Application of Risk-Based Approach - Anti Money Laundering / Countering Financing of Terrorism (AML/CFT)
Application of Risk-Based Approach
Risk Assessment
Reporting institutions are generally not required to submit the AML/CFT risk assessment information to Bank Negara Malaysia. However, such report may be required to be submitted to Bank Negara Malaysia during supervisory visits or as and when required as part of supervisory or risk assessment.
Paragraph 10.2.1 of the Policy Document requires reporting institutions to identify, assess and understand their money laundering and terrorism financing (ML/TF) risk in relation to:
- customers;
- countries or geographical areas;
- products, services, transactions or delivery channels; and
- other relevant risk factors.
Reporting institutions’ first IRA must be comprehensive, covering all the above mentioned parameters, i.e. customers, countries/geographical areas and products/ services/ transactions and delivery channel, at minimum. Reporting institutions may choose to update the IRA on a thematic basis.
Reporting institutions may consider to set the frequency of the IRA on a specific period e.g. every 1 to 2 years or where circumstances have changed that may warrant a refresh of the IRA, e.g. material changes in risk profile, significant internal audit finding, changes in business direction, new typologies suggested by authorities or Financial Action Task Force (FATF), or when embarking in new technologies, etc.
Reporting institutions may refer to the guidance documents on risk-based approach available in Part D of the Policy Document and guidance issued by the FATF which are available on its website at: http://www.fatf-gafi.org
There is no standard template to conduct the IRA. Reporting institutions may refer to Appendix 9 of the Policy Document as a guidance to assist the conduct of ML/TF risk assessment collectively at the institutional level.
While Appendix 9 has generally covered the basic requirements, it should not be treated as the sole reference in conducting the risk assessment as the list of factors or examples or criteria are not exhaustive.
Risk Profiling
In profiling the customers, reporting institutions are required to take appropriate steps to identify, assess and understand risks, by considering the relevant factors under Paragraph 10.2.1 of the Policy Document. In cases where some of the criteria are irrelevant to the reporting institution’s business, those criteria may not be considered in profiling and assessing the risks of the customers.
Reporting institutions are to assess the customers’ risk based on the type of customer, geographical location, products, services, transactions or delivery channels and other relevant factors (such as emerging threats, trends, change in behaviours, past suspicious transaction report experience, etc.).
Reporting institutions are expected to consider the applicable factors at the stage of on-boarding and during re-rating to determine the risk of a customer. Reporting institutions are also expected to document internal customer risk profiling assessments, for record keeping and audit purposes.
Reporting institutions may refer to the guidance provided in Part D of the Policy Document, in particular the Customer Due Diligence Form for suggested approach to conduct customer risk profiling.
