Statement of Guidance
Guidance Note: Compliance Monitoring
In forceView on JFSC's website Source document
Summary
This JFSC guidance note explains supervisory expectations for the compliance monitoring plan (CMP) that registered and supervised persons must maintain to test adherence to legal, regulatory and financial crime obligations. It sets out a seven-step risk-based cycle for building and running a CMP and illustrates good and poor practice with worked examples and case studies.
- Scope of obligations covered: The CMP should cover all applicable regulatory laws, financial crime laws, sector Codes of Practice, and the AML/CFT/CPF Code, and may extend to data protection, revenue, registry and industry standards.
- Seven-step cycle: Identify legal and regulatory obligations; identify the control environment; assess non-compliance risk; design and approve the CMP; undertake testing; report to the board; remediate identified gaps.
- Group firms: Where a firm relies on group-level frameworks, the CMP must be explicitly adapted to Jersey-specific risks and obligations, with local board review and approval and documented evidence of that adaptation.
- Governance and reporting: Compliance monitoring should be a standing board agenda item, with findings, remedial actions and progress on outstanding remediation reported and, where appropriate, escalated urgently.
- Breach reporting: Firms are expected to engage openly with the JFSC on discovered non-compliance and report breaches where necessary or mandated.
The guidance does not prescribe a single testing methodology but expects testing to be evidence-based, documented, and proportionate to the firm's risk profile, with regular review and escalation of material findings to the board or senior management.
Key obligations
- Maintain a documented, risk-based compliance monitoring plan (CMP) that is proportionate to the firm's nature, scale and complexity
- Identify and map all applicable legislative, regulatory and financial crime requirements relevant to the firm's licence type as part of establishing and reviewing the CMP
- Where part of a group, adapt group CMP frameworks to Jersey-specific risks and obligations, obtain local board review and approval, and retain evidence that the adapted CMP meets Jersey requirements
- Ensure the compliance function reports to the board on compliance monitoring as a standing agenda item, covering findings, remedial actions and progress on outstanding remediation
- Undertake evidence-based testing of controls in line with the approved CMP and maintain adequate working papers to support findings
- Take timely and proportionate remedial action where testing identifies gaps, weaknesses or non-compliance, and record breaches in the breaches register
- Engage openly and cooperatively with the JFSC and report breaches where required or mandated
Applies to
registered and supervised persons, banking business, fund services business, investment business, insurance business, trust company business, money services business, alternative investment funds, certified funds, general insurance mediation business