationship with the respondent but not with the recipient, hereinafter referred to as "indirect correspondents"), the recipient:
Section V. Politically Exposed Persons
Pursuant to the anti-money laundering decree, politically exposed persons (or PEPs) are considered at higher risk of money laundering as they are more exposed to potential corruption phenomena. The qualification of PEP is relevant for both the customer and the beneficial owner.
Recipients define procedures to verify whether the customer or the beneficial owner falls within the definition of PEP. For this purpose, in addition to obtaining pertinent information from the customer, they avail themselves of other sources, such as official websites of Italian authorities or countries of origin of PEPs, or commercial databases. The intensity and extent of checks are commensurate with the degree of risk associated with the different products and operations requested.
Regarding ongoing relationships already opened, within the scope of ongoing monitoring activity, recipients verify the possible acquisition or subsequent changes in the PEP status of the customer or the beneficial owner of the relationship. For this purpose, recipients, in addition to external information sources, use in an integrated manner all information otherwise in their possession (e.g.,
24
information collected during the investigation phase for the granting of financing operations, MiFID questionnaire where relevant).
When the customer or the beneficial owner falls within the definition of PEP, the recipient ensures that the initiation or continuation of the ongoing relationship or the execution of the occasional transaction is authorized by a senior manager who evaluates the PEP's exposure to money laundering risk and the degree of effectiveness of existing company safeguards to mitigate the risk.
Regarding subjects originally identified as PEPs, who have ceased to hold public office for more than one year, recipients, in the presence of a high risk of money laundering, continue to apply enhanced customer due diligence measures.
Recipients adopt adequate measures and acquire all necessary information to establish the origin of the wealth of PEPs and the funds specifically used in the relationship or in the occasional transaction. For this purpose, in the case of ongoing relationships, recipients acquire an attestation from the customer and, consistent with the risk-based approach, verify the information based on reliable documents, from independent sources, provided by the customer or publicly available as well as based on attestations from other intermediaries, where issued.
The extent of the measures adopted and the information acquired depends on the degree of risk associated with the PEP. Recipients collect information suitable to reasonably exclude that the funds used are the result of corrupt crimes or other criminal offenses.
The acquisition of this information aims to guarantee effective ongoing monitoring, also for the purpose of detecting any elements of suspicion. The customer's reluctance to provide the requested information regarding the origin of wealth or funds is an element that recipients consider for the purpose of fulfilling the obligation to report suspicious transactions.
Recipients subject ongoing relationships attributable to a PEP to reinforced ongoing monitoring. For this purpose, they adopt, among other things, procedures aimed at detecting anomalous operations related to the PEP and promptly examine information useful to evaluate the PEP's risk.
Section VI. Transactions Characterized by Unusually High Amounts or Regarding Which There Are Doubts About the Purpose
Recipients adopt procedures for detecting and evaluating anomalous transactions and operational schemes. This includes:
The enhanced customer due diligence measures adopted by recipients allow for the evaluation of the suspicious nature of the transactions and consist at least of:
25
26
PART FIVE EXECUTION BY THIRD PARTIES OF CUSTOMER DUE DILIGENCE OBLIGATIONS
Section I. Scope of Application and Responsibility
Within the limits indicated below, recipients may delegate the fulfillment of customer due diligence obligations to third parties, with the full responsibility of the recipient for the observance of said obligations remaining intact.
In particular, the following are distinguished: a) third parties who can carry out all phases of due diligence, except for the ongoing monitoring of activity. They are:
The agreement specifies the obligations to be fulfilled regarding identification and the methods and times of fulfillment, including the times for transmitting information to the recipient, as well as the responsibility of the collaborator for the incorrect performance of the assigned activity.
With the full responsibility of recipients for the observance of obligations intact, the provisions of this Part do not apply to outsourcing or agency relationships when, pursuant to the contract or agreement however named, the provider of the outsourced service or the agent are comparable to employees (19) or, in any case, to subjects stably integrated into the recipient's organization (20).
(19) For the purposes of these provisions, financial consultants authorized for off-premises offers are comparable to employees of the recipients for whom they perform their activity. (20) In banking or financial groups governed by Articles 60 and 109 of the TUB and Article 11 of the TUF, companies of the group established in Italy to which the fulfillment of due diligence obligations is outsourced are assumed to be stably integrated into the recipient's organization.
27 In no case can the due diligence obligations be delegated to convenience banks or intermediaries established in high-risk third countries.
Section II. Content and methods of execution of obligations
In the event of the use of third parties provided for in letter a) of Section I, the due diligence obligations are considered satisfied through a suitable attestation issued by the third party who has directly complied with them in relation to the establishment of a continuous relationship or the execution of an occasional transaction.
The attestation is clearly attributable to the attesting third party, through appropriate measures (signature by authorized personnel, sending via IT systems, etc.), and is transmitted by the attesting third party and not by the client.
To standardize the information acquisition process, the recipient may prepare specific forms for the issuance of attestations.
The attestation expressly confirms the correct compliance with anti-money laundering obligations by the attester, in relation to the various activities carried out. The content of the attestation varies depending on the specific due diligence obligation to which it is directed; based on this criterion, it contains: a) the identification data of the client, the executor, and the beneficial owner for the purpose of fulfilling the identification obligation; b) the indication of the types of sources used for the verification and checking of identity; c) information on the nature and purpose of the relationship to be opened and of the occasional transaction to be executed for the purpose of fulfilling the related obligation.
The recipient ensures that, in addition to the attestation, third parties are able to promptly transmit copies of the documents and information acquired, when the recipient requests it.
The attestation may be provided in paper or electronic form, independently or in connection with specific transactions.
The recipient remains responsible for due diligence and evaluates whether the elements collected and the checks carried out by third parties are up-to-date, suitable, and sufficient for the fulfillment of the obligations provided by law. In case of failure, the recipient proceeds, depending on the case and circumstances, to:
In the event of the use of third parties who can only perform client identification (see Section I, letter b), the recipient ensures that third parties transmit in any case the data and information acquired, so that the recipient itself can complete the due diligence procedure (21).
Within the scope of information collection and exchange methods with third parties, the recipient:
(21) In the case of "contracted subjects and agents", the acquisition of data takes place according to the methods provided for in Article 44 of the anti-money laundering decree.
28
29 SIXTH PART SPECIFIC PROVISIONS FOR PARTICULAR TYPES OF OPERATIONS
This Part applies when a recipient (hereinafter referred to as the counterparty recipient) offers investment services and activities or collective investment management through another banking or financial intermediary that operates in the interest of its own clients (the commissioning intermediary) (22); for matters not otherwise regulated, reference is made to the other Parts of these provisions.
In these cases, for the purpose of applying due diligence obligations, the counterparty recipient first identifies the role and position assumed by the commissioning intermediary acting on behalf of its client (the investor).
In particular, two cases can be distinguished:
In this hypothesis, the commissioning intermediary - as the direct counterparty of the recipient - becomes the holder of the financial instruments, even though it acts based on specific purchase or sale instructions given by its client; 2) the commissioning intermediary acts not only on behalf of but also in the name of the client, assuming the position of mere intermediation in the relationship between its own client (the investor) and the counterparty recipient. According to this scheme, the commissioning intermediary is therefore not the holder of the financial instruments (ownership of which lies directly with the investor).
Case 1) The commissioning intermediary assumes the position of client of the counterparty recipient. In this case, in low-risk situations, the counterparty recipient may limit itself to acquiring only the identification data of the investor on whose behalf the commissioning intermediary acts (and of its beneficial owner sub 2, where it is not a natural person) if: i. the commissioning intermediary falls among intermediaries potentially at low risk of money laundering and terrorist financing, based on the criteria provided for in Annex 1; ii. the counterparty recipient has adopted graduated risk-based measures to ensure that the risk of money laundering and terrorist financing connected to the continuous relationship with the commissioning intermediary is low, considering, among other things, the activity of the commissioner, the type of clientele served, and the countries in which it offers its services; iii. the counterparty recipient ensures that the commissioning intermediary applies graduated risk-based due diligence measures to its clients; in particular, the recipient, based on publicly available information or acquired directly from the commissioning intermediary, evaluates the suitability of the due diligence procedures adopted by it; iv. the counterparty recipient adopts graduated risk-based measures (24) to ensure that the commissioning intermediary is able to provide, upon request, all data collected regarding investors as well as any other relevant information regarding them or specific transactions. The counterparty recipient carefully evaluates the completeness of the documentation and information received and takes into account any information gaps for the purpose of a re-evaluation of the commissioning intermediary's risk profile.
If the conditions are not all met or if there is suspicion of money laundering or terrorist financing, the application of simplified obligations is excluded.
Case 2) The relationship is established directly between the investor, as client, and the counterparty recipient: the latter therefore subjects the investor to graduated risk-based due diligence measures.
For this purpose, the counterparty recipient may resort to another intermediary (generally, the commissioning intermediary), in compliance with the provisions on the execution of due diligence obligations by third parties (see Sixth Part).
(22) In the case of occasional transactions, the due diligence obligations are fulfilled by the recipient who comes into contact with the client and not by the recipient with whom the occasional transaction occurs. Reference is made, by way of example, to the delivery of cashier's checks by banks other than the one issuing the instrument. (23) This case includes the scenario of an intermediary authorized to provide investment services that participates in a fund (formal participant) in its own name and on behalf of the client (effective participant) and therefore based on a mandate without representation.
30
31 ANNEX 1 Low-risk factors
To facilitate recipients in applying simplified due diligence measures, the low-risk factors provided for in the anti-money laundering decree are reported below, accompanied, where appropriate, by explanatory examples. Furthermore, pursuant to Article 23, paragraph 3, of the anti-money laundering decree, additional low-risk factors relevant for the application of simplified measures are provided (25).
A) Low-risk factors relating to the client, executor, and beneficial owner:
B) Low-risk factors relating to products, services, transactions, or distribution channels:
(24) For example, by including specific clauses to this effect in the contract with the commissioning intermediary or by sampling the ability of the latter to transmit the requested information on customer due diligence.
32 services with low exposure to possible use for illicit purposes. Relevant in this context are products with limited functionality (e.g., with a predetermined operational threshold or subordinate to the purchase of a specific good or service for the consumer) and which do not allow anonymity or concealment of the identity of the client and/or the beneficial owner.
C) Geographic low-risk factors:
33 ANNEX 2 High-risk factors
To facilitate recipients in applying enhanced due diligence measures, the risk factors provided for in the anti-money laundering decree are reported below, accompanied, where appropriate, by explanatory examples. Furthermore, pursuant to Article 24, paragraph 4, of the anti-money laundering decree, additional risk factors relevant for the application of enhanced measures are provided (27).
A) High-risk factors relating to the client, executor, and beneficial owner:
(25) Where relevant in relation to the specific activity carried out, recipients also take into consideration the additional low-risk factors contained in Title III ("Sectoral Guidelines") of the Joint Guidelines of the European Supervisory Authorities on simplified and enhanced customer due diligence measures and on money laundering and terrorist financing risk factors associated with continuous relationships and occasional transactions (see: https://esas-joint-committee.europa.eu/Publications/Guidelines/Guidelines%20on%20Risk%20Factors_IT_04-01-2018.pdf). (26) Trust companies registered in the Register provided for in Article 106 of the TUB may consider low-risk the compensation plans based on financial instruments referred to in Article 114-bis of the TUF.
34
(27) Where relevant in relation to the specific activity carried out, recipients also take into consideration the additional high-risk factors contained in Title III ("Sectoral Guidelines") of the Joint Guidelines of the European Supervisory Authorities on simplified and enhanced customer due diligence measures and on money laundering and terrorist financing risk factors associated with continuous relationships and occasional transactions (see: https://esas-joint-committee.europa.eu/Publications/Guidelines/Guidelines%20on%20Risk%20Factors_IT_04-01-2018.pdf). (28) It remains understood that against high-risk third countries, recipients apply enhanced customer due diligence measures provided for in the Fourth Part.
34 verify the occurrence of names in the lists of persons or entities associated for the purposes of applying the freezing obligations provided for by Community Regulations or by decrees adopted pursuant to Legislative Decree 22 June 2007, n. 109; 4) structures that can be classified as vehicles for asset intermediation. This includes, by way of example, trusts, fiduciary companies, foundations, and further legal subjects that can be structured in such a way as to benefit from anonymity and allow relationships with shell banks or with companies having nominee shareholders. Specific attention is paid to corporate structures and trusts that can be classified as intermediation vehicles having their seat in countries that, following evaluations conducted by the FATF or similar international bodies, present unfavorable ratings regarding Recommendations nos. 24 and 25 and the "Immediate Outcome" no. 5 (29) regarding transparency obligations for corporate structures and trusts. Entities having their seat in countries that present negative evaluations by the OECD Global Forum on transparency and exchange of information for tax purposes are also considered high risk. With reference to fiduciary companies, the supervision by the Bank of Italy constitutes a risk mitigation factor, which may determine the application of standard due diligence measures. In the context of securitization operations, the improper use of special purpose vehicles to shield the beneficial ownership of certain assets, hindering the correct reconstruction of the financial flows generated by them, is relevant; 5) companies that have issued bearer shares or are held by nominees (so-called nominee shareholder). The reference, in the first case, is to companies constituted or capitalized through bearer instruments, especially if issued in foreign countries that, based on evaluations conducted by the FATF or similar international bodies, present unfavorable ratings regarding Recommendation no. 24 and no. 25 and the Immediate Outcome no. 5, regarding transparency obligations for corporate structures and trusts; 6) type of economic activity characterized by high use of cash. The reclassification of economic activities carried out by the customer into types particularly exposed to money laundering risks is relevant, such as the gold buying sector, currency exchange, gambling or betting activities, services provided by financial activity agents and "contracted subjects and agents" in the money remittance service; 7) type of economic activity attributable to sectors particularly exposed to corruption risks. These are, in particular, economic sectors involved in the provision of public funds, including those of Community origin, public contracts, healthcare, construction, arms trade, defense, military industry, mining industry, waste collection and disposal, production of renewable energies; 8) customer or beneficial owner who hold public offices in areas not included in the notion of PEP but for whom there is nevertheless a significant exposure to corruption risk. Reference is made, for example, to local administrators, subjects with senior roles in public administration or public bodies, consortia, and associations of a public nature; 9) anomalous or excessively complex ownership structure given the nature of the activity carried out. The legal form adopted by the customer must be considered, especially where there are particular elements of complexity or opacity that prevent or hinder the identification of the beneficial owner or the real corporate object or any shareholding or financial links with subjects having their seat in high-risk geographic areas. B) High-risk factors related to products, services, operations, or distribution channels:
(29) For this purpose, addressees may consult the consolidated table of ratings relating to the various evaluations conducted within the FATF or by similar international bodies.
35
(30) See the schematic representation of anomalous behaviors "Operationality related to international tax fraud and invoicing fraud" published by the UIF on April 23, 2012.
36 World Drug Reports published by the United Nations Office on Drugs and Crime; 3) countries subject to sanctions, embargoes, or similar measures adopted by competent national and international bodies. In this regard, addressees observe the measures issued by the European Union and other restrictive measures adopted pursuant to Article 4 of Legislative Decree 22 June 2007, n. 109, implementing Resolutions of the United Nations Security Council, for the fight against terrorist financing and the financing of weapons of mass destruction proliferation programs and against the activity of countries threatening international peace and security; 4) countries and geographic areas that finance or support terrorist activities or in which terrorist organizations operate. Reports on terrorism published by the FATF or other international organizations and agencies, such as Europol, are helpful in identifying such countries; 5) countries evaluated by authoritative and independent sources as lacking in compliance with international standards on transparency and exchange of information for tax purposes. Authoritative and independent sources include reports adopted by the OECD on tax transparency and information exchange; evaluations on the country's commitment to the automatic exchange of financial information for tax purposes under the so-called Common Reporting Standard; ratings assigned to FATF Recommendations nos. 9, 24, and 25 and to "Immediate Outcomes" nos. 2 and 5 in international mutual evaluation reports are also relevant. In the anti-money laundering policy document, addressees establish the importance to be attributed to each risk factor relating to the country or geographic area, in light of the nature and purpose of the ongoing relationship. For example, when:
37 ANNEX 3 Video-identification Procedure Addressees implement a system that guarantees, prior to the establishment of the audio/video session, the encryption of the communication channel through the adoption of standard mechanisms, updated applications, and protocols. They also guarantee the use of applications oriented towards usability and accessibility for the customer. Addressees ensure that the remote identification performed by the operator in charge of video-identification (hereinafter, "operator") respects the following conditions: a) video images are in color and allow clear visualization of the interlocutor in terms of brightness, sharpness, contrast, and image fluidity; b) audio is clearly audible, free from distortions or obvious disturbances; c) the audio/video session, which concerns the video images and audio of the customer and the operator, is conducted in environments free from particular disturbing elements. Addressees ensure that the operator in charge of the activity refrains from initiating the identification process or suspends it when the audio/video quality is poor or deemed inadequate to allow customer identification. The operator performing the identification: i) acquires the identification data provided by the customer; ii) requests the presentation of a valid identity document, bearing a recent and recognizable photograph and the applicant's handwritten signature, issued by a public administration; and iii) verifies the tax code via the valid health card in force. A copy of the document is acquired in electronic format. The operator performing the identification may exclude the admissibility of the audio/video session for any reason, including the possible inadequacy of the document presented by the customer. The audio/video session is entirely recorded and preserved. Addressees request consent for the processing of personal data contained in the audio-video recordings, specifying this aspect in the information to be provided to the interested party pursuant to provisions on personal data protection. The audio/video session is conducted following a written procedure formalized by the addressees, which provides for at least the following activities: a) the operator acquires consent to video recording and its preservation and informs that the video recording will be preserved in a protected manner; b) the operator declares their personal details; c) the customer confirms their identification data; d) the customer confirms the date and time of the recording; e) the customer confirms their intention to establish the ongoing relationship and confirms the identification data and other data entered in the online forms during pre-registration; f) the customer confirms their mobile phone number and email address; g) the operator sends a message that the customer displays to the recording device or whose content is communicated to the operator, and an email to the email address declared by the customer, with a link to a URL specifically set up for verification;
38 h) the operator asks the customer to frame, front and back, the identification document used, and ensures that it is possible to clearly view the photograph and read all the information contained therein (personal data, document number, issue and expiry dates, issuing authority). An electronic copy of the document is acquired; i) the operator asks to show, front and back, the health card on which the customer's tax code is reported; j) the operator asks the customer to perform one or more random actions to strengthen the authenticity of the interaction; k) the operator briefly summarizes the customer's expressed intention to establish the ongoing relationship and collects confirmation. When doubts, uncertainties, or inconsistencies emerge in the customer's identification, addressees carry out further checks. By way of example, they may consult the public system for the prevention of identity theft provided for by Legislative Decree 11 April 2011, n. 64. The documentation to be preserved includes the information and documents that were collected during the registration activity. Addressees preserve, in a manner compliant with the provisions on preservation of the anti-money laundering decree, the registration data as well as the customer's explicit intention to establish the ongoing relationship, stored in audio-video files, images, and metadata structured in electronic format.