Building and maintaining a risk based KYC/Due Diligence Program Wednesday, November 2 13:00PM 16:00PM



Similar documents
How small banks manage money laundering and sanctions risk

Policy on Prevention of Money Laundering and Terrorist Financing ABH Holding S.A.

The proposed Fourth Money Laundering Directive

Client Update Fourth Anti-Money Laundering Directive Comes Into Force

Public Consultation on Member State discretions

Wolfsberg Anti-Money Laundering Principles for Correspondent Banking

FINANCIAL SERVICES FLASH REPORT

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved.

The Wolfsberg Group Anti-Money Laundering Questionnaire. Financial Institution Name. 8 Canada Square, London E14 5HQ

Anti-Money Laundering and Counter- Terrorism Financial Policy

Managing bribery and corruption risk in commercial insurance broking

LexisNexis UK Anti-Money Laundering (AML) White paper

NOTICE TO BANKS MONETARY AUTHORITY OF SINGAPORE ACT, CAP. 186 PREVENTION OF MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM - BANKS

Financial crime: a guide for firms Part 1: A firm s guide to preventing financial crime

TEMPLATE FOR REFERENCE ONLY

Anti-money laundering and countering the financing of terrorism the Reserve Bank s supervisory approach

Insurance Europe Position Paper on the proposal for the fourth AML Directive. Our reference: LIF-AML Date: 14 May 2013

FSA reports on how banks deal with high-risk customers, correspondent banking relationships and wire transfers

Banks management of high money-laundering risk situations

Review of banks anti-money laundering systems and controls

Report on Anti-Money Laundering/Countering the Financing of Terrorism and Financial Sanctions Compliance in the Life Insurance Sector in Ireland

Wolfsberg Frequently Asked Questions ( FAQs ) on Politically Exposed Persons ( PEPs )

DEVELOPING AN AML (ANTI-MONEY LAUNDERING) PROGRAM:

HIGH-RISK COUNTRIES IN AML MONITORING

Anti-money laundering guidance for trust or company service providers

IDENTITY MONITORING: KEEPING A FINGER ON THE PULSE OF CLIENT IDENTITY CHANGES

ANTI-MONEY LAUNDERING AND COUNTER-TERRORISM FINANCING (AML AND CTF) PROGRAM PART A

It s a Regulatory Requirement But does it help and what does this really mean?

GUIDANCE. for. Sole Practitioner Accountants, Accounting Firms and Sole Practitioner Auditors, Auditing Firms

APCC London Regional Forum. Monday, 16 th June 2014

Svenska Handelsbanken AB FI Ref through Chair of Board Service no. 1. Finansinspektionen's decision (to be issued on 19 May 2015 at 08.

PREVENTION OF MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM - BANKS

On the prevention of the use of the financial system for the purpose of money laundering and terrorist financing PART II

In accordance with Article 14(5) of the Rules of Procedure of the Board of Supervisors, 2 the Board of Supervisors has adopted this Opinion.

Financial Services Authority. Review of firms implementation of a risk-based approach to anti-money laundering (AML)

GUIDANCE NOTE FOR DEPOSIT-TAKERS. Operational Risk Management. March 2012

Non Financial Anti Money Laundering/Anti Terrorist Financing (AML/CFT) Regulations

Bank Secrecy Act Anti-Money Laundering Examination Manual

Anti-Money Laundering and Anti-Bribery and Corruption Systems and Controls: Asset Management and Platform Firms

Financial Services Regulatory Commission Antigua and Barbuda Division of Gaming Customer Due Diligence Guidelines for

BANK EXAMINERS MANUAL FOR AML/CFT RBS EXAMINATION

INTERNATIONAL CORRESPONDENT BANKS. Knowing Your Customer (KYC) Anti-Money Laundering Prevention of Terrorist Financing

Report on Anti-Money Laundering/Countering the Financing of Terrorism and Financial Sanctions Compliance in the Irish Banking Sector

Know Your Customer (KYC), Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD)

You Can t Afford the Risks

Risk Factors for OFAC Compliance in the Securities Industry

CORRUPTION. A Reference Guide and Information Note. to support the fight against Corruption. Safeguarding public sector integrity

Nevada Registered Agents Association

Basel Committee on Banking Supervision. Consultative Document. Sound management of risks related to money laundering and financing of terrorism

Independent AML Testing of Introducing Broker- Dealers

Wolfsberg Anti-Money Laundering Principles for Private Banking (2012)

10 Shenton Way MAS Building Singapore Telephone: (65) Facsimile: (65)

2: Credit cards, etc. Overview of the sector

AML & CFT Innovations to Mitigate Risks Lessons from the e-money

INTERNATIONAL CORRESPONDENT BANKING

Briefing Seminar on the New Guidelines on Anti-Money Laundering and Counter- Terrorist Financing (AML/CFT)

Module 4: The Risk-based Approach to AML/CTF

low levels of compliance with the regulations and POCA by negligent HVD operators are enabling criminals to launder the proceeds of crime

The 2006 FFIEC Bank Secrecy Act/Anti-Money Laundering Examination Manual:

AML & Mortgage Fraud Compliance Program v ANTI-MONEY LAUNDERING & MORTGAGE FRAUD COMPLIANCE PROGRAM

Risk Based Approach putting it into practice

Financial Intelligence Centre Guidance Note 3A Guidance for accountable institutions on client identification and verification and related matters

Anti-Money Laundering and Countering Financing of Terrorism (AML/CFT) Guide for small financial adviser businesses

ACCOUNTANTS AND TAX ADVISORS

How To Manage Risk At Atb Financial

FINAL NOTICE. (1) imposes on Bank of Beirut (UK) Ltd ( Bank of Beirut ) a financial penalty of 2,100,000; and

CAIXA GERAL DE DEPÓSITOS, SA

Wolfsberg Statement Guidance on a Risk Based Approach for Managing Money Laundering Risks

Basel Committee on Banking Supervision. Consolidated KYC Risk Management

TECHNICAL PAPER: Guidance on risk-based supervision and risk assessments Prepared by Council of Europe Expert Ms Maud Bokkerink

AML Rule Tuning: Applying Statistical and Risk-Based Approach to Achieve Higher Alert Efficiency

SFC AML/CFT Seminar Governance, PEPs & Transaction Monitoring. Philip Rodd

Wolfsberg Statement on AML Screening, Monitoring and Searching (2009)

Module 4. Risk assessment for your AML/CTF program

Financial services firms approach to UK financial sanctions. Financial Services Authority

KNOW YOUR THIRD PARTY

Guideline on Anti-Money Laundering and Counter- Terrorist Financing. (For Authorized Institutions)

(unofficial English translation)

Background. FIN-2010-G001 Issued: March 5, 2010 Subject: Guidance on Obtaining and Retaining Beneficial Ownership Information

Product. AML Risk Manager for Life Insurance Complete End-to-End AML Coverage for Life Insurance

INTEGRITY DUE DILIGENCE GUIDELINES FOR LENDING TRANSACTIONS

Validating Third Party Software Erica M. Torres, CRCM

Navigate the regulatory maze

The compliance challenge

AUSTRAC. supervision strategy

Wolfsberg Statement Guidance on a Risk Based Approach for Managing Money Laundering Risks

FinCEN Issues Notice of Proposed Rulemaking that Would Extend AML Requirements to Registered Investment Advisers

PROFESSIONAL ACCOUNTANTS TO STRENGTHEN MEASURES AGAINST MONEY LAUNDERING AND FINANCING OF TERRORISM

Basel Committee on Banking Supervision

Customer Due Diligence/ Know Your Customer (CDD/ KYC) Policy

A Critical Need: The Importance of AML Compliance for Broker-Dealers

RESPONSE TO FEEDBACK RECEIVED CONSULTATION ON ANTI- MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM (AML/CFT) NOTICES AND GUIDELINES

THOMSON REUTERS ACCELUS

Regulatory Compliance Management (RCM) (formerly Legislative Compliance Management (LCM))

8 Guiding Principles for Anti-Money Laundering Polciies and Procedures in

ANTI-MONEY LAUNDERING POLICY AND GUIDANCE NOTES

GUIDANCE FOR A RISK-BASED APPROACH THE BANKING SECTOR

Appendix 1. In this appendix as all the text is new it is not underlined or struck through in the usual manner.

Transcription:

Building and maintaining a risk based KYC/Due Diligence Program Wednesday, November 2 13:00PM 16:00PM George Pearson Associate Director Deloitte & Touche

Workshop Outcomes Elements of a robust risk based KYC/DD program Review best practises to obtain beneficial ownership information, especially when a new account is opened Understand what to do with the information you obtain Assess monitoring and/or risk rating strategies to employ in your programme

Workshop Structure Group discussion Presentations from facilitators Facilitated discussion regarding topics of interest Sharing information regarding best practices developed within industries Mid workshop break

INTRODUCTION TO A RISK BASED APPROACH? Identifying and assessing the money laundering risk of your institution Implementing systems and controls to adequately manage and mitigate the risk Resources are deployed where the greatest risk lies The approach will vary according to the nature of the risks and products sold It requires pro active effort to continuously review the risks and revise mitigation strategies where necessary It is not designed to prohibit financial transactions, but to manage money laundering risks. 4

IS THIS A NEW CONCEPT? It is not an entirely new concept! Institutions have been managing risk for decades Basel II AML has brought a new class of risk with potentially damaging effects The risk of your institution being used for money laundering The risk of your institution not complying with AML regulations Risks can be reviewed using current structures with expert AML advice It should be an ongoing exercise and not a once off assessment 5

BENEFITS More effective risk management Longer term cost savings Focussed on actual threats Flexibility to adapt to changes CHALLENGES Identifying the correct information with which to conduct a risk assessment Short term Costs More expert employees required who are able to make judgement calls Regulatory response to approach 6

GUIDANCE TO FOLLOWING A RISK BASED KYC/DD APPROACH? Guidance from the Financial Action Task Force (FATF) Guidance from the Joint Money Laundering Steering Group (JMLSG) Financial Intelligence Centre Guidance Note Concerning the Identification of Clients Guidance from other regulators and international bodies Best practice followed by industry peers 7

SENIOR MANAGEMENT BUY IN AND APPROVAL Senior management who is ultimately responsible for risk management must know and understand What the money laundering risk is What the need is for regulations and subsequent compliance Approve documented policies and procedures Understand the working of the risk based approach Understand the risk posed by higher risk customers in relation to the business incentive of dealing with such clients Appoint the MLRO to ensure the policies and procedures are enforced 8

CLEARLY DOCUMENTED AML AND CDD POLICIES & PROCEDURES The golden rule is to document, document, document... If you are going to follow a risk based approach it needs to be documented in your group policy as proof to the regulator or supervisor The risk based KYC/DD process will form part of the larger risk based program Clear definition of a PEP Working methods to identify high risk clients The policy must be accessible to employees Overall it should show the institutions risk assessment procedures and risk appetite Clearly indicates that risk assessments are an ongoing exercise 9

CDD FOR NEW HIGH RISK CLIENTS Conduct enhanced due diligence on high risks Establish governance processes for client acceptance Use commercially available databases Supplement due diligence with searches on public domain websites Sufficient independence from AML/MLRO to challenge client on boarding Face to face meetings with potential client before on boarding Steer clear from the client known to me syndrome Obtain independent intelligence 10

Customer Due Diligence A Risk Based Approach Dr Tony Wicks Director of AML Solutions NICE Actimize tony.wicks@actimize.com 11

PLEASE NOTE that, to the extent that Actimize provides, in this presentation or otherwise, information or recommendations regarding any laws, regulations, or statutes, such information or recommendations do not constitute legal advice. Compliance with such laws, regulations or statutes remains the full and sole responsibility of the party to whom such laws, regulations or statutes relate. 12

Purpose of the Section Discuss international standards and industry best practices regarding Customer Due Diligence (CDD) Discuss common problems associated with implementing a CDD programme and a risk based approach 13

Customer Due Diligence Guidance & Legislation 14

Customer Due Diligence Financial Action Task Force (FATF) 40 + 9 FATF 40 key recommendations: 7 & 18 Key recommendations for commercial & correspondent banks: 5,6,7 & 8 http://www.fatf-gafi.org/ 3rd EU Money Laundering Directive Directive 2005/60/EC of the European Parliament and of the Council of 26 October 2005 Specific requirements in relation to customer due diligence http://eur-lex.europa.eu/lexuriserv/site/en/oj/2005/l_309/l_30920051125en00150036.pdf 15

Customer Due Diligence Basel Committee - Bank for International Settlements Customer due diligence for banks Considers KYC for client on-boarding http://www.bis.org/publ/bcbs85.htm FinCEN Code of Federal Regulations Title 31 Chapter X Money and Finance: Treasury Title 31 CFR 1010.220 Customer Identification Title 31 CFR 1010.610 Correspondent Banking Title 31 CFR 1010.620 Private banking http://www.fincen.gov/statutes_regs/chapterx/ 16

Customer Due Diligence South Africa - Prescribed by Section 21 FICA and FIC Guidance General Guidance Note Concerning Identification of Clients Does not mandate a one-size fits all approach Provides risk scoring matrix Risk Classes: Client attributes Nature of Product Source of funds Client conduct Country classification 17

JMLSG Guidance Typical constituents of risk: Customer, product and activity profiles Distribution channels Complexity, value and volume of transactions Jurisdiction(s) of business operation Processes and systems 18

Customer Due Diligence Example Risks 19

Examples of Risk Scenarios Economic rationale for business Business with Politically Exposed Persons Customers based in, or conducting business in or through, a high risk jurisdiction Customers engaged in a business which involves significant amounts of cash, or which are associated with higher levels of corruption Introduced business Risk posed by the products/services Non face-to-face business (depending on the circumstances) 20

Business Banking Large corporates (domestic and international) International (inc FX and Trade Finance) Treasury and investments Retail deposits Corporate advice Payments Relationship managed individual corporate by corporate basis Smaller businesses (predominately domestic) Current account International Volume business 21

Business Banking Risk Scenarios: High cash turnover businesses Money service businesses Computer/high technology/telecom/mobile phone sales and distribution Companies registered in one offshore jurisdiction as a non-resident company with no local operations but managed out of another, or where beneficial owners resident in a high risk jurisdiction Unregistered charities based or headquartered outside the country, foundations, cultural associations and similar organisations 22

Customer Due Diligence Implementation Requirements 23

CDD Basic Requirements At account opening and on an ongoing basis: Identify the customer and wider business relationships Understand the economic rationale for the business and the anticipated behavioral characteristics Risk assess the customer in relation to their presented characteristics and products & services 24

CDD Basic Requirements May also need to perform Enhanced Due Diligence for: Private banking High risk customers Non-face-to-face business Politically exposed persons 25

CDD Basic Requirements Simplified Due Diligence can be applied: Financial institutions Supervised firms subject to AML & CTF requirements Public companies that are subject to regulatory disclosure requirements Listed firms Government administrations or enterprises Customers using other low risk products 26

Corporate Banking - Basic CDD At account opening and on an ongoing basis: Verify the identify the customer (corporate) Entity Beneficial ownership Controllers/directors Understand the economic rationale for the business Understand expected account usage Risk assess the business relationship in relation to their presented characteristics and products & services 27

Corporate Banking EDD When do we apply EDD: When the applicant is a PEP or has material linkage to a PEP When there is no face-to-face contact with the applicant When the business of the customer is considered to present a higher risk of money laundering or terrorist financing Correspondent banking 28

Corporate Banking EDD Additional requirements: Deeper understanding of customer Source of business wealth over longer term Nature of individual transactions Reputational checks If PEP linkage further assessment of risk Deeper assessment of beneficial ownership Higher level management approval and oversight of business relationship More sophisticated account monitoring or greater human scrutiny 29

Common Problems 1. Different needs in high volume corporate and individually tailored deals 2. Economic rationale can we take this as given for simple products such as current / checking accounts? 3. Assessment of risk? 4. How far do we have to dig for EDD? 5. Aggregation of relationships across the bank 6. Establishing effective corporate monitoring systems 30

UK FSA Guidance Review published June 2011 35 institutions considered as part of review Focus on: Wire Transfers Correspondent Banking High Risk Customers and PEPS AML Policies & procedures Risk assessment Customer take-on Enhanced monitoring of high-risk relationships Link: http://www.fsa.gov.uk/pubs/other/aml_final_report.pdf 31

UK FSA Guidance Key Findings in relation to CDD: 1/2 of banks visited failed to apply meaningful EDD 1/3 failed to adequately identify PEPs 3/4 failed to adequately determine source of wealth Inadequate safeguards to mitigate RMs conflicts 1/3 inadequately managed due diligence records 1/2 failed to perform on-going review of high-risk 32

Q&A 33

RISK ASSESSMENT The client risk assessment will help identify high risk CDD situations Use robust models to undertake assessments which take into account a variety of risk factors Use reliable risk information Use weighted scores for determining eventual risk Dynamic and ongoing Do NOT alter risk scores in order to circumvent EDD responsibilities 34

Building and Maintaining a Risk- Based KYC/Due Diligence Program Wednesday 2 November 2011 13:00 16:00 Kevin West Director/Partner KPMG Services (Pty) Ltd 35

Developments in the RBA FATF issued its GUIDANCE ON THE RISK-BASED APPROACH TO COMBATING MONEY LAUNDERING AND TERRORIST FINANCING in June 2007 3 rd EU Directive - identify and verify the identity of their customers and/or their beneficial owners and to monitor transactions with their customers, while taking into account a risk-based approach FICA Guidance Note 3 (GN 715 of 18 July 2005): Guidance for banks on customer identification and verification and related matters. It is imperative that money laundering risk in any given circumstance be determined on a holistic basis. In other words, the ultimate risk rating accorded to a particular business relationship or transaction must be a function of all factors that may be relevant to the combination of particular client profile, product type and transaction. 36

What does RBA mean? Using a risk-based approach to discharge certain anti-money laundering (AML) and counter-terrorist financing (CFT) obligations. Measures to prevent or mitigate money laundering and terrorist financing are commensurate to the risks identified. This process encompasses recognising the existence of the risk(s), determining the risk appetite of the bank, undertaking an assessment of the risk(s) and developing strategies to manage and mitigate the identified risks. Proportionate procedures should be designed based on assessed risk (EDD). 37

Implementing a Risk-Based Approach There are no universally accepted methodologies that prescribe the nature and extent of a risk-based approach or framework. Application of a well-reasoned and documented risk-based approach is vital in managing potential money laundering and terrorist financing risks and allowing financial institutions to exercise reasonable business judgement with respect to their customers. In order to implement a reasonable risk-based approach, financial institutions should identify the criteria to assess potential money laundering and terrorist financing risks. 38

Implementing a Risk Based Approach The process encompasses: Risk assessment of business activities and clients; Controls to mitigate risks identified; Ongoing monitoring of accounts and financial transactions that pose higher risks; Keeping client information, and if applicable beneficial ownership, up to date. 39

Risk Assessment Stage 1 (Business Risk Assessment) Conducting a Risk Assessment of the following elements: Bank s risk appetite; AML/TF Typologies; Customer types; Economic activity; Products and services; Delivery channels; Sales channel Transaction channel Geographic locations; Place of birth/registration Nationality Country of residence/operation BANK A AML Risk Assessment Other relevant factors Automatically Higher Risk Relationships. 40

Risk Assessment Stage 2 (Relationship Risk Assessment) Assess overall client relationships (including duration, number of accounts, products and services used by clients and clients activities). Consider the Risk Assessment elements Should be done at the outset of a new client relationship (during customer acceptance). Conduct on-going risk assessments based on the aggregated risk of a customer relationship Assess beneficial owners of a business if required to obtain this information 41

Implementing a Risk Framework Customer relationships need to be assessed by using a Risk Framework which combines all the elements of the Risk Assessment; Initial risk assessment of a customer relationship at the outset may change over time; System needs to allow on-going customer risk assessments to be performed; Consider automating the risk assessment of a customer relationship if the type of banking allows this (ie Retail or mass market banking) 42

Tables Drive Automated Risk Assessments The system works through tables in the banking system that hold the various categorisations and risk scores which feed the scoring matrix: Customer Customer Table Risk Allocated Risk Score Product PRODUCT TABLE Risk Allocated Risk Score Economic Activity table Economic Activity Risk Allocated Risk Score Country Country table Risk Allocated Risk Score 43

How does the Risk Assessment process CUSTOMER ACCEPTANCE look? CUSTOMER MONITORING Individuals Automatically Higher Risk On-going risk assessment Customer is a PEP Initial client inform ation Sanctions Screening PEP Screening Risk Framework High Risk Medium Risk Low Risk enhanced due diligence for higher risk entities Risk Framework Schedule d Risk Assessments High Risk Medium Risk Low Risk Entities Conduct Risk Assessment if a PEP transaction monitoring Customer take-on, new products and changes to customer data Changes to risk tables 44

An example of a Risk Framework Indicator High Risk Medium Low Risk Risk Customer Type 3 2 1 Product 3 2 1 Delivery channel 3 2 1 National/Country of Registration Country of Residence/ Operation Automatically Higher Risk considerations 3 2 1 3 2 1 Between 5-10 Accumulated Risk Due Diligence Score Grading Less than 8 Low Standard Due Diligence 9 14 Medium Standard Due Diligence 15 and above High Enhanced Due Diligence 45

A B C D E F G Aggregated Element Sub Element Rating Score Weight Score Weight Score Customer Entity 60% C x 60% Industry/Occupation 40% C x 40% 40% E x 40% Product 100% 25% E x 25% Jurisdictions of Registration Nationality/Country 55% C x 55% 20% E x 20% Country of Residence/ Operation 45% C x 45% Channel Account opening 50% C X 50% Transaction 50% C X 50% 15% E x 15% TOTAL SCORE 100% XX Rating Score Low Medium High 20 55 100 86 and Inaugural Aggregated ACAMS Score Anti-Money Laundering 0-50 & Counter 51 Terrorism - 85 Financing above Conference-Africa 46

Linking Customer Risk with Due Diligence Requirements 47

Linking Channel Risk with Due Diligence Requirements 48

49

Conducting Risk Assessments on current customers Current customers who have not been risk assessed will need to be risk assessed Bulk Risk Rating Such an assessment is best performed using an IT intervention A risk framework for Bulk Risk Rating will need to be designed Conducting a Risk Based remediation on customer files for KYC 50

Ongoing Monitoring Ongoing monitoring is about taking reasonable measures to conduct ongoing monitoring of customers and financial transactions that pose high risk of money laundering and terrorist financing. Policies and procedures should detail: What kind of monitoring is done for particular high risk situations? When monitoring is done and its frequency? How it is reviewed or approved? How consistently it is applied? 51

Applying a Risk Framework to PEP s PEP s are considered high risk internationally. How are Associated PEP s classified, and how are they to be managed within the Risk Framework? Consider implementing a PEP Risk Framework. Conduct a robust PEP risk assessments and document these. Determine what is to be assessed and how often. When is a PEP no longer a PEP? Maintain a PEP register with sufficient detail. 52

Presenter s contact details Kevin West KPMG Services (Pty) Ltd (South Africa) kevin.west@kpmg.co.za Tel. +27 84 647 7992 www.kpmg.co.za 53

LEVERAGING TECHNOLOGY Compliance obligations are becoming more onerous The larger the organization the greater the risk Smaller businesses can assess technology which is scalable Technology becomes a key contributing factor to maintaining effective risk based CDD compliance Automating manual processes decreases long term costs 54

Customer Due Diligence A Risk Based Approach Dr Tony Wicks Director of AML Solutions NICE Actimize tony.wicks@actimize.com 55

PLEASE NOTE that, to the extent that Actimize provides, in this presentation or otherwise, information or recommendations regarding any laws, regulations, or statutes, such information or recommendations do not constitute legal advice. Compliance with such laws, regulations or statutes remains the full and sole responsibility of the party to whom such laws, regulations or statutes relate. 56

Purpose of this Section Discuss approaches to automate the processes of CDD Consider business benefits of a successful CDD programme 57

Customer Due Diligence Challenges 58

1. Challenges: Verification and Assessment Need to verify identity of customers Understand the ownership structures and beneficial ownerships Identify directorships, PEPs, shell companies Consider extended business relationships associated with directorships, and national and international linkages For correspondent banking operations, the need to audit and understand AML controls Respond and re-assess risk on an ongoing basis Audit, record & document 59

2. Challenges: Risk Based Approach Increasing pressure to adopt a principles based, risk based approaches to AML and CFT Move away from checklist based approaches Institutions must risk assess customers and correspondents Customer type, business relationships, ownership structures Products and services Assessment must be proportionate and systematic At point of new business and on an ongoing basis Appropriate risk based treatments 60

3. Challenges: Alignment with AML Program Integrate CDD risk assessment with transaction monitoring regime Support regular review and re-assessment Capture and maintain documentation Centralize and make information available for other processes Increase productivity, improve quality of investigations and reduce program costs Respond to introduction of new products and services 61

Customer Due Diligence Successful Strategies 62

1. Successful CDD Strategies: Map Risk Map & understand your business risks Classify & quantify risk factors Assess across two key dimensions: Your internal business risks Products & service arrangements Transaction types, Business Units Geographies Your customer risks: Customer (location, incorporation) Products & services used Business relationships & ownership Business Sector, Asset size Channels Relationships Business Units Product Size 0.9 0.8 0.7 0.6 0.5 0.4 0.3 0.2 0.1 0 Location 0.8 0.7 0.6 0.5 0.4 0.3 0.2 0.1 0 Transaction Types Geographies Sector Ownership 63

1. Successful CDD Strategies: Map Risk Assess the complete customer relationship Combination of your business risks And your customer risks High Outcome risk assessment: Customer risk tiers / bands Medium For each customer On an ongoing basis throughout Low the complete lifecycle Evidential assessment and reporting: Understand whether outcomes align to risk assessment Customers 64

2. Successful CDD Strategies: Automate Automate where possible Based on operational process and business assessment of risk Use open source data and information services CIP, PEP lists, Negative News Automate identification of business relationships Capture and store relevant documentation Reviews and document management Perform continuous risk assessment Provide manual response only when risks exceed acceptable levels Or when regular review required 65

2. Successful CDD Strategies: Automate 1. Automate applications and detection of changing risk factors 2. Systematic assessment process - identifies risk / exceptions / items for review 3. Investigate - reject and report unacceptable risk 1 Automatic Ongoing Assessment 2 3 Application Risk Assessment Response Reject 4. Mitigate acceptable risk with evidence and record justification Manual Adjustment Accept 4 66

A Commercial CDD Solution Complete Customer Record Understand Business Relationships Multi-Factor Risk Assessment 67

3. Successful CDD Strategies: Integrate Apply risk scoring as part of ongoing transaction monitoring, use transaction monitoring to improve CDD Customer Due Diligence = AML Risk Prevention Understanding the customer relationship Assessing the ongoing risk of the customer relationship Understanding the economic rationale of the relationship Assessing wider risks that might be present Managing, auditing and controlling the interaction process Transaction monitoring = AML Risk Detection Detecting red flag behaviours and known scenarios Detect patterns of unusual behaviour Integrated Approach 68

Customer Due Diligence Benefits & Business Opportunities 69

CDD Benefits and Opportunities Use CDD results to align risk in your transaction monitoring program Focuses ongoing transaction monitoring Aligns results to risk policy Reduce false-positives and wasted investigations Standardization of Compliance Process Consistency, control and audit Document decisions and risk assessment Supports independent audit and test 70

CDD Benefits and Opportunities Business & operational efficiencies Streamline Applicant and Ongoing Due Diligence Respond only where risk management is required Automation benefits regular review, risk triggers, documentation management Reduce compliance cost Single View of Customer Risk Audits client interaction and responses Capture profile of anticipated and historic behaviour Re-use across compliance, credit, operational risk and fraud investigations 71

CDD Benefits and Opportunities Additional Cross-Functional Efficiencies & Due Diligence Remove Regulatory Overlaps FINRA Rule 2090 (Know Your Customer), FINRA Rule 2111 (Suitability) FATCA US Foreign Account Tax Compliance Act Identify US customers, manage, review, document & report Bribery & Corruption Due diligence of suppliers & employees is a key requirement Fraud Prevention Enhance your fraud detection processes with customer s anticipated behaviour Generate value for the rest of your business 72

Q&A 73

74

TRAINING Develop a comprehensive training program for high risk customer facing employees which includes Private Banking PEPs Correspondent Banking Practical examples How to manage high risk customers Which due diligence or enhanced due diligence procedures must apply Risk assessment strategies Controls Regularly update training Provide for initial as well as ongoing training Provide for training as part of remediation efforts 75

MONITORING Close monitoring of new clients both for Suspicious Activity Consistency with DD information provided Continuously update customer risk profiles Data base of all high risk customers Ongoing transaction monitoring on high risk customers Lower thresholds Higher focus on higher value transactions Reporting of suspicious activity Forwarding results of monitoring to MLRO for review and remediation 76

RECORDKEEPING Keep records and provide an audit trail throughout the client lifecycle Risk assessment and score Identification and verification documents EDD research Source of wealth Expected activity Changes in customer profile Changes in risk based strategy Requests Governance Approvals 77

CONTROLS Appropriately stringent controls commensurate with the risk to ensure all: High risk client facing employees are trained Details are captured according to policy Records of identification and verification information are kept Accounts and transactions are continuously monitored High risk customers are regularly reviewed Remediation is undertaken in a timely manner 78

REMEDIATION Immediate remediation of any high risk accounts without appropriate info Immediate remediation of any PEP accounts without appropriate info Ongoing remediation when there is a lack of information Follow up on referrals from monitoring Remediate control weaknesses Remediate outdated risk assessments or frameworks Make training a part of remediation efforts Remediate gaps in training as well 79

THE LOWER RISKS A risk based approach does not mean lower risks are excluded Requires controls commensurate with the risk Less focussed but remains important May only require simplified due diligence Ensuring high risk customers don t have duplicate low risk records Managing the movement from a low risk client to high risk is important 80