INTERPRETIVE NOTE TO RECOMMENDATION 1 (ASSESSING ML/TF RISKS AND APPLYING A RISK-BASED APPROACH)

  1. The risk-based approach (RBA) is an effective way to combat money laundering and terrorist financing Terrorist financing is the financing of terrorist acts, and of terrorists and terrorist organisations.. In determining how the RBA should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. be implemented in a sector, countries should consider the capacity and anti-money laundering/countering the financing of terrorism (AML/CFT) experience of the relevant sector. Countries should understand that the discretion afforded, and responsibility imposed on, financial institutions Financial institutions means any natural or legal person who conducts as abusiness one or more of the following activities or operations for or on behalf of a customer:
    1) Acceptance of deposits and other repayable funds from the public.
    2) Lending.
    3) Financial leasing.
    4) Money or value transfer services.
    5) Issuing and managing means of payment (e.g. credit and debit cards,cheques, traveller's cheques, money orders and bankers' drafts, electronic money).
    6) Financial guarantees and commitments.
    7) Trading in:
    a) money market instruments (cheques, bills, certificates of deposit, derivatives etc.);
    b) foreign exchange;
    c) exchange, interest rate and index instruments;
    d) transferable securities;
    8) Participation in securities issues and the provision of financial services related to such issues.
    9) Individual and collective portfolio management.
    11) Otherwise investing, administering or managing funds or money on behalf of other persons.
    12) Underwriting and placement of life insurance and other investment related insurance.
    13) Money and currency changing.
    and designated non-financial bodies and professions (DNFBPs) by the RBA is more appropriate in sectors with greater AML/CFT capacity and experience. This should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. not exempt financial institutions and DNFBPs from the requirement to apply enhanced measures when they identify higher risk scenarios. By adopting a risk-based approach, competent authoritiesCompetent authorities refers to all public authorities with designated responsibilities for combating money laundering and/or terrorist financing. In particular, this includes the FIU; the authorities that have the function of investigating and/or prosecuting money laundering, associated predicate offences and terrorist financing, and seizing/freezing and confiscating criminal assets; authorities receiving reports on cross-border transportation of currency & BNIs; and authorities that have AML/CFT supervisory or monitoring responsibilities aimed at ensuring compliance by financial institutions and DNFBPs with AML/CFT requirements. SRBs are not to be regarded as a competent authorities., financial institutions and DNFBPs should be able to ensure that measures to prevent or mitigate money laundering and terrorist financing are commensurate with the risks identified, and would enable them to make decisions on how to allocate their own resources in the most effective way.
  2. In implementing a RBA, financial institutions Financial institutions means any natural or legal person who conducts as abusiness one or more of the following activities or operations for or on behalf of a customer:
    1) Acceptance of deposits and other repayable funds from the public.
    2) Lending.
    3) Financial leasing.
    4) Money or value transfer services.
    5) Issuing and managing means of payment (e.g. credit and debit cards,cheques, traveller's cheques, money orders and bankers' drafts, electronic money).
    6) Financial guarantees and commitments.
    7) Trading in:
    a) money market instruments (cheques, bills, certificates of deposit, derivatives etc.);
    b) foreign exchange;
    c) exchange, interest rate and index instruments;
    d) transferable securities;
    8) Participation in securities issues and the provision of financial services related to such issues.
    9) Individual and collective portfolio management.
    11) Otherwise investing, administering or managing funds or money on behalf of other persons.
    12) Underwriting and placement of life insurance and other investment related insurance.
    13) Money and currency changing.
    and DNFBPs should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. have in place processes to identify, assess, monitor, manage and mitigate money laundering and terrorist financing Terrorist financing is the financing of terrorist acts, and of terrorists and terrorist organisations. risks. The general principle of a RBA is that, where there are higher risks, countries should require financial institutions and DNFBPs to take enhanced measures to manage and mitigate those risks; and that, correspondingly, where the risks are lower, simplified measures may be permitted. Simplified measures should not be permitted whenever there is a suspicion of money laundering or terrorist financing. Specific Recommendations set out more precisely how this general principle applies to particular requirements. Countries may also, in strictly limited circumstances and where there is a proven low risk of money laundering and terrorist financing, decide not to apply certain Recommendations to a particular type of financial institution or activity, or DNFBP (see below). Equally, if countries determine through their risk assessments that there are types of institutions, activities, businesses or professions that are at risk of abuse from money laundering and terrorist financing, and which do not fall under the definition of financial institution or DNFBP, they should consider applying AML/CFT requirements to such sectors.
  3. Assessing proliferation financing risks and applying risk-based measures
  4. In the context of Recommendation 1, “proliferation financing risk” refers strictly and only to the potential breach, non-implementation or evasion of the targeted financial sanctions obligations referred to Recommendation 7*Paragraphs 1 and 2 of the Interpretive Note to Recommendation 7, and the related footnotes, set out the scope of Recommendation 7 obligations; including that it is limited to targeted financial sanctions and does not cover other requirements of the UNSCRs. The requirements of the FATF Standards relating to proliferation financing are limited to Recommendations 1, 2, 7 and 15 only. The requirements under Recommendation 1 for PF risk assessment and mitigation, therefore, do not expand the scope of other requirements under other Recommendations.. These obligations set out in Recommendation 7 place strict requirements on all natural and legal persons, which are not risk-based. In the context of proliferation financing risk, risk-based measures by financial institutions and DNFBPs seek to reinforce and complement the full implementation of the strict requirements of Recommendation 7, by detecting and preventing the non-implementation, potential breach, or evasion of targeted financial sanctions. In determining the measures to mitigate proliferation financing risks in a sector, countries should consider the proliferation financing risks associated with the relevant sector. By adopting risk-based measures, competent authorities, financial institutions and DNFBPs should be able to ensure that these measures are commensurate with the risks identified, and that would enable them to make decisions on how to allocate their own resources in the most effective way.
  5. Financial institutions and DNFBPs should have in place processes to identify, assess, monitor, manage and mitigate proliferation financing risks*Countries may decide to exempt a particular type of financial institution or DNFBP from the requirements to identify, assess, monitor, manage and mitigate proliferation financing risks, provided there is a proven low risk of proliferation financing relating to such financial institutions or DNFBPs. However, full implementation of the targeted financial sanctions as required by Recommendation 7 is mandatory in all cases.. This may be done within the framework of their existing targeted financial sanctions and/or compliance programmes. Countries should ensure full implementation of Recommendation 7 in any risk scenario. Where there are higher risks, countries should require financial institutions and DNFBPs to take commensurate measures to manage and mitigate the risks. Where the risks are lower, they should ensure that the measures applied are commensurate with the level of risk, while still ensuring full implementation of the targeted financial sanctions as required by Recommendation 7.
  1. Obligations and decisions for countries
    ML/TF risks
    1. Assessing ML/TF risk - Countries*Where appropriate, AML/CFT risk assessments at a supra-national level should be taken into account when considering whether this obligation is satisfied. should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. take appropriate steps to identify and assess the money laundering and terrorist financing risks for the countryAll references in the FATF Recommendations to country or countries apply equally to territories or jurisdictions., on an ongoing basis and in order to: (i) inform potential changes to the country’s AML/CFT regime, including changes to laws, regulations and other measures; (ii) assist in the allocation and prioritisation of AML/CFT resources by competent authoritiesCompetent authorities refers to all public authorities with designated responsibilities for combating money laundering and/or terrorist financing. In particular, this includes the FIU; the authorities that have the function of investigating and/or prosecuting money laundering, associated predicate offences and terrorist financing, and seizing/freezing and confiscating criminal assets; authorities receiving reports on cross-border transportation of currency & BNIs; and authorities that have AML/CFT supervisory or monitoring responsibilities aimed at ensuring compliance by financial institutions and DNFBPs with AML/CFT requirements. SRBs are not to be regarded as a competent authorities.; and (iii) make information available for AML/CFT risk assessments conducted by financial institutions and DNFBPs. Countries should keep the assessments up-to-date, and should have mechanisms to provide appropriate information on the results to all relevant competent authorities and self-regulatory bodies (SRBs), financial institutions and DNFBPs.
    2. Higher risk - Where countries identify higher risks, they should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. ensure that their AML/CFT regime addresses these higher risks, and, without prejudice to any other measures taken by countries to mitigate these higher risks, either prescribe that financial institutions Financial institutions means any natural or legal person who conducts as abusiness one or more of the following activities or operations for or on behalf of a customer:
      1) Acceptance of deposits and other repayable funds from the public.
      2) Lending.
      3) Financial leasing.
      4) Money or value transfer services.
      5) Issuing and managing means of payment (e.g. credit and debit cards,cheques, traveller's cheques, money orders and bankers' drafts, electronic money).
      6) Financial guarantees and commitments.
      7) Trading in:
      a) money market instruments (cheques, bills, certificates of deposit, derivatives etc.);
      b) foreign exchange;
      c) exchange, interest rate and index instruments;
      d) transferable securities;
      8) Participation in securities issues and the provision of financial services related to such issues.
      9) Individual and collective portfolio management.
      11) Otherwise investing, administering or managing funds or money on behalf of other persons.
      12) Underwriting and placement of life insurance and other investment related insurance.
      13) Money and currency changing.
      and DNFBPs take enhanced measures to manage and mitigate the risks, or ensure that this information is incorporated into risk assessments carried out by financial institutions and DNFBPs, in order to manage and mitigate risks appropriately. Where the FATF Recommendations identify higher risk activities for which enhanced or specific measures are required, all such measures must be applied, although the extent of such measures may vary according to the specific level of risk.
    3. Lower risk Countries may decide to allow simplified measures for some of the FATF Recommendations requiring financial institutions or DNFBPs to take certain actions, provided that a lower risk has been identified, and this is consistent with the country’s assessment of its money laundering and terrorist financing risks, as referred to in paragraph 3.

      Independent of any decision to specify certain lower risk categories in line with the previous paragraph, countries may also allow financial institutions and DNFBPs to apply simplified customer due diligence (CDD) measures, provided that the requirements set out in section B below (“Obligations and decisions for financial institutions and DNFBPs”), and in paragraph 7 below, are met.

    4. Exemptions Countries may decide not to apply some of the FATF Recommendations requiring financial institutions or DNFBPs to take certain actions, provided:
      1. there is a proven low risk of money laundering and terrorist financing; this occurs in strictly limited and justified circumstances; and it relates to a particular type of financial institution or activity, or DNFBP; or
      2. a financial activity (other than the transferring of money or value) is carried out by a natural or legal person on an occasional or very limited basis (having regard to quantitative and absolute criteria), such that there is low risk of money laundering and terrorist financing.

      While the information gathered may vary according to the level of risk, the requirements of Recommendation 11 to retain information should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. apply to whatever information is gathered.

    5. Supervision and monitoring of risk - Supervisors Supervisors refers to the designated competent authorities or non-public bodies with responsibilities aimed at ensuring compliance by financial institutions (“financial supervisors” 60Including Core Principles supervisors who carry out supervisory functions that are related to the implementation of the FATF Recommendations.) and/or DNFBPs with requirements to combat money laundering and terrorist financing. Non-public bodies (which could include certain types of SRBs) should have the power to supervise and sanction financial institutions or DNFBPs in relation to the AML/CFT requirements. These nonpublic bodies should also be empowered by law to exercise the functions they perform, and be supervised by a competent authority in relation to such functions. (or SRBs for relevant DNFBPs sectors) should ensure that financial institutions Financial institutions means any natural or legal person who conducts as abusiness one or more of the following activities or operations for or on behalf of a customer:
      1) Acceptance of deposits and other repayable funds from the public.
      2) Lending.
      3) Financial leasing.
      4) Money or value transfer services.
      5) Issuing and managing means of payment (e.g. credit and debit cards,cheques, traveller's cheques, money orders and bankers' drafts, electronic money).
      6) Financial guarantees and commitments.
      7) Trading in:
      a) money market instruments (cheques, bills, certificates of deposit, derivatives etc.);
      b) foreign exchange;
      c) exchange, interest rate and index instruments;
      d) transferable securities;
      8) Participation in securities issues and the provision of financial services related to such issues.
      9) Individual and collective portfolio management.
      11) Otherwise investing, administering or managing funds or money on behalf of other persons.
      12) Underwriting and placement of life insurance and other investment related insurance.
      13) Money and currency changing.
      and DNFBPs are effectively implementing the obligations set out below. When carrying out this function, supervisors Supervisors refers to the designated competent authorities or non-public bodies with responsibilities aimed at ensuring compliance by financial institutions (“financial supervisors” 60Including Core Principles supervisors who carry out supervisory functions that are related to the implementation of the FATF Recommendations.) and/or DNFBPs with requirements to combat money laundering and terrorist financing. Non-public bodies (which could include certain types of SRBs) should have the power to supervise and sanction financial institutions or DNFBPs in relation to the AML/CFT requirements. These nonpublic bodies should also be empowered by law to exercise the functions they perform, and be supervised by a competent authority in relation to such functions. and SRBs should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must., as and when required in accordance with the Interpretive Notes to Recommendations 26 and 28, review the money laundering and terrorist financing risk profiles and risk assessments prepared by financial institutions and DNFBPs, and take the result of this review into consideration.
    6. PF risk
    7. Assessing PF risk – Countries*Where appropriate, PF risk assessments at a supra-national level should be taken into account when considering whether this obligation is satisfied. should take appropriate steps to identify and assess the proliferation financing risks for the country, on an ongoing basis and in order to: (i) inform potential changes to the country’s CPF regime, including changes to laws, regulations and other measures; (ii) assist in the allocation and prioritisation of CPF resources by competent authorities; and (iii) make information available for PF risk assessments conducted by financial institutions and DNFBPs. Countries should keep the assessments up-to-date, and should have mechanisms to provide appropriate information on the results to all relevant competent authorities and SRBs, financial institutions and DNFBPs.
    8. Mitigating PF risk - Countries should take appropriate steps to manage and mitigate the proliferation financing risks that they identify. Countries should develop an understanding of the means of potential breaches, evasion and non-implementation of targeted financial sanctions present in their countries that can be shared within and across competent authorities and with the private sector. Countries should ensure that financial institutions and DNFBPs take steps to identify circumstances, which may present higher risks and ensure that their CPF regime addresses these risks. Countries should ensure full implementation of Recommendation 7 in any risk scenario. Where there are higher risks, countries should require financial institutions and DNFBPs to take commensurate measures to manage and mitigate these risks. Correspondingly, where the risks are lower, they should ensure that the measures applied are commensurate with the level of risk, while still ensuring full implementation of the targeted financial sanctions as required by Recommendation 7.
  2. Obligations and decisions for financial institutions and DNFBPs
    ML/TF risks
    1. Assessing MF/TF risks - Financial institutions and DNFBPs should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. be required to take appropriate steps to identify and assess their money laundering and terrorist financing risks (for customers, countries or geographic areas; and products, services, transactions or delivery channels). They should document those assessments in order to be able to demonstrate their basis, keep these assessments up to date, and have appropriate mechanisms to provide risk assessment information to competent authoritiesCompetent authorities refers to all public authorities with designated responsibilities for combating money laundering and/or terrorist financing. In particular, this includes the FIU; the authorities that have the function of investigating and/or prosecuting money laundering, associated predicate offences and terrorist financing, and seizing/freezing and confiscating criminal assets; authorities receiving reports on cross-border transportation of currency & BNIs; and authorities that have AML/CFT supervisory or monitoring responsibilities aimed at ensuring compliance by financial institutions and DNFBPs with AML/CFT requirements. SRBs are not to be regarded as a competent authorities. and SRBs. The nature and extent of any assessment of money laundering and terrorist financing risks should be appropriate to the nature and size of the business. Financial institutions and DNFBPs should always understand their money laundering and terrorist financing risks, but competent authorities or SRBs may determine that individual documented risk assessments are not required, if the specific risks inherent to the sector are clearly identified and understood.
    2. Risk management and mitigation - Financial institutions and DNFBPs should be required to have policies, controls and procedures that enable them to manage and mitigate effectively the risks that have been identified (either by the countryAll references in the FATF Recommendations to country or countries apply equally to territories or jurisdictions. or by the financial institution or DNFBP). They should be required to monitor the implementation of those controls and to enhance them, if necessary. The policies, controls and procedures should be approved by senior management, and the measures taken to manage and mitigate the risks (whether higher or lower) should be consistent with national requirements and with guidance from competent authorities and SRBs.
    3. Higher risk - Where higher risks are identified financial institutions and DNFBPs should be required to take enhanced measures to manage and mitigate the risks.
    4. Lower risk - Where lower risks are identified, countries may allow financial institutions and DNFBPs to take simplified measures to manage and mitigate those risks.
    5. When assessing risk, financial institutions and DNFBPs should consider all the relevant risk factors before determining what is the level of overall risk and the appropriate level of mitigation to be applied. Financial institutions and DNFBPs may differentiate the extent of measures, depending on the type and level of risk for the various risk factors (e.g. in a particular situation, they could apply normal CDD for customer acceptance measures, but enhanced CDD for ongoing monitoring, or vice versa).
    6. PF risk
    7. Assessing PF risk - Financial institutions and DNFBPs should be required to take appropriate steps, to identify and assess their proliferation financing risks. This may be done within the framework of their existing targeted financial sanctions and/or compliance programmes. They should document those assessments in order to be able to demonstrate their basis, keep these assessments up to date, and have appropriate mechanisms to provide risk assessment information to competent authorities and SRBs. The nature and extent of any assessment of proliferation financing risks should be appropriate to the nature and size of the business. Financial institutions and DNFBPs should always understand their proliferation financing risks, but competent authorities or SRBs may determine that individual documented risk assessments are not required, if the specific risks inherent to the sector are clearly identified and understood.
    8. Mitigating PF risk - Financial institutions and DNFBPs should have policies, controls and procedures to manage and mitigate effectively the risks that have been identified. This may be done within the framework of their existing targeted financial sanctions and/or compliance programmes. They should be required to monitor the implementation of those controls and to enhance them, if necessary. The policies, controls and procedures should be approved by senior management, and the measures taken to manage and mitigate the risks (whether higher or lower) should be consistent with national requirements and with guidance from competent authorities and SRBs. Countries should ensure full implementation of Recommendation 7 in any risk scenario. Where there are higher risks, countries should require financial institutions and DNFBPs to take commensurate measures to manage and mitigate the risks (i.e. introducing enhanced controls aimed at detecting possible breaches, non-implementation or evasion of targeted financial sanctions under Recommendation 7). Correspondingly, where the risks are lower, they should ensure that those measures are commensurate with the level of risk, while still ensuring full implementation of the targeted financial sanctions as required by Recommendation 7.

INTERPRETIVE NOTE TO RECOMMENDATION 12 (POLITICALLY EXPOSED PERSONS)

Financial institutions Financial institutions means any natural or legal person who conducts as abusiness one or more of the following activities or operations for or on behalf of a customer:
1) Acceptance of deposits and other repayable funds from the public.
2) Lending.
3) Financial leasing.
4) Money or value transfer services.
5) Issuing and managing means of payment (e.g. credit and debit cards,cheques, traveller's cheques, money orders and bankers' drafts, electronic money).
6) Financial guarantees and commitments.
7) Trading in:
a) money market instruments (cheques, bills, certificates of deposit, derivatives etc.);
b) foreign exchange;
c) exchange, interest rate and index instruments;
d) transferable securities;
8) Participation in securities issues and the provision of financial services related to such issues.
9) Individual and collective portfolio management.
11) Otherwise investing, administering or managing funds or money on behalf of other persons.
12) Underwriting and placement of life insurance and other investment related insurance.
13) Money and currency changing.
should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. take reasonable measures The term Reasonable Measures means: appropriate measures which are commensurate with the money laundering or terrorist financing risks. to determine whether the beneficiaries of a life insurance policy and/or, where required, the beneficial ownerBeneficial owner refers to the natural person(s) who ultimately owns or controls a customer and/or the natural person on whose behalf a transaction is being conducted. It also includes those persons who exercise ultimate effective control over a legal person or arrangement. of the beneficiaryThe meaning of the term beneficiary in the FATF Recommendations depends on the context:
- In trust law, a beneficiary is the person or persons who are entitled to the benefit of any trust arrangement. A beneficiary can be a natural or legal person or arrangement. All trusts (other than charitable or statutory permitted non-charitable trusts) are required to have ascertainable beneficiaries. While trusts must always have some ultimately ascertainable beneficiary, trusts may have no defined existing beneficiaries but only objects of a power until some person becomes entitled as beneficiary to income or capital on the expiry of a defined period, known as the accumulation period. This period is normally coextensive with the trust perpetuity period which is usually referred to in the trust deed as the trust period.
- In the context of life insurance or another investment linked insurance policy, a beneficiary is the natural or legal person, or a legal arrangement, or category of persons, who will be paid the policy proceeds when/if an insured event occurs, which is covered by the policy.
Please also refer to the Interpretive Notes to Recommendations 10 and 16.
are politically exposed persons Foreign PEPs are individuals who are or have been entrusted with prominent public functions by a foreign country, for example Heads of State or of government, senior politicians, senior government, judicial or military officials, senior executives of state owned corporations, important political party officials.
Domestic PEPs are individuals who are or have been entrusted domestically with prominent public functions, for example Heads of State or of government, senior politicians, senior government, judicial or military officials, senior executives of state owned corporations, important political party officials.
Persons who are or have been entrusted with a prominent function by an international organisation refers to members of senior management, i.e. directors, deputy directors and members of the board or equivalent functions.
The definition of PEPs is not intended to cover middle ranking or more junior individuals in the foregoing categories.
. This should For the purposes of assessing compliance with the FATF Recommendations, the word should has the same meaning as must. occur at the latest at the time of the payout. Where there are higher risks All references to risk refer to the risk of money laundering and/or terrorist financing. This term should be read in conjunction with the Interpretive Note to Recommendation 1. identified, in addition to performing normal CDD measures, financial institutions Financial institutions means any natural or legal person who conducts as abusiness one or more of the following activities or operations for or on behalf of a customer:
1) Acceptance of deposits and other repayable funds from the public.
2) Lending.
3) Financial leasing.
4) Money or value transfer services.
5) Issuing and managing means of payment (e.g. credit and debit cards,cheques, traveller's cheques, money orders and bankers' drafts, electronic money).
6) Financial guarantees and commitments.
7) Trading in:
a) money market instruments (cheques, bills, certificates of deposit, derivatives etc.);
b) foreign exchange;
c) exchange, interest rate and index instruments;
d) transferable securities;
8) Participation in securities issues and the provision of financial services related to such issues.
9) Individual and collective portfolio management.
11) Otherwise investing, administering or managing funds or money on behalf of other persons.
12) Underwriting and placement of life insurance and other investment related insurance.
13) Money and currency changing.
should be required to:

  1. inform senior management before the payout of the policy proceeds; and
  2. conduct enhanced scrutiny on the whole business relationship with the policyholder, and consider making a suspicious transaction report.