Advisory
Sanctions Thematic Review - 2021 (2022-05-11)
Issued 2022-05-11View on GFSC's website Source document
Summary
This is a thematic review report published by the Guernsey Financial Services Commission summarising the findings of its 2021 review into banks', fiduciaries' and fund administrators' compliance with targeted financial sanctions. It sets out areas of good practice and common weaknesses identified in firms' sanctions screening systems and governance, and signals that the Commission will assess how firms incorporate the findings into their policies and procedures as part of ongoing supervision.
The review reiterates existing Handbook (Chapter 12) requirements that firms must have appropriate and effective policies, procedures and controls to identify sanctioned customers, beneficial owners and connected parties, systems to detect and block related transactions, and compliance monitoring arrangements assessing the effectiveness of sanctions controls. Firms found to have material deficiencies during the review have been placed on Commission-imposed risk mitigation programmes.
Key areas for improvement
- Screening of underlying assets: Only 56% of fiduciary/investment firms surveyed screen underlying assets (e.g. subsidiaries, vessels); firms should assess and document whether underlying assets could be subject to sanctions.
- Efficiency vs effectiveness: Some firms over-tuned automated screening systems for efficiency, risking missed sanctions targets; effectiveness must not be sacrificed for resource savings.
- Understanding and mitigating risk: Firms should assess and document the sanctions risk exposure of their customers, products and services and determine appropriate mitigation.
- Screening policies and procedures: Policies should document the fundamentals of the screening process, including thresholds/settings used and responsible parties.
- Understanding systems: Firms must ensure sanctions screening systems, including data flows between customer and screening systems, are understood and correctly configured.
- Outsourced functions: Firms relying on Group or external vendor screening systems must obtain sufficient evidence the systems work effectively and maintain clear documentation of responsibility within the Group.
- Compliance monitoring: Compliance testing must robustly verify that the system generates alerts appropriately and that correct customer data is being screened.
The Commission notes that all firms subject to AML/CFT supervision, and other sectors such as marine and kidnap and ransom insurance, are subject to the same sanctions screening obligations even though this review did not cover every sector. No new legal requirements are introduced beyond existing Handbook Chapter 12 obligations, but firms should benchmark their practices against the findings and expect scrutiny of remediation during future supervision.
Key obligations
- Firms must maintain appropriate and effective policies, procedures and controls to identify, in a timely manner, whether a prospective or existing customer, beneficial owner, key principal or other connected party is subject to a UN, UK or States of Guernsey Policy and Resources Committee sanction
- Firms must have systems and/or controls to detect and block transactions connected with persons, entities and arrangements designated under the Bailiwick's sanctions regime
- Firms must maintain compliance monitoring arrangements that assess the effectiveness of their sanctions controls and compliance with the Bailiwick's sanctions regime
- Firms identified with material deficiencies must comply with Commission-imposed risk mitigation programmes, including re-screening customers, beneficial owners and/or third parties where required
- Firms should assess and document whether underlying assets (including subsidiaries) could be subject to sanctions and determine appropriate mitigation
- Firms should document their sanctions screening methodology, including thresholds/settings used and responsibility for the process
- Firms relying on outsourced or Group screening systems must obtain sufficient evidence that those systems operate effectively and document responsibility for the screening function
Applies to
banks, fiduciaries, fund administrators, investment firms, insurance firms (including marine general insurance and kidnap and ransom insurance), non-regulated financial services businesses (NRFSB), prescribed businesses