2019-11-06
Added · Updated
The Malta Financial Services Authority identifies key risks, reoccurring weaknesses, and expected controls for authorized entities in the insurance, banking, securities, and trust sectors. The document outlines specific deficiencies in anti-money laundering arrangements, corporate governance, and operational resilience, requiring firms to implement robust internal controls and compliance frameworks. Regulated entities are expected to assess these findings against their internal practices and address any misalignments to meet ongoing supervisory standards.
MFSA published 4 documents in the last 30 days — get each new one by email the day it lands.
IDENTIFIED RISKS & EXPECTED CONTROLS
I
SUPERVISION
RISKS IDENTIFIED, WEAKNESSES AND
EXPECTED CONTROLS
A CROSS-SECTORAL ANALYSIS
IDENTIFIED RISKS
EXPECTED CONTROLS
A CROSS-SECTORIAL ANALYSIS
Contents
CONTENTS.................................................................................................................................................... 1
FOREWORD.................................................................................................................................................. 1
TABLE OF ABBREVIATIONS........................................................................................................................ 2
BACKGROUND............................................................................................................................................. 3
CHAPTER 1 ................................................................................................................................................... 4
CROSS-SECTORAL RISKS, WEAKNESSES AND EXPECTED CONTROLS................................................ 4
SECTION I - ANTI-MONEY LAUNDERING AND COUNTER FINANCING OF TERRORISM...................................... 5
A. Risks..................................................................................................................................................................................................5
B. Reoccurring Weaknesses.....................................................................................................................................................5
C. Controls which the MFSA expects authorised entities to have in place ...............................................7
SECTION II - GENERAL RISKS, WEAKNESSES AND EXPECTED CONTROLS ....................................................... 9
A. Risks..................................................................................................................................................................................................9
B. Reoccurring Weaknesses.................................................................................................................................................. 12
C. Controls which the MFSA expects authorised entities to have in place ............................................ 14
CHAPTER 2 ................................................................................................................................................. 19
SECTOR-SPECIFIC RISKS, WEAKNESSES AND EXPECTED CONTROLS............................................... 19
SECTION I INSURANCE AND PENSIONS.............................................................................................. 20
A. Risks............................................................................................................................................................................................... 20
B. Reoccurring Weaknesses.................................................................................................................................................. 21
C. Controls which the MFSA expects authorised entities to have in place ............................................ 22
D. Expected Controls (applicable for Insurance Intermediaries).................................................................... 23
SECTION II CREDIT AND FINANCIAL INSTITUTIONS.............................................................................. 24
A. Risks............................................................................................................................................................................................... 24
B. Reoccurring Weaknesses.................................................................................................................................................. 24
C. Controls which the MFSA expects authorised entities to have in place ............................................ 26
SECTION III SECURITIES AND MARKETS ............................................................................................... 29
A. Risks............................................................................................................................................................................................... 29
B. Reoccurring Weaknesses.................................................................................................................................................. 30
B.II Reoccurring Weaknesses [EMIR].................................................................................................................................. 32
C. Controls which the MFSA expects authorised entities to have in place ............................................ 32
SECTION IV TRUSTEES AND CORPORATE SERVICE PROVIDERS.............................................................. 35
A. Risks............................................................................................................................................................................................... 35
B. Reoccurring Weaknesses.................................................................................................................................................. 35
C. Controls which the MFSA expects authorised entities to have in place ............................................ 35
CONCLUDING REMARKS.......................................................................................................................... 37
Foreword
Joseph Cuschieri
Chief Executive Officer
The Malta Financial Services Authority, as the single regulator for financial services in Malta, is responsible for prudential and conduct supervision of the entities it authorises. In liaison with the Financial Intelligence and Analysis Unit, it also seeks to ensure compliance of such firms with anti-money laundering and counter financing of terrorism standards. The financial services industry is undergoing considerable transformation and as the environment in which regulated firms operate changes, so do the risks they face. Emerging technologies, global interconnectedness and new business models bring opportunities but also pose new threats. In this context, the MFSA considers that it is of utmost importance that regulated firms place strong governance, accountability and investment in compliance and controls at the heart of their operations. its statutory objectives to safeguard investors and to ensure market integrity and financial soundness, , and their adherence with regulatory standards, continues to be one of the main priorities. Going forward, the Authority is planning to intensify off-site work and the on-site inspections of firms, both in terms of coverage and standard. As indicated in the AML and CFT Strategy, published earlier this year, the MFSA has fused the three pillars of its supervisory strategy - prudential, conduct and AML supervision to ensure a holistic supervisory approach, which will, in turn, improve overall efficacy. The publication of this document, which is directed at regulated entities operating in the insurance, banking, securities, tru sectors, is pa of increasing the supervisory engagement with authorised entities, in promoting and ensuring sound governance structures, compliance standards and conduct.
Table of Abbreviations
AIFM Alternative Investment Fund Managers
AML Anti-Money Laundering
BCP Business Continuity Plan
CDD Customer Due Diligence
CFT Counter Financing of Terrorism
CIS Collective Investment Scheme
CSP Corporate Service Provider
DRP Disaster Recovery Plan
ECB European Central Bank
EMD Electronic Money Directive
EMIR European Market Infrastructure Regulation FIAU Financial Intelligence Analysis Unit GDP Gross Domestic Product IDD Insurance Distribution Directive ICT Information and Communications Technology KPI Key Performance Indicator KRI Key Risk Indicator NPL Non-Performing Loan MFSA Malta Financial Services Authority MiFID Markets in Financial Instruments Directive MLRO Money Laundering Reporting Officer PABF Payment Account with Basic Features PAR Payment Account Regulation POG Product Oversight and Governance PSD Payment Services Directive RMICAAP Risk Management and Internal Capital Adequacy Assessment Process TII Tied Insurance Intermediary UCITS Undertakings Collective Investments in Transferable Securities
Background
In promoting the safety and soundness of the financial services sector, the MFSA focuses on the risks that operators in the industry face or could face in the future. Over the past years, the MFSA has carried out extensive supervisory work to evaluate and reduce risks on consumers and market integrity, that may arise from the operations of the entities it authorises. The MFSA is issuing this document in order to outline its views on the key risks that authorised firms1 operating in the financial services sector might pose to their clients and the market in general. This within the industry. Additionally, it highlights the common weaknesses and deficiencies, which have been operators and the expected standards which authorised entities are expected to meet. This document comprises two Chapters. Chapter 1 includes a dedicated AML and CFT section and provides a list of cross-sectoral risks, weaknesses and expected controls. Such risks, common weaknesses and expected controls apply to industry practitioners operating in the various sectors. Chapter 2 then includes four dedicated sections. It identifies sector-specific risks, weaknesses and expected controls, each relating to the Insurance and Pensions, Credit and Financial Institutions, Securities and Markets, and Trusts and Corporate Service Providers sectors. Concluding remarks are included in the final part of this publication. The list of various risks, common weaknesses and expected controls, as set out in this document per sector, should not be interpreted as being exhaustive in nature and these do not necessarily apply to all legal forms of incorporation. The MFSA expects regulated entities to discuss the contents of this document with their Board of Directors (or equivalent administrative body) and assess how the highlighted points may apply to their business. Firms are expected to address any misalignments between their internal frameworks and practices and the expectations as set out in this document and to establish the necessary processes in order to ensure that the firm will continue to meet such expectations on an ongoing basis.
1 References rate or unincorporated, which may hold a licence or other authorisation issued by the Authority or which falls within the supervisory or regulatory authority of the Authority
Chapter 1
Cross-Sectoral Risks, Weaknesses and
Expected Controls
Section I - Anti-Money Laundering and Counter Financing of
Terrorism
A. Risks
In light of the Results of the National Money Laundering and Terrorist Financing Risk Assessment2 , the Authority considers the following as being some of the key financial crime risks in the financial services sector in Malta:
2 Results of the ML/TF National Risk Assessment - https://mfin.gov.mt/en/Library/Documents/Result_of_the_NRA_2018.pdf 3 The use of which obscures the link between the payment and payer and the provenance of funds.
C. Controls which the MFSA expects authorised entities to have in place
Firms are expected to:
Firms are expected to give prominence to ongoing scrutiny of transactions. Scrutiny of transactions ledge of the customer (including the information gathered on the purpose and intended nature of the business relationship and the custome profile) as well as statistical and pattern-analysis that is independent of the aforementioned, to identify transactions which are, by their very nature, unusual. These include, but are not limited to, suspicious, illogical, unnecessarily complex, or unreasonable or are significantly different to what is usually carried out or requested by the customer. reviews of firms have identified a number of shortfalls in this area and further assessments will be conducted in relation thereto.
Section II - General Risks, Weaknesses and Expected
Controls
A. Risks
Weak Corporate Governance
A number of authorised entities tend to operate with a lean internal governance structure, which may lead to ineffective Board rnal controls. Generally speaking, for certain firms, this would be due to their relatively small size and also the related proportionality and cost considerations. This risk is further exacerbated in instances where entities are owned by a sole individual and where such ultimate beneficial owner is a dominant figure within the entity. This risk may lead to lack of independent directors forming part of Board setups and there is, at times, an insufficient level of engagement and questioning by independent directors. This risk is higher in instances where an authorised entity experiences a significant degree of shareholder intervention, thereby undermining the independence of the management body and/or senior management. A related risk is when certain Board members, having several appointments in various firms, do not dedicate sufficient time to the proposed role, or, once appointed, they do not always continue undertaking ongoing professional training and development.
Ineffective Third Line of Defence
Given the relatively small size of certain authorised firms, proportionality and cost considerations, not all firms have a permanent, independent internal audit function. In such cases, at times, firms would not have in place effective mitigating arrangements, or in case where this is outsourced, such function would not be effectively monitored on a continuous basis and periodic updates are not always provided to the Board.
Key Person Dependency Risk
Given the relatively small size of certain firms and proportionality considerations, a number of authorised entities are also exposed to key person risk, particularly with respect to the management of core operations. This may expose firms to business continuity-related issues.
Lack of Effective Risk Framework and Risk Assessment
A number of authorised entities fail to undertake, implement and maintain a comprehensive risk assessment of their business. Deficient risk frameworks and poor risk assessment may result in firms not having sufficiently robust internal control functions and proper processes in place, potentially leading to lack of readiness by firms, in the event of unusual market events impacting their business.
Compliance and Regulatory Risk
Given the ever-increasing legislative and regulatory obligations that authorised entities are expected to comply with, exposure to regulatory and compliance risks should not be under-estimated. Risk is further heightened, when firms lack sufficient expertise, appropriate internal operational resources, suitable processes, or fail to embrace new technologies. Compliance risk, which can also be considered as a subset of regulatory risk, may result in real financial and business losses due to potential penalties/other regulatory actions imposed on the firm this aside from any resultant reputational impact.
Outsourcing Resilience and Oversight Risk
A number of authorised firms outsource core critical functions. Firms lacking good contingency plans may find themselves unprepared in case of the failure of a critical service provider and this exposesthem to resilience risk. Furthermore, firms could also be exposed to oversight risk when they outsource certain core functions, if they are found as not having properly supervised companies they outsourced business to.
Poor Conflicts of Interest Management Risk
A number of authorised firms repeatedly fail to appropriately identify, monitor, manage and control the conflicts of interest inherent to their business model. This may result in poor governance practices and could possibly lead to harming the consumer.
Complex Business Models
The evolving and increasingly complex business models, including complex intra-group ownership structures, at times also involving the outsourcing of functions to intra-group entities, exposes firms to greater risk. Business models targeting high-risk customers or non-traditional business lines need longterm planning and adequate risk evaluation. A related risk is when firms have an insufficiently articulated, or uncomprehensive, risk appetite on acceptance of new business.
Business/ Strategic Risk
Technology is changing the landscape of various regulated entities operating in the financial services sector. Failure to adapt to such a changing environment gives rise to risks impacting the long-term business strategy of a firm. Failures in this regard may include the inability to rethink outdated frameworks of core systems or the lack of implementation of more efficient systems to meet consumer demands. Such shortcomings could easily lead to loss of business and market share.
Operational Resilience (including Cybersecurity and Technology Risk)
This mainly refers to the ability of authorised firms and the sector as a whole to prevent, respond to, recover and learn from operational disruptions. Operational failures pose a risk to authorised entities in terms of business continuity as well as to possible damage to the integrity of proprietary data. Our
supervisory work has shown that certain entities are exposed to operational incidents, which may heavily disrupt their business. From the supervisory work undertaken in this area, the Authority has also found that certain entities are increasingly prone to operational shortcomings. As the business of a number of firms becomes more highly automated, any IT failure can have a substantial impact on the services that they provide. Entities may also be exposed to the risk of data leakage this may lead to data protection issues, as well as significant operational and reputational risk. Technological developments and the digital transformation may make firms increasingly susceptible to cyber-attacks. This could affect business continuity, undermine confidence in the sector and threaten financial stability.
11. Capital Resources Requirements
This relates to the risk that authorised entities (subject to capital resources requirements) may fall short of their initial capital requirements and their ongoing Own Funds requirements. Specifically with respect to the banking s report some level of voluntary buffers, with the Tier 1 capital ratio adequately above the 9.875% minimum regulatory requirement under the Basel III phase-in arrangements and the additional capital add-ons highlighted under the Capital Requirements Directive (CRD) IV 4 ; however, future pressures on capital may arise due to higher risk exposures registered by the core banks and possible future activation of macro-prudential capital buffers by Authorities.
12. Prolonged Low Interest Rate environment
The prolonged low interest rate environment is a risk that the securities, insurance and banking sectors are exposed to. Major central banks, such as the ECB and the Federal Reserve, have reverted to an expansionary monetary policy. The ECB, for example, has officially announced that it will restart its asset purchase programme 5 and already has a deposit rate of below (-0.5%)6 . Specifically, with respect to the securities sector, this may lure firms to the risky search for yield behaviour could artificially inflate asset prices. On the insurance side, a sustained low level of interest rates poses a significant challenge to the sector as it would struggle to generate adequate returns to meet long-term obligations but also poses an ongoing re-investment rate risk. This could lead money managers at insurance companies to seek higher returns through riskier, and possibly lower quality, investments. A prolonged low interest rate environment also exerts pressure on bank profitability, especially for retail banks, by reducing their interest rate margin. This is leading banks to rebalance their activities, changing business models and focusing more on other income-generating business activities. This accommodative monetary policy stance is a response to subdued GDP growth in the euro area, which
4 Central Bank of Malta, Financial Stability Report 2018, p 31 - https://www.centralbankmalta.org/file.aspx?f=82555, 5 European Central Bank, Press Release: Monetary Policy Decisions, 12 September 2019 https://www.ecb.europa.eu/press/pr/date/2019/html/ecb.mp190912~08de50b4d2.en.html 6 European Central Bank, Key ECB Interest rates:
https://www.ecb.europa.eu/stats/policy_and_exchange_rates/key_ecb_interest_rates/html/index.en.html
has been lagging behind that of other major economies in recent years. Such a macroeconomic environment may also erode profitability for banks. B. Reoccurring Weaknesses
not properly mapping the risk of non-compliance, which should enable firms to then set targets
and allocate the required resources and work programme of the compliance function;
inadequate compliance culture including: not having sufficient authority recognised by the
entity, not dedicating sufficient human and technical resources (in particular when this function is outsourced), the appointed compliance officer not possessing the right expertise to fully understand the risks of the firm, compliance officer not being given full access to all the information needed to be able to adequately perform function, failure to identify and harness regulatory requirements;
repetitive and/or unjustified late submission of regulatory reporting, which may also imply that
an authorised entity may lack sufficient internal resources and proper compliance monitoring;
in instances where compliance is outsourced, at times, the function is not being carried out
effectively and not always being properly monitored by the authorised entity;
firms not ensuring that, besides the compliance function being effective, independent,
undertaking monitoring checks and reporting, the compliance officer should also be advising the Board accordingly and is involved, for example, in projects which are likely to generate risk of non-compliance;
ineffective and incomplete compliance monitoring programmes not covering all aspects of the
authorised activities and failure to keep records, evidencing the ongoing checks being carried out in this respect;
the compliance function does not always adequately report to the Board on compliance
matters, such as providing a detailed assessment of how the various parts of the authorised firm is performing against compliance standards and goals (including methodology adopted with regards to such assessments);
insufficient due diligence and oversight of outsourced critical functions - the individuals
appointed to carry out oversight of outsourced functions are not provided with the necessary training to be capable of ensuring that oversight is carried out in an effective manner;
incomplete policies and procedures which are not regularly updated and/or not being followed
by the firm and staff not being given adequate training in relation to such policies and procedures;
compliance officer involved in the execution of services that they are responsible for monitoring;
compliance registers not always being accurately kept updated;
certain firms implement changes to their business models without submitting the required
notification (or request for approval, as applicable) to the Authority, as required in the applicable MFSA Rules.
the nature, scale and complexity of its business;
the diversity of its operations, including geographical diversity;
the volume and size of its transactions;
the degree of risk associated with each area of its operation.
The MFSA expects the Board of Directors to establish and maintain effective internal controls, to be aware of the major risks facing the company and provide guidance and oversight to senior management. A good practice noted by the Authority and one that the Board of Directors tend to benefit from is when appointing an individual who can contribute further to the regulatory framework area; particularly, to strengthen the oversight of the Compliance Function. The Board of Directors is expected to:
conduct periodic discussions with senior management regarding the effectiveness of the
internal controls;
ensure regular and timely reviews of the effectiveness of internal control functions;
ensure that all issues raised, including those by external auditors and the Authority, are followed
up by management;
ensure the effective implementation and oversight of the risk management system that includes
setting and monitoring internal controls so that all major risks are identified, measured, monitored and controlled on an ongoing basis.
o development of risk appetite, risk tolerance limits and resilience strategies (that is, strategies to help manage the impact of risk on the entity) which are regularly reviewed;
h rt departments;
has a direct reporting line to the Board of Directors;
has sufficient status within the authorised entity to ensure that senior management reacts to
and acts upon its recommendations;
has sufficient resources and staff who are suitably trained and have relevant experience to
understand and evaluate the business they are auditing;
employs a methodology that identifies the key risks run by the company and allocates its
resources accordingly.
Depending on the nature, scale and complexity of its business, it may be appropriate for an entity to form an audit committee ideally confined to non-executive directors of the company. It is recommended that at least one member of the audit committee shall be independent and shall have competence in accounting and/or auditing. Where a firm opts to outsource such function, it is expected that proper monitoring and reporting arrangements to the Board are put in place.
Chapter 2
Sector-specific Risks, Weaknesses and
Expected Controls
Section I Insurance and Pensions
A. Risks
B. Reoccurring Weaknesses
C. Controls which the MFSA expects authorised entities to have in place
Section II Credit and Financial Institutions
A. Risks
Non-Financial Corporate loans
With respect to credit institutions, non-financial corporate legacy loans remain high, although improvements have been registered since the implementation of the Non-Performing Loans Reduction Plan requirement outlined by BR09/2019.
Technology Risk
In providing financial services, a number of credit and financial institutions are increasing their dependence on technology. This includes the use of biometric authentication, robo-advice, use of big data and machine learning processes(for example, for credit scoring), as well as cloud computing. Whilst providing credit and financial institutions with a number of opportunities, the use of such technologies may also be associated with potential prudential risks including legal risk, conduct risk, cyber security risk and third-party risk (particularly if external service providers are engaged). Specifically, in relation to Financial Institutions, in view of their business models and delivery channels, if not adequately managed, such risk could lead to a significant financial loss and security threats to data, the institution itself and customers.
Lifecycle and Business lines
A number of credit institutions rely on a limited number of business lines. Other banks are also at the initial stages of their life cycle. The business model of such banks is typically associated with a high degree of business model risk. The current market environment that is characterised by low and flat yield curves, tight credit spreads and a highly competitive market, puts pressure on the profitability of banks. Similarly, a significant number of Financial Institutions are still at the growth phase of their business life cycle and may therefore be faced with difficulties in sourcing enough business to generate revenue that covers expenditure (high cost-to-income ratios). This search for business often exposes Financial Institutions to a higher risk. B. Reoccurring Weaknesses
Credit Quality
In past years, regulatory authorities have continuously given attention to the issue of non-performing loans. This was one of the drivers which has led to a declining non-performing loans ratio in Malta. That being stated, pockets of vulnerabilities still persist.
Exposure towards residential real estate
A number of credit institutions have significant exposure towards residential real estate in Malta. Although currently there seems to be no indication of any material over-valuation in residential real estate prices, the regulatory Authorities have introduced borrower-based measures to strengthen the resilience of lenders and borrowers against the potential build-up of vulnerabilities which could result in financial losses both to lenders and borrowers stemming from potential unfavourable economic developments. The borrower-based measures came into force in July 2019.
Safeguarding of Funds (Financial Institutions)
In terms of PSD II and EMD II, as transposed in the Financial Institutions Act, Financial Institutions are required to safeguard funds received from customers and to ensure that these are not commingled with wn funds. In this respect, a number of Financial Institutions fail to provide the necessary assurances vis-à-vis the utilisation of adequate systems to ensure that such funds are safeguarded at all times and to carry out timely reconciliations.
Lack of adequacy of information provided (both written and verbal) to the customer and
disclosures made by the bank branch representatives A number of branch representatives of credit institutions are not always forthcoming in providing customers with information on the features and characteristics of the bank accounts that are being offered by the respective bank. At times, this information is , and in cases where this is provided, it is sometimes limited and therefore not sufficient to allow the customer to make an informed decision. Furthermore, certain credit institutions lack certain consistency in the information provided by their branches.
Knowledge of the bank branch representatives and training
Certain branch representatives, do not always possess sufficient knowledge to enable them to reply to customers requests and/or queries. Branch representatives, at times, have difficulties explaining matters, such as:
Provision of information on the PABF
The PABF is not always being immediately offered to customers in all the branches of banks and, at times, it is only offered upon enquiry and request. In addition, when offered, a number of branch representatives are not always sufficiently knowledgeable to provide complete and correct information thereon.
Tariff of charges
In certain bank branches, no written information on the fees and charges applied by the credit institutions on their productsis made available. T Tariff of Charges is, at times, only being provided to the customer on request. 8. Certain are not fully compliant with some requirements arising from the PAR, in relation to:
detailed information, both written and verbal, on the features and characteristics of the different bank accounts available and being offered by the credit institution.
Section III Securities and Markets
A. Risks
Within this section, risks are categorised in accordance with the type of authorised firm/sub-sector. Investment (MiFID) Firms
A lack of transparency of ownership and control associated with certain CIS structures can increase the risk for fund administratorsin adequately determining the source and destination of funds. Furthermore, investors in funds may be wide-ranging, including PEPs, high net worth individuals and cash-based businesses. Furthermore, nominee investments can make it more difficult for one to be able to determine the ultimate beneficial ownership of invested funds.
2. Complex performance fees and commission structures
Complex performance fee and commission structures are on the rise, posing potential challenges to fund administrators when performing fund accounting activity and risking inaccurate calculations. Investment Managers and Collective Investment Schemes (externally managed)
Financial and Operational Risks
Investment Managers may be exposed to either financial risks, which may include: liquidity, market and counterparty risk, and operational risks, which may result from having inadequate internal processes and failures in relation to people or systems of the firm or from external events impacting the firm. As stated, the mismanagement of risks could result in financial losses which adversely impact investors and the .
Valuation Risk
This risk relates to the possible incorrect valuation of underlying investments leading to an incorrect Net Asset Value and dealings, in turn resulting in incorrect allotment of redemption proceeds and share allocation in the case of subscriptions. This risk is even higher for hard-to-value/level 3 assets.
Risk Appetite of the CIS not being aligned with its Investment Risk Profile
petite, when it undertakes investments in certain asset classes/sectors, would not be aligned with the business model and underlying strategy of the scheme, as communicated to investors. B. Reoccurring Weaknesses
Lack of conformity with the applicable legislative requirements (including in terms of
documentation utilised by authorised entities), especially with MiFID II, AIFM and UCITS Directives and other relevant legislation.
Certain MiFID firms fail to make a clear distinction between the provision of advisory and nonadvisory services. Such firms, when providing non-advisory services, are documenting such a
service as execution only. Other firms are not fully satisfying the requirements when providing advisory services.
Proper identification/classification of complex instruments is not consistently being carried out by
MiFID firms. Distribution and dissemination of complex financial instruments may therefore not be fully accurate.
Weak client onboarding and mis-selling practices - Investment advice and discretionary portfolio
management services to retail clients may be prone to mis-selling risks. This risk is further exacerbated when firms have certain remuneration structures/packages which are not necessarily tied with the quality of service offered to consumers. Poor client onboarding practices and failure to implement adequate related processes and procedures (including in terms of systems), may expose firms to a wrong classification of clients and thereby increasing the risk of offering inadequate protection and products to clients. When assessing the client onboarding practices of certain Investment Firms during onsite inspections, it was noted that observations highlighted during previous Client Fact Find thematic reviews, were, at times, not taken on board.
Weak Risk Management Function
when such function is not independent, there are, at times, insufficient and/or inadequate
mitigating arrangements in place for the authorised entity to ensure that the function is nonetheless being undertaken effectively;
when such function is undertaken internally by the authorised firm, the appointed person
does not always have the necessary authority and resources to perform his/her duties and to be able to challenge and question the Board accordingly;
when the function is undertaken via a secondment arrangement, or otherwise outsourced,
there is, at times, either lack of monitoring of such outsourced function by the authorised firm, or the risk official is not granted with sufficient visibility in relation to the firm;
when the function is outsourced, at times, the risk management function would merely
constitute the generation of risk measurement and risk reports, with insufficient engagement in advising the Board on risk-related matters;
operational risk not being given the necessary coverage in the risk management reports
presented to the Board;
insufficient questioning by the Board on the technical data presented in the risk
management reports;
no proper independent annual review to oversee the effectiveness and well-functioning of
the risk management and the internal capital adequacy assessment process (RMICAAP) of
MiFID firms, is not always prepared in accordance with Title 2 Risk Management - Section 3 of Part B1 of the Investment Services Rules for Investment Services Providers;
a number of MiFID firms do not compile the risk calculation report correctly. Certain risks
identified in the RMICAAP are being omitted from the risk calculation report;
the RMICAAP of MiFID firms is not always signed by two directors, as stipulated in the Rules;
several MiFID firms have capital requirements close to the regulatory thresholds, without
having in place early warning mechanisms and/ or any contingency plan/s in case a shortfall occurs. B.II Reoccurring Weaknesses [EMIR] The below are reoccurring weaknesses which arise specifically from the outcome of supervisory work related to EMIR.
Procedures
A number of undertakings do not have a set of written procedures, which establish the processes carried out by the respective undertaking in order to be compliant with EMIR.
Delegation
Failure to keep in place the necessary documentation when delegating certain duties (such as an EMIR reporting delegation agreement) and related failure to conduct reasonable checks and requesting periodic confirmations to ensure that the delegated third-party is carrying out such duties in an accurate and timely manner, in accordance with the delegation agreement.
Risk Mitigation
Failure to implement risk-mitigating arrangements when entering into Over the Counter derivative contracts which are not cleared by a Central Counterparty Clearing Provider.
C. Controls which the MFSA expects authorised entities to have in place
Investment Firms
Identification of Conduct Risks and Controls
The MFSA expects Investment Firms to have a good planning strategy as well as adequate procedures and controls in place in order to ensure compliance with MiFID II requirements. Investment Firms must identify conduct risks and identify a sales strategy, which takes into account conduct issues in order to prevent and mitigate such risks. The Authority also expects that there is a robust due diligence process in place in order to adequately assess clients. 2. In terms of MIFID II, when investment firms hold financial instruments belonging to clients, firms need to have adequate arrangements in place to safeguard the ownership rights of clients. Firms are expected in this regard to ensure that proper [i] segregation; [i] compliance oversight; [iii] reconciliation exercises; and [iv] choice of custodians, are maintained which will help in mitigating such risk.
Financial and Operational Risks
Investment Firms are expected to undertake a risk mapping exercise and assess the level of exposure to such risks on a periodic basis. It is critical that such an exercise captures all processes of the firm, which are linked to MiFID activities, and determines whether such risk is critical or otherwise for the firm by measuring probability that the relevant risk might occur. MiFID firms are required to ensure that they have in place an effective risk management setup, policies and procedures to manage the risks that the firm is exposed to.
Market event risk: Market & Counterparty Risk Forex firms
Given the large volume of transactions undertaken by these firms, and in view of the related risk of loss of either , it is important that besides having in place appropriate risk management tools, a dealing desk is also maintained. This is in order to be able to continuously monitor such exposures. Investment Managers (including externally managed Collective Investment Schemes)
Financial and Operational Risks
Investment Managers are expected to undertake a risk mapping exercise and assess the level of exposure to such risks on a periodic basis. It is critical that such exercise captures all processes of the firm which are linked to portfolio management related activities, and determine whether such risk is critical, or otherwise, for the firm, by measuring probability that the relevant risk might occur. Full AIFMs and UCITS Management Companies are required to ensure that they have in place an effective risk management setup, policies and procedures to manage the risks that the investment manager may be exposed to.
Breach of Investment Restrictions
Investment Managers should ensure the implementation of a sound investment restrictions check process, including relevant processes and procedures and adequate systems covering such process.
Risk Appetite of a CIS not being aligned with the investment risk profile of the CIS
The Authority expects both the investment manager and a CIS Board to fully understand and actively monitor the undertaken by the CIS are aligned accordingly.
Valuation Risk
Investment Managers (and CISs) are expected to:
i. before the launch of the CIS, ensure that the proposed valuation methodology is fully disclosed
to investors;
ii. the Board of Directors also needs to be aware and have a good understanding of the proposed
methodology in order to be able to know what to question in relation to liquidity as part of their fiduciary obligations on an ongoing basis;
iii. ensure that the valuation process is effective (including use of reliable pricing sources), and
conflicts of interest are avoided or mitigated accordingly; With regard to point [ii], Board members should exercise judgement with respect to what documentation of the valuation process they would like to have access to and to ensure that such documentation is providing adequate coverage for them to understand the methodology being used to value the assets. In carrying out their valuation responsibilities, Board members need to be aware of the risks arising (such as valuation being obtained from a single source or counterparty, the reliability of data being provided for assets that are not exchange traded, use of models developed internally by the firm to undertake valuation, etc.) and assess what questions to raise during Board meetings in this respect. Recognised Fund Administrators
Section IV Trustees and Corporate Service Providers
A. Risks
take a pro-active approach to increase their understanding of the threats and vulnerabilities
posed by the structure which they are servicing and, based on that, develop proportionate and effective controls for the risks they face;
use the National AML/CFT Risk Assessment and Strategy as well as any other sectoral risk
assessment to drive risk appetite and internal business plans;
develop a risk assessment methodology to ensure (potential) clients and their activities can
be appropriately risk profiled, and consequently use the outputs to act as good gatekeepers to the financial system;
maintain an up-to-date beneficial ownership database, and invest in technologies that
ensure accurate collection of this information;
collaborate with competent authorities to ensure practices are up-to-date with supervisory
expectations on AML/CFT, including attending outreach workshops as relevant.
Concluding Remarks
The reoccurring weaknesses that the Authority has identified, and continues to encounter, as part of its ongoing supervisory work, are a matter of high concern. services sector and consumers of financial services, rests on firms ability and commitment to comply with their fundamental obligations. The Authority is therefore communicating, to regulated firms, its views on the expected standards with respect to As indicated at the outset, the Authority is aiming to increase the scrutiny of regulated operators in the industry. In the light of the various reoccurring shortcomings mentioned and the indicative guidance of expected controls, firms are strongly advised to review their internal control systems and procedures, to undertake a thorough and meaningful assessment thereof, and to proceed to take any corrective action to address possible identified deficiencies. As part of such a process, regulated firms are expected to fully undertake an assessment and self-identify any action that is required to comply with the letter and spirit and the expectations as these emanate from this document. The MFSA will expect to see this on-going exercise as part of the onsite supervisory work that will be undertaken. The Authority is committed to continue undertaking follow-up supervisory work in the future and expects to see that these initiatives have led to a factual increase in the robustness of setups and internal controls of authorised firms.
MALTA FINANCIAL SERVICES AUTHORITY
TRIQ L-IMDINA, ZONE 1, CENTRAL BUSINESS DISTRICT, BIRKIRKARA, CBD 1010 COMMUNICATIONS@MFSA.MT +356 2144 1155 WWW.MFSA.MT
Read the rest free
Source: Malta Financial Services Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from MFSA
MFSA published 4 documents in the last 30 days. We email you each new one the day it's published.