Breadcrumb

Navigation Menu

Customer Due Diligence (CDD)

Customer Due Diligence (CDD)


Verification

Verification can be a combination of various data points that the reporting institution deems to be “reliable and independent” which could cumulatively ensure the accuracy of customer and beneficial owner’s identification data. Any measures adopted should be subjected to the reporting institution’s internal governance process.

Generally, the reporting institution is required to verify the identity of a customer through acceptable government issued documents with or without photograph (e.g. MyKad, MyKid, MyPR, OKU card, driving licence, birth certificate, marriage certificate), foreign passport, employee identification documents, etc.

Alternatively, subject to the reporting institution’s assessment whether it is appropriate to mitigate the risks, reporting institutions may accept scanned or copy documentation and apply additional measures which include:

  1. third party verification of identity from the client’s primary bank account provider, lawyer or accountant in accordance with paragraph 16 of the Policy Document;
  2. corroborative evidence from Jabatan Pendaftaran Negara, Suruhanjaya Syarikat Malaysia and Central Credit Reference Information System (CCRIS) databases;
  3. use of commercial providers to validate documentation provided; 
  4. use of new and robust technology solutions including but not limited to, biometric technologies which should be linked incontrovertibly to the customer;
  5. through non face-to-face mechanisms e.g. video conference with customers and submission of selfies to compare the physical identity of a customer with scanned or photographed copies of identification documents; and/or
  6. other reliable and independent source. 

Reporting institutions are expected to undertake adequate and reasonable measures to mitigate risks arising from the adoption of any non face-to-face mechanisms. For further details, please refer to the “Guidance on Verification of Individual Customers for CDD” issued by Bank Negara Malaysia.

Any documents requested or obtained during the CDD process should be kept and recorded to meet the record keeping requirement as set out under paragraph 21.1 of the Policy Document.

The record keeping of these documents may be in the form of a photocopy, soft copy (scanned copy or snapped picture) or biometric record (such as Government Multi-Purpose Card Consortium (GMPC) verification, etc.).

Paragraph 14.10.4 of the Policy Document specifies the information that a reporting institution should obtain to identify and verify the identity of customers that are legal persons.

The reporting institution is required to take adequate measures to confirm the identity of its customers which may include constituent documents, such as certificate of incorporation, and other searches available in the public registrar databases.

Reporting institutions are required to assess the relevant risks in verifying the foreign shareholders.

Verification process must be on a reasonable basis, and can be satisfied by obtaining documents from foreign official public registers or by way of self-declaration by the client, depending on the reporting institution’s risk assessment in on-boarding such client.

Under such circumstance, the exemption on verification of the identity of directors and shareholders of that legal person applies (see paragraph 14.10.9 of the Policy Document).

Reporting institutions are required to identify and maintain information relating to the identity of the directors and shareholders of the public listed company using reliable sources (see paragraph 14.10.10 of the Policy Document).

Standard CDD

A person authorised must be represented with a letter of authority or director’s resolution from the legal person.

Where it involves an authorised signatory, i.e. when a legal person opens an account, establishes business relations and authorises another person to conduct transactions on its behalf, the reporting institution must obtain documentary evidence on the appointment of such person and the specimen signatories and/or recognised digital signature of the person appointed.

Reporting institutions must be guided by their risk assessment on what documentary evidence would suffice for the purposes of identifying and verifying the person authorised.

Beneficial Owner

Yes, consistent with paragraph 14.10.6 (a) of the Policy Document, reporting institutions are required to identify directors or shareholders or partners with equity interest of  more than 25%.

The requirement to conduct CDD on RCPS holders of a legal person client will depend on whether the RCPS holding could give rise to the holder having a controlling ownership interest, at minimum, with equity interest of more than 25 percent, as required under Paragraph 14.10.6(a) of the Policy Document and other conditions as stipulated under the same paragraphs (b) and (c).

For example, after a certain specified period, the RCPS holders may redeem and hence resulting in the holders having controlling ownership interest in the legal person, which is when the beneficial ownership requirements on identification and verification of the persons apply.

CDD : Clubs, Societies and Charities

No, for such clients, reporting institutions are required to conduct CDD on the persons with controlling ownership interests. This may include the office bearers (i.e. the Executive Committee) or any person authorised to represent the said club, society or charity, and any party who may have controlling ownership interest, and not its members per se. Please see paragraph 14.10.17 of the Policy Document.

Simplified CDD

No, simplified CDD is not applicable to DNFBP and NBFI reporting institutions. All DNFBPs and NBFI reporting institutions are required to conduct standard CDD when establishing business relations or conducting transactions with its customers or clients, as required under paragraphs 14.10 and 14A to 14H of the Policy Document.

Enhanced CDD

No. The requirement to obtain information on source of funds and/or source of wealth only applies when overall ML/TF risks are assessed as higher risk. Reporting institutions are not expected to establish source of funds or wealth for each and every customer or transaction.  

Generally, reporting institutions are required to enquire on source of funds and/or source of wealth, as part of the enhanced CDD under the following scenarios:

  • after customer risk profiling, when a customer is assessed as having higher ML/TF risks, regardless of any amount of transaction;
  • for all foreign politically exposed persons (PEPs) or when a domestic PEP is assessed as having higher ML/TF risks, in which case, both source of fund and wealth must be obtained; or
  • when providing nominee services to the customers or clients, i.e. nominee shareholding, directorship or partnership services, by reporting institutions who are lawyers, accountants, company secretaries or trust companies.

Information on the source of wealth and source of funds are good sources of monitoring for the reporting institutions.

“Source of wealth” refers to the source of a person’s total assets. Documents and information that may reflect the source of wealth of a person include inheritance document, property title, copies of trust deeds, audited accounts, salary details, tax returns and bank statements. It may be possible to gather general information from commercial databases or other open sources.

“Source of funds”, on the other hand, refers to the origin of a specific asset used in connection to the business relations with the reporting institution. Source of funds may be determined through enquiry on the customer.

In the case of PEPs, both information on the source of wealth and source of funds are to be obtained.

Understanding both the source of wealth and source of funds of a PEP is also necessary for on-going due diligence purposes where the aim is to ensure that the reason for the business relationship between reporting institutions, the PEP and the transactions undertaken on the PEP’s behalf, are commensurate with what one could reasonably expect from that PEP, given his/her particular circumstances.

Non Face-to-Face Business Relationship

Yes, DNFBP and NBFI reporting institutions can establish non face-to-face business relationship with their clients, having put in place policies and procedures to address any specific risks associated with non face-to-face relationships. 

This includes appropriate measures for identification and verification of a client's identity that must be as effective as that for face-to-face client and implement monitoring and reporting mechanisms to identify potential ML/TF activities, as required under paragraph 14.14 of the Policy Document.

Before such non face-to-face measures are implemented, reporting institutions are required to seek their Board’s approval (see paragraph 14.14.2 of the Policy Document).

The requirement for Board approval is connected to the risk levels of the product and services.

If the process and procedures in place for the said products and services are the same, Board approval is only required once, for all product and services on-boarded via non face-to-face channel or e-KYC.

A new approval would need to be obtained when there are changes to the ML/TF risk level of the parameters assessed by the reporting institution. 

The requirements for non face-to-face (non-FTF) do not have a retrospective effect. For non-FTF business relationships, reporting institutions shall ensure their non-FTF arrangements for customer identification and verification of identity is as effective as a face-to-face relationship.

Should there be any changes to the ML/ TF risk levels, reporting institutions need to re-assess the parameter and may require a new Board approval.

Failure to Satisfactorily Complete CDD

Reporting institutions must obtain all CDD information (9 data points) as specified in paragraph 14.10.1 of the Policy Document before continuing any business relationship.

In the event of a failure to obtain the complete information, reporting institutions must not continue the business relationship or transaction with the customer and must consider lodging a suspicious transaction report.

However, where a reporting institutions form suspicion of ML/TF and reasonably believe that performing CDD may tip-off the customer, the reporting institutions are permitted to proceed to establish business relation or transaction without completing the CDD process, document the basis of not completing the CDD process and immediately lodge a suspicious transaction report.     

Specific CDD : Lawyers

The CDD obligation does not extend to both parties to a sale and purchase transaction but applies to the client of the lawyer.

Are DPMS reporting institutions required to conduct CDD on their customers for the following transactions?: 

  • the transaction involves other goods being sold by the DPMS and does not involve any sale of precious metals nor precious stone; or
  • the transaction involves the sale of precious metals or stones together with other types of goods, however, the value of the precious metals or stones is less than RM50,000.

If the lawyer is representing a seller, CDD applies on the seller and vice-versa.

However, in the course of facilitating the transaction, if any suspicion arises on either party to the transaction, i.e. seller or buyer, the reporting institution may consider submitting a suspicious transaction report on either party to FIED, BNM.

Specific CDD : Dealers in Precious Metals and Stones

DPMS reporting institutions are required to conduct CDD on customers and persons conducting the transaction when engaging in any cash transaction equivalent to RM50,000 and above, including:

  • in a single transaction or through several transactions in a day that appear to be linked and across all branches of the reporting institution;
  • aggregate payments over a period of time for a single purchase; or
  • for both buying and selling of precious metals or precious stones from or to customers.

In view of the above, CDD is not applicable if the transaction does not involve sale of precious metals or precious stones.

Specific CDD : Registered Estate Agents (REAs)

In the event of a co-broke or co-agency transaction, the REAs are required to conduct CDD on their respective client. For example,

  • REA A representing the purchaser is required to conduct CDD on the purchaser; and
  • REA B representing the seller is required to conduct CDD on the seller.

In the absence of co-broke or co-agency arrangement, REA is required to conduct CDD on both parties to a property or tenancy transaction. Please refer to Appendix A for illustration.

Specific CDD : Licensed Gaming Outlet

The AML/CFT requirements do not restrict third party payment. However, in the case that the payment is above RM50,000, the reporting institution must conduct CDD on the third party i.e. either as person conducting the transaction or beneficial owner.