Advisory
Advisory - AML/CFT Compliance During COVID-19 (2020-04-21)
Issued 2020-04-21View on CIMA's website Source document
Summary
This is a non-binding advisory issued by CIMA on 21 April 2020 to help its regulated entities maintain adequate AML/CFT/CPF and sanctions compliance during the COVID-19 pandemic. It explicitly states it is not a legal document and cannot be relied upon for points of law; underlying obligations remain those set out in the relevant AML/CFT statutes and CIMA's Guidance Notes.
Heightened ML/TF Risks
The advisory highlights heightened money laundering and terrorist financing risks arising from COVID-19 and sets out CIMA's expectations for how regulated entities should adapt their AML/CFT systems and controls while working remotely.
- Fraudulent investment schemes
- Misuse of stimulus funds
- Increased use of virtual assets
- Increased use of cash-intensive businesses
Remote Customer Verification
The advisory addresses acceptable alternative methods for verifying customer identity remotely, while stressing that normal verification processes should be completed as soon as practicable.
- Video conferencing
- 'Selfie' verification
- E-format statements/bills
- Recently expired government ID issued after 1 March 2020
Other Compliance Expectations
- Risk assessments: Updating institutional risk assessments
- Deviations: Documenting any deviations from normal compliance practices and the plan to revert to them
- Training: Providing AML/CFT training online
- Electronic signatures: Considering the validity of electronic signatures
- Engagement with CIMA: Continuing engagement with CIMA during remote/off-site supervision and inspections
- Deadline extensions: Deadline extensions will be considered case-by-case
The document applies broadly to all CIMA-regulated entities subject to AML/CFT obligations.
Key obligations
- Regulated entities must continue to comply with customer identity verification obligations, using risk-based remote verification methods (e.g. video conferencing, certified 'selfie' documents, e-format statements/bills, or recently expired government ID) where normal processes are impractical.
- Where a deviated/remote verification method is used, the regulated entity must complete verification using normal processes as soon as practicable.
- Regulated entities should impose risk-based restrictions (e.g. transaction limitations) on new relationships where verification has not yet been completed by normal means.
- Regulated entities should update Institutional Risk Assessments to reflect heightened ML/TF risks arising from COVID-19 and consider recalibrating transaction monitoring systems.
- Regulated entities must document steps taken to mitigate ML/TF/PF/sanctions risks due to COVID-19, including reasons for any deviation from normal compliance practices and evidence of the plan to return to normal practices afterward.
- Regulated entities are encouraged to provide AML/CFT/CPF/sanctions training via online platforms, and must retain documentation where in-person training was postponed or cancelled.
- Regulated entities must consider the legal and counterparty acceptability of electronic signatures and appropriate arrangements for witnessing them.
- Regulated entities must continue to report suspicious activities and comply with sanctions obligations as required by relevant laws.
- Regulated entities should continue to interact and communicate with CIMA during remote supervisory activities and inspections.
Applies to
regulated entities