Advisory
Financial Crime Governance, Risk and Compliance – Smaller Firms in the Trust and Corporate Service Provider Sector: Thematic Review 2017
Issued 2018-05-14View on GFSC's website Source document
Summary
This is a GFSC thematic review report summarising findings from a 2017 survey and on-site visits to 35 smaller trust and corporate service providers (TCSPs) in Guernsey, focusing on how they structure financial crime governance, risk and compliance frameworks. It is not a rule change but sets out the Commission's observations, examples of good and poor practice, and its expectations for firms in this sector.
- Business Risk Assessments: Firms are expected to document a clear, tailored risk appetite and financial crime risk assessment (including terrorist financing risks), avoiding overly generic or overly granular BRAs.
- Compliance Monitoring Programmes: CMPs should be risk based and tailored to the firm's specific business, not a generic 'tick box' exercise; a fifth of firms surveyed had deficiencies serious enough to warrant Commission-imposed risk mitigation programmes.
- Governance and resourcing: Boards should maintain oversight of financial crime compliance and ensure compliance resourcing (in-house and/or outsourced) is appropriate to the firm's risk profile.
- Client due diligence and periodic reviews: Firms should hold complete, adequate client and beneficial owner verification documentation and promptly clear action points arising from periodic risk reviews.
- Audit function: While a separate AML/CFT audit function is not a regulatory requirement, the Commission urges firms without one to consider periodic audits given the sector's higher inherent ML/TF risk.
The report is intended to help all regulated Bailiwick firms, not just those surveyed, benchmark their own financial crime controls against observed good and poor practices; it does not itself introduce new binding rules or deadlines beyond reinforcing existing Handbook and Regulations requirements.
Key obligations
- Firms should document their financial crime (ML/TF) risk appetite clearly and make it readily accessible to all relevant staff
- Firms should ensure their Business Risk Assessment specifically identifies and analyses financial crime risks (including terrorist financing) relevant to their products, services and customers, not just generic or operational risks
- Compliance monitoring programmes must be risk based and tailored to the firm's specific business rather than a standardised checklist approach
- Firms should maintain complete and adequate client and beneficial owner verification documentation and address gaps identified during periodic reviews
- Firms should promptly clear outstanding action points arising from periodic financial crime risk reviews
- Firms without a separate audit function should consider, based on their client risk profile, implementing periodic audits of their AML/CFT controls
Applies to
Trust and Corporate Service Providers (TCSPs), fiduciary sector firms, financial services businesses regulated under the Bailiwick of Guernsey AML/CFT framework