Identifying and assessing the level of money laundering and terrorism financing (ML/TF) risk to your business or organisation is an essential part of your Anti-Money Laundering and Counter-Terrorism Financing (AML/CFT) program. According to section 17 of Financial Intelligence Anti-Money Laundering Act (FIAMLA) 2002, financial institutions are under a statutory duty to locate, analyse and understand ML/TF risks for clients, products and services, transactions, geographical areas, and delivery channels. Financial institutions usually carry out the exercise before the onboarding of a particular client business relationship or during the course of an on-and-off activity. During the course of the exercise, risk factors must be duly assessed to objectively and reasonably determine the risk profile of the client.
The rationale behind carrying a risk assessment exercise is that it supports management in prioritising and diverting resources to high and sensitive areas. It also alerts regulators of significant risks identified and prompting that remediation actions are being taken to mitigate the risks and sufficient controls are being implemented to reduce residual risks. The Basel Committee on Banking Supervision (BCBS) produced a document entitled “Sound Management of Risks related to Money laundering and Financing of Terrorism” which stated that effective risk management of ML/TF risks is achieved through the verification and assessment of ML/TF risks within bank’s internal and external environment before the determination of the risk profile and the development of policies and control measures to curtail the risks identified.
As per Section 17(2) of the FIAMLA, there are six key areas that businesses are required to assess when undertaking the business risk assessment:
(i) the nature, scale and complexity of the financial institution’s activities;
(ii) the products and services provided by the financial institution’s;
(iii) the persons to whom and how the products and services are provided;
(iv) the nature, scale, complexity and location of the customer’s activities;
(v) reliance on third parties for elements of the customer due diligence process; and
(vi) technological developments.
Frequency of risk assessment exercise
The frequency of the risk assessment exercise depends on several factors, including the methodology used and the findings. For instance, if there is no significant change in the risk environment, financial institutions may choose to proceed annually. Irrespective of its frequency, financial institutions need to report the status of its ML/TF risk management annually. Lastly, the failure to adequately monitor ML/TF risks can trigger legal or operational risks or even expose financial institutions to the damage of its reputation.
Conducting a risk assessment exercise
Financial institutions are given the discretion to choose over the methodologies to conduct a risk assessment. However, the risk assessment exercise should include the following three phases:
- Determination of Inherent risk;
- Analysis of policies and controls; and
- Derivation of Residual risk
Inherent risk refers to the exposure of risks of money laundering or terrorism financing by financial institutions. To locate a financial institution’s inherent risk, the risk assessment is spanned across the risk factors. Each or a combination of risk factor(s) is given a risk weight based on the nature, scale and activity in question.
Once the inherent risks have been identified, policies and internal control measures are analysed to infer whether the measures are being applied proportionately to reduce the risk that ML/TF materialise. The internal control measures shall be attached to Key Performance Indicators or ratings to measure their effectiveness. The assessment of internal control measures includes inter alia,
- Know Your Client (KYC), Customer Due Diligence (CDD), Enhanced Due Diligence (EDD)
- Monitoring and controls
- Training
- Internal audit
- Record Keeping
The assessment carried out and focused on training will, for instance, verify whether staffs training needs have been examined; whether officials holding prominent positions and functions have received extensive training; whether training has been completed timely. The assessment should consider the area of deficiencies, calling for improvement.
Residual risk is the risk that can only be determined following the assessment of inherent risk and control measures. It is calculated through the weighting of risk factors against the control measures. Such ratings help to measure the effectiveness of policies and controls. Financial institutions must be able to justify the risk classification objectively and reasonably and should ensure the accuracy of the assessment before giving their internal sign-off.
How Can Temple Consulting help you?
Temple Consulting Ltd (‘TCL’) established in 2007, has been assisting financial entities in meeting their regulatory and legal requirements through various compliance exercises, including business risk assessment.
Our role will be fully aligned with the requirements of the law, as outlined above.
We have a team of Compliance Consultants with proven expertise in business risk assessment.
We remain available over the phone, by email and to be present on-site as required.
In the event of absences/leave, there is no disruption in our service delivery. There is always be a senior representative of TCL present to liaise with your organisation as required.
We work to demonstrate awareness of the National Risk Assessment outcomes and align internal processes with the recommendations made, demonstrating best practice, and streamlining any future NRA-related regulatory queries or action.
Sources/References
- FIAML 2002, FIAML Regulations 2018
- FSC Handbook
- Wolfsberg Group– Frequently Asked Questions on Risk Assessments for Money Laundering, Sanctions and Bribery & Corruption (2015)
- UK Joint Money Laundering Steering Group – http://www.jmlsg.org.uk/industry-guidance/article/jmlsg-guidance-current
Recent Comments