Advisory

Financial Crime Governance, Risk and Compliance – Fund Managers & Fund Administrators (Thematic Review 2017)

Guernsey Financial Services Commission (GFSC) · Guernsey

Issued 2017-11-15

Current version last checked: 2026-07-12

Summary

This is a thematic review report published by the Guernsey Financial Services Commission summarising findings from a 2016 review of financial crime governance, risk and compliance frameworks at 34 fund managers and fund administrators (predominantly smaller firms). It sets out good practice observed and areas for improvement, rather than creating new rules, and is intended to help all regulated firms benchmark their own policies, procedures and controls against existing AML/CFT requirements.

  • Business risk assessments: Firms should ensure business risk assessments are firm-specific, kept up to date, and consistent with information given to staff and the Commission; risk appetite should be clearly set and communicated.
  • Compliance monitoring programmes: Compliance monitoring programmes must be tailored to the firm's actual risks (not a generic rules-based template), include sample testing, and cover areas such as intermediary relationships, payments out of scheme property, and automated sanctions screening system testing.
  • Board oversight and MI: Boards should receive adequate financial crime management information, track outstanding action points from risk reviews, and monitor timeliness of SAR disclosure.
  • Customer/scheme risk reviews: Firms should conduct periodic and trigger-based risk reviews of schemes and investors, review due diligence adequacy at each review, and consider commercial rationale for relationships, without unnecessarily re-verifying documents that remain adequate for the assessed risk.

The report does not impose new statutory obligations but reinforces existing requirements under the Criminal Justice (Proceeds of Crime) Regulations and the AML/CFT Handbook, illustrated with practice examples and areas for improvement identified during the review.

Key obligations

  • Firms must establish a compliance review policy that takes into account the size, nature and complexity of the business and includes ongoing sample testing of policies, procedures and controls
  • Firms must ensure compliance monitoring programmes are tailored to the firm's specific financial crime risks rather than relying solely on generic or purely rules-based programmes
  • Firms using automated sanctions screening systems should test that those systems are operating correctly, including after system upgrades
  • Firms must test intermediary relationships to confirm they are low risk, subject to CDD, and limited to permitted financial products/services under Section 6.5 of the AML/CFT Handbook
  • Firms must assess whether identification/due diligence documentation held for investors and schemes remains adequate for the assessed risk as the business relationship develops
  • Boards must maintain oversight of financial crime compliance, including tracking and resolving outstanding action points from risk reviews and monitoring SAR disclosure timeliness

Applies to

Fund Managers, Fund Administrators, financial services businesses within the Bailiwick of Guernsey subject to the POI Law and AML/CFT Regulations

Topics

Version history

2026-07-12

source file (current)