Statement of Guidance
Feedback on AML/CFT On-Site Visits (July 2012)
Archived by the regulatorGFSC has archived this document: it is no longer current, is retained for reference only, and may no longer reflect current requirements.
View on GFSC's website Source document
Summary
This is an archived 2012 guidance paper from the Guernsey Financial Services Commission summarising findings from its 2011 AML/CFT on-site inspection programme (94 visits). It is not a new rule but consolidates common strengths and weaknesses observed across financial services and registered businesses, intended to help firms review their own AML/CFT policies, procedures and controls. The Commission notes it is archived and may no longer reflect current requirements.
- Business risk assessment: Some firms used generic, group-derived assessments not tailored to their own business model, or omitted risks they believed already mitigated, undermining demonstrable risk management.
- Relationship risk assessment: Assessments sometimes failed to clearly show the basis for ML/FT risk ratings or confused ML/FT risk with other risk types; confusion existed over who is responsible where multiple parties administer a structure.
- High risk handling: Some businesses lacked documented policies for risk-rating customers, failed to treat relationships as high risk when one high-risk factor was present (e.g. PEPs, high-risk jurisdictions), or blocked high-risk business without controls to prevent inadvertent onboarding.
- Low risk handling: Simplified due diligence was sometimes applied without proper regard to the regulations/handbook, or without documenting the reasons for a low-risk determination; confusion over 'introducer' and 'intermediary' definitions led to incorrect low-risk classification.
- Monitoring: Periodic and trigger-based review programmes were generally in place, but delays arose from resourcing or sign-off bottlenecks, and some firms did not assess whether trigger-based monitoring was appropriate given risk.
- Record keeping: Generally satisfactory, though some policies were outdated and files held overseas or by third parties were not always readily retrievable on request.
- Training: General staff training was mostly adequate, but group-level training was sometimes not tailored to Bailiwick legislation, lacked formal structure, and MLROs/Boards often received the same training as general staff rather than the required additional, role-specific training; training logs were not always kept up to date.
- UN Sanctions: Awareness was generally good, but smaller businesses without automatic checking software struggled to monitor sanctions lists, particularly for non-face-to-face customers.
The paper is descriptive feedback rather than a source of new binding rules, but it repeatedly points back to existing obligations under the AML/CFT regulations and Handbooks (e.g. mandatory relationship risk assessments and additional MLRO/Board training) that firms are expected to already be meeting.
Key obligations
- Businesses must carry out a documented relationship risk assessment for each individual business relationship and occasional transaction.
- Where any single aspect of a business relationship or occasional transaction carries a high ML/FT risk, the overall relationship or transaction must be treated as high risk (it cannot be downgraded based on customer knowledge alone).
- Businesses adopting reduced or simplified due diligence for low-risk business must base that determination on the regulations and handbook provisions and document the reasons for the low-risk classification.
- MLROs must receive additional, in-depth training covering areas such as suspicion reports and production and restraining orders, beyond general staff training.
- The Board and senior management must receive additional training on relevant enactments, offences and penalties, including potential director and shareholder liability.
- Businesses must maintain up-to-date AML/CFT training logs evidencing the nature and dates of training undertaken.
- Files and records must remain readily retrievable by the Commission even where held overseas or by third parties.
Applies to
financial services businesses, registered businesses, banks