Advisory
ML and TF Business Risk Assessments Thematic Review - 2022
Issued 2022-12-15View on GFSC's website Source document
Summary
This is a GFSC thematic review reporting on the Commission's examination of money laundering (ML) and terrorist financing (TF) Business Risk Assessments (BRAs) prepared by 104 firms across the Bailiwick's financial and professional services sectors. It summarises good practice, identifies seven areas for improvement, and restates the existing statutory and Handbook requirements for BRAs rather than creating new rules.
- TF risk understanding: TF risk assessments were generally less developed than ML assessments; firms should use the National Risk Assessment to better identify relevant TF vulnerabilities across customers, jurisdictions, products, services, transactions and delivery channels.
- Tailoring to specific risks: Firms should make greater use of their own management information (MI) so that BRAs are specific to the business rather than generic.
- Transactions: Firms handling cross-border fund flows should incorporate MI on geographic origin/destination and consider risks tied to countries listed in Handbook Appendices H and I.
- Delivery channels: Firms should more thoroughly analyse ML/TF risks arising from introducers, intermediaries, non-face-to-face customers, outsourcing and reliance on independent financial advisers.
- Effective annual reviews: Annual reviews of BRAs must identify and correct references to outdated regulatory provisions and capture emerging risks from new products or technology.
- Overall level of ML and TF risk: BRAs should clearly state the firm's overall level of ML and TF risk exposure together with the rationale for that conclusion.
- Accessibility: BRAs should avoid excessive length, multiple documents, jargon and acronyms that obscure the key risks for the intended audience.
The review also restates the binding legal framework: under Paragraph 3 of Schedule 3 to the Criminal Justice (Proceeds of Crime) (Bailiwick of Guernsey) Law 1999 and Handbook sections 3.6 to 3.12, specified businesses must produce separate, suitable and sufficient ML and TF business risk assessments, determine their risk appetite and mitigation, and review these at least annually (or more frequently on material change), with board-approved policies, procedures and controls to manage identified risks.
Key obligations
- Carry out and document a suitable and sufficient ML business risk assessment and a suitable and sufficient TF business risk assessment, specific to the business.
- Review business risk assessments regularly, at a minimum annually, and more frequently when business changes occur, updating them as needed.
- When conducting BRAs, consider all relevant risk factors to determine overall risk level, risk appetite, and appropriate mitigation.
- Ensure BRAs address customers and beneficial owners, countries/geographic areas, and products, services, transactions and delivery channels, including risks from new products, business practices and new/developing technologies before adoption.
- Have board-approved policies, procedures and controls in place that are appropriate and effective to mitigate and manage risks identified in the BRA and in the National Risk Assessment.
- Ensure separate ML and TF risk appetite statements are documented.
- Use firm-specific management information (MI) rather than generic content to make BRAs relevant to the business.
- Clearly state the firm's overall level of ML and TF risk exposure with supporting rationale.
- Avoid outdated regulatory references and excessive length/jargon that reduce the accessibility of BRAs.
Applies to
banking, trust and company services providers, investment firms, insurance firms, lawyers, accountants, estate agents, non-regulated financial services business, personal fiduciary licensees
Deadlines
- at a minimum annually: Business risk assessments (ML and TF) must be reviewed at least once a year, and more frequently when business changes occur, per Schedule 3 paragraph 3(1)(b).