2019-03-27

Added · Updated

Provisions on Organization, Procedures and Internal Controls to Prevent the Use of Intermediaries for Money Laundering and Terrorist Financing

The document establishes mandatory organizational, procedural, and internal control frameworks for a broad range of financial intermediaries, including banks, SIMs, SGRs, payment institutions, and trust companies, to prevent money laundering and terrorist financing. It mandates a risk-based approach requiring entities to adopt specific governance structures, including a dedicated anti-money laundering function, a responsible officer for suspicious transaction reporting, and internal audit oversight. The rules further detail the operational requirements for risk assessment methodologies, group-level coordination, specific activities such as money transfers, and the designation of central contact points.

Banca d'Italia logo

Italy

Banca d'Italia

Click to view thumbnail

The present document is consistent with the original contained in the archives of the Bank of Italy Digitally signed by Head Office Via Nazionale, 91 - P.O. Box 2484 - 00100 Rome - Share capital Euro 156,000.00 Tel. 06/47921 - telex 630045 BANKIT - VAT No. 00950501007 - www.bancaditalia.it

PROVISIONS ON ORGANIZATION, PROCEDURES AND INTERNAL CONTROLS AIMED AT PREVENTING THE USE OF INTERMEDIARIES FOR THE PURPOSES OF MONEY LAUNDERING AND TERRORIST FINANCING

INDEX PROVISIONS ON ORGANIZATION, PROCEDURES AND INTERNAL CONTROLS AIMED AT PREVENTING THE USE OF INTERMEDIARIES FOR THE PURPOSES OF MONEY LAUNDERING AND TERRORIST FINANCING ..............................................1 PRELIMINARY PROVISIONS.....................................................................................................1 NORMATIVE SOURCES..............................................................................................................................1 RECIPIENTS......................................................................................................................................1 DEFINITIONS ......................................................................................................................................2 COMMUNICATIONS TO THE BANK OF ITALY...............................................................................................3 PART ONE GENERAL PRINCIPLES.........................................................................................3 SECTION I. PRINCIPLE OF PROPORTIONALITY........................................................................................3 SECTION II. RISK-BASED APPROACH .....................................................................................3 SECTION III. MINIMUM ORGANIZATIONAL CONTROLS.......................................................................................4 PART TWO ORGANIZATIONAL STRUCTURES TO SAFEGUARD AGAINST MONEY LAUNDERING RISKS ...................................................................................................................................5 SECTION I. GENERAL PRINCIPLES ...........................................................................................................5 SECTION II. BODY WITH STRATEGIC SUPERVISION FUNCTIONS.....................................................6 SECTION III. BODY WITH MANAGEMENT FUNCTIONS .............................................................................7 SECTION IV. BODY WITH CONTROL FUNCTIONS..........................................................................8 PART THREE THE STRUCTURE OF ANTI-MONEY LAUNDERING CONTROLS.............................................9 PREAMBLE..........................................................................................................................................9 SECTION I. THE ANTI-MONEY LAUNDERING FUNCTION.........................................................................................9 1.1. ORGANIZATIONAL FRAMEWORK........................................................................................9 1.2. TASKS .................................................................................................................................9 1.3. THE HEAD OF THE FUNCTION......................................................................................11 1.4. OUTSOURCING............................................................................................................11 1.5. RELATIONSHIPS WITH OTHER CORPORATE FUNCTIONS .........................................................................12 1.6. COMMUNICATIONS...................................................................................................................12 SECTION II. THE RESPONSIBLE FOR REPORTING SUSPICIOUS TRANSACTIONS....................................13 SECTION III. THE INTERNAL AUDIT FUNCTION .............................................................................14 SECTION IV. CONTROLS REGARDING DISTRIBUTION NETWORK AND BROKERS................................................14 SECTION V. STAFF TRAINING....................................................................................15 PART FOUR PROVISIONS APPLICABLE TO GROUPS ................................................16 SECTION I. GENERAL PROVISIONS ..................................................................................................16 SECTION II. THE ANTI-MONEY LAUNDERING FUNCTION IN GROUPS. ..................................................................16 SECTION III. REPORTING OF SUSPICIOUS TRANSACTIONS IN GROUPS. ........................................17 PART FIVE PROVISIONS FOR SPECIFIC ACTIVITIES ...........................................19 SECTION I. MONEY TRANSFER SERVICE ("MONEY TRANSFER").............................................19 SECTION II. INFORMATIONAL DATA RELATING TO FUNDS TRANSFERS ................................................19 SECTION III. TRUST COMPANIES REGISTERED IN THE SEPARATE SECTION OF THE ROLL PURSUANT TO ARTICLE 106 OF THE TUB...................................................................................................................................19 PART SIX FURTHER PROVISIONS FOR INTERMEDIARIES OBLIGED TO ESTABLISH THE CENTRAL CONTACT POINT................................................21 SECTION I - PREAMBLE......................................................................................................................21 SECTION II - APPOINTMENT AND TASKS OF THE CENTRAL CONTACT POINT................................................21 SECTION III - ORGANIZATIONAL STRUCTURES OF THE CENTRAL CONTACT POINT........................................22 PART SEVEN THE ASSESSMENT OF MONEY LAUNDERING RISKS................................24 SECTION I. GENERAL PRINCIPLES .........................................................................................................24 SECTION II. METHODS FOR CONDUCTING THE EXERCISE ..................................................................24 SECTION III. IDENTIFICATION OF RELEVANT RISK .......................................................................24 SECTION IV. IDENTIFICATION OF VULNERABILITIES ........................................................................25 SECTION V. DETERMINATION OF RESIDUAL RISK LEVEL.......................................................25 SECTION VI. MATRIX FOR DETERMINING RESIDUAL RISK ....................................................26 SECTION VII. REMEDIAL ACTION .....................................................................................................26 SECTION VIII. TIMETABLES AND METHODS FOR CONDUCTING THE EXERCISE..................................................26 ANNEX SCHEMA OF THE ANNUAL REPORT PRODUCED BY THE ANTI-MONEY LAUNDERING FUNCTION........................................................................................................................28

1 PRELIMINARY PROVISIONS Normative sources The matter is regulated by: – Legislative Decree 21 November 2007, No. 231, as amended by Legislative Decree 25 May 2017, No. 90, and in particular:  Article 7, paragraph 1, letter a), which grants the Bank of Italy the power to issue provisions on organization, procedures and internal controls and adequate customer due diligence;  Article 15, which assigns the Bank of Italy the task of: (i) setting criteria and methodologies for the analysis and assessment of money laundering risks to which obliged subjects are exposed in the exercise of their activities (Article 15, paragraph 1); (ii) identifying categories of obliged subjects for whom provisions on self-assessment of money laundering risk do not apply, due to the irrelevance of the money laundering risk of the activity carried out or the offer of products and services that present typified risk characteristics (Article 15, paragraph 3);  Article 16, paragraph 2, which grants the Bank of Italy the power to identify the size and organizational requirements based on which obliged subjects adopt specific controls, checks and procedures for the assessment and management of money laundering risk and for the introduction of an anti-money laundering function;  Article 43 paragraph 4, which grants the Bank of Italy the power to adopt provisions on the requirements, procedures, control systems and functions of the central contact point, in line with the provisions of Delegated Regulation (EU) No 1108/2018; – Regulation (EU) 2015/847 of the European Parliament and of the Council of 20 May 2015 on information accompanying transfers of funds; – Commission Delegated Regulation (EU) 2018/1108 supplementing Regulation (EU) 2015/847 of the European Parliament and of the Council with regard to regulatory technical standards on criteria for the appointment of central contact points for electronic money issuers and payment service providers and on their functions. The following are also relevant: – Guidelines of the European Supervisory Authorities, adopted pursuant to Article 25 of Regulation (EU) 2015/847, on the measures that payment service providers adopt to identify missing or incomplete informational data relating to the orderer or the beneficiary as well as on the procedures to be put in place to manage a funds transfer not accompanied by the required informational data. Recipients These provisions apply to:

2 a) banks; b) securities intermediation companies (SIM); c) asset management companies (SGR); d) variable capital investment companies (SICAV); e) fixed capital investment companies, securities and real estate (SICAF); f) intermediaries registered in the roll provided for by Article 106 of the TUB; g) electronic money institutions; h) payment institutions; i) branches established in Italy of banking and financial intermediaries having their registered office and central administration in another EU country or a third country ( 1 ); j) banks, payment institutions and electronic money institutions having their registered office and central administration in another Member State obliged to designate a central contact point in Italy pursuant to Article 43, paragraph 3, of Legislative Decree 21 November 2007, No. 231( 2 ); k) trust companies registered in the roll provided for pursuant to Article 106 of the TUB; l) credit guarantee consortia ( 3 ); m) subjects providing micro-credit, pursuant to Article 111 of the TUB; n) Poste Italiane S.p.a., for the bancoposta activity; o) Cassa Depositi e Prestiti S.p.a. In credit securitization operations governed by Law 30 April 1999, No. 130, the obligations under these provisions are fulfilled by the subjects referred to in Article 2, paragraph 6, of the same law. Definitions For the purposes of these provisions, the following terms are understood as:

  1. "financial activity agents": agents registered in the list provided for by Art. 128-quater, paragraphs 2 and 6, of the TUB;
  2. "Authority": the Authorities referred to in Title I, Chapter II of Legislative Decree 231/2007;
  3. "line controls": controls carried out by operational structures (e.g., hierarchical, systematic and sample checks), also through units dedicated exclusively to control tasks that report to the heads of operational structures, or carried out within the back office, incorporated into IT procedures and aimed at ensuring the correct conduct of operations;

( 1 ) The provisions of Part Two and Part Seven, Section VII, apply with reference to the representatives of the branches. ( 2 ) The provisions of Part Two do not apply to the recipients referred to in letter j). ( 3 ) The reference is to be understood as referring to credit guarantee consortia provided for in Article 155 of the T.U., in the text prior to the entry into force of Title III of Legislative Decree 141/2010.

3 4) "anti-money laundering decree": Legislative Decree 21 November 2007, No. 231, as amended by Legislative Decree 25 May 2017, No. 90, implementing Directive (EU) 2015/849 on the prevention of the use of the financial system for the purpose of money laundering of proceeds of criminal activities and terrorist financing; 5) "recipients": the subjects recipients of these provisions indicated in the "recipients" paragraph; 6) "anti-money laundering directive": Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015, as amended by Directive (EU) 2018/843, on the prevention of the use of the financial system for the purpose of money laundering of proceeds of criminal activities and terrorist financing; 7) "corporate control functions": the anti-money laundering function, the compliance function, the risk management function and the internal audit function; 8) "group": the banking group referred to in Article 60 of the TUB and applicable provisions, the financial group referred to in Article 109 of the TUB and applicable provisions, the group referred to in Article 11 of the TUF and applicable provisions, as well as, outside these cases and if recipients of these provisions, controlled and controlling companies pursuant to Article 2359 of the Civil Code; 9) "EU countries": countries belonging to the European Economic Area; 10) "third countries": countries not belonging to the European Economic Area; 11) "staff": employees and those who operate on the basis of relationships that determine their insertion into the corporate organization, even in a form other than subordinate employment; 12) "money laundering risk": the risk arising from the violation of legal, regulatory and self-regulatory provisions aimed at preventing the use of the financial system for purposes of money laundering, terrorist financing or financing of weapons of mass destruction development programs, as well as the risk of involvement in episodes of money laundering and terrorist financing or financing of weapons of mass destruction development programs; 13) "contracted operators and agents": operators however named, other than financial activity agents, of which payment service providers and electronic money issuing institutions, including those having their registered office and central administration in another Member State, avail themselves for the exercise of their activity on the territory of the Italian Republic; 14) "UIF": the Financial Intelligence Unit for Italy. Communications to the Bank of Italy Communications to the Bank of Italy provided for by these provisions are addressed to the Customer Protection and Anti-Money Laundering Service, Anti-Money Laundering and Usury Checks Division.

3 PART ONE GENERAL PRINCIPLES Section I. Principle of Proportionality These provisions establish the controls in terms of organization, procedures and internal controls that recipients adopt for the fight against money laundering and terrorist financing ( 4 ). They integrate and apply in a unitary manner with the provisions on governance structure, organization and internal control set by other sectoral regulations. Recipients apply these provisions according to the principle of proportionality, in line with the nature, size, and complexity of the activity carried out, the type and range of services provided ( 5 ). Section II. Risk-Based Approach In application of the risk-based approach (cd. risk based approach), recipients adopt an organizational structure, operational and control procedures, as well as information systems suitable to ensure compliance with laws and regulations on anti-money laundering, taking into account the nature, size and complexity of the activity carried out as well as the type and range of services provided. To this end, recipients: a. define a motivated policy indicating the choices they concretely intend to make on the various relevant profiles regarding organizational structures, procedures and internal controls (e.g. structure of the anti-money laundering function in groups; possible assignment of the delegation for the responsible officer for suspicious reporting), due diligence (e.g. measures to be concretely adopted for enhanced or simplified due diligence) and data retention (cd. anti-money laundering policy); b. carry out a comprehensive, periodically updated assessment of their exposure to money laundering risk (cd. self-assessment of exposure to money laundering risk), as provided for in Part Seven; c. adopt the measures deemed most suitable to prevent money laundering risk, consistent with their exposure to money laundering risk.

( 4 ) All obligations contained in the anti-money laundering decree are provided for both for the fight against money laundering and for the fight against terrorist financing. Therefore, in these provisions, every reference to the anti-money laundering purpose or money laundering risk must always be understood as also including the purpose of fighting terrorist financing or the risk of terrorist financing. Recipients apply the controls provided for in these provisions also in the key of fighting the financing of weapons of mass destruction development programs. ( 5 ) In order to apply these provisions consistently with the principle of proportionality, recipients consider at least: the total balance sheet, possibly consolidated; geographical presence and volume of activity in each area; the legal form adopted and possible membership in a group; the types of activities exercised as well as their nature and complexity; the chosen business model and strategies adopted; the type of organizational structure; the overall strategy prepared for effective risk management; ownership structures and financing methods; the type of customers and the complexity of products and contracts; outsourced activities and distribution channels used.

4 Section III. Minimum Organizational Controls Without prejudice to the obligation to calibrate anti-money laundering organizational structures according to the principle of proportionality and risk-based approach, recipients adopt at least the following minimum organizational controls: a) they assign to a corporate control function the responsibility of ensuring the adequacy, functionality and reliability of anti-money laundering controls, as provided for in Part Three, Section I (anti-money laundering function); b) they formalize the assignment of responsibility for the reporting of suspicious transactions as provided for in Part Three, Section II (responsible for reporting suspicious transactions); c) they assign to a corporate control function the task of continuously verifying the degree of adequacy of the anti-money laundering organizational structure and its compliance with the regulations, as provided for in Part Three, Section III (internal audit function). Credit guarantee consortia may, in any case, assign the tasks referred to in letters a) and c) to an administrator, provided that they are recipients of specific delegations in matters of controls and are not recipients of other delegations that prejudice their autonomy, except in the case of a sole administrator.

5 PART TWO ORGANIZATIONAL STRUCTURES TO SAFEGUARD AGAINST MONEY LAUNDERING RISKS Section I. General Principles Recipients adopt an organizational and control system as well as strategies, rules, resources, procedures and functions clearly identified and adequately specialized suitable to ensure the effective prevention of money laundering risk. In particular, they ensure:

  • the adoption of adequate strategies, policies, procedures and processes for the identification, measurement, assessment and monitoring of money laundering risk, as well as measures suitable to prevent the risk to which they are exposed;
  • the clear definition, at different levels, of roles, tasks and responsibilities, as well as the preparation of procedures to ensure compliance with customer due diligence obligations, reporting of suspicious transactions, retention of documentation and evidence of relationships and operations;
  • the establishment of an anti-money laundering function tasked with overseeing the activity of prevention and management of money laundering risks;
  • an architecture of control functions coordinated in its components, also through suitable information flows, and at the same time consistent with the articulation of the structure, the complexity, the corporate size, the type of services and products offered as well as with the entity of the risk associated with the characteristics of the clientele;
  • a control activity on the part of staff regarding compliance with internal procedures and all regulatory obligations, with particular regard to the continuous analysis of customer operations, communication and reporting obligations and the protection of confidentiality in matters of reporting. The internal control system is able to promptly intercept procedural deficiencies and behaviors, capable of determining violations of the legislation. To mitigate the risk of money laundering, the involvement of corporate bodies and the correct fulfillment of the obligations falling on them is fundamental. In particular, corporate bodies, each according to their own competencies and responsibilities, are required to: define corporate policies consistent with anti-money laundering principles and rules; adopt policy lines suitable to preserve corporate integrity; put in place organizational and operational measures suitable to avoid the risk of money laundering; carry out controls on compliance with regulations and adequate risk coverage. The articulation of tasks and responsibilities of corporate bodies is clearly defined. These provisions, in regulating the organizational structures necessary to prevent and mitigate risks of involvement in money laundering incidents, do not refer to corporate bodies identified by name, but refer to the functions of "strategic supervision", "management" and "control" concretely assigned to corporate bodies or their components in line with civil and supervisory regulations ( 6 ).

( 6 ) If the applicable regulation does not provide for a distinction between the function of strategic supervision and the function of management, reference is made to the board of directors.

6 Section II. Body with strategic supervision function The body with strategic supervision function approves and periodically reviews the strategic guidelines and risk governance policies related to money laundering; in line with the risk-based approach, the policies are appropriate to the size and type of risks to which the recipient's activity is concretely exposed, as represented in the risk self-assessment document. In particular, the body with strategic supervision function:

  • approves a policy that illustrates and justifies the choices made by the recipient on various relevant profiles regarding organizational structures, procedures and internal controls, due diligence and data retention, in accordance with the principle of proportionality and with the actual exposure to money laundering risk (so-called anti-money laundering policy);
  • approves the establishment of the anti-money laundering function, identifying its tasks and responsibilities as well as methods of coordination and collaboration with other corporate control functions;
  • approves the guidelines for an organic and coordinated internal control system, functional for the prompt detection and management of money laundering risk, and ensures its effectiveness over time;
  • approves the principles for managing relationships with customers classified as "high risk";
  • appoints and removes the manager of suspicious transaction reports and the anti-money laundering manager, after consulting the body with control functions;
  • ensures that tasks and responsibilities in anti-money laundering matters are allocated clearly and appropriately, guaranteeing that operational and control functions are distinct and provided with qualitatively and quantitatively adequate resources;
  • ensures that an adequate, complete and timely information flow system is set up towards corporate bodies and between control functions;
  • ensures confidentiality protection within the suspicious transaction reporting procedure;
  • at least annually, examines reports on the activities carried out by the anti-money laundering manager and the controls performed by the competent functions, as well as the document on the results of the money laundering risk self-assessment;
  • ensures that deficiencies and anomalies found as a result of various levels of controls are brought to its attention promptly and promotes the adoption of appropriate corrective measures, evaluating their effectiveness;
  • evaluates the risks resulting from operations with third countries associated with higher money laundering risks, identifying safeguards to mitigate them, and monitors their effectiveness.

7 Section III. Body with management function The body with management function oversees the implementation of the strategic guidelines and risk governance policies approved by the body with strategic supervision function and is responsible for adopting all necessary interventions to ensure the effectiveness of the anti-money laundering organization and control system. In preparing operational procedures, it takes into account the indications and guidelines issued by competent authorities and international bodies. The body with management function defines and oversees the implementation of an internal control system functional for the prompt detection and management of money laundering risk, ensuring its effectiveness over time, in line with the outcomes of the risk self-assessment exercise; it ensures that operational procedures and information systems allow for the correct fulfillment of customer due diligence and document and information retention obligations. In matters of suspicious transaction reporting, the body with management function defines and oversees the implementation of a procedure adequate to the specificities of the activity, the size and complexity of the recipient, according to the principle of proportionality and the risk-based approach. The procedure is capable of guaranteeing certainty of reference, homogeneity in behaviors, generalized application to the entire structure, full use of relevant information, and reconstructability of the evaluation process. The same body also adopts measures aimed at ensuring compliance with the confidentiality requirements of the reporting procedure, as well as tools, including IT tools, for the detection of anomalous transactions. The body with management function defines and oversees the implementation of initiatives and procedures necessary to ensure the timely fulfillment of communication obligations to Authorities as provided by anti-money laundering legislation. Furthermore, the body with management function:

  • defines the anti-money laundering policy submitted for approval by the body with strategic supervision function and oversees its implementation;
  • defines and oversees the implementation of information procedures aimed at ensuring that risk factors are known to all corporate structures involved and to bodies entrusted with control functions;
  • defines and oversees the implementation of procedures for managing relationships with customers classified as "high risk", in line with the principles fixed by the strategic supervision body;
  • establishes staff training and education programs on obligations provided by anti-money laundering regulations; training activities must be continuous and systematic and take into account the evolution of legislation and procedures prepared by the recipient;
  • establishes suitable tools to allow verification of the activities carried out by staff to detect any anomalies that emerge, specifically in behaviors, the quality of communications addressed to contacts and corporate structures, as well as in staff relationships with customers;
  • ensures, in cases of remote operations (e.g., carried out through digital channels), the adoption of specific IT procedures for compliance with anti-money laundering legislation, with particular reference to the automatic identification of anomalous transactions.

8 Section IV. Body with control function The body with control function monitors compliance with legislation and the completeness, functionality, and adequacy of anti-money laundering control systems. In exercising its powers, it relies on internal structures to carry out necessary checks and verifications and uses information flows from other corporate bodies, the anti-money laundering manager, and, where present, other internal control functions. In this context, the body with control function:

  • evaluates the suitability of procedures for customer due diligence, information retention, and suspicious transaction reporting;
  • analyzes the reasons for deficiencies, anomalies, and irregularities found and promotes the adoption of appropriate corrective measures. The body with control function is consulted in the procedures for appointing the anti-money laundering function manager and the suspicious transaction reporting manager, and in defining the elements of the overall architecture of the money laundering risk management and control system. Pursuant to Article 46 of the anti-money laundering decree, members of the body with control function communicate without delay to the Bank of Italy all facts of which they become aware in the exercise of their functions that may constitute serious, repeated, systematic, or multiple violations of applicable legal provisions and their implementing provisions.

9 PART THREE THE ANTI-MONEY LAUNDERING SAFEGUARDS FRAMEWORK Preamble An effective anti-money laundering organizational framework is based on broad involvement of all operational structures and corporate functions and on the clear definition of their tasks and responsibilities. The role of line controls, which rely on adequate safeguards and information systems, and of the anti-money laundering manager, whose activity is to be exercised transversally across all operations carried out by the recipient, is fundamental. This activity concerns both the verification of the functionality of procedures, structures, and systems, and support and consulting on management choices. Section I. The anti-money laundering function 1.1. Organizational framework Recipients establish a function dedicated to preventing and combating the realization of money laundering operations (anti-money laundering function). They organize the function in accordance with the principle of proportionality; in any case, the anti-money laundering function is independent and equipped with qualitatively and quantitatively adequate resources for the tasks to be performed, activatable also autonomously. The anti-money laundering function reports directly to the bodies with strategic supervision, management, and control functions and has access to all activities of the recipient as well as to any information relevant for the performance of its tasks. The various tasks comprising the anti-money laundering function's activity may be entrusted to distinct organizational structures present within the recipient, provided that the overall management of money laundering risk is consolidated through the appointment of a manager with tasks of direction, coordination, and supervision. The function may be attributed to structures performing compliance control or risk management functions only following an assessment of the suitability of such a choice regarding the size and type of money laundering risks that the function is called to concretely manage. The anti-money laundering function cannot be assigned to the internal audit function. Regardless of the chosen organizational solution, the personnel performing tasks attributable to the anti-money laundering function must be adequate in number, technical-professional skills, and ongoing training, also through continuous training programs. 1.2. Tasks The anti-money laundering function continuously verifies that corporate procedures are consistent with the objective of preventing and combating violations of anti-money laundering norms. To this end, the function:

  • identifies applicable norms and evaluates their impact on internal processes and procedures;

10

  • collaborates in defining the internal control system and procedures aimed at preventing and combating money laundering risks;
  • continuously verifies the adequacy of the money laundering risk management process and the suitability of the internal control system and procedures, proposing organizational and procedural modifications to ensure adequate money laundering risk safeguards;
  • conducts, in coordination with the STR manager, checks on the functionality of the reporting process and the appropriateness of the evaluations performed by the first level on customer operations;
  • collaborates in defining money laundering risk governance policies and the various phases of the risk management process;
  • conducts, in coordination with other interested corporate functions, the annual money laundering risk self-assessment exercise to which the recipient is exposed;
  • provides support and assistance to corporate bodies and senior management;
  • evaluates in advance the money laundering risk associated with the offer of new products and services;
  • verifies the reliability of the information system for fulfilling customer due diligence, data retention, and suspicious transaction reporting obligations;
  • transmits monthly to the UIF aggregated data concerning the recipient's overall operations;
  • transmits to the UIF, based on instructions issued by it, objective communications concerning transactions at risk of money laundering;
  • oversees, in coordination with other corporate functions competent in training matters, the preparation of an adequate training plan, aimed at achieving continuous staff updates;
  • promptly informs corporate bodies of significant violations or deficiencies found in the exercise of their respective tasks;
  • prepares information flows directed to corporate bodies and senior management. Recipients may assign the anti-money laundering function the task of carrying out enhanced customer due diligence activities only in cases where - due to objective, environmental, or subjective circumstances - the money laundering risk is particularly high. If this task is attributed to operational structures, the anti-money laundering manager verifies the adequacy of the enhanced due diligence process conducted by line structures and its outcomes. The anti-money laundering function drafts and transmits to the body with management function and the body with strategic supervision function a document that defines in detail responsibilities, tasks, and operational methods in money laundering risk management (so-called anti-money laundering manual). The document - constantly updated - is available and easily accessible to all staff. The anti-money laundering function pays particular attention: to the adequacy of internal systems and procedures regarding customer due diligence and retention obligations, as well as systems for identifying, evaluating, and reporting suspicious transactions; to the effective detection of other situations subject to communication obligations, as well as to the appropriate retention of documentation and evidence required by legislation.

11 The function may carry out, in coordination with the internal audit function, on-site checks on a sample basis to verify the effectiveness and functionality of the same and identify any areas of criticality. At least once a year, the function presents to the bodies with strategic supervision, management, and control functions a report on initiatives adopted, identified dysfunctions, and related corrective actions to be taken, as well as on staff training activities. The report also includes the results of the self-assessment exercise conducted pursuant to Part Seven. The function collaborates with the Authorities referred to in Title I, Chapter II of the anti-money laundering decree. 1.3. The function manager The anti-money laundering function manager (anti-money laundering manager) is a natural person possessing adequate requirements of independence, authority, and professionalism. The anti-money laundering manager is among the managers of corporate control functions. The appointment and removal, adequately motivated, are the competence of the strategic supervision body, after consulting the body with control functions. If consistent with the principle of proportionality, the responsibility for the function may be attributed to the compliance control function manager or the risk manager. The anti-money laundering manager reports directly to corporate bodies, without restrictions or intermediaries. The anti-money laundering manager is placed in an adequate hierarchical-functional position and cannot have direct responsibilities for operational areas nor be hierarchically dependent on subjects responsible for these areas. If justified by the small size of the recipient, the responsibility for the function may be attributed to an administrator holding specific delegations in control matters, provided they lack other delegations that would prejudice their autonomy, except in the case of a sole administrator. Personnel called to collaborate in the anti-money laundering function, even if inserted in operational areas, reports directly to the function manager for matters relating to their respective tasks. Given the relevance of the tasks attributed to the anti-money laundering function, recipients may define in internal legislation further safeguards for the stability and independence of the manager. 1.4. Outsourcing The performance of checks attributed to the anti-money laundering function may be entrusted to external subjects possessing suitable requirements in terms of professionalism, authority, and independence. The responsibility for the correct management of money laundering risks remains, in any case, with the recipients, who are required to safeguard the risks arising from the choices made and maintain the technical and managerial skills necessary to continuously monitor activities entrusted to external subjects. In case of outsourcing, recipients appoint an internal manager for the anti-money laundering function with the task of verifying the correct performance of the service by the supplier and adopt the necessary organizational safeguards to guarantee the maintenance of direction and control powers by corporate bodies.

12 The decision to resort to outsourcing must not prejudice the quality of the control system. Recipients formalize an outsourcing agreement with the supplier that defines at least:

  • respective rights and obligations; expected service levels, expressed in objective and measurable terms, as well as information necessary for verifying their compliance; potential conflicts of interest and appropriate safeguards to prevent them or, if not possible, mitigate them; the duration of the agreement and renewal methods, as well as mutual commitments related to the termination of the relationship;
  • the minimum frequency of information flows towards the internal manager and corporate bodies and control functions, without prejudice to the obligation to promptly respond to any requests for information and consulting;
  • confidentiality obligations for information acquired in the exercise of the function;
  • the possibility to review service conditions upon the occurrence of regulatory changes or in the recipient's operations and organization;
  • the possibility for the recipient, Supervisory Authorities, and the UIF to access useful information and premises where the service provider operates for monitoring, supervision, and control activities. Without prejudice to specific provisions on outsourcing within groups, outsourcing of tasks attributed to the anti-money laundering function by recipients presenting significant size and operational complexity is not consistent with the principle of proportionality. The anti-money laundering function is an integral part of corporate control functions. Therefore, recipients apply these provisions jointly with those of the Bank of Italy regarding outsourcing or delegation of corporate control functions to which they are subject. 1.5. Relations with other corporate functions The anti-money laundering function collaborates with other corporate functions (e.g., compliance control function, internal audit, legal area, organization, risk management, human resources, information systems) to develop its risk management methodologies in a manner consistent with corporate strategies and operations, and to realize processes compliant with legislation. The adequacy and effectiveness of the anti-money laundering function are subject to periodic verification by internal audit. 1.6. Communications Recipients transmit to the Bank of Italy: a. within 20 days from the relevant resolution, the decision to appoint or remove the anti-money laundering function manager (7); b. by April 30 of each year, the report of the anti-money laundering function, which includes the risk self-assessment exercise.

(7) Recipients fulfill communication obligations through the corporate bodies reporting procedure (so-called OR.SO.) regulated by the Bank of Italy Communication of June 7, 2011, when applicable.

13 Section II. The Suspicious Transaction Reporting Officer Pursuant to Article 36 of the anti-money laundering decree, the Suspicious Transaction Reporting Officer (SOS) is the legal representative of the recipient or a delegate of the recipient; the delegation may also be conferred upon the head of the anti-money laundering function. The delegation is deliberated by the body with strategic supervision functions, after consulting the body with control functions. In the case of a branch, the Suspicious Transaction Reporting Officer is the legal representative thereof, save for the possibility of delegation to a member of the branch's staff. If recipients are required to establish a central contact point, the SOS coincides in any case with the head of the central contact point (Article 36 of the anti-money laundering decree). Recipients ensure that the SOS possesses adequate requirements of independence, authority, and professionalism and carries out their activity with autonomy of judgment and in respect of the confidentiality obligations provided for by the anti-money laundering decree, also vis-à-vis senior management and other corporate functions. The role of the SOS is adequately formalized and made known within the structure and at the distribution network. The appointment and revocation of the said officer are communicated promptly to the UIF in the manner indicated by it. The SOS has no direct responsibilities in operational areas nor is hierarchically dependent on subjects belonging to these areas. The delegation cannot be conferred upon the head of the internal audit function nor on subjects external to the recipient, save as provided for groups (see Part Four, Section II). At recipients of significant size, the delegation may be attributed to more than one subject, with identification of criteria that ensure coordination and information sharing among delegates. Based on internal organizational procedures, it is the responsibility of the SOS to: a) evaluate, in light of all available elements, the suspicious transactions communicated by the head of the dependency or another operational point or organizational unit or structure competent for the concrete management of customer relationships (so-called first level); b) evaluate, in light of all available elements, the suspicious transactions of which it has otherwise become aware within the scope of its own activity; c) transmit to the UIF the reports deemed founded, omitting the indication of the names of the subjects involved in the transaction reporting procedure; d) maintain evidence of the evaluations carried out within the procedure, also in the event of non-sending of the report to the UIF. The Reporting Officer: acquires any useful information from the structure that performs the first level of analysis of anomalous transactions and from the anti-money laundering manager, where the two subjects do not coincide; has free access to information flows directed to significant corporate bodies and structures for the prevention and combating of money laundering (e.g., requests received from the judicial authority or investigative bodies); uses in evaluations also any elements derivable from freely accessible information sources. The SOS is required to know and apply with rigor and effectiveness instructions, schemes, and indicators issued by the UIF; performs a role of interlocution with the UIF and responds promptly to any requests for further investigation coming from it. The SOS communicates, with organizational methods suitable to ensure respect for the confidentiality obligations provided for by the anti-money laundering decree, the outcome of its own evaluation to the first-level responsible subject that originated the report.

14 In respect of the confidentiality obligations provided for by the anti-money laundering decree on the identity of subjects participating in the transaction reporting procedure, the SOS provides – also through the use of suitable information bases – information on the names of customers subject to suspicious transaction reports to the heads of structures competent for the attribution or updating of the risk profile of said customers. Section III. The Internal Audit Function The internal audit function continuously verifies the degree of adequacy of the corporate organizational structure and its conformity with the reference discipline and supervises the functionality of the overall internal control system. The function, through systematic controls, also of an inspection type, verifies inter alia:

  • the constant respect of the obligation of adequate verification, both in the phase of establishing the relationship and in the development of the relationship over time;
  • the actual acquisition and orderly conservation of data and documents, as provided for by the legislation;
  • the actual degree of involvement of personnel as well as of the heads of central and peripheral structures, in the implementation of communication and reporting obligations. The interventions, remote and inspection, are subject to planning to allow that all peripheral and central operational structures are subject to verification in a reasonable period of time and that initiatives are more frequent regarding structures most exposed to money laundering risks as well as with reference to relationships with a high-risk profile. The internal audit function carries out follow-up interventions to ensure the adoption of corrective interventions for deficiencies and irregularities found and their suitability to avoid similar situations. The internal audit function reports, at least annually, to corporate bodies on the activity carried out and its outcomes, without prejudice to the respect of the confidentiality obligations provided for by the anti-money laundering decree. If justified based on the principle of proportionality, the responsibility of the function may be attributed to a director, provided that it is the recipient of specific delegations in matters of controls and is not the recipient of other delegations that prejudice its autonomy, save for the case of the sole director. Section IV. Safeguards in the matter of distribution network and intermediaries For services offered through networks of agents in financial activity, financial consultants, contracted subjects and agents (8) or other subjects linked to the recipient by contractual constraints (hereinafter "distribution network"), the recipient adopts the necessary precautions to ensure respect for the provisions on combating money laundering by the distribution network.

(8) Payment service providers and Italian electronic money institutions and payment service providers or electronic money institutions established in the Community territory established on the territory of the Republic are also required to respect the specific provisions of Chapter V of the anti-money laundering decree in relation to the activity carried out through one or more "contracted subjects and agents".

15 To this end, the recipient:

  • indicates, within the scope of collaboration contracts concluded with staff of the distribution network, the code of conduct for anti-money laundering purposes that they must follow in the performance of activity on behalf of the recipient;
  • provides staff of the distribution network with operational tools and procedures, also computerized, that assist them in the execution of operations and related compliance for anti-money laundering purposes;
  • sets up specific and periodic training programs for the distribution network, so that staff have adequate knowledge of the legislation and related responsibilities and are able to consciously use tools and procedures of aid in the execution of compliance;
  • constantly monitors the respect by the distribution network of the anti-money laundering code of conduct established by legislation and in contractual terms;
  • carries out periodic checks at the operational points of staff of the distribution network. When enhanced customer due diligence is required due to the higher risk of money laundering, the recipient intervenes to support the distribution network in fulfilling the obligations provided for in Article 25 of the anti-money laundering decree. In the case of intervention of a credit intermediary, the recipient may avail itself of the data and information already collected by the intermediary, verifying the correctness of the compliance carried out for customer identification and controlling that the information flow is transmitted promptly for the purposes of conservation obligations. The recipient interrupts any relationship with the intermediary if it has ascertained serious non-compliance by this in the execution of anti-money laundering obligations. Any agreements concluded between the recipient and intermediaries indicate the anti-money laundering code of conduct to which they must adhere in the exercise of their activity; furthermore, they provide that intermediaries participate periodically in adequate training and updating initiatives. Section V. Staff Training An effective application of anti-money laundering legislation presupposes full awareness of its purposes, related principles, obligations, and corporate responsibilities. Recipients implement training and staff training programs on the obligations provided for by anti-money laundering legislation. Training and instruction ensure specific preparation of personnel with more direct contact with customers and of those assigned to the anti-money laundering function. To these members of staff, continuous updating on the evolution of money laundering risks and on typical schemes of criminal financial operations is required. The staff training and instruction activity is carried out with continuity and systematicity, within the framework of organic programs; annually, a report on the training and instruction activity in the matter of anti-money laundering legislation is submitted for approval to the body with management functions.

16 PART FOUR DISPOSITIONS APPLICABLE TO GROUPS Section I. General Provisions In groups, strategic guidelines in the matter of money laundering risk management and anti-money laundering controls are adopted by the corporate bodies of the parent company. The parent company ensures that the corporate bodies of the other companies belonging to the group implement in their own corporate reality the group strategies and policies. Groups, in particular, develop a global approach to money laundering risk. To this end, the parent company defines and approves: a) a group methodology for the assessment of money laundering risks compliant with that indicated in Part Seven; b) formalized procedures for coordination and sharing of relevant information among companies belonging to the group; c) general standards in the matter of customer due diligence, data conservation, and identification and reporting of suspicious transactions. The parent company establishes a common information base that allows all companies belonging to the group to evaluate customers in a homogeneous manner. The parent company identifies organizational solutions suitable to ensure respect for the provisions applicable in relation to different areas of operation and, at the same time, ensures that risk management takes into account all evaluation and measurement elements possessed by the single components. In groups with cross-border operation, the parent company ensures that procedures at branches and group companies with headquarters in third countries are aligned with group standards and allow information sharing within the group, including notice of the having reported suspicious transactions, save for respect for limits imposed or specific compliance provided for by the legislation of the host country. If the legislation of the host country does not allow branches and group companies established therein to adapt to general standards or to share relevant information with other group companies, the parent company communicates this to the Bank of Italy in the terms and with the methods provided for by the delegated regulation of the European Commission adopted pursuant to Article 45, paragraph 7, of the anti-money laundering directive and adopts the further measures indicated therein. Section II. The Anti-Money Laundering Function in Groups. For the outsourcing of the anti-money laundering function within the group (so-called centralized model), recipients apply the provisions in the matter of outsourcing of corporate control functions within the group provided for by the relevant sector discipline to which they are eventually subject. In the absence of sector discipline, the anti-money laundering function may be outsourced to the parent company or to another company of the group, independently of the size and operational complexity of the recipient, in respect of the provisions of which in Part Three, Section I, paragraph 1.4.

17 In the case where groups do not resort to the centralized model as well as where the anti-money laundering function is outsourced only by some companies of the group, the group companies that have not outsourced the function to the parent company or to another company of the group: a. inform, in a complete and timely manner, the anti-money laundering manager of the parent company or group of the outcomes of control activities carried out at the company by the anti-money laundering manager, where relevant for the activity of the manager of the parent company or group; b. ensure to the anti-money laundering manager of the parent company or group access to all databases containing information useful for the performance of related tasks. Section III. The Reporting of Suspicious Transactions in Groups. Group companies with headquarters in Italy may confer upon the Suspicious Transaction Reporting Officer of the parent company or another company of the group with headquarters in Italy the delegation referred to in Article 36 of the anti-money laundering decree (so-called centralized model); each delegation is adequately formalized and made known within the group, as well as promptly communicated to the UIF. If the delegation is conferred, the transactions to be evaluated are transmitted to the group delegate based on a procedure characterized by a limited number of intermediate levels of analysis of the same; speed, confidentiality, and ease of comparison between the first-level manager and the delegate must be ensured. The latter acquires, directly or through the structures identified from time to time at the other companies of the group, all useful information possessed by the same; the group delegate informs of the outcome of its own evaluation the first-level manager of the group company that initiated the reporting procedure. Groups that, due to size or structural articulation, present greater complexity, may designate more group delegates (e.g., dividing delegations by geographical area or by type of product or service offered), but in any case in a limited number. In such hypotheses, the parent company ensures: a. criteria for the division of competences unique and coherent, so as to avoid uncertainties, overlaps, or gaps; b. a coordination function that guarantees the homogeneity and coherence of procedures and evaluation criteria used; c. a unified interlocution with Authorities and, in particular, with the UIF; d. the sharing among group delegates of the corporate information asset, for the purposes of full use of available information; e. the access of each delegate to reports made and those evaluated as not worthy of transmission or under evaluation by other delegates. The group SOS, for the purposes of deepening transactions and anomalous relationships from a group perspective: i) may acquire information from group companies, also from those that have not conferred the delegation; ii) provides to the SOS of group companies relevant information on common customers. The parent company ensures that group companies with headquarters in Italy or in another Member State allow in any case the SOS of the parent company or group

18 access to information relating to reports transmitted and those deemed unfounded, accompanied by the motivation of the decision. Pursuant to Article 38 of the anti-money laundering decree, access to information takes place with methods aimed at guaranteeing the confidentiality of the identity of subjects participating in the reporting procedure.

19 PART FIVE DISPOSITIONS FOR SPECIFIC ACTIVITIES Section I. Money Remittance Service (so-called "money transfer") The money transfer activity is particularly vulnerable to money laundering risk due to the extensive territorial branching, the occasional and impersonal nature of the relationship with the customer, the prevalent cross-border operation, and the high recourse to cash for the execution of operations. Recipients providing money transfer activity equip themselves with suitable computerized procedures that allow: – to monitor in real time the operations carried out and identify any anomalous or split operations with reference to the names of the requester and the beneficiary of the fund transfer; – to automatically block anomalous transactions, when necessary; – to update the lists of subjects subject to international financial sanctions with a frequency suitable to guarantee timely respect for the compliance provided for by Legislative Decree 22 June 2007, n. 109. Section II. Informational Data Relating to Fund Transfers Regulation (EU) 2015/847 identifies the information on the orderer and the beneficiary that must be contained in payment messages (e.g., transfers) and requires payment service providers to equip themselves with procedures capable of identifying payments lacking the necessary information and determining when to execute, reject, or suspend a fund transfer. The Joint Guidelines of European Supervisory Authorities, adopted in implementation of Regulation (EU) 2015/847, contain indications to facilitate intermediaries in the fulfillment of the task of: i) identifying fund transfers falling within the scope of application of Regulation (EU) 2015/847; ii) developing and maintaining effective procedures to identify transfers lacking the necessary information; iii) identifying money laundering risk factors to be considered to decide whether to execute, reject, or suspend a fund transfer lacking the information provided for. Recipients subject to the application of Regulation (EU) 2015/847 equip themselves with procedures and adopt the measures provided for by the Joint Guidelines. Recipients send to the Bank of Italy the reports provided for in paragraphs 52, 53, 54, and 55 of the Guidelines. Section III. Trust Companies Registered in the Separate Section of the Register pursuant to Article 106 of the TUB The activity of trust companies registered in the separate section of the register provided for by Article 106 of the TUB, which includes inter alia the administration of assets and the fiduciary title of share packages, is vulnerable to money laundering risk, as it is potentially suitable to limit the transparency of ownership or management of certain assets.

20 Companies ensure that, in the fulfillment of anti-money laundering obligations, all operational structures and corporate functions are involved, in coherence with the activity carried out predominantly by the company, with the profile and characteristics of the customer base, with the different types of assets entrusted to fiduciary administration. The peculiarities of the relationship between trust companies and customers require specific attention at the moment of its establishment, as relevant elements may emerge in this phase for the purposes of identifying anomalies. Due diligence measures calibrated on the entire duration of the relationship make it necessary that companies adopt information tools capable of organizing and processing, also in synthetic form, all data useful to monitor with maximum effectiveness each concrete risk profile: essential information on each customer (economic capacity, professional activity, economic and financial profile, etc.); reasons for recourse to fiduciary administration; any unusual operations carried out; any inconsistencies with the economic or professional profile, to be evaluated according to both quantitative (amount and frequency of operations) and qualitative (type and characteristics of service usage) parameters. Particular attention must be paid to operations conducted and concluded autonomously by the settlor, without the intervention or prior consent of the trust company (so-called "free currency" operations), also in the case where these operations are perfected through the banking system. Companies, at the time of signing the fiduciary contract, agree in writing with the customer methods suitable to obtain prompt communication of such operations, as well as measures suitable to ensure their evaluation by trust companies and the necessary informational transparency for the purposes of respect for anti-money laundering legislation.

PART SIX FURTHER PROVISIONS FOR INTERMEDIARIES OBLIGED TO ESTABLISH A CENTRAL CONTACT POINT Section I - Preamble Pursuant to the anti-money laundering directive, payment service providers and electronic money institutions having their registered office in a Member State that operate in another EU State may, provided certain conditions are met, be considered established in the latter, even without a branch. In these cases, they must apply the anti-money laundering rules of the host State. The host State may require payment service providers and electronic money institutions to establish a central contact point, in compliance with the conditions identified by Delegated Regulation (EU) No 1108 of 2018. The tasks provided for in the same delegated regulation are assigned to the central contact point. In implementation of European rules, the anti-money laundering decree has: i) included among the addressees of the Italian rules payment service providers and electronic money institutions having their registered office and central administration in another Member State that operate in Italy through one or more affiliated subjects and agents; ii) imposed the obligation on the subjects referred to in i) to establish a central contact point. Pursuant to Article 43, paragraph 4, of the anti-money laundering decree, the Bank of Italy is empowered to adopt provisions on the requirements, procedures, control systems and functions of the central contact point, in line with the provisions of Delegated Regulation (EU) No 1108/2018.

Section II - Appointment and tasks of the central contact point The addressee assigns the functions of the central contact point to its own organizational unit (e.g., an office without customer relations) or to a company or entity established in Italy. The functions of the central contact point cannot be assigned to a natural person. The addressee that operates in Italy also through a branch designates the latter as the central contact point in relation to the activity carried out by it in Italy through affiliated subjects and agents. The addressee establishes its domicile at the central contact point for all acts, obligations and effects provided for by the anti-money laundering decree and its implementing provisions. Pursuant to the delegated regulation, the central contact point performs the tasks provided for by: – Articles 4 and 5 of the delegated regulation. In particular, pursuant to Article 4, letter f), the central contact point represents the addressee in communications with the Bank of Italy and the UIF; – Article 6, paragraph 1, of the delegated regulation (9).

(9) Under the delegated regulation, Member States may assign to the central contact point the task of analyzing and reporting suspicious transactions. This option was exercised by the anti-money laundering decree, which assigns to the central contact point tasks of evaluating, analyzing and reporting suspicious transactions to the UIF (see Articles 36, paragraph 6, and 44, paragraph 1, letter c), of the decree).

The addressee ensures that the documentation, information and data necessary to demonstrate compliance with anti-money laundering obligations, including the obligation of adequate customer due diligence, are available at the central contact point, for the purposes of the checks carried out by the Bank of Italy and the UIF. The addressee may discharge through the central contact point additional tasks and functions in the field of anti-money laundering.

Section III - Organizational structures of the central contact point The addressee identifies the legal and organizational form, procedures and control systems of the central contact point suitable to mitigate and manage the money laundering risks to which its operations in Italy are exposed. To this end, it takes into account the results of the self-assessment exercise conducted by the central contact point pursuant to Part Seven. The addressee establishes at the central contact point all the functions and procedures necessary for the performance of the tasks indicated in Section II. The addressee equips the central contact point with quantitatively and qualitatively adequate resources, in terms of technical-professional skills and financial terms, in relation to the tasks to be performed, the size and complexity of the network of affiliated subjects and agents it relies on, and the exposure to money laundering risk of the specific services offered. The addressee assigns the role of head of the central contact point to a natural person possessing the requirements provided for the anti-money laundering officer and communicates his/her name to the Bank of Italy and the UIF. Pursuant to Article 36, paragraph 6, of the anti-money laundering decree, the head of the central contact point is also responsible for the reporting of suspicious transactions. The head of the central contact point may be appointed anti-money laundering officer. The addressee ensures that adequate structures and procedures are set up at the central contact point so that the central contact point can autonomously analyze and evaluate all transactions carried out in Italy by the addressee and identify those potentially suspicious. To this end, the central contact point takes into account the relevant information that affiliated subjects and agents are required to communicate to the central contact point pursuant to Article 44, paragraph 1, letter c), of the anti-money laundering decree. For the fulfillment of reporting obligations, the addressee makes available to the central contact point the relevant information in its possession. The addressee equips the central contact point with suitable procedures, including IT procedures, for: a. the transmission of communications by affiliated subjects and agents referred to in Article 44, paragraph 1, of the anti-money laundering decree; b. the performance of adequate customer due diligence, where such task is discharged through the central contact point; c. the retention of documents, data and information; d. remote control and monitoring of transactions carried out at affiliated subjects or operational agents operating in Italy; e. the transmission to the Competent Authorities of data, communications or periodic or event-driven information, including those referred to in Article 45, paragraph 2, of the anti-money laundering decree; to this end, the central contact point manages, on behalf of the addressee, any access credentials to the systems and platforms for data transmission.

PART SEVEN THE ASSESSMENT OF MONEY LAUNDERING RISKS Section I. General principles Pursuant to Article 15 of the anti-money laundering decree, addressees conduct a self-assessment of the money laundering risks to which they are exposed and adopt procedures in conformity with the criteria and methodologies of this Part. The self-assessment is conducted based on a methodology comprising the following macro-activities: a. identification of inherent risk: addressees identify the current and potential risks to which they are exposed, also taking into account elements provided by external information sources; b. analysis of vulnerabilities: addressees analyze the adequacy of the organizational structure, prevention and monitoring safeguards relative to the risks previously identified in order to identify any vulnerabilities; c. determination of residual risk: addressees evaluate the level of risk to which they are exposed due to the level of inherent risk and the robustness of mitigation safeguards; d. remedial action: addressees implement appropriate corrective interventions in response to any existing critical issues and for the adoption of appropriate measures to prevent and mitigate money laundering risk. Confidi are exempt from the obligation to conduct the self-assessment provided for in this Part. The Bank of Italy provides, through specific communications, more detailed indications regarding individual types of intermediary for the conduct of the self-assessment exercise.

Section II. Methods of conducting the exercise The self-assessment is carried out by evaluating the exposure to the risk of involvement in money laundering phenomena for each business line considered relevant. The criteria for identifying business lines are defined by addressees based on their nature, organization, specificity and operational complexity, taking into account the risk factors listed in Section III. For subjects characterized by lower operational complexity, segmentation into business lines may take into account the principle of proportionality. The self-assessment document accounts for the reasons that led to the identification of specific business lines and the weight attributed to each line relative to overall operations.

Section III. Identification of inherent risk In the assessment of money laundering risks, addressees consider at least the risk factors relating to the following aspects: a. operations: the volume and amount of transactions and typical operations; b. products and services: the products and services offered and the reference market; c. clientele: the type of clientele, with particular regard to customers classified as high risk; d. distribution channels: the distribution channels used for opening and maintaining relationships and for the sale of products and services; e. geographic area and countries of operation: geographic risk is evaluated with reference to the clientele, the possible presence in the geographic area of branches or group companies, as well as operations carried out abroad. For each of the business lines, the level of inherent risk determined based on the above evaluation elements is identified, to be expressed with a judgment on a scale of four values. The attribution of the inherent risk level is accompanied by a description of the evaluation elements (data and information) considered, the analyses carried out and the reasons for the choices made. For the purposes of the assessment, addressees also avail themselves of information coming from external sources, including: risk assessment exercises conducted at the national and European level (10); mutual evaluation reports adopted by the Financial Action Task Force or similar international bodies; Community regulations or decrees issued by the Minister of Economy and Finance pursuant to Legislative Decree 22 June 2007 No. 109 against persons and entities associated with terrorist financing activities or adopted within the framework of combating activities of countries threatening international peace and security; the results of supervision and control activities by Competent Authorities.

Section IV. Identification of vulnerabilities Addressees adopt policies and procedures aimed at mitigating the money laundering risks identified in the phase of identifying inherent risk (Section III); subsequently to the determination of the intensity of inherent risk, for each of the activity lines, the level of vulnerability of the safeguards is evaluated, to be expressed with a judgment on a scale of four values. In carrying out this assessment, addressees take into account the indications and evaluations coming from the company's control functions. The attribution of the vulnerability level is accompanied by a brief illustration of the safeguards in place and a description of any weaknesses identified, with the explicit statement of the reasons that determined the score. The determination of the identified vulnerability level takes into account what was found by the Bank of Italy in carrying out its own supervisory controls.

Section V. Determination of the residual risk level The combination of the inherent risk and vulnerability judgments for each business line determines, based on the matrix illustrated below, the attribution of the residual risk band of the business line, according to a scale of four values. The overall residual risk level is determined by the residual risk values of the individual business lines identified, weighted according to the weight attributed to each line.

(10) Reference is made to the report containing the assessment of money laundering risks weighing on the market of the European Union (so-called Supranational Risk Assessment Report) drawn up by the European Commission and the “National Risk Analysis” (so-called National Risk Assessment) conducted by the Financial Security Committee.

Section VI. Matrix for determining residual risk

Section VII. Remedial action Once the residual risk level of the business lines and the overall level have been determined, addressees identify the corrective or adjustment initiatives to be adopted to prevent and mitigate residual risks; the attribution of the residual risk level is accompanied by a description of the evaluation elements considered, the analyses carried out and the corrective or adjustment initiatives identified. Remedial actions are proposed by the management body, taking into account the indications contained in the annual report of the anti-money laundering function, and approved by the body with strategic supervision functions. Adjustment measures are implemented by the management body, through the anti-money laundering function. The anti-money laundering function continuously verifies the adequacy of the measures adopted to ensure adequate safeguarding against money laundering risks. This Section also applies in the case of updating or integrating the self-assessment exercise (see Section VIII).

Section VIII. Times and methods of conducting the exercise The self-assessment exercise is updated annually by the anti-money laundering function and is transmitted to the Bank of Italy by April 30 of the year following the reference year of the assessment (see Part Three, Section I).

In the event of opening new business lines, the anti-money laundering function conducts the self-assessment for the new lines. The exercise is updated promptly when new risks of significant magnitude emerge or significant changes occur in existing risks, operations, or organizational or corporate structure. In groups, the parent company coordinates the exercise carried out by each of the companies belonging to the group and conducts a group self-assessment exercise.

ANNEX Schema of the annual report produced by the anti-money laundering function

  1. Placement of the anti-money laundering function within the corporate organization (or group).
  2. Activities of the anti-money laundering function during the reference period, any identified dysfunctions and related corrective actions in the sectors: a. of adequate verification and customer profiling. In this context, specific details must be provided regarding: any delays in completing the adequate verification activity, including the failure to identify the beneficial owner; the number (in absolute terms and as a percentage of existing customers) of subjects included in the highest risk classes (e.g., politically exposed persons, cross-border correspondent relationships, relationships with subjects resident in high-risk third countries, etc.); b. of data retention; c. of the process of identifying and reporting suspicious transactions (indicating the number of reports sent to the UIF during the year and those evaluated and archived); d. of the identification and application of international anti-terrorism and anti-proliferation of weapons of mass destruction financial sanctions.
  3. Self-assessment exercise of money laundering risks.
  4. Adjustment initiatives defined in light of the findings of the money laundering risk self-assessment exercise and their progress status.
  5. Training activities carried out during the reference period and planned for the following year.
  6. Any specific issues of the intermediary and other relevant information.
  7. Activity plan of the anti-money laundering function for the following year. In the case of trust companies registered in the separate section of the register of Article 106 of the TUB, the report of the anti-money laundering function, in addition to the information above, provides detailed indications regarding: i. customer acquisition channels, with particular regard to the frequency and outcome of checks carried out on the possible distribution network during the reference period and the interventions adopted; ii. the presence of subjects who have received more than three mandates to operate in relation to different trust mandates.

More like this from BOI

We email you every new BOI publication the day it's published.

Share