Home › Academy › Library › Guidelines on MLTF risk management and access…
Synthesis note · Guide

Guidelines on MLTF risk management and access to financial services.pdf

European Banking Authority (EBA) · 2023 · Guide · 34 pages · Intermediate

The EBA's guidelines aim to enhance the management of money laundering and terrorist financing (ML/TF) risks in financial institutions. They promote a balanced approach to avoid unjustified de-risking, which can harm access to financial services for vulnerable customers. These recommendations seek to establish effective policies and controls to manage ML/TF risks while ensuring access to financial products.

General Information

The document is a guide published by the European Banking Authority (EBA) in March 2023, entitled "Guidelines on policies and controls for the effective management of money laundering and terrorist financing (ML/TF) risks when providing access to financial services." It is a final report of 34 pages addressed to credit and financial institutions as well as competent authorities in the European Union. The scope covers the management of money laundering and terrorist financing (ML/TF) risks in the context of access to financial services, notably in connection with Directive (EU) 2015/849 and Directive (EU) 2014/92 on payment accounts with basic features. The document aims to frame policies, procedures, and controls to avoid unjustified de-risking, particularly for vulnerable clients, during the period contemporaneous to its publication.

Executive Summary

The guide addresses the phenomenon of de-risking, defined as the decision of financial institutions to refuse or terminate business relationships with clients or categories of clients considered at high ML/TF risk. This phenomenon, analyzed in an EBA Opinion of January 2022, can lead to unjustified financial exclusion, harming access to financial services and the fight against financial crime (p. 3-4). The importance of the subject lies in the need to balance effective ML/TF risk management and ensuring non-discriminatory access to financial services, notably for vulnerable populations such as asylum seekers (p. 4-5). The main findings are that generalized de-risking without individual risk assessment is inappropriate and that adapted measures must be implemented to manage ML/TF risks while ensuring financial inclusion (p. 3-5). Key recommendations include adopting policies and procedures differentiating risks by client, implementing proportionate mitigation measures before any refusal decision, mandatory documentation of refusal or termination decisions, and establishing accessible complaint mechanisms (p. 10-14, 22). The guide also specifies the adaptation of due diligence requirements for basic payment accounts and clients unable to provide traditional identification, in compliance with European legislation (p. 11-13). These guidelines aim to harmonize practices of institutions and supervisory authorities, with entry into force three months after publication in all official EU languages (p. 3, 10).

Context and Objectives

The guide was developed in response to a request from the European Commission following the EBA Opinion on de-risking published in January 2022, which highlighted the extent and negative effects of unjustified de-risking in the European Union (p. 4). The main challenge is to reconcile effective fight against money laundering and terrorist financing with clients' rights, notably the most vulnerable, to access essential financial services. The guide aims to clarify the obligations of financial institutions regarding ML/TF risk management, particularly in the context of opening and maintaining payment accounts with basic features (p. 4-5). It complements existing EBA guidelines on ML/TF risk factors by specifying policies, procedures, and controls to adopt to avoid systematic refusal of clients based on high-risk categories without individual assessment (p. 4, 9). The scope covers all financial institutions subject to Directive (EU) 2015/849 and AML/CFT supervisory competent authorities in the EU. Limitations include exclusion of issues related to proliferation financing, which are not covered by the European directive (p. 22).

Summary of Key Points by Theme

De-risking and ML/TF risk management:

- De-risking is defined as refusal or termination of business relationships with clients or categories at high ML/TF risk without appropriate individual assessment (p. 3, 9).

- The guide stresses the need for a differentiated approach, assessing risks at individual level, to avoid systematic refusals (p. 9-10).

Policies and procedures for due diligence (CDD):

- Institutions must adopt risk-sensitive policies, including clear criteria to reject or terminate a business relationship, first exploring all possible mitigation measures (p. 10-11).

- Mitigation measures include adjusting monitoring and applying targeted restrictions on products or services, respecting national law (p. 11).

Documentation and reporting:

- Any refusal or termination decision must be documented with reasons, and this documentation must be accessible to competent authorities (p. 13-14).

- Criteria for suspicion of ML/TF for reporting to financial intelligence units must be clearly defined in internal policies (p. 13).

Access to basic payment accounts:

- Institutions must adapt their CDD requirements for payment accounts with basic features, considering their limited functionality which reduces ML/TF risks (p. 15).

- Digital onboarding solutions must not generate automated discriminatory rejections (p. 15).

Vulnerable clients and alternative identification:

- The guide details procedures for clients unable to provide traditional identification, notably asylum seekers, refugees, homeless persons, or individuals whose expulsion is impossible (p. 12-13).

- Reliable alternative documents, issued by official authorities or recognized organizations, may be accepted, subject to national law (p. 12-13).

- Possibility to defer certain initial CDD measures in specific cases, notably for prepaid accounts (p. 13).

Targeted limitation of access to products and services:

- Institutions may apply proportionate restrictions on products or services, such as amount limits, number of transactions, bans on cash withdrawals from certain countries, considering the client’s personal situation (p. 13-14).

Complaint mechanisms:

- Institutions must inform refused clients of their right to appeal to competent authorities or alternative dispute resolution bodies, providing necessary contact details (p. 22, 33-34).

Public consultation and adjustments:

- The guide was subject to public consultation, with 25 responses received from financial institutions, associations, NGOs, and individuals (p. 20-34).

- Clarifications were made notably on reporting obligations, types of applicable restrictions, distinction between refugees and asylum seekers, and documentation of refusal decisions (p. 21-34).

- The guide covers all client types, including politically exposed persons and "accidental Americans," without creating specific sections for these categories (p. 19-20).

Compliance and implementation:

- Competent authorities must notify the EBA of their compliance within a set deadline after publication (p. 8).

- The guidelines apply three months after publication in all official EU languages (p. 10).

- They fit within the European regulatory framework, notably the AMLD and PAD directives, and complement existing EBA guidelines on ML/TF risk factors (p. 9).

Main Findings and Lessons Learned

Established facts:

- Generalized de-risking without individual risk assessment is common in the EU and leads to unjustified financial exclusion, notably for vulnerable populations (p. 4).

- Due diligence requirements can constitute an obstacle for some clients, notably those without traditional identity documents (p. 12).

- The right of access to a payment account with basic features is guaranteed by Directive 2014/92/EU but can be hindered by de-risking practices (p. 15).

Hypotheses:

- Adoption of differentiated policies and adapted mitigation measures will reduce unjustified de-risking while maintaining effective ML/TF risk management (p. 16-18).

- Systematic documentation of refusal decisions will facilitate supervision and defense of institutions (p. 18).

Author’s interpretations:

- A balanced approach between financial inclusion and risk management is possible and necessary (p. 4-5).

- Proposed measures will strengthen consistency of practices between institutions and supervisory authorities (p. 3).

Uncertainties:

- Practical implementation of mitigation measures and acceptance of alternative documents depend on national legislation (p. 12-13).

- The exact impact on operational costs of institutions is not quantified but considered acceptable given social benefits (p. 17, 31).

Conclusions and Recommendations

The EBA concludes that publishing these guidelines is necessary to reduce the negative effects of unjustified de-risking and improve equitable access to financial services, notably for vulnerable clients (p. 18-19). It recommends institutions implement detailed and risk-sensitive policies and procedures, including:

- Individual client risk assessment, avoiding categorical refusals (p. 9-10).

- Systematic exploration of mitigation measures before any refusal or termination decision (p. 11-12).

- Mandatory documentation of refusal or termination decisions and making these documents available to competent authorities (p. 14).

- Adaptation of due diligence requirements for basic payment accounts and clients without traditional identification, with acceptance of reliable alternative documents (p. 12-15).

- Establishment of accessible complaint mechanisms clearly communicated to clients (p. 22, 33-34).

Competent authorities must integrate these guidelines into their supervisory practices and notify their compliance to the EBA within the prescribed deadlines (p. 8). The guidelines will enter into force three months after their official publication in all EU languages (p. 10).

Key takeaways

References

Year
2023
Type
Guide
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/document_library/Public…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.