Circular
2017 AMLRs Key Changes, Outsourcing AML/CFT Operations & FASB Updates (2017-11-22)
Issued 2017-11-22View on CIMA's website Source document
Summary
This is a 2017 CIMA supervisory circular summarizing major changes brought by the Anti-Money Laundering Regulations, 2017 (AMLRs), which replaced the Money Laundering Regulations (2015 Revision) and came into force on 2 October 2017.
Key AMLR Changes
- Expanded scope: The scope of 'relevant financial business' has expanded, e.g. to cover fund/money management for others and life insurance underwriting/placement.
- New definitions: New definitions have been added for beneficial owner, PEP, and legal person/arrangement.
- Risk-based approach: Financial service providers (FSPs) must now adopt a risk-based approach (RBA) to AML/CFT, implement employee screening, and conduct sanctions and FATF non-compliant territory checks.
- Deputy MLRO: Mandatory appointment of a Deputy Money Laundering Reporting Officer is required.
- Due diligence changes: Enhanced due diligence requirements apply for higher-risk customers and PEPs, alongside changes to simplified due diligence and eligible-introducer assurances.
- Equivalent-jurisdictions list: The old 'Schedule 3' equivalent-jurisdictions list has been removed and is now maintained by the AML Steering Group, with Mexico, Panama and Turkey excluded as of 5 October 2017.
- Increased penalties: Penalties for contravention have increased substantially, up to CI$500,000 on summary conviction, or on indictment, fines and up to two years' imprisonment.
Outsourcing of AML/CFT Functions
The circular separately addresses outsourcing of AML/CFT functions, reminding FSPs that outsourcing arrangements, including intra-group ones, must comply with CIMA's Statement of Guidance on Outsourcing and must not diminish the FSP's ultimate responsibility for compliance.
- Minimum expectations: Outsourcing arrangements must meet minimum expectations including a written agreement, a contingency/exit plan, monitoring processes, unimpeded data access, and audit/risk controls equivalent to the regulated entity's own standards.
Accounting Standard Changes
Finally, the circular flags upcoming accounting standard changes relevant to banks and insurers.
- FASB CECL standard: FASB's current expected credit loss (CECL) standard (ASU 2016-13) takes effect for FASB-reporting banks on 1 January 2020.
- IFRS 9 parallel calculations: Banks under the Banks and Trust Companies Law that follow IASB/IFRS 9 have been running parallel calculations since the June/July 2017 Quarterly Prudential Return to assess capital impact.
- Insurance contract disclosures: FASB's ASU 2015-09 introduces disclosure enhancements for short-duration insurance contracts, which CIMA is still assessing for impact on licensees.
Key obligations
- FSPs must adopt a documented risk-based approach (RBA) to AML/CFT, including identifying, assessing, managing, monitoring and periodically re-evaluating ML/TF risks.
- FSPs must establish and implement employee screening procedures.
- FSPs must conduct sanctions checks and checks against FATF non-compliant territories.
- FSPs must appoint a Deputy Money Laundering Reporting Officer in addition to the Money Laundering Reporting Officer.
- FSPs must apply enhanced due diligence (EDD) to higher-risk customers, including politically exposed persons, their family members and close associates, and to customers/business from high-risk jurisdictions or correspondent banking relationships.
- Where relying on simplified due diligence, FSPs must ensure any lower-risk assessment is consistent with the national risk assessment or a Supervisory Authority's findings, not made unilaterally.
- Where relying on eligible introducers, FSPs must obtain enhanced written assurances, including source-of-funds confirmation and assurance that identification/verification data will be made available on request.
- FSPs outsourcing AML/CFT functions (including intra-group) must comply with CIMA's Statement of Guidance on Outsourcing and retain ultimate responsibility for compliance.
- Before outsourcing a compliance function or MLRO/DMLRO position, an FSP must assess associated risks (including country risk) and must not proceed if risks cannot be effectively managed and mitigated.
- Intra-group outsourcing arrangements must include, at minimum: a written outsourcing agreement, a contingency/exit plan, monitoring/reporting/oversight processes, unimpeded data access, and audit/risk controls equivalent to the regulated entity's own.
- Banks licensed under the Banks and Trust Companies Law that follow IASB accounting standards (excluding branches of foreign banks) must continue performing parallel runs for IFRS 9 impairment impact as part of the Quarterly Prudential Return process.
- Banks following FASB accounting standards must meet the requirements of ASU 2016-13 (CECL) by its effective date.
Applies to
financial service providers (FSPs), banks, trust companies, insurance entities/insurers, investment entities
Deadlines
- 2 October 2017: Effective date on which the Anti-Money Laundering Regulations, 2017 came into force, replacing the Money Laundering Regulations (2015 Revision).
- 5 October 2017: Date the updated equivalent-jurisdictions list (replacing former Schedule 3) was issued, excluding Mexico, Panama and Turkey.
- January 1, 2020: Effective date by which banks following FASB accounting standards must meet the requirements of ASU 2016-13 (current expected credit loss approach).
- since the June/July 2017 Quarterly Prudential Return: Banks under the BTCL following IASB standards have been performing parallel runs to assess IFRS 9 impairment impact from this QPR onward.