2017-05-16 | CD-SIBOIF-998-1-MAY16-2017Added · Updated
The Board of Directors of the Superintendence of Banks and Other Financial Institutions (SIBOIF) amended Article 40 of the Standard for the Management and Prevention of Terrorism Financing and Proliferation Financing Risks to prohibit financial institutions from delegating or outsourcing any stage of transaction monitoring and list screening. While institutions may utilize monitoring systems provided by their cross-border financial groups, they must retain non-delegable responsibility for maintaining, parameterizing, validating, and locally auditing these tools. The resolution entered into force upon notification on May 16, 2017.
Resolution No. CD-SIBOIF-998-1-MAY16-2017 Dated May 16, 2017
STANDARD REFORMING ARTICLE 40 OF THE "STANDARD FOR THE MANAGEMENT AND PREVENTION OF TERRORISM FINANCING AND PROLIFERATION FINANCING RISKS"
The Board of Directors of the Superintendence of Banks and Other Financial Institutions,
CONSIDERING
I
That on January 18, 2017, the "Standard for the Management and Prevention of Terrorism Financing and Proliferation Financing Risks" (Standard GPR-FT/FP), contained in Resolution No. CD-SIBOIF-980-1-ENE18-2017, published in La Gaceta No. 27, on February 8, 2017, was approved. This standard aims to establish the minimum guidelines that financial institutions must observe to manage and prevent risks related to terrorism financing (FT) and the financing of the proliferation of weapons of mass destruction (FP).
II
That given the integration of financial groups, globalization, and the development of technology in facilitating services related to information systems, and taking into account the experiences in its application by institutions belonging to the supervised industries, particularly those forming financial groups, it is necessary to reform Article 40 of the aforementioned Standard. These institutions, in their programs for monitoring AML/FT/FP, rely not only on their own technological tools but also on complementary tools available at the financial group level; however, the responsibility they hold to manage and prevent FT/FP risks remains intact and non-delegable, in accordance with national regulatory requirements and their own needs according to their risk profile and comprehensive monitoring program.
III
That Recommendation No. 18 of the Financial Action Task Force (FATF) on "Internal controls and subsidiaries and affiliates" requires financial groups to implement anti-money laundering and counter-terrorist financing programs at the group level; furthermore, financial institutions must ensure that their foreign branches and subsidiaries apply measures against these risks in accordance with the requirements of the country of origin through their group-level programs.
IV
That in accordance with the considerations stated above and based on what is established in Articles 3, numeral 13), and 10, numeral 5), of Law No. 316: "Law of the Superintendence of Banks and Other Financial Institutions," and its reforms; and Article 10, letter a), of Law No. 793, "Law Creating the Financial Analysis Unit."
In exercise of its powers,
RESOLVES
CD-SIBOIF-998-1-MAY16-2017
To issue the following:
STANDARD REFORMING ARTICLE 40 OF THE "STANDARD FOR THE MANAGEMENT AND PREVENTION OF TERRORISM FINANCING AND PROLIFERATION FINANCING RISKS"
First: Article 40 of the "Standard for the Management and Prevention of Terrorism Financing and Proliferation Financing Risks" (Standard GPR-FT/FP); contained in Resolution CD-SIBOIF-980-1-ENE18-2017 dated January 18, 2017, published in La Gaceta, Official Gazette No. 27, on February 8, 2017; is hereby amended, which shall read as follows:
"Article 40. Prohibition.- Under no modality may a Financial Institution (IFiS) delegate or outsource any stage or activity of the comprehensive process for monitoring transactions and screening lists of its clients and users, whether regular or occasional, for the early detection of unusual activities, and for the analysis, escalation, documentation, and generation of reports of suspicious operations or immediate and confidential communications to the Financial Analysis Unit (UAF) resulting from the comparison of their databases against the UN Security Council lists. In the event that an IFiS uses or decides to use monitoring systems and/or software developed and/or provided by another entity of the cross-border Financial Group to which it belongs in accordance with the relevant regulations, it must be capable and in a position to maintain them in accordance with national regulatory requirements, its own needs, and monitoring program, including ensuring that rules, scenarios, and alerts are parameterized, validated, calibrated, and analyzed by its own local personnel; and must be locally audited and certified; all of the foregoing, along with the related documentation and manuals, and the working papers of the audits performed, must be readily and permanently available to the SIBOIF for any type of review or verification deemed pertinent within its authority and supervisory duties."
Second: This standard shall enter into force upon its notification, without prejudice to its subsequent publication in La Gaceta, Official Gazette.
(f) S. Rosales C. (f) V. Urcuyo V. (f) Gabriel Pasos Lacayo (f) Fausto Reyes B. (f) illegible (Silvio Moisés Casco Marenco) (f) illegible (Freddy José Blandón Argeñal) (f) illegible (José Edelberto Zelaya Castillo) Ad Hoc Secretary.
URIEL CERNA BARQUERO Secretary of the Board of Directors SIBOIF