Advisory
Governance, Risk and Compliance Controls to Counter Financial Crime - Estate Agency, Legal and Accountancy Services - Thematic Review 2024
Issued 2024-04-04View on GFSC's website Source document
Summary
This is a thematic review report published by the Guernsey Financial Services Commission summarising findings from an on-site and desk-based review of governance, risk and compliance controls at Estate Agency, Legal and Accountancy businesses registered as prescribed businesses under the Proceeds of Crime Law. It sets out good and poor practice observed, five areas for improvement, and asks all prescribed businesses in these sectors to self-assess against the findings and confirm remedial action to the Commission.
- Scope of review: Conducted in Q4 2023 across all 107 registered prescribed businesses (estate agents, lawyers, accountants); 18 firms selected for on-site assessment and 105 customer files reviewed, of which 52 contained one or more deficiencies against Schedule 3 and the Handbook.
- Effective policies, procedures and controls: Some firms lacked adequate policies and procedures, including ML/TF/PF business risk assessments, required under Schedule 3 paragraph 15(1)(b) and Handbook Rule 2.14.
- Risk assessments and customer identification: Some firms failed to correctly identify the customer in a transaction or conducted tick-box risk assessments that did not consider all relevant risk factors.
- Source of funds and source of wealth: Some firms did not sufficiently corroborate SOF/SOW information, particularly where relying on controls performed by other financial services or prescribed businesses.
- Oversight of outsourced functions: Some firms lacked sufficient Board/Partner oversight of outsourced compliance functions.
- Business relationships vs occasional transactions: Some firms did not properly determine whether an engagement was a business relationship or occasional transaction, leading to inconsistent periodic reviews and regulatory reporting.
The report also reminds all firms of the requirement to conduct sanctions screening of customers, beneficial owners and key principals at take-on, during periodic reviews, and on trigger events, and highlights two Handbook rules: 12.37 (disclosure to the Commission following an identified sanctions connection) and 12.38 (maintenance of a sanctions register). A self-assessment question set is included at the end of the report to help firms review their financial crime governance and compliance controls.
Key obligations
- All firms registered as a prescribed business must read the thematic report and subsequently confirm to the Commission that any relevant changes have been made as a result of considering the report and question set.
- Firms are asked to review the Financial Crime Risk Return submitted for the reporting period ending 30 June 2023 to ensure their submissions are accurate, and update relevant Financial Crime Risk Return practices where appropriate.
- Firms must undertake sanctions screening for all new business relationships and occasional transactions, including screening of the customer, beneficial owner and other key principals, at take-on, during periodic reviews, and when a trigger event occurs.
- Firms must comply with Handbook Rule 12.37, disclosing certain information to the Commission following an identified sanctions connection.
- Firms must comply with Handbook Rule 12.38, maintaining a sanctions register.
- Firms must ensure adequate policies and procedures covering all required aspects of Schedule 3 and the Handbook, including conducting and maintaining ML, TF and PF Business Risk Assessments.
- Firms must ensure staff can correctly identify the customer in a transaction and that risk assessments consider all relevant risk factors and mitigations.
- Where higher risk factors are identified, firms must corroborate source of funds/source of wealth information and assess the veracity of that corroboration.
- Firms must maintain sufficient Board/Partner oversight of any outsourced compliance functions.
- Firms must have a well-reasoned, monitored process for determining whether a customer engagement is a business relationship or an occasional transaction, consistent with Financial Crime Risk Return guidance.
Applies to
Estate agents, Lawyers, Accountancy businesses, Prescribed businesses
Deadlines
- reporting period ending 30 June 2023: Firms are asked to review the Financial Crime Risk Return submitted for this period to ensure accuracy in light of the report's guidance.