Breadcrumb

Customer Due Diligence (CDD)

Customer Due Diligence (CDD)


General

[Banking and Deposit-Taking Institutions]

How would CDD be conducted on cash deposit machines (CDM) transactions? 

MSB licensees are required to take reasonable measures to identify and verify beneficial owners especially when they have knowledge based on previous transactions or publicly available information that the customer (i.e. person conducting the transaction) is acting on behalf of the beneficial owner, for example:

  1. Exchange transactions with the representative of the beneficial owner (e.g. a domestic PEP) are allowed if MSB licensees are able to comply with the CDD requirements on beneficial owners and his/her representative.
  2. Where there is a partial disclosure of the identity i.e. name of the beneficial owner by the representative, MSB licensees are allowed to perform the exchange transactions with the representative; and must consider lodging a STR on the representative including information on the BO to FIED.
  3. Where there is no disclosure of the identity i.e. name of the beneficial owner by the representative, MSB licensees are allowed to perform the exchange transactions with the representative; and must lodge a STR on the representative to FIED.

If the customer is unable to provide or refuse to provide the information and/or documents, MSB licensees must not perform the transaction for the customer.

Money-changing and Wholesale Currency Business

The Policy Document stipulates threshold based CDD for money-changing transactions.

Reporting institutions may offer money changing and wholesale currency business without conducting CDD when the transaction amount is less than RM3,000.

E-money

The Policy Document stipulates strict CDD tiers for e-money accounts, which is in accordance to the thresholds and features. Reporting institutions may use Appendix 3 of the Policy Document as reference.

Reporting institutions are required to conduct CDD when any of the following conditions are met:

  1. the account limit is equivalent to RM3,000 or above;
  2. the monthly transaction limit is equivalent to RM5,000 or above;
  3. the annual transaction limit is equivalent to RM60,000 or above;
  4. the account is used for payments of goods and/or services outside of Malaysia;
  5. the account is used for cash withdrawals; and
  6. the account is used for wire transfers.

If any of the above conditions are met, reporting institutions are expected to conduct CDD in accordance with the relevant tiers.

For example, if an e-money account has an account limit of RM1,500, with monthly and annual transaction limits of RM2,000 and RM24,000 respectively. However, it can be used for domestic wire transfers, then the said account shall not be offered without CDD. Instead, the reporting institution may opt to offer the product with Simplified CDD.

As per paragraph 8.2 of the Policy Document, only selected requirements pertaining to CDD in paragraphs 10.3, 10.4, 10.5 and Appendix 2 of the ICTF are superseded. Reporting institutions shall adhere to CDD requirements stipulated in the Policy Document, with effect from 1 January 2020.

No. The monthly or annual transaction thresholds stipulated in the Policy Document are solely on the usage of funds in the e-money.

For example, a customer reloads RM100 into their e-money account and proceeds to buy RM30 worth of goods / services on the e-money platform. In this case, the utilised funds of RM30 from the account is computated for the monthly / annual transaction limit.

Verification

Verification can be a combination of various data points that the financial institution deems to be “reliable and independent” which could cumulatively ensure the veracity of customer and beneficial owner’s identification data. Any measures adopted should be subjected to the reporting institution’s internal governance process.

Generally, reporting institutions would verify the identity through acceptable government issued documents with or without photograph (e.g. MyKad, MyKid, MyPR, OKU card, driving licence, birth certificate, marriage certificate), foreign passport, employee identification documents, etc.

Alternatively, subject to the reporting institution’s assessment whether it is appropriate to mitigate the risks, reporting institutions may accept scanned or copy documentation and apply additional measures which include:

  1. third party verification of identity from the client’s primary bank account provider, lawyer or accountant in accordance with paragraph 16 of the Policy Document;
  2. corroborative evidence from Jabatan Pendaftaran Negara, Suruhanjaya Syarikat Malaysia and Central Credit Reference Information System (CCRIS) databases;
  3. use of commercial providers who triangulate data sources to verify documentation provided; 
  4. use of new and robust technology solutions including but not limited to, biometric technologies which should be linked incontrovertibly to the customer;
  5. through non face-to-face mechanisms e.g. video conference with customers and submission of selfies to compare the physical identity of a customer with scanned or photographed copies of identification documents; and/or
  6. other reliable and independent source. 

Reporting institutions are expected to undertake adequate and reasonable measures to mitigate risks arising from the adoption of any non face-to-face mechanisms.

For further details, please refer to the “Guidance on Verification of Individual Customers for CDD” issued by Bank Negara Malaysia.

Yes, any documents requested or obtained during the CDD process should be kept and recorded to meet the record keeping requirement as set out under paragraph 24.1 of the Policy Document.

The record keeping of these documents may be in the form of a photocopy, soft copy (scanned copy or snapped picture) or biometric record (such as Government Multi-Purpose Card Consortium (GMPC) verification, etc.).

Under such circumstance, the exemption on verification of the identity of directors and shareholders of that legal person applies.

Reporting institutions are required to identify and maintain information relating to the identity of the directors and shareholders of the public listed company using reliable sources (see the following paragraphs)

  1. Banking and DTIs - paragraph 14A.9.9
  2. Insurance and Takaful - paragraph 14B.11.15
  3. MSB - paragraph, 14C.10.10
  4. NBIs - paragraph 14D.9.9
Standard CDD

A person authorized must be represented with a letter of authority or director’s resolution from the legal person.

Where it involves an authorized signatory, i.e. when a legal person opens an account, establishes business relations and authorizes another person to conduct transactions on its behalf, the reporting institution shall obtain documentary evidence pertaining to the appointment of such person and the specimen signatories and/or recognized digital signature of the person appointed.

For treasury related transactions, the reporting institution shall obtain name of the authorized dealer, documentary evidence authorizing the person to act on behalf of the legal person and authorized telephone number to carry out the transaction.

Reporting institutions must be guided by their risk assessment on what documentary evidence would suffice for the purposes of identifying and verifying the person authorized.

For example, reporting institutions may consider whether a letter from human resource would be deemed sufficient for such purposes. In such cases, the letter should at the very least contain the name and NRIC number of the authorized person to facilitate identification purposes.

Reporting institutions may also consider requesting the name and contact number of a personnel in the human resource department or other relevant department that may be contacted for verification purposes.

ITOs should focus on the relationship between policyholders and payors and apply a risk-based approach when dealing with different payors.

For example, if an ITO identifies that the payor is actually a family member of a policyholder, then the ITO may adopt simplified CDD if the risk posed by the payor is assessed as low.

The Policy Document is currently not applicable to merchant acquiring activities. As such, reporting institutions are not obliged to conduct CDD on merchants.

Nevertheless, should the merchant that is on-boarded also utilises e-money product/ services offered by the reporting institution, it is then regarded as a customer (legal person) of the reporting institution. As such, they may need to fulfil CDD requirements, in accordance with the relevant tiers. The classification of legal person or natural person is as per the definition in paragraph 6 of the Policy Document. However, Bank Negara Malaysia will conduct assessments from time to time on specific entities to identify associated ML/TF risks.

Specific CDD: CDD on E-Money / CDD for Non-Bank Issuers of E-Money

Cash withdrawals are transactions that provide customers access to cash, and hence do not include refunds to bank accounts.

Notwithstanding the above, reporting institutions may conduct CDD and collect any information that they deem necessary, in accordance with their internal policies and procedures/ risk based approach.

Simplified CDD

Yes, Board approval may be obtained one-off. For example, in the event where a reporting institution adopts the same Simplified CDD framework to a new product, a new approval is not required, subject to any changes to the ML/TF risk level of the parameters assessed by the reporting institution.

Additionally, for MSB licensees, prior approval from BNM is required to implement simplified CDD.

No. For account limits between RM3,000 and RM4,999, simplified CDD can be applied only when ALL conditions in (a) to (e) are met i.e.

  1. the monthly transaction is below RM5,000;
  2. the annual transaction is below RM60,000;
  3. the account is used for payments of goods and/or services within Malaysia only;
  4. the account is used for domestic wire transfers; and
  5. cash withdrawal or cross-border wire transfers are not permitted

If any of the above conditions cannot be met, then standard CDD measures should apply.

The linking of accounts is intended for the traceability of funds by way of identifying the source of funds channelled into the e-money account.

However, reporting institutions may allow linking of accounts belonging to close associates/family members, e.g. spouse/parents, provided that reporting institutions conduct their own risk assessments and are satisfied that the risk is low.

For example, the customer’s e-money account (in this case is a child), is reloaded with savings / current / payment card account belonging to his / her mother for the child’s school / monthly allowance purposes.

The Policy Document does not prescribe any specific verification methods, and instead stipulates principle-based requirement for the verification of customer identity, which applies for both Standard and Simplified CDD tiers.

A reporting institution is required to verify customer’s identity using reliable, independent documents, data or information, or a combination of several data points. 

The extent and mode of verification employed shall be determined by the reporting institution, provided it is commensurate with the ML/TF risks and the reporting institution is satisfied with the identity of the customer. Further, the reporting institution must be able to substantiate the same to supervisors.

Examples of documents that may be used include any government issued identification card (e.g. MyKad, MyKid, MyPR, birth certificate), employee identification issued by ministries and statutory bodies, foreign passport or identification issued by the United Nations, utility bills, documents used by municipal council, etc.

As such, leveraging on the CDD previously conducted by other reporting institutions, among others, may be the method determined by the reporting institution, provided that it is satisfied that the customer is indeed who he says he is and is able to justify the same to supervisors.

However, when a reporting institution relies on a third party (i.e. another reporting institution) for CDD, requirements in paragraph 16 Policy Document shall be adhered to.

Enhanced CDD

No. The requirement to obtain information on source of funds and/or source of wealth applies when overall ML/TF risks are assessed as higher risk. Reporting institutions are not expected to establish source of wealth for each and every customer or transaction.

Generally, reporting institutions are required to enquire on source of funds and/or source of wealth, as part of the enhanced CDD under the following scenarios:

  1. subsequent to the conduct of customer risk profiling, when a customer is assessed as having higher ML/T risks, regardless of any amount of transaction;
  2. for all foreign politically exposed persons (PEPs) or when a domestic PEP is assessed as having higher ML/TF risks, in which case, both source of fund and wealth must be obtained; or
  3. when providing nominee services to the clients, i.e. nominee shareholding, directorship or partnership services, i.e. by reporting institutions who are lawyers, accountants, company secretaries or trust companies.

Information on the source of wealth and source of funds are good sources of monitoring for the reporting institutions.

“Source of wealth” refers to the source of a person’s total assets. Documents and information that may reflect the source of wealth of a person include inheritance document, property title, copies of trust deeds, audited accounts, salary details, tax returns and bank statements. It may be possible to gather general information from commercial databases or other open sources.

“Source of funds”, on the other hand, refers to the origin of a specific asset used in connection to the business relations with the reporting institution, including amount invested, deposited or wired. Source of funds may be determined through enquiry on the customer, complemented by documents such as record of salary payments or receipt of sale proceeds, etc.

In the case of PEPs, both information on the source of wealth and source of funds are to be obtained.

Understanding both the source of wealth and source of funds of a PEP is also necessary for on-going due diligence purposes where the aim is to ensure that the reason for the business relationship between reporting institutions, and the PEP and the transactions undertaken on the PEP’s behalf, are commensurate with what one could reasonably expect from that PEP, given his/her particular circumstances.

Non Face-to-Face Business Relationship

The requirement for Board approval is connected to the risk levels of the product and services.

If the process and procedures in place for the said products and services are the same, Board approval is only required once, for all product and services on-boarded via non face-to-face channel / e-KYC.

A new approval would need to be obtained when there are changes to the ML/TF risk level of the parameters assessed by the reporting institution.

The requirements for non face-to-face (non-FTF) do not have a retrospective effect. For non-FTF business relationships, reporting institutions shall ensure their non-FTF arrangements for customer identification and verification of identity is are as effective as a face-to-face relationship.

Should there be any changes to the ML/TF risk levels, reporting institutions need to re-assess the parameter and may require a new Board approval, and where applicable, prior written approval from the Director of the Money Services Business Regulation Department or Director of the Payments Oversight Department, Bank Negara Malaysia.

Yes, customers on-boarded through e-KYC are also allowed to make payments for remittance and money changing transactions using an e-wallet besides bank account.  However, the reporting institution concerned is required to ensure that its customers fulfil the requirement of having a bank account in order to undertake such transactions.

The reporting institution concerned must ensure that the system deployed is able to tag its customers based on the on-boarding methods and assign the transaction limits according to the respective customer groups i.e.

  1. Customers on-boarded through e-KYC:
    1. Not exceeding an aggregate amount of RM30,000 per day for an individual, including expatriate; and
    2. Not exceeding an aggregate amount of RM5,000 per month for an individual who is a foreign worker
  2. Customers on-boarded over the counter: Not exceeding an aggregate amount of RM50,000 per day

Notwithstanding this, a customer on-boarded through e-KYC is allowed to transact at a higher limit of RM50,000 per day, provided that proper face-to-face KYC has been conducted on the customer concerned.

Yes, reporting institutions need to conduct specific CDD on all new customers who are on-boarded through e-KYC for money changing transactions below RM10,000. For money changing transactions above RM10,000, standard CDD measures shall apply.