This document provides guidelines on customer due diligence and the factors that financial institutions should consider when assessing the risk of money laundering and terrorist financing. It also specifies how to adjust due diligence measures based on the identified risk. The guidelines apply to individual business relationships and occasional transactions, while allowing for other factors to be considered.
This document is a consolidated version of the guidelines (EBA/GL/2021/02) issued by the European Banking Authority (EBA) in 2023, applicable since 7 October 2021, with amendment in October 2023. It concerns the risk factors related to money laundering and terrorist financing (ML/TF) that credit and financial institutions must consider when assessing the risks associated with their business relationships and occasional transactions. The scope covers financial institutions subject to Directive (EU) 2015/849, particularly ML/TF risk assessments at both individual and global levels, as well as customer due diligence (CDD) measures. The document comprises 128 pages, of which approximately 45 pages were provided for this summary.
The EBA guide on ML/TF risk factors aims to strengthen the fight against money laundering and terrorist financing in the European financial sector. It details the obligations of financial institutions and competent authorities to identify, assess, and manage these risks in accordance with Directive (EU) 2015/849. The importance of this document lies in the need for a risk-based approach, adapted to the nature and complexity of institutions' activities, to ensure the integrity of the financial system. The main findings emphasize that institutions must conduct both global (business-wide) and individual (client or transaction) risk assessments, taking into account factors related to clients, countries, products, services, and distribution channels. These assessments must be documented, regularly updated, and integrated into AML/CFT policies. The guide stresses the need for due diligence proportionate to the identified risk level, ranging from simplified (SDD) to enhanced (EDD) measures, notably for politically exposed persons (PEPs), relationships with high-risk third countries, or unusual transactions. It also recommends avoiding systematic de-risking to preserve financial inclusion. Finally, the use of innovative technologies for identity verification is encouraged, subject to rigorous risk assessment. In conclusion, institutions must adopt proactive and proportionate ML/TF risk management, supported by robust control systems and appropriate governance, with strong involvement from senior management.
This guide was developed by the EBA to clarify and harmonize the practices of financial institutions and supervisory authorities in assessing and managing money laundering and terrorist financing risks. It responds to the legal requirement arising from Articles 17 and 18(4) of Directive (EU) 2015/849, aiming to strengthen customer due diligence and ML/TF risk prevention. The main challenge is to ensure consistent and effective application of AML/CFT measures within the European Union, taking into account the specificities of different types of institutions, products, clients, and geographical areas. The document aims to guide institutions in implementing a risk-based approach, proportionate to their profile and exposures. It covers enterprise-wide risk assessments, as well as individual assessments of business relationships and occasional transactions. The stated limitations notably exclude compliance with European financial sanctions, which falls under a different regulatory framework.
1. General principles of risk assessments:
- Institutions must understand ML/TF risks inherent to their business-wide activity and to each individual relationship or transaction (p. 7-11).
- Each assessment involves identifying risk factors and evaluating overall risk, including inherent risk and mitigation measures (p. 7).
- Assessments must be documented, regularly updated, and integrated into AML/CFT policies (p. 7-9).
2. Identification of ML/TF risk factors:
- Factors concern the client (activity, reputation, behavior), countries or geographical areas, products and services, as well as distribution channels (p. 13-23).
- Examples: clients operating in high-risk sectors (construction, arms), PEPs, high-risk jurisdictions, opaque or complex products, non-face-to-face relationships (p. 13-23).
3. Risk evaluation and weighting:
- Risk factors must be weighted according to their relative importance, without a single factor solely determining classification (p. 24).
- Institutions must understand and be able to explain their methodology, notably when using automated systems (p. 24-25).
4. Customer due diligence (CDD) measures:
- Mandatory application of CDD measures according to proportionality principle, adjusted to risk level (p. 25-26).
- Identification and verification of the client and beneficial owners, establishing the nature and purpose of the business relationship (p. 26-33).
- Use of simplified measures (SDD) in low-risk cases, under strict conditions, and enhanced measures (EDD) in high-risk cases (p. 33-41).
- Specific measures for PEPs, high-risk third countries, correspondent banking relationships, and unusual transactions (p. 36-40).
5. Financial inclusion and de-risking:
- Institutions must avoid systematic de-risking that would exclude entire categories of higher-risk clients (p. 26-27).
- Adaptation of measures for clients unable to provide traditional identity documents, e.g., asylum seekers (p. 26-27).
6. Innovative technologies:
- Possible use of technological solutions for identification and verification, subject to rigorous assessment of ICT, legal, fraud, and compliance risks (p. 31-32).
- Final responsibility remains with the institution even when using an external provider (p. 31-32).
7. Monitoring and updating:
- Ongoing monitoring of business relationships and transactions to detect anomalies (p. 41-42).
- Regular updating of client information and risk reassessment (p. 8, 41-42).
Findings:
- Institutions must perform ML/TF risk assessments at two levels: global and individual, considering a wide range of factors (p. 7-11, 13-23).
- CDD measures must be proportionate to identified risk, with specific obligations for high-risk cases (PEP, high-risk third countries, unusual transactions) (p. 33-41).
- The use of innovative technologies is permitted but regulated to ensure reliability and compliance (p. 31-32).
Assumptions:
- Weighting of risk factors relies on informed judgment and may vary by institution and context (p. 24-25).
- Simplified measures apply only when risk is deemed low and under strict conditions (p. 33-35).
Author interpretations:
- Generic or ill-adapted assessments do not meet regulatory requirements (p. 9-10).
- Systematic de-risking is discouraged as it harms financial inclusion (p. 26-27).
Uncertainties:
- The document does not cover compliance with European financial sanctions (p. 10).
- Sectoral guidelines (Title II) are not provided, limiting understanding of sector-specific details.
The EBA recommends that financial institutions adopt a comprehensive and proportionate risk-based approach to identify, assess, and manage ML/TF risks. Assessments must be specific to each institution, regularly updated, and integrated into AML/CFT policies. Customer due diligence measures must be adapted to the risk level, with strict application of enhanced measures in high-risk situations, notably for PEPs, high-risk third countries, and unusual transactions. Institutions must avoid systematic de-risking to preserve access to financial services. The use of innovative technologies for identity verification is encouraged, subject to rigorous risk assessment. Finally, internal governance must ensure strong senior management involvement, with adequate documentation and reporting to competent authorities. These recommendations aim to strengthen the resilience of the European financial system against ML/TF risks.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.