Following the issuance of the FSC  AML CFT Handbook (“the Handbook”) in January 2020, the Financial Services Commission (“FSC”) has brought amendments on the 31st of March 2021, pertaining to the areas of:

  • Independent Audit
  • Business Risk Assessment

 

Changes in the area of Business Risk Assessment (BRA)

A financial institution must, under Section 17(1) of FIAMLA identify, assess and understand and monitor that person’s money laundering and terrorist financing risks.

 

The addition to the application of BRA are as follows:

  • While performing business, Management, Compliance and Risk Management should all work together on performing the Business Risk Assessment. Primarily, the responsibility for the quality and execution of the risk analyses lies with the first line of defence. This is the business, as risks manifest themselves first there.

 

  • It is expected that this risk assessment is reviewed at least annually and in the case of trigger events and this review should be documented to evidence that an appropriate review has taken place.

 

  • The appropriate strategy in order to manage and control ever-evolving risks is to have an effective internal compliance culture under the board of directors’ ultimate responsibility.

 

  • In cases, where not all the risk elements have been considered when conducting the business risk assessment, the financial institution has to demonstrate how effective and robust its business risk assessment is in line with its inherent risks and vulnerabilities and the Commission will assess to what extent the business risk assessment conducted reflect residual risks faced by the financial institution.

 

Incorporation of Chapter 13 on Independent Audit

This chapter is of essence for Financial Institutions since the requirement for an independent audit is a legal requirement under the FIAML Regulations 2018.

Regulation 22(1)(d) of the FIAML Regulations 2018 stipulates that “financial institutions shall have in place an independent audit function to review and verify compliance with and effectiveness of the measures taken” in accordance with FIAMLA and FIAML Regulations 2018.

 

The rationale behind the setting up of an audit function is that it will enable financial institutions to evaluate its AML/CFT regime and ascertain whether the established policies, procedures, systems and controls are functioning effectively.

 

The Independent Audit ensures that the AML/CFT regime are up to date and this mechanism will help the financial institutions to identify areas where there are shortcomings.

 

 

How does the Independent audit function?

Every Independent Audit should mandatorily test compliance in the following non-exhaustive areas:

  • AML/CFT policies and procedures
  • Internal Risk Assessment
  • Risk Assessment on the use of third-party service providers (Outsourcing)
  • Compliance Officer function and effectiveness
  • MLRO function and effectiveness
  • Implementation and Effectiveness of Mitigating Controls, including customer due diligence and enhanced measures
  • AML/CFT Training
  • Record Keeping Obligations
  • Targeted Financial Sanctions
  • Suspicious Transaction Monitoring and Reporting

 

Furthermore, if the financial institution relies on automated systems or manual processes to implement its AML/CFT regime, the effectiveness and reliability of those systems and processes must be duly considered during the Independent Audit exercise.

 

Choosing an Audit professional

Regulation 22(1)(d) of the FIAML Regulations 2018 stipulates that the audit needs to be carried out independently.

 

What does the terminology ‘independent’ want to convey in the context of Independent Audit?

 

The word independent here implies that “the person or firm conducting the audit should be independent and must not be involved in the development of a financial institution’s AML/CFT risk assessment, or the establishment, implementation or maintenance of its AML/CFT programme.”

The person or the firm conducting the audit should have the necessary skills, qualifications, relevant experience of the audit process, have a proper understanding of FIAMLA and its supporting regulations as well as sufficient knowledge of the financial institution industry.

Questions to ask to assess the independence of the Audit Professional / Firm

The factors to be taken into account by financial institutions in assessing the independence of Audit Professionals are as follows:

  • Was the audit professional involved in the development of the entity’s risk assessment or the creation, implementation or maintenance of AML/CFT programme?
  • Is there any financial interest for the audit professional in the business? In the affirmative, the financial institution needs to ensure if their interest would be adversely impacted by the audit and how this could influence the audit performance and outcome.
  • The relationship of the audit professional with any shareholder, director, senior management and employees of the financial institution.

 

Frequency of the Audit Function

The frequency of the audit function is dependent on the financial institution’s size, nature, context complexity and internal risk assessment.

 

The financial institution needs to target an independent audit at least once per year or whether material changes to the legislative framework, regulatory obligation or to the financial institutions prompt an earlier review. The financial institution also has the discretion choose over the frequency of the audit function, The greater the ML/TF risks or the speed at which the financial institution’s business changes, the more frequent will be the audit.

 

Filing to the Commission

Financial Institutions are not required to file the independent audit report with the FSC periodically. However, the financial institution shall file its independent audit report for a specified period, upon the request of the Commission.

Sources:

          

Date: 12.04.2021