REGULATORY RISKS (risks related to federal and state requirements)

Similar documents
Non-Banking Financial Institution (NBFI) Third Party Payment Processor (TPPP) AMLQuestionnaire

Risk Based Approach and Enterprise Wide Risk Assessment Edwin Somers / Inneke Geyskens-Borgions 26 September 2017

FINANCIAL SERVICES FLASH REPORT

The top anti-money laundering and sanctions compliance challenges for financial institutions for 2018 and beyond May 2018

COMPLIANCE REIMAGINED THE AML COMPLIANCE LANDSCAPE. Financial institutions seek enterprise-wide, cost-effective solutions

IIB - INTERNATIONAL BANKING ANTI-MONEY LAUNDERING SEMINAR

Effective Risk Management With AML Risk Assessment. January 25, 2017

Preventing Board and Management Liability for Violations of AML Rules

Thomson Reuters SCREENING RESOLUTION SERVICE

IdentityMind SANCTIONS SCREENING PRECISION.

Sanctions Compliance & Evaluation. April 19, 2013

LESSONS LEARNED FROM BSA ENFORCEMENT ACTIONS

The Agent s Independent Review cannot be conducted by the designated Compliance Officer or an employee reporting directly to the Compliance Officer.

Customer Due Diligence A Risk Based Approach. Dr Tony Wicks Director of AML Solutions NICE Actimize

Customer Due Diligence Risk-Based Approach. Dan Soto CCO Ally Financial

DFSNY Rule 504 Gathering the Evidence

Commercial Due Diligence

Anti-Money Laundering & Countering Terrorist Financing: Building an Effective Compliance Framework

BSA Hot Topics. Presented to: New York Bankers Association. May 2015

Auditing for Effective Training

Managing Sanctions Compliance in a Global Economy

Extract from Instruction for procedures against Money Laundering and Terrorist Financing for the SEB Group

AML and Tax Compliance in the Asia-Pacific Region: Investing in KYC Systems, Data, and Processes

IMAS Guidance to Assessing Money Laundering and Financing of Terrorism (ML/FT) Risk

RSM ANTI-MONEY LAUNDERING SURVEY BEST PRACTICES AND BENCHMARKING FOR YOUR BSA/AML PROGRAM

Bank M2M Europe MAJOR ENHANCEMENTS IN AML/CTF COMPLIANCE AND OTHER RELEVANT DEVELOPMENTS

The Mission would be grateful if the action plan could be circulated to the members of the Committee and published on the Committee's website.

Global Trade Advisory M&A Deloitte Tax LLP

Foundation Event Series One Developing and documenting Policies and Procedures. Jacelle Richardson Anguilla Financial Services Commission

Enhancement of Sanctions Data Quality

JOB TITLE: VP, BSA Officer REPORTS TO: SVP, Deposit Operations and Regulatory Compliance/CRA Officer DEPARTMENT: Compliance

Better Compliance. Relevant. Timely. Accurate.

Understanding the New DFS Part 504 Regulations and the Associated AML Program Testing Challenges

ORGANIZATION OF AMERICAN STATES

Anti-Money Laundering and Sanctions Compliance. You Can t Afford the Risks

Anti-Money Laundering

AML/CFT Supervisor Workshop: Reserve Bank of New Zealand

WELCOME. 1

BSA Risk Assessments and Transaction Monitoring Systems: Partners in Crime Prevention and Detection

OPERATIONAL TRANSFORMATION OF ANTI-MONEY LAUNDERING THROUGH ROBOTIC PROCESS AUTOMATION

ViF Business Conduct Guidelines

This document articulates ethical and behavioral guidance for all NGA Human Resources companies, employees, and business partners (such as suppliers,

Developing an Integrated Anti-Fraud, Compliance, and Ethics Program

IAASB Main Agenda (March 2005) Page Agenda Item 12-C

Bank Secrecy Act Training: Who, What, When, How and Why? Presented by Lynn English Lafayette Federal Credit Union

Compliance Risk Rating

Astrus Third Party Intelligence

Norvik Banka MAJOR ENHANCEMENTS IN AML/CTF COMPLIANCE AND OTHER RELEVANT DEVELOPMENTS

Pay to Play. The LAW REPORT. Develop a Good Understanding of Core Terms of the Rule. Overview of an Effective Compliance Program

Guidance for the AML/CFT Statistical return Year ended 31 December 2017 Regulated entities

Human Rights Policy. 1. Introduction. Rabobank Group

Electronic Banking Remote Deposit Capture Third Party Payment Processors Automated Monitoring Systems Staffing & Resources

Operational Considerations for Transparency. September 2011

Sanctions Risk Management Symposium

Periodic Comprehensive Review of the External Auditor

FINANCIAL INTELLIGENCE ANALYSIS UNIT. Risk Procedures. Ms Katia Satariano Senior Compliance Officer

CONFLICTS OF INTEREST POLICY AND PROCEDURES

Banking Money Services Business. Xenia Vieth, Esq. Banco Popular North America

CONSULTATION DOCUMENT AML/CFT SUPERVISORY STRATEGY

Applicant Data Privacy Notice

Financial Services Compliance

CBI REPORT ON AML COMPLIANCE IN THE CREDIT UNION SECTOR SAMPLE ACTION PLAN. Governance

Swedbank AS MAJOR ENHANCEMENTS IN AML/CTF COMPLIANCE AND OTHER RELEVANT DEVELOPMENTS

Here is a model social media policy prepared by Stuart Fross, partner at

Internal Compliance Program (ICP)

GUIDELINES FOR STRENGTHENING CONTROL OF CONTAINERS

OFAC Reporting: The Check s NOT in the Mail

Info paper Is your sanctions filter working?

RC & TACKLING TRADE BASED MONEY LAUNDERING (TBML) risk compliance RISK & COMPLIANCE MAGAZINE. risk & compliance REPRINTED FROM: APR-JUN 2018 ISSUE

AML Review Readiness. Agenda. AML Overview and Key concepts. Introduction. AML Overview and Key concepts. AML Independent Review Readiness.

Australian Remittance and Currency Providers Association Ltd. ACN: ABN: PO Box 1757 Lane Cove NSW 2066

Arjun Kalra - Senior Manager - Crowe Horwath Risk Consulting Practice Chuck Taylor BSA Officer City National Bank

SETTING POLICIES and GUIDELINES for CONDUCTING INTERNAL INVESTIGATIONS

Helping you build a better team.

LBMA Responsible Gold Guidance Compliance Report

Corporate Legal Audit Program

Minneapolis Public Schools Special School District No. 1 Minneapolis, Minnesota. Communications Letter of the Student Activity Accounts.

LIFELINE AUSTRALIA BOARD ETHICAL GUIDELINES

BACKGROUND SCREENING in the oil and gas industry

Scope Policy Statement Reason For Policy Procedure Definitions Sanctions Additional Contacts History. Scope. University Policies.

Institute of Internal Auditors. Dallas Chapter August 6, 2009

The FFIEC BSA/AML Examination Manual 2010 Revisions

Broad Run Investment Management, LLC

Estate Agency Affairs Board FIC AMENDMENT ACT

REGULATORY HOT TOPICS FOR INTERNAL AUDITORS: EVALUATING THE USE OF AML TECHNOLOGY

KPMG FORENSIC SM. Astrus. A Web-enabled integrity due diligence solution. kpmg.com/astrus

Daiichi Sankyo Group Global Anti-Bribery & Anti-Corruption Policy

TOTAL PAYMENTS PAYMENTS-AS-A-SERVICE SOLUTION FOR US FINANCIAL INSTITUTIONS

BSA/AML Compliance in Acquisitions

Guidelines of ECF for AML/CFT Grandfathering

COMPLIANCE: Strategic Planning

RESPONSIBLE SOURCING TOOL RST. Seafood Tool 05

Anti Money Laundering Compliance Solutions. Copyright 2016 Allsec Technologies. All rights reserved.

Financial Crime Supervision & Policy Division Guidance Note Visit Trends & Observations

Information paper. Transaction filtering, systems testing and annual certification: driving business benefits

Firco Trade Compliance Transforming Your Trade Screening. accuity.com

Financial Crime Mitigation

Practical Ideas for an Effective BSA/AML Compliance Function: Risk Assessment and Program Development

Compliance and Examinations

Draft Examples. February 2019

Transcription:

REGULATORY RISKS (risks related to federal and state requirements) Compliance Program Compliance Program is documented, implemented and aligns to the Risk Assessment Compliance Program is documented, but does not align to the Risk Assessment. No documented Compliance Program or implemented Compliance Program. Designated Compliance Officer Independent Program Review Compliance Officer is designated and his/her roles and responsibilities are defined. by an independent and competent party at a frequency aligned to the overall risk for the company. Compliance Officer is designated without defined roles and responsibilities. infrequently by the Compliance Officer, or is performed by someone reporting to the Compliance Officer. Compliance Officer is not designated and the roles and responsibilities are undefined. by the Compliance Officer or is not performed. Employee Training Transaction Monitoring There are standardized and frequent trainings for all employees, including new hire training prior to the processing of a transaction. Transactions system allows for ongoing automated transaction monitoring alerts for suspicious There are some periodic trainings for employees and new hire training. There is periodic manual transaction monitoring performed for suspicious There is limited to no employee training. There is no transaction monitoring performed for suspicious Recordkeeping All key records have been identified along with the required maintenance period, and there is monitoring to ensure the recordkeeping occurs appropriately. Most key records are identified along with the required maintenance periods. There is no monitoring for compliance with the requirements. There is no designation of key records to maintain or the required maintenance periods. Your Additional Regulatory Risk Factors

OPERATIONAL RISKS (risks related to inadequate processes, systems or human failures that are not detected) Employee Turnover Low turnover of key or frontline personnel. Low turnover of key personnel, but frontline personnel may have moderate turnover. High turnover, especially in key personnel. System Data Integrity Error recognition software is in place to prevent invalid data for customer transactions. Data Security Electronic data is secured and there is a Business Continuity Plan in place for backups of key records. Employees can override error recognition software and still complete the transaction. Electronic data is secured, butthereisnotastrongbusiness Continuity Plan in place. There is no error recognition software in place. Electronic data is not secured and there is no Business Continuity Plan in place. Your Other Operational Considerations

CUSTOMER RISK (risks related to the types of customers [e.g., consumer/business, occupation, anticipated types of transactions]) Customer Base Customers are all well known. Customers vary and are not all well known. There is a large and growing customer base with very few known customers. Customer Identification Customer identification is entered Customer identification is maintained into and maintained within a system on hard copy paperwork and not in a that can be used for transaction system. monitoring. Customer identification is not consistently obtained and maintained. Customer Identification Based on Transaction Amount Transaction system requires additional customer identifica- tion for transactions above a certain amount. There is manual monitoring in place to ensure additional customer identification is obtained for transactions above a certain amount. There is no process in place to obtain additional customer identification for transactions above a certain amount. Politically Exposed Person (PEP) No members are known to be a PEP. Some members are known to be a PEP. Numerous members are known to be a PEP or are connected to an international political figure. Your Customer Types

PRODUCT & SERVICES RISK (risks related to the types of products and services offered ) (the risk that remains after low, moderate, high Money Transfers Limited number of money transfers that are mostly domestic to low-risk jurisdictions. Moderate number of money transfers, with some inter- national transfers to typically low-risk countries. Large number of money trans- fer transactions. Frequent transfers to, or from, high-risk jurisdictions. Mobile Money Transfer Very few, if any, mobile money transfer transactions. Some mobile money transfer transactions by known customers. Many mobile money transfer transactions. Your Product Types

REGULATORY RISKS (risks related to federal and state requirements) Compliance Program Compliance Program is documented, implemented and aligns to the Risk Assessment Compliance Program is documented, but does not align to the Risk Assessment. No documented Compliance Program or implemented Compliance Program. Designated Compliance Officer Independent Program Review Compliance Officer is designated and his/her roles and responsibilities are defined. by an independent and competent party at a frequency aligned to the overall risk for the company. Compliance Officer is designated without defined roles and responsibilities. infrequently by the Compliance Officer, or is performed by someone reporting to the Compliance Officer. Compliance Officer is not designated and the roles and responsibilities are undefined. by the Compliance Officer or is not performed. Employee Training Transaction Monitoring There are standardized and frequent trainings for all employees, including new hire training prior to the processing of a transaction. Transactions system allows for ongoing automated transaction monitoring alerts for suspicious There are some periodic trainings for employees and new hire training. There is periodic manual transaction monitoring performed for suspicious There is limited to no employee training. There is no transaction monitoring performed for suspicious Recordkeeping All key records have been identified along with the required maintenance period, and there is monitoring to ensure the recordkeeping occurs appropriately. Most key records are identified along with the required maintenance periods. There is no monitoring for compliance with the requirements. There is no designation of key records to maintain or the required maintenance periods. Your Additional Regulatory Risk Factors

OFAC SANCTIONS COMPLIANCE RISK (risks related to screening transactions and customer lists for the likes of terrorists and drug traffickers) (the risk that remains after low, moderate, high OFAC Sanctions Program Company has procedures for Company screens of customers and screening of customers, vendors; adjudicating false-positives; employees, board members, perform batch screenings periodically; vendors, and third parties; and personnel are well trained in adjudicating false-positives; perform OFAC. batch screenings periodically; monitor transactions and personnel are well trained in OFAC. Company screens international customers. Customer Base Products & Services Stable, well-known customer base in a localized environment. Limited number of funds transfers, limited third-party transactions, and no international funds transfers. Customer base changing due to growth, merger, or acquisition in the domestic market. A moderate number of funds transfers. Possibly, a few international funds transfers. A large, fluctuating client base in an international environment. A high number of transactions including international. Geographic Considerations No other types of international transactions, such as cross-border ACH or trade finance. Limited other types of international transactions. A high number of other types of international transactions. Regulatory Risk Third Party Screening Tools Adjududication of False- Positive Matches No history of OFAC actions. No evidence of apparent violation or circumstances that might lead to a violation. Third party tools are tested periodically to ensure current SDN and Sanctions Lists are in use. Company has procedures and personnel are well trained in adjudicating potential matches and fully document how they clear the match. A small number of recent actions (e.g., actions within the last five years) by OFAC, including notice letters or civil money penalties, with evidence that the company addressed the issues and is not at risk of similar violations in the future. Third party tools are tested periodically to ensure current SDN and Sanctions Lists are in use. Company has procedures and personnel adjudicate potential matches and document the match is cleared. Multiple recent actions by OFAC, where issues were not addressed, thus leading to an increased risk of the company undertaking similar violations in the future. Third party tools are only tested during the independent review to ensure current SDN and Sanctions Lists are in use. Company personnel document potential matches and clear the transaction without documenting their actions.. Your OFAC Sanctions Risks