Circular
AML/CFT & Sanctions Onsite Inspections & Findings Pt 2 (2020-05-29)
Issued 2020-05-29View on CIMA's website Source document
Summary
This is a supervisory information circular issued by CIMA summarizing the results of its 2019 AML/CFT and sanctions onsite inspection program (the second part of a two-part circular). It is informational rather than a rulemaking, reporting statistics on the number of inspections conducted in 2019 (200 total, 175 AML/CFT-focused) and the volume and nature of inspection findings (1,322 requirements issued).
- AML/CFT and sanctions compliance: Findings concentrated in this area.
- Operational risk: Also a concentrated area of findings.
- Corporate governance: Also a concentrated area of findings.
- Regulatory reporting: Also a concentrated area of findings.
- Business continuity: Also a concentrated area of findings.
The circular breaks down deficiencies by licensee type, covering deposit-taking institutions, company managers, trust and corporate service providers, insurers, mutual fund administrators, and securities licensees.
- Outdated AML/CFT policies: A common category of findings.
- Inadequate PEP procedures: A common category of findings.
- Incomplete CDD/KYC documentation: A common category of findings.
- Weak risk-based approaches: A common category of findings.
- Governance gaps: A common category of findings.
- Outsourcing deficiencies: A common category of findings.
The circular also summarizes CIMA's 2019 enforcement actions, totaling 25, including revocations, a controllership, a winding-up petition, fines, and warning notices.
The circular applies broadly to CIMA-regulated licensees across sectors, and while it does not create new legal rules, it signals CIMA's supervisory priorities and puts licensees on notice that similar deficiencies will attract enforcement action, including administrative fines, license revocation, or director unfitness findings. It closes by urging licensees to self-assess their AML/CFT compliance programs and warns there will be 'no tolerance for repeat deficiencies,' indicating heightened scrutiny going into 2020, including via a newly established AML Division. Because this document is a narrative summary/report of past inspection findings rather than a rule or statutory instrument, it does not impose new formal legal obligations beyond existing AML/CFT regulatory requirements; instead it functions as guidance highlighting risk areas and reinforcing existing compliance duties under the AML Regulations and sector laws.
Key obligations
- Licensees should review and remediate the AML/CFT, corporate governance, and operational risk deficiencies identified in the circular (e.g. outdated AML/CFT policies, inadequate PEP and CDD/KYC procedures, insufficient risk-based approach documentation, inadequate outsourcing due diligence) to ensure ongoing compliance with applicable AML/CFT laws and regulations.
- Licensees are urged to regularly assess their compliance programs to ensure they remain commensurate with their business risks.
- Licensees must address identified deficiencies from inspections in a timely and thorough manner, as repeat deficiencies will not be tolerated and may result in enforcement action.
Applies to
Deposit-taking Institutions, Companies Management (Trust and Corporate Service Providers), Trust and Corporate Service Providers, Insurer Licensees, Mutual Fund Administrators, Securities licensees, Financial Service Providers