The Presidents/Chief Executives
All Banks/DFIs
Dear Sir/Madam,
Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) Regulations
Asset Side Customers
35. Banks/DFIs shall make comprehensive assessment of controls on asset products and related customers to ensure effective implementation of due diligence requirements as per their own assessment of materiality and risk without compromising on identity and verification requirements. This shall include monitoring of the customers and related risks on ongoing basis as per standard norms and best practices to mitigate the risks related to such products/ customers.
Compliance
9. Banks/DFIs shall incorporate procedures to record and maintain data of account opening cases rejected by compliance or central account opening units, the cases where customers’ risk ratings recommended by business units were challenged or revised, and the cases where accounts were closed based on ML/TF risks.
10. Banks/DFIs shall:
| (a) | in addition to oversight by Board, assign monitoring of compliance and AML/CFT function as term of reference to one of the Management Committees responsible for risk and control; | |
| (b) | include compliance and AML/CFT related responsibilities in Key Performance Indicators (KPIs) of responsible staff down the line, in order to strengthen the compliance/ AML/CFT function. Moreover, ML/TF risks should be included in KPIs of officer(s) responsible for Enterprise Risk Management and Operational Risk Management functions; | |
| (c) | not assign unrealistic business targets and conflicting roles to their employees. Appropriate strategies may be devised to ensure provision of safe and smooth banking services; and | |
| (d) | regularly assess working strength of the compliance function and all its sub-divisions and deficiency if any, observed should be addressed on priority basis. |
3. All banks/DFIs are also advised to complete their internal risk review of remaining legacy portfolio of customers who opened their bank accounts prior to introduction of revised AML/CFT framework in 2012 at the earliest but not later than December 31, 2017.
4. Besides, related policies and procedures shall also be brought in line with the above amendments in AML/CFT regulations at the earliest but not later than December 31, 2017.
5. In addition to the above, SBP has developed ‘Frequently Asked Questions (FAQs) on Use of Biometric Technology’ which are attached herewith for guidance purpose.
All other instructions on the subject shall remain unchanged.
Enclosed:
Yours sincerely,
AMJAD IQBAL
Additional Director