AML/CFT Compliance Programme - Anti Money Laundering / Countering Financing of Terrorism (AML/CFT)
AML/CFT Compliance Programme
AML/CFT Compliance Programme
If a reporting institution meets the small-sized definition (please refer Appendix 2 of the Policy Document), the reporting institution can apply the simplifications and exemptions in relation to the AML/CFT Compliance Programme as per paragraph 11.1.1 of the Policy Document.
Please note that the simplification or exemption does not apply to the substantive AML/CFT requirements, such as customer due diligence, suspicious transaction report, record keeping etc.
Bank Negara Malaysia's approval prior to the application of the simplifications or exemptions is not required.
Notwithstanding, Bank Negara Malaysia, may at any time, specify that a reporting institution is required to comply with any of the AML/CFT Compliance Programme.
No, the definition is based on total number of practicing certificate holders in the firm, regardless of whether they undertake Gazetted Activities or otherwise. For example, a firm with 7 practising certificate holders, of which only 3 undertake Gazetted Activities, such a firm does not meet the small-sized reporting institution criteria.
No, under such scenario, the company is not a small-sized reporting institution and must implement the complete AML/CFT Compliance Programme requirements.
Where a sector is subject to more than one criteria for definition of small-sized reporting institution, both criteria must be satisfied to apply the flexibility. If the company only meets one of the criteria and not the other, the company is not considered as asmall-sized reporting institution.
The determination of whether a reporting institution meets the small-sized criteria shall be based on the figures at the end of the preceding calendar year, i.e. January to December. Hence, where the reporting institution does not meet the criteria as per the reference figures, the reporting institution must comply with the complete AML/CFT Compliance Programme.
Compliance Management Arrangements at the Head Office
Yes, all reporting institutions, regardless of size, are required to appoint a compliance officer, as per section 19 of the AMLA.
Yes, the reporting institution may appoint any individual with management responsibilities within the reporting institution to be the compliance officer. The person appointed must satisfy the criteria provided under paragraph 11.5 of the Policy Document. He or she must have the sole discretion and independence to evaluate and report suspicious transactions.
The appointed compliance officer may also be carrying on other functions within the reporting institution.
While the Policy Document does not provide a definition of “management” per se, the appointed compliance officer must have sufficient stature, authority and seniority within the reporting institution to participate and be able to effectively influence decisions relating to AML/CFT matters.
Reporting institution may appoint compliance officer from other subsidiaries within the Group provided that he or she fulfils the criteria provided under paragraph 11.5 of the Policy Document.
Regardless whether the compliance officer is internally or externally appointed, the reporting institution remains responsible and accountable to ensure the effectiveness of the compliance functions.
Section 19(4) of the AMLA require reporting institutions to designate compliance officers at management level in each branch, for the purpose of application of AML/CFT compliance programme as well as reporting of suspicious transactions.
Further, paragraph 11.5 of the Policy Document stipulates compliance management arrangements at Head Office including the requirement to notify Bank Negara Malaysia on the appointment or change in the appointment of compliance officer at Head Office.
In this regard, reporting institutions are required to appoint a compliance officer at each branch, but are only required to notify Bank Negara Malaysia on the compliance officer appointed at the Head Office.
Nevertheless, for some DNFBP sectors, branch offices operate independently of the Head Office. Under such scenario, each branch is required to notify Bank Negara Malaysia on the appointment of the compliance officer.
No, AML/CFT certification is not compulsory for compliance officers, but highly encouraged to enable effective discharge of their responsibilities.
Reporting institutions may be guided by the examples provided under paragraphs 11.5.5, 11.5.6, 11.5.7 and 11.5.8 of the Policy Document when assessing the fitness and propriety of an individual to be appointed as a compliance officer.
Any employee of a reporting institution may be held personally liable for any failure to observe the AML/CFT requirements, in accordance with their respective job function, including the compliance officer.
No, there is no specific due date for the appointment of a compliance officer. However, reporting institutions are required to appoint a compliance officer and notify Bank Negara Malaysia within 10 working days from the appointment, or for any change in the appointment.
Employee Screening
Yes, the screening of employees can be differentiated on a risk-based basis, depending on the position, job scope or other relevant factors related to the employee.
Reporting institutions are expected to assess their employees’ vulnerability to money laundering, terrorism financing, fraud and bribery risks, and use various sources of information to assist in the screening process to ensure that employees do not abuse their position or be vulnerable or used as a conduit to facilitate ML/TF activities.
Reporting institutions may choose any suitable method to conduct employee screening and be guided by methods provided in paragraph 11.7 of the Policy Document.
Examples of methods for the conduct of employee screening may include face-to-face meeting, phone or video interviews, online checks, skills test, submission of documents or statutory declarations, criminal checks with relevant authorities, consumer credit reports, transaction monitoring, obtaining employment reference, etc.
The parameters and triggers for re-screening are to be determined by each reporting institution.
Examples of best practices would include consideration of global watch list (including negative news screening), criminal checks with relevant authorities, transaction monitoring as well as credit reports and also changes in circumstances, either professionally or personally e.g. promotion, secondment to another division function, financial hardships, or staying in the same position for a long period of time, etc.
Employee Training and Awareness Programmes
Training should be conducted regularly and supplemented with refresher courses at appropriate intervals. Any form of training, e.g. classroom, online or webinar, are acceptable depending on the needs of the employee, the job function and responsibilities undertaken by the employee.
Reporting institutions should have clear and comprehensive training contents. The training materials should be frequently reviewed to include any latest changes to the AML/CFT or other regulatory requirements. In addition, tests or examinations are highly encouraged to demonstrate higher levels of effectiveness.
Where a reporting institution satisfies the small-sized reporting institution definition, a more simplified training approach can be adopted, including via on-the-job training.
Reporting institutions are to ensure that the training provided to its employees is properly documented.
Reporting institutions are also encouraged to contact their respective self-regulatory bodies, regulatory or licensing authorities and their relevant training institutes for AML/CFT training specific for their sectors. This could be as part of the on-going Continuing Professional Education (CPE) / Continuing Professional Development (CPD) programmes.
Independent Audit Function
Yes, the function may be delegated to other Board level committees (i.e. audit or risk) so long as the committee is independent and the AML/CFT findings or issues relating to the adequacy and implementation of the AML/CFT policies and procedures are ultimately tabled to the Board.
For example, the decision on frequency and scope of the audit can be delegated to the Board Audit Committee.
The role of AML/CFT independent audit function can be undertaken internally by any officer, with relevant knowledge and expertise to carry out the function, who is independent of the compliance function (i.e. Compliance Officer). Alternatively, the reporting institution may also appoint external auditors to carry out the function. The appointment of an independent auditor, internal or external and its roles and responsibilities shall be determined by the Board or Senior Partners.
In carrying out the independent audit review, as per paragraph 11.9.4 of the Policy Document, the auditors must, at a minimum, check and test the firm's compliance with AML/CFT policies, procedures and controls and the effectiveness or extent of its implementation when dealing with clients or on the necessary approvals by Board or Senior Partners, as well as assess whether the firm's current measures are in line with requirements under AMLA and the Policy Document.
The frequency of the independent audit depends on the firm’s assessment of its ML/TF risk exposure and is determined by the Board or Senior Partners.
On the scope of the independent audit, reporting institutions may refer to paragraph 11.9.6 of the Policy Document. Further, reporting institutions must also consider whether there were previous non-compliances under the AMLA which resulted in enforcement actions taken against the reporting institution.
Yes, except for licensed casino and non-bank financial institutions, all other reporting institutions are no longer required to submit an annual audit report to FIED, BNM.
However, reporting institutions must ensure that the audit report and necessary corrective measures undertaken are made available to FIED, BNM and the relevant supervisory authorities upon request.
