| Guidelines This chapter describes how banks should include risks related to money laundering and financing of terrorism within their overall risk management framework. The contents of this chapter are based on: |
| Related standards |
| Related guidelines |
| Other related publications |
Banks may be used, intentionally or unintentionally, for criminal activities including money laundering and the financing of terrorism. Sound management of the risks related to money laundering and terrorist financing is relevant to the overall safety and soundness of banks and the banking system as it:
The inadequacy or absence of sound anti-money laundering / counter terrorism financing (AML/CFT) risk management exposes banks to serious risks, including reputational, operational, compliance and concentration risks. These risks have been highlighted by enforcement actions taken by authorities and the corresponding costs incurred by banks due to their lack of diligence in applying appropriate risk management policies, procedures and controls.
AML/CFT-related risks are interrelated. In addition to incurring fines and sanctions, risks could also result in significant financial costs to banks (eg through the termination of wholesale funding and facilities, claims against the bank, investigation costs, asset seizures and freezes, and loan losses), as well as the diversion of limited and valuable management time and operational resources to resolve problems.
The fight against money-laundering and the financing of terrorism is led by the Financial Action Task Force (FATF). The FATF Recommendations set out a comprehensive and consistent framework of measures which countries should implement to combat money laundering and terrorist financing, as well as the financing of proliferation of weapons of mass destruction.
The Committee supports the adoption of the standards issued by the FATF.1 The guidance set out in this chapter is intended to be consistent with and to supplement the goals and objectives of the FATF standards, and should not be interpreted as modifying the FATF standards. In some instances, the Committee has included cross-references to FATF standards to assist banks in complying with national requirements based on the implementation of those standards. The FATF standards that require countries to apply other measures in their financial sectors and other designated non-financial sectors, or establishing powers and responsibilities for the competent authorities, are not dealt with in this chapter.
| 1 | See The FATF Recommendations. Relevant FATF recommendations are R.1 – R.2, R.9, R.10-R.20, R26-R27, R.35 and R.40. |
The following terms are used throughout this chapter and have the meaning given below:
| 2 | See FATF, Guidance on correspondent banking services (October 2016). |
| 3 | Such as SWIFT Relationship Management Application (RMA) keys. |
| 4 | “Person” in this context refers to natural and legal persons or legal arrangements. |
| 5 | Financial intelligence units are described in Recommendation 29 in the FATF Recommendations. |
Sound risk management requires the identification and analysis of ML/FT risks within a bank and the design and effective implementation of policies and procedures that are proportionate with the identified risks. In conducting a comprehensive risk assessment to evaluate ML/FT risks, a bank should consider all relevant inherent and residual risk factors at the country (or, where relevant, supranational), sectoral, bank and business relationship level, among others, to determine its risk profile and the appropriate level of mitigation to be applied. The policies and procedures for CDD, customer acceptance, customer identification and monitoring of the business relationship and operations (product and service offered) will then have to consider the risk assessment and the bank’s resulting risk profile. A bank should have appropriate mechanisms to keep risk assessments up-to-date and document and provide risk assessment information to competent authorities such as supervisors. Regulated entities should use relevant information from country risk assessments and understand the overall national risk environment, and countries should proactively communicate the findings of risk assessments to financial institutions, including any updates.
A bank should develop a thorough understanding of the inherent ML/FT risks present in its customer base, products, delivery channels and services offered (including products under development or to be launched) and the jurisdictions within which it or its customers do business. This understanding should be based on specific operational and transaction data and other internal information collected by the bank as well as external sources of information such as national and supranational risk assessments and country reports from international organisations. Policies and procedures for customer acceptance, due diligence and ongoing monitoring should be designed and implemented to adequately control those identified inherent risks. Any resulting residual risk should be managed in line with the bank’s risk profile established through its risk assessment. This assessment and understanding should be demonstrable as required by, and should be acceptable to, the bank’s supervisor.
Effective ML/FT risk management requires proper governance arrangements. The board of directors should have a clear understanding of ML/FT risks. Information about ML/FT risk assessment should be communicated to the board in a timely, complete, understandable and accurate manner so that it is equipped to make informed decisions. The board of directors ensures senior management appoints an appropriately qualified AML/CFT officer to have overall responsibility for the AML/CFT function. The officer should have the stature and necessary authority within the bank to ensure that issues raised receive the necessary attention from the board, senior management and business lines.
As part of the first line of defence, there should be internal procedures for detecting and reporting suspicious transactions.
All banks should implement ongoing employee training programmes for AML so that bank staff are adequately trained to implement the bank’s AML/CFT policies and procedures. The timing and content of training for various sectors of staff will need to be adapted by the bank according to their needs and the bank’s risk profile. Training course organisation and materials should be tailored to an employee’s specific responsibility or function to ensure that the employee has sufficient knowledge and information to effectively implement the bank’s AML/CFT policies and procedures. New employees should be required to attend training as soon as possible after being hired. Refresher training should be provided to ensure that staff are reminded of their obligations and their knowledge and expertise are kept up to date. The scope and frequency of such training should be tailored to the risk factors to which employees are exposed due to their responsibilities and the level and nature of risk present in the bank.
As part of the second line of defence, the officer in charge of AML/CFT should have responsibility for ongoing monitoring of the fulfilment of all AML/CFT duties by the bank. This implies sample testing of compliance and review of exception reports, and to alert senior management or the board of directors of material failures to address AML/CFT risks. The AML/CFT officer should be the contact point regarding all AML/CFT issues for internal and external authorities, including supervisory authorities or financial intelligence units (FIUs).
The business interests of a bank should not conflict with the effective discharge of the responsibilities of the AML/CFT officer. The AML/CFT officer should, for example, not have business line responsibilities or be entrusted with responsibilities for data protection or the internal audit function. Where any conflicts between business lines and the responsibilities of the chief AML/CFT officer arise, procedures should be in place to ensure AML/CFT concerns are objectively considered at the highest level.
The AML/CFT officer may also perform the function of the chief risk officer or the chief compliance officer or equivalent. They should have a direct reporting line to senior management or the board. In case of a separation of duties the relationship between the aforementioned chief officers and their respective roles must be clearly defined and understood.
The AML/CFT officer should have the responsibility for reporting suspicious transactions. The AML/CFT officer should be provided with sufficient resources to execute all responsibilities effectively and play a central and proactive role in the bank’s AML/CFT regime. To do so, they must be fully conversant with the bank’s AML/CFT regime, statutory and regulatory requirements and the ML/FT risks arising from the business.
Internal audit as the third line of defence, plays an important role in independently evaluating the effectiveness of compliance with AML/CFT policies and procedures.7 A bank should establish policies for conducting audits of (i) the adequacy of the bank’s AML/CFT policies and procedures in addressing identified risks, (ii) the effectiveness of bank staff in implementing the bank’s AMF related policies and procedures; (iii) the effectiveness of compliance oversight and quality control including parameters of criteria for automatic alerts; and (iv) the effectiveness of the bank’s training of relevant personnel.
Periodically, internal auditors should conduct AML/CFT audits on a bank-wide basis. In addition, internal auditors should be proactive in following up their findings and recommendations. Generally, the processes used in auditing should be consistent with internal audit’s broader audit mandate, subject to any prescribed auditing requirements applicable to AML/CFT measures.
External auditors also have an important role to play in evaluating banks’ internal controls and procedures, and in confirming that they are compliant with AML/CFT regulations and supervisory practice. In cases where a bank uses external auditors to evaluate the effectiveness of AML/CFT policies and procedures, it should ensure that the scope of the audit is adequate to address the bank’s risks and that the auditors assigned to the engagement have the requisite expertise and experience. A bank should also ensure that it exercises appropriate oversight of such engagements.
A bank should implement an adequate monitoring system based on its size, activities and complexity as well as the risks present in the bank. For most banks, especially those which are internationally active, effective monitoring is likely to require automation of the monitoring process. When a bank considers that an IT monitoring system is not necessary in its specific situation, it should document its decision and be able to demonstrate to its supervisor or external auditors that it has in place an effective alternative. When an IT system is used, it should cover all accounts and transactions of the bank’s customers. The IT system must enable the bank to undertake trend analysis of transaction activity and to identify unusual business relationships and transactions that could present a risk, to prevent ML or FT.
The monitoring system should be able to provide accurate information for senior management relating to both transactional and profile information of customers to better monitor risk changes. In compiling the customer’s profile, the bank should incorporate updated, comprehensive and accurate CDD information for the customer. The monitoring system should allow the bank, and where appropriate the group, to develop a centralised information knowledge base (ie organised by customer, product, across group entities, transactions carried out during a certain timeframe etc). Banks should be able to risk-rate customers and manage alerts with all the relevant information at their disposal, without having a unique customer file. The IT monitoring system must use adequate parameters based on national and international experience on the methods and prevention of ML and FT. A bank may use the standard parameters provided by the developer of the IT monitoring system; however, these parameters must reflect and account for the bank’s own risk situation.
The IT monitoring system should enable a bank to determine its own criteria for additional monitoring, filing a suspicious transaction report (STR) or taking other steps to minimise risk. The AML/CFT officer should have access to and benefit from the IT system as relevant for their function (even if operated or used by other business lines). The IT system should allow for the generation of alerts for unusual transactions, which should then be subject to further assessment by the AML/CFT officer. Any risk criteria used in this context should adequately reflect the risk assessment of the bank
A bank should develop and implement clear customer acceptance policies and procedures to identify the types of customer that are likely to pose a higher risk of ML and FT pursuant to the bank’s risk assessment.8 When assessing risk, a bank should consider relevant factors, such as: a customer’s background, occupation (including a public or high-profile position), source of income and wealth, country of origin and residence (when different), products used, nature and purpose of accounts, linked accounts, business activities and other customer-oriented risk indicators, to determine the level of overall risk and the appropriate mitigants.
| 8 | The FATF standards and Guidance on Financial Inclusion and Anti-Money Laundering and Terrorist Financing Measures also include useful guidelines on how a bank may effectively implement a risk-based approach (see in particular Recommendation 1 and 10). |
Such policies and procedures should require due diligence for all customers proportionate to the level of risk. For situations assessed as lower risk, simplified measures may be permitted, if this is allowed by law. For example, basic account-opening procedures may be appropriate for an individual who expects to maintain a small account balance to conduct routine retail banking transactions. It is important that the customer acceptance policy is not so restrictive that it results in a denial of banking services to the general public, especially individuals who are financially or socially disadvantaged.9
| 9 | The FATF Financial Inclusion Guidance provides useful guidelines on designing AML/CFT procedures that are not overly restrictive to the financially or socially disadvantaged. |
Where risks are higher, banks should adopt enhanced measures to mitigate and manage risks. Enhanced due diligence may be essential for an individual planning to maintain a large account balance and conduct regular cross-border wire transfers, or an individual who is a politically exposed person (PEP). Enhanced due diligence is required for foreign PEPs. Decisions to enter into or pursue business relationships with higher-risk customers should require the application of enhanced due diligence measures, such as approval by senior management. The bank’s customer acceptance policy should also define the circumstances under which the bank would not accept a new business relationship or would terminate an existing one.
Customer due diligence should be applied to customers, persons acting on their behalf and beneficial owners. In accordance with the FATF standards, banks should identify customers and verify their identity.10
| 10 | See Interpretive note to Recommendation 10 of the FATF. This requirement applies unless the country has determined through a risk assessment that particular types of activities (and customers associated with these activities) may, on a limited basis, be exempted because there is an assessed low risk of ML or FT in line with the interpretive note to Recommendation 1. |
A bank should establish a systematic procedure for identifying and verifying its customers and, where applicable, any person acting on their behalf and any beneficial owner(s). Generally, a bank should not establish a banking relationship, or carry out any transactions, until the identity of the customer has been satisfactorily established and verified in accordance with FATF Recommendation 10. The procedures should also include taking reasonable measures to verify the identity of the beneficial owner(s). A bank should also verify that any person acting on behalf of the customer is appropriately authorised.
The identity of customers, beneficial owners, and persons acting on their behalf, should be verified using reliable, independent source documents, data or information. The best documents for the verification of identity are those most difficult to obtain illicitly or to counterfeit. When relying on other sources, the bank must ensure that the methods (which may include checking references with other financial institutions and obtaining financial statements) and sources of information are appropriate, and in accordance with the bank’s policies and procedures and risk profile of the customer. A bank may require customers to complete a written declaration on the identity and details of the beneficial owner, although the bank should not rely solely on such declarations. In no case should a bank disregard its customer identification and verification procedures just because the customer is unable to be present for an interview. The bank should also consider risk factors such as why the customer has chosen to open an account far away from its seat/office, in particular in a foreign jurisdiction. It is also important for banks to consider the relevant risks associated with customers from jurisdictions that are known to have AML/CFT compliance deficiencies and apply enhanced due diligence when this is required by the FATF, other international bodies or national authorities.
A bank should use customer information to build an understanding of the customer’s profile and behaviour. Examples of information typically collected include:
A bank should have policies and procedures in place to conduct due diligence on its customers sufficient to develop customer risk profiles either for particular customers or categories of customers. The information collected for this purpose should be determined by the level of risk associated with the customer’s business model and activities as well as the requested financial products or services. These risk profiles will facilitate the identification of any account activity that deviates from “normal” activity or behaviour for that customer or customer category and that could be considered as unusual, or suspicious. Customer risk profiles may assist the bank in determining if the customer or customer category is higher-risk and requires the application of enhanced CDD measures and controls. The profiles should also reflect the bank’s understanding of the intended purpose and nature of the business relationship/occasional banking transaction, expected level of activity, type of transactions, and, where necessary, sources of customer funds, income or wealth as well as other similar considerations. Any significant information collected on customer activity or behaviour should be used in updating the bank’s risk assessment of the customer.
A bank should obtain customer identification papers and other information and documentation as part of the CDD conducted on the customer. This could include copies of official documents (eg passports, identity cards, driving licences), account files (eg financial transaction records) and business correspondence, including the results of any analysis undertaken such as the risk assessment and inquiries to establish the background and purpose of the relationships and activities.
A bank should also obtain all the information necessary to establish to its full satisfaction the identity of their customer, any person acting on behalf of the customer and of beneficial owners. While a bank is required to both identify its customers and verify their identities, the nature and extent of the information required for verification will depend on the risk assessment, including the type of applicant (personal, corporate etc), and the expected size and use of the account. The specific requirements involved in ascertaining the identity of natural persons are usually prescribed in national legislation. Higher-risk customers will require the application of enhanced due diligence to verify customer identity. If the relationship is complex, or if the size of the account is significant, additional identification measures may be advisable, and these should be determined based on the level of overall risk.
When a bank is unable to complete CDD measures, it should not open the account, commence business relations or perform the transaction. However, there may be circumstances where it would be permissible for verification to be completed after the establishment of the business relationship, because it would be essential not to interrupt the normal conduct of business. In such circumstances, the bank should adopt adequate risk management procedures for the conditions and restrictions under which a customer may use banking services prior to verification. In situations where an account has been opened but verification problems arise that cannot be resolved, the bank should close or otherwise block access to the account. In any event, the bank should consider filing a STR in cases where there are problems with completion of the CDD measures.11 Additionally, where CDD checks raise suspicion or reasonable grounds to suspect that the assets or funds of the prospective customer may be the proceeds of predicate offences or crimes related to ML/FT, banks should not open accounts with such customers. In such situations, banks should file an STR with the relevant authorities and ensure that the customer is not informed (even indirectly) that an STR has been, or will be filed.
| 11 | Subject to any national legislation concerning handling of suspicious transactions. |
A bank should have in place procedures and capacity that enable identification of any designated entities or individuals (eg terrorists, terrorist organisations) in accordance with their national legislation and the relevant United Nations Security Council Resolutions (UNSCRs).
While the transfer of funds from an account in the customer’s name in another bank subject to the same CDD standard as the initial deposit may provide some comfort, a bank should nevertheless conduct its own due diligence and consider the possibility that the previous account manager may have asked for the account to be closed because of a concern about illicit activities. If a bank has any reason to believe that an applicant has been refused banking services by another bank due to concerns over illicit activities, it should consider:
A bank should not open an account or continue conducting business with a customer who insists on anonymity or who gives an obviously fictitious name. Confidential numbered accounts12 should not function as anonymous accounts and should be subject to the same CDD procedures as all other customers’ accounts, even if the procedures are carried out by selected staff. While a numbered account can offer additional confidentiality for the customer, their identity must be verified by the bank and be known to enough staff to allow for effective due diligence, especially if other risk factors indicate that the customer is higher risk. A bank should ensure that the AML/CFT officer (as well as other control and compliance functions), and the bank’s supervisors, have full access to this information as needed.
| 12 | In a numbered account, the names of the customer and beneficial owner are known to the bank but are substituted by an account number or code name in subsequent documentation. |
Ongoing monitoring is essential for effective and sound ML/FT risk management. A bank can only effectively manage its risks if it understands the normal and reasonable banking activity of its customers and can then identify unusual transactions (or attempted transaction) which fall outside the regular pattern of customers’ activities. Without such knowledge, the bank is likely to fail in its obligations to identify and report suspicious transactions to the appropriate authorities. Ongoing monitoring should be conducted for all business relationships and transactions, but the extent of the monitoring should be based on the risk as identified in the bank’s risk assessment and CDD efforts. Enhanced monitoring should be adopted for higher-risk customers or transactions. A bank should also carry out cross-sectional product/service monitoring to identify and mitigate emerging risk patterns.
All banks should have systems in place to detect unusual or suspicious transactions or patterns of activity. In establishing such systems, a bank should consider the customer’s risk profile developed as part of the bank’s risk assessment, information collected during its CDD efforts, and other information obtained from law enforcement and other authorities in its jurisdiction. For example, a bank may be aware of particular schemes or arrangements to launder the proceeds of crime, identified by authorities as occurring within its jurisdiction. As part of its risk assessment process, it should have assessed the risk that such activity may be occurring within the bank through a category of customers, group of accounts, transaction pattern or product usage. Based on this knowledge, the bank should design and apply appropriate monitoring tools and controls to identify such activity.
Using CDD information, a bank should be able to identify transactions that do not appear to make economic sense, that involve large cash deposits or that are not consistent with the customer’s normal and expected transactions.
A bank should have enhanced due diligence policies and procedures for customers who have been identified as higher risk. In addition to the policies and procedures for account opening, including their risk-based level of approval, a bank should also have specific policies regarding the extent and nature of required CDD, frequency of ongoing account monitoring and updating of CDD information and other records. The ability of the bank to effectively monitor and identify suspicious activity requires access to updated, comprehensive and accurate customer profiles and records.
A bank should ensure that it has appropriate and proportionate integrated management information systems, to provide both business units (eg relationship managers) and risk and compliance officers (including investigating staff) with timely information needed to identify, analyse and effectively monitor customer accounts. The systems used and the information available should support the monitoring of customer relationships across lines of business and include all available information on that customer relationship, including transaction history, account opening documentation, significant changes in the customer’s behaviour or business profile, and any unusual transactions.
The bank should screen its customer database(s) whenever there are changes to sanction lists, at the onboarding of new customers or changes to relevant customer information, including new beneficial owners or customer representatives. The bank should also screen its customer database(s) periodically to detect foreign PEPs and other higher-risk accounts and subject them to enhanced due diligence.
A bank should ensure that all information obtained through CDD is recorded. This includes both: (i) recording the documents the bank is provided with when verifying the identity of the customer or the beneficial owner; and (ii) transcription into the bank’s own IT systems of the relevant CDD information contained in such documents or obtained by other means.
A bank should develop and implement clear rules on the records that must be kept to document due diligence conducted on customers and individual transactions. These rules should consider, if possible, any prescribed privacy measures. They should include a definition of the types of information and documentation that should be included in the records as well as the retention period for such records, which should be at least five years from the termination of the banking relationship or the occasional transaction. In the event of ongoing investigation/ litigation, all records should be retained until the closure of the case even if the accounts are closed. Maintaining complete and updated records is essential for a bank to adequately monitor its relationship with its customer, understand the customer’s ongoing business and activities, and, if necessary, provide an audit trail in the event of disputes, legal action, or inquiries or investigations that could lead to regulatory actions or criminal prosecution.
Adequate records documenting the evaluation process for ongoing monitoring and review, and any conclusions drawn should also be maintained. These will help to demonstrate the bank’s compliance with CDD requirements and ability to manage ML and FT risk.
Banks should ensure that records remain accurate, up-to-date and relevant by undertaking regular reviews of existing records and updating the CDD information. Retaining up-to-date information will enhance the bank’s ability to effectively monitor the account for unusual or suspicious activities. It may also assist competent authorities including law enforcement agencies or FIUs to effectively use this information to fulfil their own AML/CFT responsibilities.
A bank should be able to demonstrate to its supervisors, on request, the adequacy of its assessment, management and mitigation of ML/FT risks; its customer acceptance policy; its procedures and policies concerning customer identification and verification; its ongoing monitoring and procedures for reporting suspicious transactions; and all measures taken in the context of AML/CFT.
Ongoing monitoring and review of accounts and transactions enables banks to identify suspicious activity, eliminate false positives and report promptly genuine suspicious transactions. The process for identifying, investigating and reporting suspicious transactions to the FIU should be clearly specified in the bank’s policies and procedures and communicated to all personnel through regular training. These policies and procedures should contain a clear description for employees of their obligations and instructions for the analysis, investigation and reporting of such activity within the bank, including guidance on how to complete such reports.
A bank should have procedures for assessing whether its statutory obligations under recognised suspicious activity reporting regimes require a transaction to be reported to the appropriate law enforcement agency or FIU and/or supervisory authorities. These procedures should reflect the principle of confidentiality, ensure that investigations are conducted swiftly, and that reports contain relevant information and are produced and submitted in a timely manner. The AML/CFT officer should ensure prompt reporting to applicable authorities where funds or other property that is suspected to be the proceeds of crime remain in an account.
Once suspicion has been raised in relation to an account or relationship, a bank should promptly report the suspicious activity and ensure that appropriate action is taken to mitigate the risk of the bank being used for criminal activities. This may include a review of either the risk classification of the customer or account or of the entire relationship. Appropriate action may necessitate escalation to the appropriate level of decision-maker to determine how to handle the relationship, considering any other relevant factors, such as cooperation with law enforcement agencies or the FIU.
The financing of terrorism has similarities compared to money laundering, but it also has specificities that banks should consider, including: (i) funds that are used to finance terrorist activities may be derived either from criminal activity or from legal sources; and (ii) the nature of the funding sources may vary according to the type of terrorist organisation. In addition, transactions associated with the financing of terrorists may be conducted in very small amounts.
A bank should be able to identify and to enforce funds freezing decisions made by the competent authority. It should otherwise not deal with any designated entities or individuals (eg terrorists, terrorist organisations) consistent with relevant national legislation and UNSCRs.
CDD should help a bank to detect and identify potential FT transactions. In developing customer acceptance policies and procedures, a bank should appropriately consider the specific risks of entering into or continuing business with individuals or entities linked to terrorist groups, and ensure effective controls in place to mitigate risks of dealing in prohibited transactions. Before establishing a business relationship or carrying out an occasional transaction with new customers, a bank should screen customers against lists of known or suspected terrorists issued by competent (national and international) authorities. Likewise, ongoing monitoring should verify that existing customers are not added to these same lists.
All banks should have systems in place to detect prohibited transactions (eg transactions with entities designated by the relevant UNSCRs or national sanctions). Screening should be carried out irrespective of the risk profile attributed to the customer. For this purpose, a bank may adopt automatic screening systems, but it should ensure that such systems are fit for purpose. A bank should freeze, without delay and without prior notice, the funds or other assets of designated persons and entities, following applicable laws and regulations.
Where a bank operates in other jurisdictions, sound ML/FT risk management requires consideration of host country legal requirements. Each group should develop group-wide AML/CFT policies and procedures that are consistently applied and supervised across the group. Policies and procedures at the branch or subsidiary levels, even though reflecting local business considerations and the requirements of the host jurisdiction, must still be consistent with and supportive of the group’s broader policies and procedures. In cases where the host jurisdiction requirements are stricter than the group’s requirements, group policy should allow the relevant branch or subsidiary to adopt and implement the host jurisdiction’s local requirements.
Policies and procedures should be designed to identify, monitor and mitigate group-wide risks and not merely to comply strictly with all relevant laws and regulations. Every effort should be made to ensure that the group’s ability to obtain and review information in accordance with its global AML/CFT policies and procedures is not impaired due to modifications to local policies or procedures necessitated by local legal requirements. A bank should have robust information-sharing among the head office and all of its branches and subsidiaries. Where the minimum regulatory or legal requirements of the home and host jurisdictions differ, offices in host jurisdictions should apply the higher of the two standards to the extent that host country laws and regulations permit.
According to FATF Standards,13 if the host country does not permit the proper implementation of group standards, the financial group should apply additional measures and inform the home supervisor. If the additional measures are not sufficient, competent authorities in the home country should consider additional supervisory measures including, as appropriate, requesting that the group close its operations in the host country.
| 13 | See Interpretative Note to recommendation 18 (Internal controls and foreign branches and subsidiaries) in the FATF Standards. |
Implementing group-wide AML/CFT procedures is more challenging than many other risk management processes because some jurisdictions continue to restrict the ability of banks to transmit customer names and balances across national borders. For effective group-wide monitoring and for ML/FT risk management purposes, it is essential that banks be authorised to share information about their customers (subject to adequate legal protection) with their head offices or parent bank. This applies in the case of both branches and subsidiaries.
A bank should have a thorough understanding of all risks associated with its customers across the group, either individually or as a category, and should document and update these on a regular basis, proportionate to the level and nature of risk in the group. In assessing customer risk, a bank should identify all relevant risk factors such as geographical location and patterns of transaction activity (declared or self-stated) and usage of bank products and services. It should establish criteria for identifying higher-risk customers, which should be applied across the bank, its branches and subsidiaries, and through outsourced activities to identify customers that pose a higher risk of ML/FT. Customer risk assessments should be applied on a group-wide basis or at least be consistent with the group-wide risk assessment. Considering differences in risks associated with customer categories, group policy should recognise that customers in the same category may pose different risks in different jurisdictions. The information collected in the assessment process should be used to determine the level and nature of overall group risk and support the design of appropriate group controls to mitigate these risks. The mitigating factors can include additional information from the customer, tighter monitoring, more frequent updating of personal data and visits by bank staff to the customer’s location.
Banks’ compliance and internal audit staff, particularly the AML/CFT officer, or external auditors, should evaluate compliance with all aspects of their group’s policies and procedures, including:
Internationally active banking groups should ensure that they have a strong internal audit and a global compliance function since these are the primary mechanisms for monitoring the overall application of the bank’s global CDD and the effectiveness of its policies and procedures for sharing information within the group. This should include the responsibility of the AML/CFT officer for group-wide compliance with all relevant AML/CFT policies, procedures and controls nationally and abroad.
A bank should ensure it understands whether AML/CFT legislation allows it to rely on the procedures undertaken by other banks (for example within the same group) when business is being referred. A bank should not rely on introducers that are subject to standards that are less strict than those governing the bank’s own AML/CFT procedures. This requires banks to monitor and evaluate the AML/CFT standards in place in the jurisdiction of the referring bank. A bank may rely on an introducer that is part of the same group and could consider placing a higher level of reliance on the information provided by this introducer, provided they are subject to the same standards as the bank, and the application of these requirements is supervised at the group level. A bank adopting this approach should ensure that it obtains customer information from the referring bank, as this information may need to be reported to FIUs if a transaction involving the referred customer is determined to be suspicious.
Relevant information should be accessible by the banking group’s head office for the purpose of enforcing group AML/CFT policies and procedures. Each office of the banking group should be able to comply with minimum AML/CFT and accessibility policies and procedures applied by the head office.
Customer acceptance, CDD and record-keeping policies and procedures should be implemented through the consistent application of policies and procedures throughout the organisation, with adjustments as necessary to address variations in risk according to specific business lines or geographical areas of operation. Different approaches to information collection and retention may be necessary across jurisdictions to conform to local regulatory requirements or relative risk factors. However, these approaches should be consistent with the group-wide standards.
Regardless of its location, each office should establish and maintain effective monitoring policies and procedures that are appropriate to the risks present in the jurisdiction and in the bank. This local monitoring should be complemented by a robust process of information-sharing with the head office, and if appropriate with other branches and subsidiaries regarding accounts and activity that may represent heightened risk.
To effectively manage the ML and FT risks arising from such accounts, a bank should integrate this information based not only on the customer but also on its knowledge of both the beneficial owners of the customer and the funds involved. A bank should monitor significant customer relationships, balances and activity on a consolidated basis, regardless of whether the accounts are held on-balance sheet, off-balance sheet, as assets under management or on a fiduciary basis, and regardless of where they are held.14 While these guidelines have been developed primarily for banks, they might also be of interest for financial conglomerates.
| 14 | See also recommendation 18 in the FATF standards which sets out more details regarding banks’ head office oversight of group compliance, audit and/or AML/CFT functions. |
Where a bank implements centralised processing systems and databases, it should adequately document and integrate the local and centralised transaction/account monitoring functions to ensure that it has the ability to monitor for patterns of potential suspicious activity across the group and not just at either the local or centralised levels.
A bank conducting business domestically and abroad should appoint an AML/CFT officer for the whole group (group AML/CFT officer). The responsibilities of the group AML/CFT officer include:
Bank subsidiaries and branches should be required to proactively provide the head office with information concerning higher-risk customers and activities relevant to the global AML/CFT standards. They should respond to requests for account information from the head office or parent bank in a timely manner. The bank’s group-wide standards should include a description of the process to be followed in all locations for identifying, monitoring and investigating potential unusual circumstances and reporting suspicious activity.
The bank’s group-wide policies and procedures should consider issues and obligations related to local data protection and privacy laws and regulations. They should also consider the different types of information that may be shared within a group and the requirements for storage, retrieval, sharing/distribution and disposal of this information.
The group’s overall ML/FT risk management function should evaluate the potential risks posed by activity reported by its branches and subsidiaries and, where appropriate, assess the group-wide risks presented by a given customer or category of customers. It should have policies and procedures to ascertain if other branches or subsidiaries hold accounts for the same customer (including any related or affiliated parties).
The bank should also have policies and procedures governing global account relationships that are deemed higher-risk or have been associated with potentially suspicious activity These should include escalation procedures and guidance on restricting account activities, including the closing of accounts as appropriate.
A bank and its branches and subsidiaries should, in accordance with their respective domestic laws, be responsive to requests from law enforcement agencies, supervisory authorities or FIUs for information about customers that is needed to combat ML and FT. A bank’s head office should be able to require all branches and subsidiaries to search their files against specified lists or requests for individuals or organisations suspected of aiding and abetting ML and FT, and report matches.
A bank should be able to inform its supervisors, if so requested, about its global process for managing customer risks, its risk assessment and management of ML/FT risks, its consolidated AML/CFT policies and procedures, and its group-wide information-sharing arrangements.
The application of ML/FT risk management controls in mixed financial groups (ie those that also include securities and insurance businesses) poses additional issues that may not be present for deposit-taking and lending operations. Mixed groups should have the ability to monitor and share information on the identity of customers and their transaction and account activities across the entire group, and be alert to customers that use their services in different sectors.
Differences in the nature of activities and patterns of relationships between firms and customers in each sector may require or justify variations in the AML/CFT requirements imposed on each sector. The group should be alert to these differences when cross-selling products and services to customers from different business arms, and the appropriate AML/CFT requirements for the relevant sectors should be applied.
In line with FATF Recommendation 26, supervisors should apply the Core Principles for effective banking supervision to banks’ ML/FT risk management, including consolidated group supervision for AML/CFT purposes. Supervisors should be able to apply a range of effective, proportionate and dissuasive sanctions in cases when banks fail to comply with their AML/CFT requirements.
Banking supervisors are expected to set out supervisory expectations governing banks’ AML/CFT policies and procedures. National supervisors are encouraged to provide guidance to assist banks in designing their own customer identification policies and procedures. Examples of such guidance are set out under AFS10.88 to AFS10.146 below.
Supervisors should adopt a risk-based approach to supervising banks’ ML/FT risk management.15 Such an approach requires that supervisors:
| 15 | Supervisors should also consider the risk-based approach to supervision described in Interpretive Note 26 in the FATF Standards. |
| 16 | For this purpose, it is expected that supervisors would build on countries’ assessment as described in the Interpretative Note to Recommendation 1 in the FATF standards. |
| 17 | Including, where appropriate, any supranational risk assessment. |
Higher-risk lines of business or customer categories may require specialised expertise and additional procedures to ensure an effective review. The bank’s risk profile should also be used in determining the frequency and timing of the supervisory cycle. Banks with higher risk profiles may require more frequent review than others. Supervisors should also verify whether banks have adequately used their discretion to apply AML/CFT measures on a risk basis. They should also evaluate banks’ internal controls and how they determine compliance with supervisory and regulatory guidance, and prescribed obligations. The supervisory process should include not only a review of policies and procedures but also, when appropriate, a review of customer documentation and the sampling of accounts and transactions, internal reports and STRs. Supervisors should always have the right to access all documentation related to transactions conducted or accounts maintained in that jurisdiction, including any analysis the bank has made to detect unusual or suspicious transactions.
Supervisors should ensure that banks maintain sound ML/FT risk management to protect their own safety and soundness and to protect the integrity of the financial system.18 Supervisors should make it clear that they will take appropriate action (including public action where warranted) against banks and their officers who demonstrably fail to follow their own internal procedures and regulatory requirements. Supervisors (or other relevant national authorities) should be able to apply appropriate countermeasures and ensure that banks are aware of and apply enhanced CDD measures to business relationships and to transactions when called for by the FATF, or that involve jurisdictions where AML/CFT standards are considered inadequate. The FATF and some national authorities have identified several countries and jurisdictions that are considered to have strategic AML/CFT deficiencies or that do not comply with international AML/CFT standards,19 and such findings should be a component of a bank's ML/FT risk management.
| 18 | Many supervisors also have a duty to report any suspicious, unusual or illegal transactions that they detect, for example, during on-site examinations. |
| 19 | For instance, jurisdictions may be publicly identified by: (i) the FATF’s Public Statement, which identifies: (a) jurisdictions that have strategic AML/CFT deficiencies and to which countermeasures apply; and (b) jurisdictions with strategic AML/CFT deficiencies that have not made sufficient progress in addressing the deficiencies or have not committed to an action plan developed with the FATF to address the deficiencies; or (ii) the FATF public document, Jurisdictions under Increased Monitoring (13 June 2025), which identifies jurisdictions with strategic AML/CFT deficiencies that have provided a high-level political commitment to address the deficiencies through implementation of an action plan developed with the FATF. As of June 2025, FATF publishes high-risk jurisdictions subject to a call for action (ie "black list") and jurisdictions under increased monitoring (ie "grey list"). |
Supervisors should consider a bank’s overall monitoring and oversight of compliance at the branch and subsidiary level as well as the ability of group policy to accommodate local regulatory requirements and ensure that where there is a difference between the group and local requirements, the stricter of the two is applied. Supervisors should also ensure that in cases where a branch or subsidiary cannot apply the stricter of the two standards, the reasons for this and the differences between the two should be documented and appropriate mitigating measures implemented to address risks identified as a result of those differences.
In a cross-border context, home country supervisors20 should not be impeded in verifying a bank’s compliance with group-wide AML/CFT policies and procedures during on-site inspections. Inspections may require a review of customer files and a sampling of accounts or transactions in the host jurisdiction. Home country supervisors should have access to information on sampled individual customer accounts and transactions and on the specific domestic and international risks associated with such customers to the extent necessary to enable a proper evaluation of the application of CDD standards and an assessment of risk management practices. This use of information for a legitimate supervisory need, safeguarded by the confidentiality provisions applicable to supervisors, should not be impeded by local bank secrecy or data protection laws. Although the host country supervisors and/or other authorities retain responsibility for the enforcement of compliance with local AML/CFT requirements (which would include an evaluation of the appropriateness of the procedures), they should ensure they fully cooperate and assist home country supervisors who may need to assess how the bank oversees compliance with group-wide AML/CFT policies and processes.
| 20 | In those countries where the examination process is undertaken by external auditors, this exemption should also apply to the competent auditors. |
The role of group audit (external or internal) is particularly important in assessing the effectiveness of AML/CFT policies and procedures. Home country supervisors should ensure that there is an appropriate policy based on the risks, and adequate resources allocated regarding the scope and frequency of audit of the group’s AML/CFT. They should also ensure that auditors have full access to all relevant reports during the audit process.
Supervisors should ensure that information about banks’ customers and transactions is subject to the same confidentiality measures applicable to other information shared between supervisors on banks’ activities.
It is essential that all jurisdictions that host foreign banks provide an appropriate legal framework to facilitate the passage of information required for customer risk management purposes to the head office or parent bank and home country supervisors. There should be no impediments to on-site visits to host jurisdiction subsidiaries and branches by head office auditors, risk managers, compliance officers (including the AML/CFT officer and/or AML/CFT group officer), nor any restrictions on their ability to access all the host jurisdiction bank’s records, including customers’ names and balances. This access should be the same for both branches and subsidiaries. If impediments to information-sharing prove to be insurmountable, and there are no satisfactory alternative arrangements, the home supervisor should advise the host supervisor that the bank may be subject to additional supervisory actions. These could include enhanced supervisory measures on the group, or requesting the parent to close down its operations in the host jurisdiction.
Where a bank’s head office staff are granted access to information on local customers, there should be no restrictions on them reporting such information back to head office. Such information should be subject to adequate safeguards on confidentiality and use and may be subject to applicable privacy and privilege laws in the home country.
The Committee believes that there is no justifiable reason why local legislation should impede the transfer of customer information from a bank branch or subsidiary to its head office or parent bank in the home jurisdiction for risk management purposes, including ML and FT risks. If the law in the host jurisdiction restricts disclosure of such information to “third parties”, it is essential that the head office or parent bank and the home supervisor are clearly excluded from definitions of a third party. Jurisdictions that have legislation that impedes, or can be interpreted as impeding, such information-sharing for ML/FT risk management purposes, are urged to remove any such restrictions and to provide specific gateways appropriate for this purpose.
Prudential and AML/CFT supervisors should establish an effective cooperation mechanism regardless of the institutional setting,21 to ensure that ML/FT risks are adequately supervised in the domestic and cross-jurisdictional context for the benefit of the two functions.
| 21 | For further details, see Annex 5 of Sound management of risks related to money laundering and financing of terrorism: revisions to supervisory cooperation (July 2020). |
In some countries, banks are permitted to use other banks, financial institutions or other entities to perform CDD. These arrangements can take various forms but usually fall into one of the following two situations: (i) Reliance on third parties; and (ii) outsourcing/agent relationship.
Banks in some countries are allowed to rely on CDD performed by other financial institutions or designated non-financial businesses and professions who are themselves supervised or monitored for AML/CFT purposes.22 In these situations, the third party will usually have an existing business relationship with the customer, and the banks may be exempt from applying their own CDD measures at the beginning of the relationship. The FATF standards23 permit reliance for these aspects:
standards further require that a financial institution relying upon a third party should immediately obtain the necessary information concerning these three CDD measures. FATF standards further require that a financial institution relying upon a third party should immediately obtain the necessary information concerning these three CDD measures.
Some countries restrict the ability to rely on third parties in various ways. For example, limiting reliance to financial institutions, allowing reliance only for third parties’ existing relationships (and prohibiting chains of reliance) or not allowing reliance on foreign entities.
Banks should have clear policies and procedures on whether and when it is acceptable and prudent to rely on a third party. Such reliance in no way relieves the bank of its ultimate responsibility for having adequate CDD policies and procedures and other AML/CFT requirements on customers, such as understanding expected activity, whether customers are high-risk, and whether transactions are suspicious.
In relying on another bank or financial institution to conduct certain aspects of CDD, banks should assess the reasonableness of such reliance. In addition to ensuring this is legally permissible, relevant criteria for assessing reliance include:
Banks with subsidiaries or branches outside their home jurisdiction frequently use the group to introduce their customers to other parts of the group. In countries that permit a cross-border reliance on affiliates, banks that rely on other parts of the group for customer identification should ensure that the above assessment criteria are in place. The FATF standards allow countries to exempt country risk from this assessment if the financial institution is subject to group-wide AML/CFT standards and supervised on a group level by its financial supervisor.
Banks may also use third parties to perform various elements of their CDD obligations on a contractual basis, often in an outsourcing/agent relationship (ie the outsourced entity applies the CDD measures on behalf of the delegating bank). Typically, there are fewer restrictions on who can act as the agent of a bank, but this is often offset by prescribed arrangements and record-keeping.
For both reliance and outsourcing, banks may choose to limit the size, scope or nature of transaction types when utilising third parties. In all cases, supervisors should have timely access to customer information upon request. Although these two categories seem similar or related, there are significant differences between them and banks should ensure they understand those differences and reflect these in their policies and procedures.
Banks may choose to apply identification and other CDD processes directly or can appoint one or more third parties to take these measures on their behalf, sometimes in an agent relationship. While AML/CFT compliance functions may be performed by third parties, the responsibility for complying with CDD and AML/CFT requirements remains with the bank. The extent of the use of third parties usually depends on the business model of the bank.
Banks that choose to use third parties should ensure that a written agreement is in place that sets out the AML/CFT obligations of the bank and how these will be executed by the third party. In some countries, the relationship between banks and their third parties is regulated.
It is important for banks to understand the difference between using a third party as its agent and relying on another bank’s customer identification and CDD processes. Under the law of agency, an agent is usually a legal extension of the bank. When a bank’s, customer or potential customer, deals with an agent of a bank, the same consequences are produced as when it is legally dealing with the bank itself. The third party will therefore be obligated to apply the bank’s policies and requirements with respect to identification and verification and CDD.
In practice, banks’ third parties need to have the necessary technical expertise, knowledge and training to apply the customer identification and CDD measures of the bank. In some cases, where third parties’ business models are based on acting for several banks, they usually develop significant in-house expertise of their own. Third parties are not always themselves subject to AML/CFT obligations, although many often are.
Examples of third parties routinely used by banks to apply their customer identification obligations include retail deposit brokers, mortgage brokers and solicitors. ML/FT risk mitigation can be compromised when banks do not ensure that applicable customer identification requirements and CDD are applied by their third parties.
The written agreement between the bank and third party should include at a minimum:
Banks should also:
The bank should obtain all relevant information from the third party in a timely manner and ensure the information is complete and kept up to date in the bank’s customer record.
Contracts with third parties should be reviewed and updated as necessary to ensure that they continue to address the third parties’ role accurately and reflect any updates to duties.
This section focuses on higher-risk correspondent banking relationships, in particular cross border correspondent banking involving the execution of third-party payments. In line with FATF Recommendation 13, cross-border correspondent relationships (as opposed to domestic relationships) are the ones that should prompt additional customer due diligence measures.
Correspondent banking services enable respondent banks to conduct business and provide services that they cannot offer otherwise (owing to the lack of an international presence and cross-border payment systems).24
| 24 | Such as “cash management (eg interest-bearing accounts in a variety of currencies), international wire transfers, cheque clearing, payable-through accounts and foreign exchange services”. |
Correspondent banks that execute and/or process transactions for customers of respondent banks generally do not have direct business relationships with these customers, which may be individuals, corporations or financial services firms, established in jurisdictions other than that of the correspondent bank. As the customers of the correspondent bank are the respondent banks, correspondent banks must conduct appropriate due diligence on the respondent banks but are not generally required to do so on the respondent banks’ customers.25
| 25 | See FATF, Guidance on correspondent banking services, October 2016, paragraph 3. |
Because of the structure of this activity and the limited information available regarding the nature or purpose of the underlying transactions, correspondent banks may be exposed to ML/FT risks.
Respondent banks are responsible for conducting due diligence on their customers using correspondent banking services. This section addresses both correspondent banks that provide the services and respondent banks that use the services.
If the respondent bank is an affiliate of the correspondent bank, the AML/CFT policies and procedures applicable at the consolidated group level apply to the respondent bank.
The FATF guidance on correspondent banking services clarifies that, while additional CDD measures are required for cross-border correspondent banking, not all such correspondent banking services carry the same level of ML/FT risks.26
| 26 | See FATF, Guidance on Correspondent Banking Services (FATF Correspondent Banking Guidance), October 2016, paragraph 13a. |
Banks that undertake correspondent banking activities should assess the ML/FT risks associated with the relationship.
Risk indicators that correspondent banks should consider in their risk assessment include:
| 27 | The correspondent bank should have a broad knowledge of the products and services offered and types of customers served by the respondent bank (see FATF guidance, recommendation 22). |
| 28 | The ability to obtain this information may depend on legal or technical permissibility. |
| 29 | The LEI system may be used for this purpose provided that the group’s ultimate accounting consolidating parent and all group entities in the accounting consolidation perimeter and eligible branches have an LEI, and that the ultimate parent relationship is reported for all subsidiaries. In addition, the relevant LEI should have an “issued” status (for active entities), which means that the associated reference data are kept current under the conditions required by the LEI System. |
| 30 | See paragraph 25 of the FATF Guidance on Correspondent Banking Services. |
Correspondent banks should take a holistic view of these indicators and other available information, to first determine the inherent risk of each respondent bank relationship, and then to consider risk mitigation factors to determine the residual risk and whether it can manage this residual risk level (see FATF Correspondent Banking Guidance). In general, factors that could reduce ML/FT risks would include the effectiveness of the respondent bank’s risk management policies and procedures as well as the specific measures put in place by the correspondent bank.
In some instances, inherently higher-risk relationships, products or services may be mitigated by strong risk management practices and other factual circumstances, resulting in adequately manageable residual risk. For example, a correspondent banking relationship with a foreign respondent bank located in a higher-risk foreign jurisdiction could pose an inherently higher risk that may be mitigated in part by effective group-wide AML/CFT controls in place in both the correspondent and respondent banks. Correspondent banks can also manage their risk by adapting their product offering or limiting the volume of activity with a particular respondent.
Nested, or downstream, correspondent banking refers to the use of a bank’s correspondent relationship by several respondent banks through their relationships with the bank’s direct respondent bank to conduct transactions and obtain access to other financial services.
Downstream correspondent banking relationships are an integral and generally legitimate part of correspondent banking. Nesting may be a way for regional banks to help small local banks within the respondent’s region obtain access to the international financial system or to facilitate transactions where no direct relationship exists between banks.
Providing access to third-party foreign financial institutions that are not the customer of the correspondent bank, and so not necessarily known, can obscure financial transparency and increase ML/FT risks. As a result, correspondent banks should require that respondent banks disclose whether accounts include nested relationships31 as part of account opening and ongoing risk profile reviews. Respondent banks should disclose accurate information regarding the existence of nested relationships.
| 31 | This does not require that a list of the nested relationships should be produced. |
Correspondent banks should assess the ML/TF risk associated with customers which are respondent banks with nested relationships on an individual case by case basis, consistent with the risk-based approach. The level of risk may vary depending on the nature of nested foreign financial institutions served by respondent banks, including size and geographical location, products and services offered, markets and customers served, and the degree of transparency provided by the respondent bank (eg in formatting payment transactions).
To assess the ML/FT risks associated with a nested relationship, correspondent banks should understand the purpose of the nested relationship. To this end, they may consider the following factors, among others:
Before entering into a business relationship with a respondent bank, correspondent banks should gather sufficient information to understand the nature of the respondent’s business and assess ML/FT risks both at the outset and on an ongoing basis. There is no requirement or expectation for a correspondent bank to apply CDD measures to customers of the respondent bank or to duplicate the data on its customers obtained and stored by the respondent bank.
Information on a respondent bank’s AML/CFT policies and procedures may be obtained from the respondent bank, for example via a questionnaire, or from publicly available information (such as financial information or any mandatory supervisory information relating to the respondent bank). An industry-wide questionnaire may be useful, provided it is used as a starting point for the risk assessment. The correspondent bank should verify the identity of the respondent bank using reliable, independent source documents, data or information; take measures to verify other CDD information on the respondent bank obtained on a risk-sensitive basis; and identify any beneficial owners.
At account opening, banks may collect – and subsequently update – respondent banks’ information by using third-party databases that contain relevant information on banks (often referred to as “KYC utilities”). KYC utilities may provide efficiency gains for both correspondent and respondent banks to gather and provide information. For the correspondent bank, using a KYC utility could be useful for gathering information on the respondent bank, especially to assess the risk indicators. In principle, supervisors should not object to banks’ use of utilities in correspondent banking risk assessment processes, provided final responsibility for CDD remains with the correspondent bank.
Banks should also consider gathering information from public sources. These may include the website of the supervisory authority of the respondent bank, for cross-checking identification data with the information obtained by the supervisor in the licensing process, or with regard to potential AML/CFT administrative sanctions that have been imposed on the respondent bank. This may also include public registries (see FATF guidance on correspondent banking services, paragraph 25.
In assessing whether to enter into a correspondent banking relationship, the correspondent bank should also consider relevant information on the jurisdiction in which the respondent operates, for example from international bodies or other sources. Where deficiencies are identified in certain jurisdictions, correspondent banks should also consider the corrective measures under way to strengthen the jurisdiction’s AML/CFT controls, as well as efforts by domestic authorities to instruct respondent banks on how to strengthen their controls and mitigate ML/FT risks. This is relevant especially where a correspondent bank is considering whether an existing correspondent banking relationship could be subject to additional monitoring or restrictions, rather than termination.
All correspondent banking relationships should be subject to an appropriate level of due diligence following a risk-based approach. The level of due diligence should be proportionate to the respondent bank’s risk profile. Banks should not treat the CDD process as a “paper-gathering exercise” but as an essential step to support assessment of ML/FT risk. This involves the correspondent bank assessing the respondent bank’s AML/CFT controls on a risk-sensitive basis (for example, receiving a description of the respondent bank’s AML/CFT procedures and systems, including sanctions screening, checking if the internal audit function regularly reviews the adequacy of the respondent bank’s AML/CFT controls). Based on the correspondent bank’s own risk assessment, the information-gathering should be complemented by liaising directly with the respondent bank’s local management and compliance officer, or potentially by an on-site visit. Policies and procedures should be proportionate to the risks identified, ensuring effective mitigation while avoiding unnecessary barriers to financial services.
CDD information should also be reviewed and updated regularly, in accordance with the risk-based approach. Updates could be based on changes to risks associated with the respondent relationship. This information should be used to update the bank’s risk assessment process. This approach should ensure effective mitigation while promoting financial inclusion and explicitly discouraging unnecessary de-risking or over-compliance.
The decision to enter into a correspondent banking relationship with a respondent bank should be approved by the senior management of the correspondent bank. When significant ML/FT risk factors emerge in an existing correspondent banking relationship, the correspondent bank should review the relationship. Following the review, the decision to continue the relationship with additional risk mitigation measures or to terminate it should be escalated to senior management.
Correspondent banks must not enter into or continue correspondent banking relationships with “shell” banks. Correspondent banks should not enter into correspondent banking relationships if they are not satisfied, based on the information gathered or received, that the respondent bank is not a shell bank.
Correspondent banks should establish appropriate policies, procedures and systems to detect financial activity that is not consistent with the purpose of the services provided to respondent banks or any financial activity that is contrary to commitments that may have been concluded between the correspondent bank and the respondent bank. The level of ongoing monitoring should be proportionate to respondent banks’ risk profiles.
Respondent banks should ensure that full and accurate originator and beneficiary information is included in payment messages sent to correspondent banks in accordance with FATF Recommendation 16 to enable correspondent banks to screen sanctions and monitor transactions.
If a correspondent bank decides to allow correspondent accounts to be used directly by third parties to transact business on their own behalf (payable-through accounts), it should conduct enhanced monitoring of these activities in line with the specific risks assessed. The correspondent bank should satisfy itself that the respondent bank has conducted adequate CDD on the customers with direct access to correspondent accounts and that the respondent bank can provide relevant CDD information upon request.
As part of ongoing monitoring, if there are doubts after analysing unusual activity alerts generated by the monitoring process, the correspondent bank could issue a Request for Information on that particular transaction to the respondent bank.
Before considering withdrawing from a correspondent banking relationship, the correspondent bank may consider additional measures such as limiting the services provided, real-time monitoring, sample testing of transactions or on-site visits.
Senior management should be regularly informed of high-risk correspondent banking relationships and how they are monitored, particularly where risks are considered very high.
Originating banks are responsible for using the right format for payment messages. They should require that information on the originator and beneficiary accompanies wire transfers, while others in the payment chain are required to monitor the payments they process based on this information. The Committee encourages all banks to apply high transparency standards, in full compliance with FATF Recommendation 16, and applicable national laws and regulations.
The quality of information provided in payment messages should be part of ongoing monitoring. The correspondent bank as an intermediary should monitor the payment messages transmitted by the respondent bank for the purpose of detecting those which lack required originator and/or beneficiary information, including meaningless fields,32 and straight through processing, and verify the reliability of the respondent’s controls, for instance via sample testing (ie a closer look at a few transactions to identify cases where they do not comply with the wire transfer information requirements).
| 32 | That is, information that makes no obvious sense, such as “one of my customers” or a pure string of characters. |
Sample testing may also help the correspondent bank to adjust the level and type of monitoring, including the timing of ex post reviews.
The respondent bank, acting as the ordering financial institution, remains responsible for performing customer due diligence on the originator and must verify originator information for accuracy and maintain this information in accordance with local regulatory requirements.
The use of the LEI as additional information in payment messages is one of the identifiers mandated by FATF Recommendation 16 for originators and beneficiaries that are legal entities (and is supported in ISO 20022 payment messages). Where available, the use of the LEI would facilitate the determination by the correspondent bank that the information in the message is sufficient to unambiguously identify the originator and beneficiary of a transfer.
If a respondent bank has correspondent banking relationships with several entities belonging to the same group, the head office of the group should ensure that the assessments of the risks by the different entities of the group are consistent with the group-wide risk assessment policy. The group’s head office should coordinate the monitoring of the relationship with the respondent bank, particularly for a high-risk relationship, and ensure that adequate information-sharing mechanisms inside the group are in place.
If a correspondent bank has business relationships with several entities belonging to the same group but established in different host countries, the correspondent bank should consider the fact that these entities belong to the same group. Nevertheless, the correspondent bank should also independently assess the ML/FT risks presented by each business relationship.
Banks should establish specific procedures to manage correspondent banking relationships. Business relationships should be formalised in written agreements that clearly define the roles and responsibilities of the banking partners.
As part of their risk management procedures, correspondent banks should include notice periods for terminating or limiting business relationships in the terms and conditions governing the correspondent banking relationship. From the respondent bank’s perspective, such notice periods should inform banks’ business continuity plans.33 As part of contingency planning for critical functions, a respondent bank may consider having more than one correspondent banking account for its payment services, where necessary for its continued operation.
Senior management should also be aware of the roles and responsibilities of the different services within the bank (eg business lines, compliance officers (including the chief or group AML/CFT officer), audit) pertaining to correspondent banking activities.
A bank’s internal audit and compliance functions34 have important responsibilities in evaluating and ensuring compliance with procedures related to correspondent banking activities. Internal controls should cover identification measures of the respondent banks, the collection of information, the ML/FT risk assessment process, ongoing monitoring of correspondent banking relationships and compliance with the duties to detect and report suspicions (about respondents and/or possible underlying subjects involved in the transactions).
This module describes expectations to combat money laundering and terrorist financing.
This module describes expectations and practices relating to capital adequacy.
This module describes expectations for corporate governance.
This module describes expectations for credit risk and counterparty credit risk management.
This module describes expectations for external audit and sets out references related to public disclosure.
This module describes expectations for banks’ internal audit and compliance functions.
This module describes expectations for liquidity risk management.
This module sets out references related to market risk and interest rate risk.
This module describes expectations for the management of operational risk and operational resilience.
This module describes expectations for the management of problem assets and expected credit losses.
This module describes the application of proportionality in prudential regulation and supervision.
This module describes expectations for risk management.
This module describes the nature and application of prudential supervision.