Home › Academy › Library › Guidelines on risk-based supervision -…
Synthesis note · Guide

Guidelines on risk-based supervision - consolidated version

European Banking Authority (EBA) · 2023 · Guide · 50 pages · Intermediate

This document presents guidelines on the risk-based approach to the supervision of anti-money laundering and countering the financing of terrorism. It outlines compliance and reporting obligations for competent authorities and financial institutions, as well as the steps to be taken during supervision. The guidelines should be integrated into the practices of competent authorities to ensure effective supervision in…

General Information

This document is the consolidated version of the Guidelines on risk-based supervision, published by the European Banking Authority (EBA) in 2023. It is a 50-page guide (only the first 33 pages are provided) specifying the characteristics of a risk-based supervision (RBS) approach in the context of anti-money laundering and counter-terrorist financing (AML/CFT). It is based on Article 48(10) of Directive (EU) 2015/849 and Regulation (EU) 2023/1113. The scope covers competent authorities supervising credit institutions and financial institutions in the European Union, focusing on the design, implementation, and improvement of RBS models for AML/CFT. The initial application date is 4 July 2022, with amendments planned until December 2024 (p. 1-6).

Executive Summary

This guide addresses the implementation of risk-based supervision in AML/CFT by European competent authorities. It is crucial as it harmonizes supervisory practices in the EU, strengthens the effectiveness of the fight against money laundering and terrorist financing, and meets the legal requirements of Directive (EU) 2015/849. The main findings are that AML/CFT supervision must be a continuous, cyclical process proportionate to the identified risk level, considering both inherent and residual risks. The guide defines an RBS model in four steps: risk factor identification, risk assessment, AML/CFT supervision, and model monitoring/review. It emphasizes the importance of grouping similar entities into clusters for collective supervision, while allowing individual assessment if significant risk differences appear. Cooperation between national and international authorities, including financial intelligence units, tax authorities, and law enforcement, is essential and must be rapid and effective. Information sources for risk identification are multiple, including national and supranational assessments, intelligence reports, and data from prudential supervision. Risk assessment must distinguish inherent from residual risks, considering mitigation measures implemented by entities. Supervision must be adapted in frequency, intensity, and nature according to the risk level, favoring on-site inspections for high-risk entities. The guide also recommends establishing a medium-term supervision strategy and plan, supported by a supervision manual detailing procedures and enabling consistent application of professional judgment. Finally, it highlights the importance of assessing the competence and integrity of AML/CFT compliance officers within supervised entities. Key recommendations are: apply a cyclical and proportionate RBS model, group entities into homogeneous clusters, strengthen inter-authority cooperation, use a wide range of supervision tools adapted to risk, and formalize supervision via a strategy, plan, and manual. These measures aim to improve detection and prevention of ML/TF risks in the European financial sector (p. 1-34).

Context and Objectives

This document was developed to specify the characteristics of a risk-based supervision approach in AML/CFT, in accordance with the requirements of Directive (EU) 2015/849 and Regulation (EU) 2023/1113. The objective is to harmonize the practices of European competent authorities, improve AML/CFT supervision effectiveness, and ensure consistent and proportionate application of anti-money laundering and counter-terrorist financing measures. The guide aims to frame the design, implementation, review, and improvement of RBS models, taking into account sector specificities, supervised entities, and identified risks. It also defines cooperation modalities between national and international authorities. The scope is limited to competent authorities supervising credit institutions and financial institutions in the EU, excluding non-financial sectors or other related areas. The document covers only the first 33 pages provided, limiting full coverage of the original 50 pages (p. 1-6).

Summary of Key Points by Theme

- Risk-Based Supervision (RBS) Model: The RBS model includes four key steps: identification of ML/TF risk factors, risk assessment, tailored AML/CFT supervision, and model monitoring/review. This process is continuous and cyclical, requiring regular updating (p. 7-8, 18-19).

- Proportionality: Supervision must be proportionate to the identified ML/TF risk level, regardless of entity size or systemic importance. Small institutions may present high risks and must be supervised accordingly (p. 7).

- Clustering: Authorities must identify clusters of entities sharing similar characteristics (size, activity, clientele, geographic area, distribution channels) and exposed to comparable risk levels. Entities with significant risk differences must be assessed individually or in a different cluster. Criteria include ownership structure, governance, significant changes in products or services (p. 7-9).

- Inter-Authority Cooperation: Rapid and effective cooperation between competent authorities, financial intelligence units, tax authorities, law enforcement, and foreign authorities is essential. It must rely on tools and measures provided by Directive (EU) 2015/849 and EBA guidelines. The objective is to ensure coherent and comprehensive AML/CFT supervision, especially for entities operating internationally (p. 9-10).

- Risk Factor Identification: Authorities must use a wide range of information sources (national and supranational assessments, FIU reports, supervisory data, public and private information, advanced analytical tools, regulatory notifications) to identify risk factors related to sectors, subsectors, clusters, and individual entities. Information must be sufficient, reliable, and adapted to the risk level (p. 10-13).

- Domestic and Foreign Risk Factors: Authorities must understand national ML/TF risks (typologies, scale, nature of offenses) and risks related to significant links with other Member States or third countries, notably those with strategic AML/CFT deficiencies according to international lists and reports (p. 13-14).

- Sectoral and Individual Risk Assessment: Authorities must conduct comprehensive sectoral assessments to prioritize supervision, then individual assessments for each entity, integrating inherent and residual risks. Residual assessment relies on the quality and effectiveness of mitigation measures implemented (p. 18-22).

- Risk Factor Weighting: Risk factors must be weighted according to their relative importance, avoiding dominance by a single factor. Automated scoring systems must be understood and validated by authorities (p. 22-23).

- Risk Categorization: Entities, sectors, and subsectors must be classified into four risk categories (less significant, moderately significant, significant, very significant) for inherent and residual risks, facilitating comparison and allocation of supervisory resources (p. 23-25).

- Supervision Strategy and Plan: Authorities must develop a medium-term AML/CFT strategy defining objectives, means, and timeline to mitigate identified risks, as well as an operational plan detailing implementation, resource allocation, and flexibility to integrate emerging risks (p. 26-28).

- Supervision Tools: A varied range of tools must be used according to risk, including on-site inspections (full or targeted), ad hoc inspections, off-site reviews, AML/CFT feedback, thematic inspections, and follow-ups. On-site inspections are preferred for high-risk entities, allowing in-depth evaluation of systems, procedures, culture, and governance (p. 28-31).

- Supervision Manual: An AML/CFT manual must formalize procedures, methodologies, evaluation criteria, inter-authority cooperation, and application modalities of supervision tools, while allowing room for supervisors' professional judgment. It must also provide for assessment of AML/CFT compliance officers, notably their integrity and competence, with cooperation with prudential supervisors if necessary (p. 31-34).

Main Findings and Lessons Learned

- Findings: Risk-based AML/CFT supervision is a continuous, cyclical, and proportionate process requiring in-depth understanding of inherent and residual risks at sectoral, cluster, and individual levels. Inter-authority cooperation is indispensable. Supervision tools must be adapted to risk level, with preference for on-site inspections for high-risk entities. A formalized supervision manual is necessary to ensure consistency and flexibility. Assessment of AML/CFT compliance officers is a key supervision element.

- Assumptions: The quality and reliability of collected data are sufficient to conduct relevant risk assessments. Entities provide necessary information and cooperate with authorities. Automated scoring tools accurately reflect real risks.

- Interpretations: Weighting of risk factors and categorization into four levels enable efficient allocation of supervisory resources. Clustering optimizes collective supervision while allowing individual assessment in case of discrepancies. Supervision must be independent from prudential or conduct assessments, focused on ML/TF risks.

- Uncertainties: Data on mitigation measures may be insufficient or unreliable, limiting residual risk assessment. Effectiveness of inter-authority cooperation may vary by jurisdiction. Impact of emerging technologies (e.g., DLT) on ML/TF risks requires increased vigilance. Limits of remote supervision (virtual inspections) remain to be evaluated.

Conclusions and Recommendations

The EBA recommends competent authorities adopt and implement a risk-based AML/CFT supervision model structured in four steps: risk factor identification, risk assessment, tailored supervision, and continuous monitoring. It is essential that supervision be proportionate to risk level, that entities be grouped into homogeneous clusters except in special cases, and that inter-authority cooperation be strengthened and systematic. Authorities must develop a medium-term supervision strategy and plan, supported by a detailed manual ensuring supervision consistency and flexibility. Use of a diversified range of supervision tools, favoring on-site inspections for high-risk entities, is recommended. Regular assessment of AML/CFT compliance officers' competence and integrity is also advised, with coordination with prudential supervisors. These measures must be implemented within set deadlines, with mandatory reporting to the EBA on guideline compliance. The approach must remain dynamic to integrate emerging risks and adapt resources accordingly (p. 1-34).

Key takeaways

References

Year
2023
Type
Guide
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2023-11/6fa613c3-54cd-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.