“(1) Paragraph (2) applies if a designated supervisory authority considers that another person who was at the material time an officer of P was knowingly concerned in a contravention of a relevant requirement by P. (2) The designated supervisory authority may impose one of the following measures on the person concerned— (a) a temporary prohibition on the individual concerned holding an office or position involving responsibility for taking decisions about the management of a relevant person or a payment service provider (“having a management role”); (b) a permanent prohibition on the individual concerned having a management role.” (a) a temporary prohibition on the individual concerned holding an office or position involving responsibility for taking decisions about the management of a relevant person or a payment service provider (“having a management role”); (b) a permanent prohibition on the individual concerned having a management role.”
“We are agreed that: 1) There are material errors in SAJ04; 2) As a result of those material errors, HMRC cannot and do not rely on SAJ04 or the alleged failures within the Table of Failures based on SAJ04; and 3) The Appellants have not had an opportunity to recheck the remaining schedules/spreadsheets produced by SAJ to see if similar failures permeate those spreadsheets.”
“Officer Simon Allington-Jones carried out analysis of the transactional data from1 September 2018 to31 August 2020 for both the agent and aggregator data provided by BSEL. The purpose of this was to assess whether BSEL had established and maintained PCPs to effectively mitigate and manage the risks of MLTF as required by regulation 19(1)(a). Full details of the testing carried out can be found in the witness statement of Officer Allington-Jones.”
“No PCPs in place to mitigate the risks surrounding customers using agents not local to their residential address. Analysis of the transactional data for the period1 September 2019 to31 August 2020 identified transactions totalling£4,189,281 where even the first two digits of the customer postcode and agent postcode did not match.”
“[Mr Furnival] said that he needs to consider the needs of the business alongside the regulatory requirements and needs to be on an equal footing with similar businesses in the market.”
“[BSEL] is very very keen to be super compliant, but we are also concerned that where we are in the market we are on an equal playing field with our competitors if you like. So there's a level playing field in terms of the way the regulations are applied in the way they are interpreted etcetera.”
“Whether a departure from the principle of open justice was justified in any particular case would depend on the facts of that case…the court has to carry out a balancing exercise which will be fact-specific. Central to the court’s evaluation will be the purpose of the open justice principle, the potential value of the information in question in advancing that purpose and, conversely, any risk of harm which its disclosure may cause to the maintenance of an effective judicial process or to the legitimate interests of others.”
“The Tribunal may make an order prohibiting the disclosure or publication of— (a) specified documents or information relating to the proceedings; or (b) any matter likely to lead members of the public to identify any person whom the Tribunal considers should not be identified.”
“ultimately accountable for the management of compliance and risk in BSEL and is responsible for ensuring adequate and effective compliancepractices and internal controls exist. The Board shall, under the direction of the Chairperson of the Board, be responsible for: • Oversight on the general conduct of the operations of BSEL• Oversight on the maintenance of compliance and internal controls.”
“The job of the MLRO is to act as the focal point within the relevant firm for the oversight of all activity relating to anti-money laundering. He needs to be senior, to be free to act on his own authority and to be informed of any relevant knowledge or suspicion in the relevant firm. In turn he has to pass on issues to NCIS as he thinks appropriate.”
“to provide assurance on the adequacy and effectiveness of the company’ssystem of internal controls…RAC is responsible for understanding BSEL’s major risk areas and ensuring that appropriate internal controls are in place to manage the risk exposures. Additionally, the RAC is responsible for the monitoring of control process and the adequacy of the system of internal control and compliance framework by reviewing internal and external audit reports.”
“An agent for [named aggregator] attempted to fraudulently bypass our controlling measures by employing multiple IDs in an attempt to remit to a large number of beneficiaries. This matter is being investigated by the Compliance department, which will provide further information at an appropriate stage. The fraud attempt was averted, which did NOT allowthe funds to leave the country. Subsequently, the aggregator [name] has offboarded the agent.”
“Overall, BSEL maintains adequate CDD procedures that align with UK regulatory requirements and facilitate the identification of all customers and agents at the time of entering into a business relationship or undertaking an occasional transaction. The ‘Comprehensive Policies and Procedures to Mitigate Compliance and Operational Risks’ document (“Comprehensive P&Ps”) provides clear guidance on the CDD requirements for both standard and enhanced due diligence of customers…Every transaction is risk rated according to the CDD thresholds outlined in the Comprehensive P&Ps. The CDD thresholds are clearly defined, and the documentation required for each category (Low, Medium and High) is commensurate with the level of risk associated with that particular transaction… BSEL has appropriate EDD requirements for high risk transactions that ensure that additional work is done to verify the identity of the customer and scrutinise the nature of the transaction. In addition, all transactions are screened for the involvement of PEPs (sender and beneficiary) by Remit ERP, BSEL’s core transaction processing system, and EDD measures are applied accordingly where there is a positive hit.”
“The EU’s Fourth Anti-Money Laundering Directive (4AMLD) was introduced on June 25th 2015 and introduced an explicit legislative requirement to perform an AML/CTF risk assessment. 4AMLD wastransposed into UK law by theMoney Laundering Regulations 2017 s.18, which requires firms to take appropriate steps to identify and assess the risks of money laundering and terrorist financing to which its business is subject. Such risk assessments must also be in writing and kept up to date. The main purpose of an Enterprise-Wide Risk Assessment (EWRA) is to drive improvements in risk management by identifying the financial crime risks faced by BSEL. This is completed by determining how these risks are mitigated by controls; establishing the residual risk that remains; and defining the further actions that are required to mitigate unacceptable risk exposures. The risk assessment process detailed below has been tailored to fit the BSEL’s specific business model and FCC risk exposure, specifically acknowledging the high-risk nature of remitting cross border transactions to beneficiaries situated in high-risk jurisdictions. From an inherent risk perspective, BSEL’s FCC risk assessment process and scoring methodology are focused on developing a granular understanding of specific areas of risk exposure within the customer base, as well as developing understanding of the geographical risks and product / service risks posed by the financial activities/transactions of this customer base.”
“Over the last 12 months, less than 5% of customer transactions were ratedHigh risk (transaction value over£8500 or cumulative transaction value over a six month period is higher than£8500 ) and were therefore subject to EDD.”
“BSEL’s geographical risk exposure is more significant, as it provides payment services to the following countries: Bangladesh, Pakistan, Sri Lanka, and India. In October 2018, HMT published two statements identifying jurisdictions with strategic deficiencies in their AML/CTF regimes. These countries included both Pakistan and Sri Lanka, so both countries are considered as high risk. While Bangladesh is no longer on the FATF AML deficient countries list, it is exposed to significant terrorist financing risk, predominantly from domestic terrorist groups, with a number of attacks occurring in recent years, and is therefore considered as a high-risk country from a CTF perspective. In general to assess country risk BSEL should take into account the HMT Advisory Notice on higher risk jurisdictions, FATF guidance on AML deficient countries, whether the country is sanctioned or is in close proximity to sanctioned countries, and Transparency International’s Corruption Perception Index (CPI). For distribution risk, BSEL operates a large agent network that requires significant oversight through CDD, ongoing RM visits and the completion of annual training. To demonstrate that BSEL faces a higher level of geographic and distribution risk, more weighting has been applied to these risk categories. If the weightings are adjusted at any point in the future, the responsible individual (i.e. MLRO) will provide and document sufficient justification for the amendment, which must be approved by the Risk and Audit Committee.”
“Where control assessment reviews indicate that the controls are operating effectively and do not identify any findings, the residual risk rating should be lower than the inherent risk rating. Where reviews identify substantive findings on specific controls, and the findings remain open any reduction to the residual risk rating due to those controls are not applicable.”
“These system enhancements demonstrate BSEL’s commitment to investment in their technology and continued refinement of their financial crime compliance framework. As evidenced in the Business Requirements document 2017, BSEL have been proactive in analysing their systems and controls requirements to identify enhancements and new functionality such as the risk matrix that has delivered additional automation, which has increased the effectiveness and sustainability of the financial crime controls within their core processing platform.”
“In the last five months, BSEL has continued to develop its RiskAssessment Matrix by classifying the risk of various transaction scenarios andconfiguring these scenarios to trigger alerts in the Remit ERP system...The current iteration of the Risk Assessment Matrix contains specific details on how the scenarios are configured, and what controls are in place to mitigate high risk scenarios and alerts.”
“The scoring methodologies underlying BSEL’s FCC risk assessment process reflect that it is exposed to its highest levels of inherent AML risk through its agent network and the jurisdictions to which it remits funds (Bangladesh, Pakistan, Sri Lanka and Nepal). For the inherent risk categories, additional weighting has therefore been applied to Distribution Risk and Geographic Risk. These risks need to be managed through a rigorous client due diligence process (especially for agents), and robust transaction monitoring systems and investigations processes. For control effectiveness, additional weighting has been applied to the controls required to mitigate the distribution and geographic risks posed by BSEL’s business operations (CDD for agents, CDD for retail customers, transaction monitoring and sanctions screening). These underlying assumptions will need to be reassessed as part of the planning process for the next iteration of the FCC risk assessment process, when BSEL’s business activities during the intervening period can be analysed to determine whether revisions to this methodology are required”
“Given the control framework in place, BSEL has assessed its residual risk of facilitating money laundering and CTF as MEDIUM. This is based on the overall inherent risk posed by its customer type, jurisdiction, transaction type, products and services and delivery channel risks having been assessed as MEDIUM and the effectiveness of its control framework having been assessed as averaging 'EFFECTIVE'.”
“This audit focused on BRAC Saajan Exchange Limited’s (‘BSEL’) AML, CTF and sanctions control framework. We conducted a review of relevant policies and procedures in order to assess the effectiveness of the controls which BSEL has implemented to mitigate its risk of money laundering and/or terrorist financing. In order to determine whether BSEL is compliant with its legal and regulatory requirements, we conducted a review of relevant policies, procedures and systems against legal requirements set out in the legislation and guidance, detailed at page 8 of this report. In our opinion, BSEL has sufficient controls in place to ensure that it complies with legal requirements imposed upon it from an AML/CTF and sanctions perspective. We are of the opinion that BSEL is complying with its legal and regulatory obligations pursuant to the MLR 2017 and the majority of the recommendations made in this report are generally to reflect best practice. We identified four recommendations of medium priority, and in our opinion these recommendations should be implementable by BSEL within a relatively short timeframe.”
“In accordance with Regulation 18 MLR 2017, the EWRA addresses customer, geographical, product, delivery channel and transaction risks. Risk areas have been identified for each risk type and a scoring methodology is clearly illustrated in respect of inherent risk, control effectiveness and the overall residual risk. The EWRA also details other risks which the business faces to include (but not limited to) fraud, regulatory risk, business disruption,data security, IT security, currency risk, market risk, liquidity risk and reputation risk. Upon considering the EWRA, we would recommend re-classifying transaction risk given that the majority of transactions are conducted in cash and this presents a higher risk of money laundering, irrespective of the average transaction amount.”
“I, David M Kirby acting as the UK MLRO and approved by HMRC as the appointed person under theMoney Laundering Regulations 2017 is exercising my authority to act honestly, reasonably and with independent judgment in assessing and determine the risks presented to BSEL. I have determined that the measures detailed above have been implemented by applying additional elements of due diligence to mitigate the risks in relation to high risk third countries. The measures have been determined as adequate and proportionate to meet the new requirements and obligations, as provided under Part 3: customer due diligence of ‘The Money Laundering and Terrorist Financing (Amendment) Regulations 2019 ’.”
“[BSEL] is very keen to be super compliant, but we are also concerned that where we are in the market we are on an equal playing field with our competitors if you like. So there's a there's a level playing field in terms of the way the regulations are applied in the way they are interpreted etcetera.”
“ZK said EDD should be applied to remittances to high-risk jurisdictions (HRJs) and should go above and beyond normal customer due diligence (CDD). For example, verifying source of funds (SOF) in a high-risk situation. ZK continued and said it does not necessarily mean SOF must be appliedon every transaction. ZK said it does mean you have to go beyond the standardrequirements and for EDD to be meaningful source of funds verification is the most relevant. [BSEL] need to consider what else you are going to establish; including, asking for the purpose of the transaction.”
“To examine and evaluate the adequacy and effectiveness of the policies, controls and procedures adopted to comply with the MLR 2017 (as amended by the) MLR 2019; and make recommendations in relation to those policies, controls and procedures.”
“This audit focused on BRAC Saajan Exchange Limited’s (“BSEL”) AML, CTF and sanctions control framework. We conducted a review of relevant policies and procedures in order to assess the effectiveness of the controls which BSEL has implemented to mitigate its risk of money laundering and/or terrorist financing. In order to determine whether BSEL is compliant with its legal and regulatory requirements, we conducted a review of relevant policies, procedures and systems against legal requirements set out in the legislation and guidance, detailed at page 9 of this report. With the exception of our one high priority recommendation, we are of the opinion that BSEL is complying with its legal and regulatory obligations pursuant to the MLR 2017 (as amended by MLR 2019) and the majority of the recommendations made in this report are generally to reflect best practice. We identified one recommendation of high priority, which should be dealt with by BSEL on an urgent basis. We identified 3 recommendations of medium priority, and in our opinion these recommendations should be implementable by BSEL within a relatively short timeframe.”
“Bangladesh, which previously rated as a high-risk country in the March 2020 enterprise-wide risk assessment, has been downgraded to medium risk. The previous assessment of the country was made on the basis of FATF’s assessment of 2016, when Bangladesh was asked to implementrecommendations for the improvement of its AML regime. Since then, there have been three updates, August 2019 being the most recent one, where Bangladesh has been assessed by FATF as fully compliant / mostly compliant on most of the recommendations (the link below refers). Additionally,Bangladesh is also not on the European Union list of high risk third countries.”
“The Business has revised its Risk Assessment (RA) and Policies, Controls and Procedures (PCP). The updated RA and PCP address the specific points detailed within the Suspension Notice and the Business has also provided assurances and evidence that the updated PCP have been fully implemented throughout the Business and its agent network. As such, I am satisfied that the Business is a fit and proper person under Regulation 58(1). As a result, the registration of the Business has been reinstated with effect from13 November 2020 . This decision is specifically in relation to the Regulations and associated risks detailed in the Suspension Notice of22 October 2020 , it should not be taken as acceptance that the Business is fully compliant with its obligations under the Regulations or that it will be able to demonstrate compliance in the future. In addition, please be aware that my ongoing review of the Business’s current and historical compliance with the Regulations will continue and this could result in further sanctions, including where appropriate a financial penalty.”
“We are of the opinion that BSEL is complying with its legal and regulatory obligations pursuant to MLR 2017 (as amended by MLR 2019), subject to one audit finding relating to EDD requirements. The remaining 21 recommendations included in the report were made to reflect recent guidance and best practice only. With regard to EDD, we recommended that BSEL should amend its procedures as a priority in order to comply with Regulation 33 MLR 2017 (as amended by Regulation 5 MLR 2019). In particular, we noted that BSEL must apply EDD measures as stipulated by the aforementioned regulations for all funds transfers exceeding 1,000 Euros in respect of any High Risk ThirdCountry (“HR3C”) it transacted with. Since the audit, we can confirm that BSEL has taken steps to comply with these requirements set out above by amending its Compliance Policy to apply EDD for all funds transfers, regardless of the transfer amount, in respect of customer transactions to/from any HR3C; introducing a beneficiary identifier process, including a new policy of refusing to accept beneficiaries from HR3C as customers; requiring verification of the occupation and income of customers wishing to send money to a HR3C; and refreshing the ID and address verification of active customers transacting with an HR3C on a six-monthly basis rather than annually.”
“From the material I inspected, I formed the impression that excellent and very in-depth due diligence is carried out on all agents, all to the same high standard. Furthermore, BSEL keep excellent records which record the due diligence undertaken.”
“I was able to verify that the high level of customer due diligence described to me at this stage of the inspection, was actually in place. In my opinion, Brac Sajaan have one of the best operational approaches to compliance and due diligence that I have seen during my time working with the Choice Group.”
“This Regulation is not intended to impose unnecessary burdens or costs on payment service providers or on persons who use their services. In this regard, the preventive approach should be targeted and proportionate.”
“The risk of money laundering and terrorist financing is not the same in every case. Accordingly, a holistic, risk based approach should be used. The risk-based approach is not an unduly permissive option for Member Statesand obliged entities. It involves the use of evidence-based decision-making in order to target the risks of money laundering and terrorist financing facing the Union and those operating within it more effectively.”
“Directive (EU) 2015/849 of the European Parliament and of the Council constitutes the main legal instrument in the prevention of the use of the Union financial system for the purposes of money laundering and terrorist financing. That Directive…sets out an efficient and comprehensive legal framework for addressing the collection of money or property for terrorist purposes by requiring Member States to identify, understand and mitigate the risks related to money laundering and terrorist financing.”
“Recent terrorist attacks have brought to light emerging new trends, in particular regarding the way terrorist groups finance and conduct their operations…In order to keep pace with evolving trends, further measures should be taken to ensure the increased transparency of financial transactions…with a view to improving the existing preventive framework and to more effectively countering terrorist financing. It is important to note that the measures taken should be proportionate to the risks.”
“While the aims of Directive (EU) 2015/849 should be pursued and any amendments to it should be consistent with the Union’s ongoing action in the field of countering terrorism and terrorist financing, such amendments should be made having due regard to the fundamental right to the protection of personal data, as well as the observance and application of the proportionality principle.”
“…recognising that not all cross border correspondent banking services present the same level of money laundering and terrorist financing risks, the intensity of the measures laid down in this Directive can be determined by application of the principles of the risk based approach and do not prejudge the level of money laundering and terrorist financing risk presented by the respondent financial institution.”
“There are over 100,000 businesses within scope of the MLRs, requiring businesses to know their customers and manage their risks. The MLRs are deliberately not prescriptive, providing flexibility in order to promote a proportionate and effective risk based approach to combating money laundering and terrorist financing.”
“Given the large remittance and business links between Pakistan and the UK, both countries are exposed to this corridor being abused for money laundering or terrorist financing. There is a risk of criminal groups exploiting these links to facilitate money laundering, particularly the laundering of the proceeds of corruption, fraud and drug trafficking. Criminals have exploited tools including MSBs, cash smuggling, front businesses, trade based money laundering and property to launder funds both from the UK to Pakistan and vice versa.”
“Cash is inherently high risk due to it being untraceable, readily exchangeable and anonymous… use of cash remains a high risk for both money laundering and terrorist financing.”
“The MSB sector encompasses a range of services relating to the transmission or conversion of funds, including money transmission services, foreign exchange and cheque cashing. The sector is highly diverse, with providers ranging from local convenience stores offering remittance services to large multinational corporations and web-based businesses providing peer-to-peer money transfers. MSBs play an important function in many communities by providing financial services to those without access to banking services. Cross-border remittances facilitated by MSBs have also been shown to play a key role in supporting economic development within developing countries.”
“the largest principal MSBs have sophisticated compliance and systems, HMRC considers that other businesses do not allocate sufficient resource to AML/CTF policies and controls.”
“There is evidence of MSBs seeking to register with banks as different cash- rich businesses or routing their business through third party accounts and other MSBs. HMRC has also found strong evidence that the principal-agent relationship is being exploited to launder criminal funds, including through businesses becoming agents of well-known money transmitters while operating their own separate systems for illicit transactions.”
“The 2015 NRA identified key terrorist financing risks within the MSB sector as complicit employees involved in remitting funds destined for terrorists, terrorist exploitation of the CDD threshold, and low reporting from the sector in relation to terrorist financing. While the due diligence threshold has been lowered from€1,000 to€0 through the Funds Transfer Regulation 2017, the general risks in the sector remain. The low cost of transferring funds and the ability to reach a wide number of jurisdictions linked to terrorism continue to make MSBs an attractive method for moving terrorist funds in small volumes.”
“A risk-based approach is where you assess the risks that your business may be used for money laundering or terrorist financing, and put in place appropriate measures to manage and lessen those risks. An effective risk-based approach will identify the highest risks of money laundering and terrorist financing that your business faces, and put in place measures to manage these risks.”
“A risk-based approach should balance the costs to your business and customers with a realistic assessment of the risk that your business may be exploited for the purpose of money laundering and terrorist financing. It allows you to use your informed judgement to focus your efforts on the highest-risk areas and reduce unnecessary burdens on customers presenting alimited risk of money laundering and/or terrorist financing.”
“The following is an example list of common risk indicators that call for enhanced due diligence. It's not an exhaustive list, and neither are these signs always suspicious. It depends on the circumstances of each case.”
“• there's no apparent reason for a customer using your business's services, for example, another business is better placed to handle the size of transaction or the destination of the transmission; • non face-to-face customers; • the customer sends or receives money to or from himself; • agents who undertake business outside normal business hours; • agents who carry out transactions too fast to be possible; • multiple money service business premises operating in very small area.”
“Where the beneficiary of a money transmission is in a high risk country you should do enhanced due diligence checks on your customer. To help you decide if you're sending money to a high-risk country, FATF and the EC publish a list of high risk and non-cooperative countries.”
“Firms should note that the following risk factors are not exhaustive, nor is there an expectation that firms will consider all risk factors in all cases. Firms should take a holistic view of the risk associated with the situation and note that, unless Directive (EU) 2015/849 [4MLD] or national legislation states otherwise, the presence of isolated risk factors does not necessarily move a relationship into a higher or lower risk category.”
“34. Firms should take a holistic view of the ML/TF risk factors they have identified that, together, will determine the level of ML/TF risk associated with a business relationship or occasional transaction. 35. As part of this assessment, firms may decide to weigh factors differently depending on their relative importance. 36. When weighting risk factors, firms should make an informed judgement about the relevance of different risk factors in the context of a business relationship or occasional transaction. This often results in firms allocating different ‘scores’ to different factors; for example, firms may decide that a customer’s personal links to a jurisdiction associated with higher ML/TF risk is less relevant in light of the features of the product they seek. 37. Ultimately, the weight given to each of these factors is likely to vary from product to product and customer to customer (or category of customer) and from one firm to another.”
“The Management Committee (MANCOM) meets monthly and is a key sub-committee which ensures that all department heads are aware of and cancontribute to any areas of risk, opportunity or challenge which the company is facing.”
“The terms of reference for the RAC should be extended toinclude a suitably senior member of the business. A good candidate forinclusion would be incoming the Chief Operating Officer [sic] who is expected to be appointed soon. This will help to ensure that the business, which ultimately owns the financial crime risk, is properly represented at the RAC.”
“We have been in the process of getting myself registered but I believe there have been some queries we have gone back to HMRC with and are yet awaiting a response from them.”
“a business, professional or commercial relationship between a relevant person and a customer, which— (a) arises out of the business of the relevant person, and (b) is expected by the relevant person, at the time when contact is established, to have an element of duration.”
“A relevant person must apply customer due diligence measures if the person— (a) establishes a business relationship; (b) carries out an occasional transaction that amounts to a transfer of funds within the meaning of Article 3.9 of the funds transfer regulation exceeding 1,000 euros; (c) suspects money laundering or terrorist financing; or (d) doubts the veracity or adequacy of documents or information previously obtained for the purposes of identification or verification.”
“(1) This regulation applies when a relevant person is required by regulation 27 to apply customer due diligence measures. (2) The relevant person must— (a) identify the customer unless the identity of that customer is known to, and has been verified by, the relevant person; (b) verify the customer's identity unless the customer's identity has already been verified by the relevant person; and (c) assess, and where appropriate obtain information on, the purpose and intended nature of the business relationship or occasional transaction.” (a) identify the customer unless the identity of that customer is known to, and has been verified by, the relevant person; (b) verify the customer's identity unless the customer's identity has already been verified by the relevant person; and (c) assess, and where appropriate obtain information on, the purpose and intended nature of the business relationship or occasional transaction.”
“• another money service business is your customer • you set up a customer account • there's a contract to provide regular services • you give preferential rates to repeat customers • any other arrangement [which] facilitates an ongoing business relationship or repeat custom, such as providing a unique customer identification number for the customer to use.”
“(1) A relevant person may rely on a person who falls within paragraph (3) (‘the third party’) to apply any of the customer due diligence measures required by regulation 28(2) to (6) and (10) but, notwithstanding the relevant person's reliance on the third party, the relevant person remains liable for any failure to apply such measures. (2) When a relevant person relies on the third party to apply customer due diligence measures under paragraph (1) it— (a) must immediately obtain from the third party all the information needed to satisfy the requirements of regulation 28(2) to (6) and (10)…in relation to the customer, customer's beneficial owner, or any person acting on behalf of the customer; (b) must enter into arrangements with the third party which— (i) enable the relevant person to obtain from the third party immediately on request copies of any identification and verification data and any other relevant documentation on the identity of the customer, customer's beneficial owner, or any person acting on behalf of the customer; (ii) require the third party to retain copies of the data and documents referred to in paragraph (i) for the period referred to in regulation 40. (3) The persons within this paragraph are— (a) another relevant person who is subject to these Regulations under regulation 8;…” (a) must immediately obtain from the third party all the information needed to satisfy the requirements of regulation 28(2) to (6) and (10)…in relation to the customer, customer's beneficial owner, or any person acting on behalf of the customer; (b) must enter into arrangements with the third party which— (i) enable the relevant person to obtain from the third party immediately on request copies of any identification and verification data and any other relevant documentation on the identity of the customer, customer's beneficial owner, or any person acting on behalf of the customer; (ii) require the third party to retain copies of the data and documents referred to in paragraph (i) for the period referred to in regulation 40. (a) another relevant person who is subject to these Regulations under regulation 8;…”
“Reliance is where BSEL may agree to rely on the CDD undertaken by a thirdparty. Where appropriate, BSEL may rely on a third party to conduct CDD on BSEL’s part. Any agreement must be in writing and the requirements are set out in the regulations. The third party must consent to being relied upon.In these circumstances, BSEL continues to be liable for any failure in relation to CDD/EDD. i.e. BSEL can outsource responsibility, but not accountability.”
“The legal basis of the relationship and responsibilities of the parties aredetailed in the Aggregator Agreement and are subject to the law of agencyin England and Wales.”
“The use of the agency model is widespread in the MSB sector. Law of Agency applies - where the agent is authorised to act on behalf of the principal. The arrangements between the agent/aggregator and the principal is set outin an agency/aggregator agreement. An agent/aggregator who acts within the scope of authority conferred by their principal binds the principal in the obligations the agent/aggregator creates with third parties. The agent/aggregator binds the principal to perform the service the customer has paid for.”
“(1) A relevant person must— (a) establish and maintain policies, controls and procedures to mitigate and manage effectively the risks of money laundering and terrorist financing identified in any risk assessment undertaken by the relevant person under regulation 18(1);… …. (3) The policies, controls and procedures referred to in paragraph (1) must include— (a)-(b)…; (c) customer due diligence (see regulations 27 to 38);… (4) … (5) In determining what is appropriate or proportionate with regard to the size and nature of its business, a relevant person may take into account any guidance which has been— (a) issued by the FCA; or (b) issued by any other supervisory authority or appropriate body and approved by the Treasury….” (a) establish and maintain policies, controls and procedures to mitigate and manage effectively the risks of money laundering and terrorist financing identified in any risk assessment undertaken by the relevant person under regulation 18(1);… (a)-(b)…; (c) customer due diligence (see regulations 27 to 38);… (a) issued by the FCA; or (b) issued by any other supervisory authority or appropriate body and approved by the Treasury….”
“Firms should take a holistic view of the risk associated with the situation and note that, unless Directive (EU) 2015/849 or national legislation states otherwise, the presence of isolated risk factors does not necessarily move a relationship into a higher or lower risk category.”
“though the residuary words are often described as general terms, the application of the ejusdem generis principle means that they end up being read as having a narrower meaning”. (2) That principle of statutory interpretation is particularly apposite here, where the provisions form part of legislation designed to be proportionate; or where the MSB is directed to use “informed judgement to focus [its] efforts on the highest-risk areas and reduce unnecessary burdens on customers”
“(1) A relevant person must apply enhanced customer due diligence measures and enhanced ongoing monitoring, in addition to the customer due diligence measures required under regulation 28 and, if applicable, regulation 29, to manage and mitigate the risks arising— (a) in any case identified as one where there is a high risk of money laundering or terrorist financing— (i) by the relevant person under regulation 18(1), or (ii) in information made available to the relevant person under regulations 17(9) and 47; (b) in any business relationship with a person established in a high-risk third country or in relation to any relevant transaction where either of the parties to the transaction is established in a high-risk third country (c) … (d) if a relevant person has determined that a customer or potential customer is a PEP, or a family member or known close associate of a PEP (in accordance with regulation 35); (2) … (3) For the purposes of paragraph (1)(b)— (a) a “high-risk third country” means a country which has been identified by the European Commission in delegated acts adopted under Article 9.2 of the fourth money laundering directive as a high-risk third country Post-Brexit, this reference has been replaced, and the relevant list is now set out in a new UK list in Schedule 3ZA to the MLR, see SI 2021/392. Pakistan is on the UK list. ; (b) a “relevant transaction” means a transaction in relation to which the relevant person is required to apply customer due diligence measures under regulation 27; (c) being “established in” a country means— (i) in the case of a legal person, being incorporated in or having its principal place of business in that country, or, in the case of a financial institution or a credit institution, having its principal regulatory authority in that country; and (ii) in the case of an individual, being resident in that country, but not merely having been born in that country. (3A) The enhanced due diligence measures taken by a relevant person for the purpose of paragraph (1)(b) must include— (a) obtaining additional information on the customer and on the customer's beneficial owner; (b) obtaining additional information on the intended nature of the business relationship; (c) obtaining information on the source of funds and source of wealth of the customer and of the customer's beneficial owner; (d) obtaining information on the reasons for the transactions; (e) obtaining the approval of senior management for establishing or continuing the business relationship; (f) conducting enhanced monitoring of the business relationship by increasing the number and timing of controls applied, and selecting patterns of transactions that need further examination.” (a) in any case identified as one where there is a high risk of money laundering or terrorist financing— (i) by the relevant person under regulation 18(1), or (ii) in information made available to the relevant person under regulations 17(9) and 47; (b) in any business relationship with a person established in a high-risk third country or in relation to any relevant transaction where either of the parties to the transaction is established in a high-risk third country (c) … (d) if a relevant person has determined that a customer or potential customer is a PEP, or a family member or known close associate of a PEP (in accordance with regulation 35); (a) a “high-risk third country” means a country which has been identified by the European Commission in delegated acts adopted under Article 9.2 of the fourth money laundering directive as a high-risk third country Post-Brexit, this reference has been replaced, and the relevant list is now set out in a new UK list in Schedule 3ZA to the MLR, see SI 2021/392. Pakistan is on the UK list. ; (b) a “relevant transaction” means a transaction in relation to which the relevant person is required to apply customer due diligence measures under regulation 27; (c) being “established in” a country means— (i) in the case of a legal person, being incorporated in or having its principal place of business in that country, or, in the case of a financial institution or a credit institution, having its principal regulatory authority in that country; and (ii) in the case of an individual, being resident in that country, but not merely having been born in that country. (a) obtaining additional information on the customer and on the customer's beneficial owner; (b) obtaining additional information on the intended nature of the business relationship; (c) obtaining information on the source of funds and source of wealth of the customer and of the customer's beneficial owner; (d) obtaining information on the reasons for the transactions; (e) obtaining the approval of senior management for establishing or continuing the business relationship; (f) conducting enhanced monitoring of the business relationship by increasing the number and timing of controls applied, and selecting patterns of transactions that need further examination.”
“A relevant person must apply customer due diligence measures if the person— (a) establishes a business relationship; (b) carries out an occasional transaction that amounts to a transfer of funds within the meaning of Article 3.9 of the funds transfer regulation exceeding 1,000 euros;…”
“If enhanced due diligence is appropriate, then you must do more to verify identity and scrutinise the background and nature of the transactions than for standard customer due diligence. How this goes beyond standard due diligence must be made clear in your risk assessment and procedures”
“the risk of MLTF here is that these customers have chosen agents not based on convenience or economic factors, but rather on ease of carrying out illicit transactions or carrying them out without detection. There is also an increased possibility of these transactions not being carried out face to face and thus posing a higher risk of MLTF as potential criminals may seek to exploit this to conceal their identity.”
“(1) A relevant person must— (a) establish and maintain policies, controls and procedures to mitigate and manage effectively the risks of money laundering and terrorist financing identified in any risk assessment undertaken by the relevant person under regulation 18(1); (b) regularly review and update the policies, controls and procedures established under sub-paragraph (a); (c) maintain a record in writing of— (i) the policies, controls and procedures established under sub-paragraph (a); (ii) any changes to those policies, controls and procedures made as a result of the review and update required by sub-paragraph (b); and (iii) the steps taken to communicate those policies, controls and procedures, or any changes to them, within the relevant person's business. (2) The policies, controls and procedures adopted by a relevant person under paragraph (1) must be— (a) proportionate with regard to the size and nature of the relevant person's business, and (b) approved by its senior management. (3) The policies, controls and procedures referred to in paragraph (1) must include— (a) risk management practices; (b) internal controls (see regulations 21 to 24); (c) customer due diligence (see regulations 27 to 38); (d) reliance and record keeping (see regulations 39 to 40); (e) the monitoring and management of compliance with, and the internal communication of, such policies, controls and procedures. (4) The policies, controls and procedures referred to in paragraph (1) must include policies, controls and procedures— (a)-(c) … (d) under which anyone in the relevant person's organisation who knows or suspects (or has reasonable grounds for knowing or suspecting) that a person is engaged in money laundering or terrorist financing as a result of information received in the course of the business or otherwise through carrying on that business is required to comply with— (i) Part 3 of theTerrorism Act 2000 ; or (ii) Part 7 of theProceeds of Crime Act 2002 ; (e) which, in the case of a money service business that uses agents for the purpose of its business, ensure that appropriate measures are taken by the business to assess— (i) whether an agent used by the business would satisfy the fit and proper test provided for in regulation 58; and (ii) the extent of the risk that the agent may be used for money laundering or terrorist financing. (5) In determining what is appropriate or proportionate with regard to the size and nature of its business, a relevant person may take into account any guidance which has been— (a) issued by the FCA; or (b) issued by any other supervisory authority or appropriate body and approved by the Treasury….” (a) establish and maintain policies, controls and procedures to mitigate and manage effectively the risks of money laundering and terrorist financing identified in any risk assessment undertaken by the relevant person under regulation 18(1); (b) regularly review and update the policies, controls and procedures established under sub-paragraph (a); (c) maintain a record in writing of— (i) the policies, controls and procedures established under sub-paragraph (a); (ii) any changes to those policies, controls and procedures made as a result of the review and update required by sub-paragraph (b); and (iii) the steps taken to communicate those policies, controls and procedures, or any changes to them, within the relevant person's business. (a) proportionate with regard to the size and nature of the relevant person's business, and (b) approved by its senior management. (a) risk management practices; (b) internal controls (see regulations 21 to 24); (c) customer due diligence (see regulations 27 to 38); (d) reliance and record keeping (see regulations 39 to 40); (e) the monitoring and management of compliance with, and the internal communication of, such policies, controls and procedures. (a)-(c) … (d) under which anyone in the relevant person's organisation who knows or suspects (or has reasonable grounds for knowing or suspecting) that a person is engaged in money laundering or terrorist financing as a result of information received in the course of the business or otherwise through carrying on that business is required to comply with— (i) Part 3 of theTerrorism Act 2000 ; or (ii) Part 7 of theProceeds of Crime Act 2002 ; (e) which, in the case of a money service business that uses agents for the purpose of its business, ensure that appropriate measures are taken by the business to assess— (i) whether an agent used by the business would satisfy the fit and proper test provided for in regulation 58; and (ii) the extent of the risk that the agent may be used for money laundering or terrorist financing. (a) issued by the FCA; or (b) issued by any other supervisory authority or appropriate body and approved by the Treasury….”
“Sarah Chapman commenced this review during the Coronavirus Pandemic, when working from home was the norm. It is surprising that HMRC has elected to focus on this as a risk indicator given the particular circumstances that BSEL found itself in at that time. Furthermore, the particular nature of the underlying risk is not entirely clear. The Coronavirus Pandemic has utterly transformed the prevailing attitude towards remote use of computers.”
“Transactions totalling£5,340,952 in the period1 September 2018 to31 August 2020 where three or more sender accounts shared the same telephone number.”
“Company risk-assessments were not a pre-requisite prior to onboarding in 2017, 2018, 2019 or within the BSEL compliance policy. We started requesting Risk assessment to our aggregators on Jan 2020, they were notified, particularly with the new companies which came on board in 2020.”
“However, my review of these [PCPs] has identified that these references to risk within the PCPs did not meet the requirements of regulation 18(1) and would not have been adequate in order for BSEL to assess whether these aggregators had established PCPs to effectively mitigate and manage the specific risks each faced.”
“Where a disclosure is made to the nominated officer, that officer must consider it in the light of any relevant information which is available to the relevant person and determine whether it gives rise to knowledge or suspicion or reasonable grounds for knowledge or suspicion that a person is engaged in money laundering or terrorist financing.”
“Staff must report to the nominated officer as soon as possible if they know or suspect that someone, not necessarily the customer, is involved in money laundering or terrorist financing. The nominated officer will then decide whether to make a report.”
“If you do not receive a refusal notification from the NCA within the notice period it is up to you to interpret your position and you may, if you consider that you have met the requirements for making a disclosure, assume a defence at the end of the notice period.”
“Suspicion is not defined in legislation. The Court of Appeal (R v Da Silva) defined suspicion of money laundering as a possibility, which is more than fanciful, that the other person was or had been engaged in, or benefited from criminal conduct and that the suspicion formed was of a settled nature. There does not need to be anything amounting to evidence of the suspected money laundering. The threshold for suspicion under POCA is generally considered to be low.”
“Where a disclosure is made to the nominated officer, that officer must consider it in the light of any relevant information which is available to the relevant person and determine whether it gives rise to knowledge or suspicion or reasonable grounds for knowledge or suspicion that a person is engaged in money laundering or terrorist financing.”
“The financial crime team, in conjunction with the Management decided to set the limit as below: Senders per beneficiary: Six Beneficiaries per sender: Six The above will be implemented in production by Friday, November 13, 2020.”
“Customer/Beneficiary Limits the number of sending customers per beneficiary, and the number of beneficiaries per customer, has been limited as set out below: • Senders per beneficiary: Six • Beneficiaries per sender: six Beneficiary Identifiers the system will allocate a unique identifier to each beneficiary, and this will be used for ongoing monitoring. This identifier is established through a combination of at least three of the beneficiary’s details as listed below: • Full name • Country/city • mobile number • Bank account number • Mobile wallet number.”
“My understanding of our conversation is as follows: • The virtual beneficiary profile (based on name and bank account number/telephone number was trialled successfully last week… • The automated process of identifying beneficiaries with multiple senders is expected to be implemented fully by the end of this week, this will use the virtual beneficiary profile. Prior to this the monitoring has been manual, the system did not have the ability to automate it. • There is not an absolute limit of six senders per beneficiary or six beneficiaries per sender, this is instead a trigger point at which further investigation will be carried out. The sender profile on the system cannot have more than six beneficiaries on it at one time so in order to send to a seventh beneficiaries the most historical beneficiary would drop off of the preferred beneficiary list.”
“large amounts of invalid phone numbers, 879 beneficiaries with no telephone number recorded at all, a lack of consistency in the length of the numbers and the use of numbers by multiple beneficiaries. For example, the number 880088 was used for 11,294 beneficiaries on transactions totalling over£9 million .”
“Until November 2020 BSEL had not established PCPs regarding multiple senders transacting large amounts from the same address, such as identifying the transactions as linked or having controls in place to restrict the numbers of customers per household.”
“Customers from Same Address is an enhancement which was implemented in October 2015 and generates a report which shows customers registered in the same postcode and residing at the same address. Compliance officers monitor any of the transactions which have been identified and review the profile of all customers registered at the same address including the KYC documents on the profiles, check for electronic ID verification results and contacting all the customers at the address at the contact numbers on record. If necessary, further action may be taken such as follow up on the customers or escalating the matter to a senior compliance officer or the MLRO or adding the customer to BSEL’s Internal Blacklist.”
“BSEL did not establish PCPs to obtain the date and time of when the transaction took place, from its aggregators. Without this BSEL was unable to identify suspicious activity in relation to split transactions that occurred within short periods of time, leaving it vulnerable to criminals exploiting this to split illicit funds without detection.”
“[M Ltd] has been by far the most efficient and compliant aggregator…The upload of correct IDs and KYC documentation has been right first time from their agent network.”
“M Ltd did operate a network of agents and, although historically some of [its] data was in bulk, BSEL started to capture the details of its agents in early 2020. M Ltd was offboarded in December 2019.”
“Principals should ensure that an agent meets minimum expectations, in particular that: ● the beneficial owners, senior managers, officers and nominated officer of the agency are fit and proper persons for their fiduciary role; ● they should be of good character, they should not have criminal records (see Appendix 1: Relevant offences under schedule 3 of the Regulations), or have been the subject of any professional conduct or disciplinary action, and they must demonstrate professional standards and competence in business conduct…”
“To reach a decision we’ll consider a range of information including whether you have: • been convicted of or are being investigated for money laundering or other offences involving dishonesty, fraud or financial crime • been disqualified from acting as a company director • been subject to a confiscation order under theProceeds of Crime Act 2002 • a track record of consistent non-compliance with the Money Laundering Regulations, or with the EU Payments Regulation which applies to moneytransmission service providers • been disciplined or expelled by another supervisor or professional body for regulatory or professional failings.”
“In the case of an agent of an authorised payment institution, the identity of the directors and persons responsible for the management of the agent and evidence that they are fit and proper persons.”
“Similarly, BSEL should consider performing criminal record checks on UK based agents using a risk based approach to target higher risk agents.”
“As recommended by FATF, BSEL undertakes a specific risk assessment of its agents, both prior to commencing business and on an ongoing basis.Once on-boarded, every agent is automatically considered high risk for the first six months of operations and during this time BSEL conducts EDD.After this time, the agent may be re-classified as either low or medium risk depending on the prevailing risk assessment. The risk assessment takesinto account location specific volume, location specific number of transactions, unusual spikes in volume, number of SARs in the last 12 months,notifications from law enforcement, fraud alerts and the agent visit report.”
“it fails to identify agents as high risk unless they have multiple high risk indictors and thus is not appropriate to assess the level of risk they pose. For example, an agent whose business is a high risk type such as a travel agent with an average transaction size of£1,000 , sending all of its transactions to a high risk third country, but with no other identified risks, would score 2.82, leading to a risk rating of only medium.”
“must establish and maintain policies, controls and procedures to mitigate and manage effectively the risks of money laundering and terrorist financing identified in any risk assessment undertaken by the relevant person under regulation 18(1).”
“(1) This regulation applies when a relevant person is required by regulation 27 to apply customer due diligence measures. (2) The relevant person must— (a) identify the customer unless the identity of that customer is known to, and has been verified by, the relevant person; (b) verify the customer's identity unless the customer's identity has already been verified by the relevant person;… (3) Where the customer is a body corporate— (a) the relevant person must obtain and verify— (I) the name of the body corporate; (ii) its company number or other registration number; (iii) the address of its registered office, and if different, its principal place of business; … (16) The relevant person must be able to demonstrate to its supervisory authority that the extent of the measures it has taken to satisfy its requirements under this regulation are appropriate in view of the risks of money laundering and terrorist financing, including risks— (a) identified by the risk assessment carried out by the relevant person under regulation 18(1); (b) identified by its supervisory authority and in information made available to the relevant person under regulations 17(9) and 47 (17) … (18) For the purposes of this regulation— (a) except in paragraph (10), “verify” means verify on the basis of documents or information in either case obtained from a reliable source which is independent of the person whose identity is being verified;…”. (a) identify the customer unless the identity of that customer is known to, and has been verified by, the relevant person; (b) verify the customer's identity unless the customer's identity has already been verified by the relevant person;… (a) the relevant person must obtain and verify— (I) the name of the body corporate; (ii) its company number or other registration number; (iii) the address of its registered office, and if different, its principal place of business; (a) identified by the risk assessment carried out by the relevant person under regulation 18(1); (b) identified by its supervisory authority and in information made available to the relevant person under regulations 17(9) and 47 (a) except in paragraph (10), “verify” means verify on the basis of documents or information in either case obtained from a reliable source which is independent of the person whose identity is being verified;…”
“Paragraph 4.95 of HMRC guidance for MSBs states that as a minimum a private individual’s given and family name, date of birth and residential address should be obtained and verified in order to meet the requirements of MLR 2017. BSEL failed to verify the residential address and thus the identity of some of its customers as required by Regulation 28(2)(b). BSEL’s PCPs confirms that it did not verify the addresses of those customers who provided a passport as their single form of ID and whose transactions did not exceed£2,000 either in a single transaction or cumulatively within a 90 day period. For transactions to Bangladesh from January 2020 to November 2020 the threshold was£3,000 .”
“As part of your customer due diligence measures, you must identify individuals. You should obtain a private individual’s given and family name, date of birth and residential address as a minimum. Documentation purporting to offer evidence of identity may come from a number of sources. These documents differ in their integrity, reliability and independence. Some are issued after due diligence on an individual’s identity has been undertaken; others are issued on request, without any such checks being carried out. There is a broad hierarchy of documents: certain documents issued by government departments and agencies, or by a court; then certain documents issued by other public sector bodies or local authorities; then certain documents issued by regulated firms in the financial services sector; then those issued by other firms subject to the Regulations, or to equivalent legislation; then those issued by other organisations. You should verify these using identity evidence that has been issued by a recognised body, for example a Government department, that has robust identity proofing measures, and includes security features that prevent tampering, counterfeiting and forgery with the customer’s full name and photo, with a customer’s date of birth or residential address such as: ● a valid passport ● a valid photo card driving licence (full or provisional) ● a national identity card ● a firearms certificate ● an identity card issued by the Electoral Office for Northern Ireland.” certain documents issued by government departments and agencies, or by a court; then ● a valid passport ● a valid photo card driving licence (full or provisional) ● a national identity card ● a firearms certificate ● an identity card issued by the Electoral Office for Northern Ireland.”
“The relevant person must be able to demonstrate to its supervisory authority that the extent of the measures it has taken to satisfy its requirements under this regulation are appropriate in view of the risks of money laundering and terrorist financing, including risks— (a) identified by the risk assessment carried out by the relevant person under regulation 18(1); (b) identified by its supervisory authority and in information made available to the relevant person under regulations 17(9) and 47.”
“The relevant person must conduct ongoing monitoring of a business relationship, including— (a) scrutiny of transactions undertaken throughout the course of the relationship (including, where necessary, the source of funds) to ensure that the transactions are consistent with the relevant person's knowledge of the customer, the customer's business and risk profile; (b) undertaking reviews of existing records and keeping the documents or information obtained for the purpose of applying customer due diligence measures up-to-date.”
“in the period1 September 2018 to31 August 2020 1,984 customers with the same name and date of birth had more than one account with transactions totalling£16,881,725.89 , across 263 different agents. For example, [Mr JK] with a date of birth of [XX] had five separate accounts with transactions totalling£13,505.63 .”
“shared his screen to show some examples of multiple customers residing at the same address, the details of which have been e-mailed separately to TC to ascertain whether these had been previously identified by BSEL.”
“(1) A relevant person must have in place appropriate risk-management systems and procedures to determine whether a customer or the beneficial owner of a customer is— (a) a politically exposed person (a “PEP”); or (b) a family member or a known close associate of a PEP, and to manage the enhanced risks arising from the relevant person's business relationship or transactions with such a customer. (2) In determining what risk-management systems and procedures are appropriate under paragraph (1), the relevant person must take account of— (a) the risk assessment it carried out under regulation 18(1); (b) the level of risk of money laundering and terrorist financing inherent in its business; (c) the extent to which that risk would be increased by its business relationship or transactions with a PEP, or a family member or known close associate of a PEP, and (d) any relevant information made available to the relevant person under regulations 17(9) and 47. (3) If a relevant person has determined that a customer or a potential customer is a PEP, or a family member or known close associate of a PEP, the relevant person must assess— (a) the level of risk associated with that customer, and (b) the extent of the enhanced customer due diligence measures to be applied in relation to that customer. (4) In assessing the extent of the enhanced customer due diligence measures to be taken in relation to any particular person (which may differ from case to case), a relevant person— (a) must take account of any relevant information made available to the relevant person under regulations 17(9) and 47; and (b) may take into account any guidance which has been— (i) issued by the FCA; or (ii) issued by any other supervisory authority or appropriate body and approved by the Treasury.” (a) a politically exposed person (a “PEP”); or (b) a family member or a known close associate of a PEP, (a) the risk assessment it carried out under regulation 18(1); (b) the level of risk of money laundering and terrorist financing inherent in its business; (c) the extent to which that risk would be increased by its business relationship or transactions with a PEP, or a family member or known close associate of a PEP, and (d) any relevant information made available to the relevant person under regulations 17(9) and 47. (a) the level of risk associated with that customer, and (b) the extent of the enhanced customer due diligence measures to be applied in relation to that customer. (a) must take account of any relevant information made available to the relevant person under regulations 17(9) and 47; and (b) may take into account any guidance which has been— (i) issued by the FCA; or (ii) issued by any other supervisory authority or appropriate body and approved by the Treasury.”
“Politically exposed persons are persons that are entrusted with prominent public functions, whether in the UK or abroad. The definition does not include: middle ranking or more junior officials persons who were not a politically exposed person under the 2007 regulations where they ceased to hold a prominent public function prior to26 June 2017 , such as former MPs or UK Ambassadors In the UK, civil servants below Permanent or Deputy Permanent Secretary-level will not normally be treated as having a prominent public function. When assessing whether a person is a PEP, you should be mindful of whether a person is acting on the instruction of, or on behalf of, a PEP. This is more likely to be the case when the relevant persons hold prominent functions in a third country which presents a relatively higher risk of money laundering.”
“The nature and scope of a particular firm’s business will generally determine whether the existence of PEPs in their customer base is an issue for the firm, and whether or not the firm needs to screen all customers for this purpose. In the context of this risk analysis, it would be appropriate if the firm’s resources were focused in particular on products and transactions that are characterised by a high risk of money laundering.”
“The FCA expects that firms take appropriate but proportionate measures in meeting their financial crime obligations. The MLRs set out that all firms must apply a risk sensitive approach to identifying PEPs and then applying enhanced due diligence measures.”
“to be applied to customers who conduct ‘occasional’ transactions below the applicable thresholds in the circumstances which are described in Recommendations 10 and 16 (wire transfers). Consequently, financial institutions…are not expected to determine whether such customers are PEPs.”
“In order not to impair the efficiency of payment systems, and in order to balance the risk of driving transactions underground as a result of overly strict identification requirements against the potential terrorist threat posed by small transfers of funds, the obligation to check whether information on the payer or the payee is accurate should, in the case of transfers of funds where verification has not yet taken place, be imposed only in respect of individual transfers of funds that exceed EUR 1,000, unless the transfer appears to be linked to other transfers of funds which together would exceed EUR 1 000, the funds have been received or paid out in cash or in anonymous electronic money, or where there are reasonable grounds for suspecting money laundering or terrorist financing.”
“We were informed by the Compliance Officers we interviewed that there were 5 positively matched PEPs found in the time period under review …However, we were also advised that one of these customers was not in fact identified as a PEP until their third transaction because KYC6 did not produce an alert for their first two transactions in 2019. We queried the reasons why an alert was not initially produced and BSEL advised that they were unable to check the reasons themselves but would make further enquiries.”
“These failures occurred despite regulation 57(4) breaches being part of the reason for its registration being suspended in October 2020. This led me to conclude that BSEL had consistently failed to comply with the Regulations.”
“I am satisfied, and evidence below, that the Business is not a fit and proper person for the purposes of Regulation 58, having regard to Regulation 58(4)(a)(i), as it has consistently failed to comply with the requirements of the Regulations. In addition, it is not a fit and proper person for the purposes of Regulation 58, having regard to Regulation 58(4)(b), due to the risk that the Business may be used for money laundering and/or terrorist financing(MLTF).”
“I established that the Business was aware of a number of the risks that it faced but, due to resource implications, had decided not to implement effective PCP to mitigate these risks. The information provided by the Business also identified that it had knowingly allowed serious MLTF risks to continue for considerable periods of time whilst controls were, and still are, being implemented. This allowed the risk of the Business being used for MLTF to continue and breaches of the Regulations to occur.”
“The Business has deliberately failed to mitigate all of the risks its faces, including the serious failure to effectively identify and prevent beneficiaries receiving funds from excessive numbers of senders and as such the significant risk of the Business being used for MLTF on vast amounts of funds has continued.”
“In order to determine whether I am satisfied that you are a fit and proper person, I have had regard to the following: • Whether the Business has consistently failed to comply with the requirements of the Regulations in accordance with Regulation 58(4)(a)(i). • The risk that the Business may be used for money laundering or terrorist financing (MLTF) in accordance with Regulation 58(4)(b). • Whether you have adequate skills and experience and have acted or may be expected to act with probity in accordance with Regulation 58(4)(c). Based on the information I have reviewed, I am satisfied you are not a fit and proper person for the purposes of Regulation 58. I have set out below how I have reached this decision.”
“(a) whether the applicant has consistently failed to comply with the requirements of [the MLR]; (b) the risk that the applicant's business may be used for money laundering or terrorist financing; and (c) whether the applicant, and any officer, manager or beneficial owner of the applicant, has adequate skills and experience and has acted and may be expected to act with probity.”
“You currently hold the position in the Business as the Business Systems Manager. However, you are noted by the Business as the person responsible for drafting the policies, controls and procedures (PCPs) for the Business from September 2018 to September 2020.. You also were present on the call between the Business and Officer Chapman on10 March 2021 and demonstrated your knowledge of all the system controls that were in place, agent risk assessments and when PCPs were implemented. Therefore, due to your involvement, knowledge and level of responsibility to ensure the Business’s compliance with the Regulations, you are aware of its obligations and requirements under the Regulations.”
“As can be seen from the Document Revision History of the compliance policy, the last revision that I made was on3 July 2017 to version 7.1 of the compliance policy. The reason for the revision was to assist the then new MLRO, Mr Ola Olayinka in updating the compliance policy. I did not have any involvement in amending or drafting any policies since3 July 2017 .”
“He was therefore responsible for ensuring BSEL’s compliance with the Regulations; and he had responsibility for ensuring that BSEL had PCPs in place to mitigate and manage effectively the risks of MLTF to which BSEL was subject.”
“although you joined the Business in September 2020, you had responsibility for the continued non-compliance and risk of MLTF from that time”
“[his] failure to ensure that BSEL’s PCPs were compliant with Regulation 19(1)(a) has resulted in BSEL contravening this relevant requirement and in BSEL also breaching Regulations 28(2), 28(11), 28(16), 33(1) and 35(1) MLR 2017.”
“a person who has control, authority or responsibility for managing the business of that firm, and includes a nominated officer”. (2) Unlike the Personal Decisions issued under Reg 58, a prohibition notice can only be issued to officers of the company. In particular, the power to issue prohibition notices is not extended to a “manager”, as defined. (3) The Cambridge Dictionary defines “management committee” as "a group of people who are chosen or elected to make decisions about how a club or charity is run”
“I think that 'knowingly' means with knowledge of the facts upon which the contravention depends. I think it is immaterial whether the director had knowledge of the law or not. I think he is bound to know what the law is, and the only question is, did he know the facts which made the act complained of a contravention of the statute?”