2024-12-11 | NBB_2024_19

Added · Updated

Results of the horizontal supervisory review of compliance by credit institutions with their obligations regarding targeted financial sanctions in the context of domestic transactions

The National Bank of Belgium reports that credit institutions generally comply with obligations to screen customers and counterparties against UN, EU, and Belgian sanctions lists, with most rescreening databases at least daily. The review highlights that only 22 surveyed institutions do not produce daily alert statistics for their AMLCOs, and identifies best practices such as centralized monitoring, reconciliation of external lists with official sources, and automated data quality checks. The document also draws attention to new European Banking Authority Guidelines on internal policies for restrictive measures, which will enter into force on 30 December 2025.

National Bank of Belgium logo

Belgium

National Bank of Belgium

Click to view thumbnail

Public NBB_2024_19 – 11 December 2024 Communication - Page 1/5 14 Boulevard de Berlaimont - 1000 Brussels +32 2 221 30 17 Company number: 0203.201.340 Brussels RLE www.nbb.be Communication Public Brussels, 11 December 2024 Reference: NBB_2024_19 Your correspondents: Le Beau de Hemricourt Charlotte tel. +32 2 221 56 35 charlotte.lebeaudehemricourt@nbb.be Boussauw Justien tel. +32 2 221 38 33 justien.boussauw@nbb.be Results of the horizontal supervisory review of compliance by credit institutions with their obligations regarding targeted financial sanctions in the context of domestic transactions Scope of application

  • Obliged entities within the meaning of Article 5 §1 of the Act of 18 September 2017 on the prevention of money laundering and terrorist financing and on restriction of the use of cash that are subject to supervision by the National Bank of Belgium. Summary/Objectives The purpose of this communication is to report on the results of the horizontal supervisory review of “domestic sanctions screening” by:
  • Belgian credit institutions; 1
  • branches established in Belgium of credit institutions governed by the law of a member country the European Economic Area;2
  • branches established in Belgium of credit institutions governed by the law of a country that is not a member of the European Economic Area.3 The National Bank of Belgium carried out a horizontal supervisory review to verify compliance by credit institutions with their obligations to screen customers and the counterparties of the latter in the context of domestic financial transactions. Structure
  1. Description of the supervisory review
  2. Results of the supervisory review
  3. Good practices 1 Article 135 of the Act of 25 April 2014 on the legal status and supervision of credit institutions (hereinafter the “Banking Act”). 2 Articles 324 and 325 of the Banking Act. 3 Article 337 of the Banking Act.

Public NBB_2024_19 – 11 December 2024 Communication - Page 2/5 Dear Sir or Madam, In the exercise of its supervisory powers in relation to the fight against money laundering and terrorist financing, the National Bank of Belgium (hereinafter “the Bank”) carried out a horizontal supervisory review which consisted of studying the answers to a questionnaire sent to credit institutions governed by Belgian law and branches of such institutions established in Belgium4 (hereinafter “the institutions concerned”). The aim of this exercise was to ensure that all financial institutions active in Belgium comply with their legal obligations in terms of targeted financial sanctions, particularly in the context of domestic financial transactions. DESCRIPTION OF THE SUPERVISORY REVIEW In Belgium, various institutions have arranged for the reciprocal multilateral outsourcing of the screening of counterparties to domestic transactions and have established rules to this effect (the “Domestic Sanction Screening System”, hereinafter the “DSSS”). The Bank considers that participating financial institutions can rely on the DSSS to demonstrate that they have an adequate organisation for the screening5 of counterparties to domestic financial transactions when the latter are customers of another participating financial institution. Building on the DSSS, the Bank wishes to ensure that policies, procedures and internal controls are in place, at both institutions participating in the DSSS and non-participating institutions, to comply with the restrictive provisions relating to financial embargoes in the context of domestic financial transactions. Consequently, in May and June 2024, the Bank surveyed all institutions concerned. The Bank then carried out a horizontal analysis of the responses to the questionnaires and requested clarifications from certain institutions. The results of this analysis and selected good practices identified are detailed below. RESULTS OF THE SUPERVISORY REVIEW APPLICABLE SANCTIONS LISTS Financial institutions must comply at least with the financial embargoes and asset freezing measures imposed by the United Nations (hereinafter the “UN”), the European Union (hereinafter the “EU”) and the Belgian legislature. The horizontal review revealed that these obligations are understood by the institutions concerned, which stated that they screen their customers and their customers’ counterparties against at least the sanctions lists issued by the UN, the EU and Belgium. OBLIGATION TO SCREEN CUSTOMERS AND COUNTERPARTIES OF THE LATTER It should be recalled that financial institutions are obliged to screen their customers before entering into a relationship with them and again when new persons or entities are added to the asset freezing lists. Financial institutions must also conduct screening before executing transactions involving third parties, such as financial transactions. The Bank is pleased to note that all institutions concerned stated that they screen their customers before entering into a relationship. 6 In addition, with a few exceptions that have since been rectified, they 4 Regardless of whether it is governed by the law of an EEA member country. 5 Some institutions use the term “scanning” to refer to customer screening. For the sake of clarity, only the term “screening” is used in this communication. 6 The Bank only surveyed institutions not participating in the DSSS, as the DSSS already imposes this obligation contractually.

Public NBB_2024_19 – 11 December 2024 Communication - Page 3/5 rescreen their customer database at least daily. With respect to the screening of counterparties to domestic financial transactions, the Bank again notes that, with a few exceptions, which were also remedied during the Bank’s review, the institutions concerned stated that they comply with their obligations in this regard. INTERNAL CONTROLS TO DETECT INCIDENTS IN THE SCREENING PROCESS The Bank also questioned the institutions concerned about their internal controls to detect incidents in the customer and customer counterparty screening process. The aim was not to assess the design or effectiveness of these controls, but rather to raise awareness in the sector of the need to implement them. In response to the questions posed by the Bank, some institutions introduced new internal controls, such as the periodic provision to the AMLCO of incident reports on IT controls. One of the internal controls which, in many cases, enables rapid detection of incidents in the screening process is the provision to and analysis by the AMLCO of statistics on the number of alerts generated daily by the systems. The Bank notes that only 22 of the institutions concerned stated that they do not produce such statistics. 7 The frequency with which these statistics are provided to the AMLCO is as follows: The provision and analysis of these statistics enable in particular consistency tests to be carried out. The AMLCO should be able to explain (non)variations in alert volumes from period to period. BEST PRACTICES Generally speaking, depending on the size and structure of the group (if applicable), the operation of the control environment differs. Some institutions have a centralised IT team that carries out tests and resolves incidents, while others divide these responsibilities between the IT and compliance departments. Still others rely on controls carried out centrally by their parent company. It is therefore up to the institutions concerned to assess their control environment to determine whether it is sufficient for the rapid detection of incidents in the customer and customer counterparty screening process. Should this assessment conclude that additional controls need to be implemented, the Bank provides below a non-exhaustive list of best practices identified in the sector during its horizontal supervisory review. 8 7 The Bank notes, however, that in most cases the AMLCO has access to systems enabling it to consult statistics on an ad hoc basis. 8 The Bank noted some confusion in the answers to the questionnaire. The Bank is not referring here to the effective processing of alerts or to the handling of incidents, but rather to the smooth functioning of systems and the rapid identification of incidents. 17 26 5 4 Daily Monthly Quarterly Weekly

Public NBB_2024_19 – 11 December 2024 Communication - Page 4/5 CENTRALISED STATISTICS In addition to statistics on the volume of alerts generated daily, certain institutions have developed other key performance indicators which, for example, enable them to detect abnormal (non)variations in the volumes of data processed and/or alerts generated. These statistics sometimes take the form of dashboards to facilitate the related analyses. Moreover, the Bank notes that some of the institutions concerned stated that these key performance indicators are shared at the ordinary meetings of various committees. The Bank considers this to be an excellent practice. SANCTIONS LISTS A vast majority of the institutions concerned use external sanctions lists. The Bank point outs in this respect that it is necessary to carry out - periodic and/or ongoing – checks to ensure that these lists are complete and correct and that they are effectively received. Such checks should be provided for in the institution’s control plan and be documented. For example, the checks may consist of reconciling external lists with official lists or checking daily any differences between the two. Manual or automated checks are required to ensure that the lists received are not empty or corrupted. With regard to institutions that have decided to maintain internal lists, the Bank reiterates the need to monitor regulatory developments in order to be informed immediately of the addition of new persons or entities to the applicable asset freezing lists. Checks similar to those required for external lists are essential to ensure that the lists used are complete and correct. The Bank reiterates that each institution remains responsible for the effective management of sanctions risks, whether it uses external and/or internal lists to screen customers and financial transactions. Regardless of whether the lists used are external or maintained internally, checks must be provided for to ensure that they are correctly and immediately incorporated into the systems. In particular, the time between the publication of lists by the authorities and the incorporation thereof into the lists used by the screening system should be verified. PREPARATION AND UPLOADING OF CUSTOMER AND TRANSACTIONS DATA Some of the institutions concerned mentioned various automated checks to ensure the proper preparation and quality of the data to be screened (e.g. checking the fields and the correct uploading (upon sending and receiving) of customer and transactions data into the systems). These checks may consist of ensuring that the uploaded files (or certain fields within them) are not empty or that they are different from the previous day’s files. Some institutions also compare the number of customers in the files to be screened with the average over a defined previous period. Likewise, the connection between two systems (e.g. the banking system and the screening module) should be tested periodically. The placement of a blocking filter at the entrance to the payment system prevents a payment from being processed without being screened and therefore reduces the related risks. FUNCTIONING OF SCREENING SYSTEMS Like other systems critical to the proper functioning of the institution, the screening system must be monitored. Such monitoring can be carried out by internal and/or external teams. In fact, some institutions use outsourced solutions specialised in detecting system stoppages. As with the use of external sanctions lists, the Bank points out in this respect that each institution remains responsible for managing its own risks.

Public NBB_2024_19 – 11 December 2024 Communication - Page 5/5 Control plans may also include, by way of example:

  • regular updating and testing, in the appropriate environments, of the system;
  • checks to ensure that individuals on the applicable sanctions lists indeed generate an alert in the screening system and other performance tests;
  • periodic review of parameters (including concordance rates);
  • periodic review of the system by an external expert;
  • periodic internal audit of the system and its configuration;
  • regression tests of the system when updates or modifications are made. The Bank would like to take this opportunity to draw the attention of obliged entities to the publication on 14 November 2024 of new Guidelines by the European Banking Authority on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures9 which will enter into force on 30 December 2025. A copy of this communication is being sent to the accredited (statutory) auditor(s) of your institution by electronic means. 10 Yours faithfully, Pierre Wunsch Governor 9 These guidelines are currently being translated into the official languages of the EU. 10 If applicable.