Breadcrumb

AML/CFT Compliance Programme

AML/CFT Compliance Programme


Employee Screening Programme

Yes, the screening of employees can be differentiated on a risk-based basis, depending on the position, job scope or other relevant factors related to the employee.

Reporting institutions are expected to assess their employees’ vulnerability to money laundering, terrorism financing, fraud and bribery risks, and use various sources of information to assist in the screening process to ensure that employees do not abuse their position or be vulnerable or used as a conduit to facilitate ML/TF activities.

Reporting institutions may choose any suitable method to conduct employee screening and be guided by the requirements in paragraph 11.5 of the Policy Document.

Examples of methods for the conduct of employee screening may include face-to-face meeting, phone or video interviews, online checks, skills test, submission of documents or statutory declarations, criminal checks with relevant authorities, consumer credit reports, transaction monitoring, obtaining employment reference, etc.

The parameters and triggers for re-screening are to be determined by each reporting institution.

Examples of best practices would include consideration of global watch list (including negative news screening), criminal checks with relevant authorities, transaction monitoring as well as credit reports and also changes in circumstances, either professionally or personally e.g. promotion, secondment to another division function, financial hardships, or staying in the same position for a long period of time, etc.

Employee Training and Awareness Programmes

Training should be continuous. Any form of training, e.g. classroom, online or webinar, are acceptable depending on the needs of the employee, the job function and responsibilities undertaken by the employee.

Reporting institutions should have clear and comprehensive training contents. The training materials should be frequently reviewed to include any latest changes to the AML/CFT or other regulatory requirements. In addition, tests or examinations are highly encouraged to demonstrate higher levels of effectiveness.

Reporting institutions are to ensure that the training provided to their employees is properly documented.

Life insurance principals are required, under paragraph 11.6 of the Policy Document, to ensure their agents receive initial and on-going training on relevant AML/CFT obligations. This also applies in cases where the insurance agent provides both life and general insurance services.

Independent Audit Function

Yes, the function may be delegated to other Board level committees (i.e. audit or risk) so long as the committee is independent and the AML/CFT findings or issues relating to the adequacy and implementation of the AML/CFT policies and procedures are ultimately tabled to the Board.

For example, the decision on frequency and scope of the audit can be delegated to the Board Audit Committee.

The frequency of the audit depends on the reporting institutions’ assessment of its ML/TF risk exposure and is determined by the Board.

On the scope of the independent audit, reporting institutions are to refer to the requirements under paragraph 11.7.6 of the Policy Document. Further, reporting institutions must also consider whether there were previous non-compliances under the AMLA which resulted in enforcement actions taken against the reporting institution.

Yes, reporting institutions are no longer required to submit an annual audit report to FIED, BNM.

However, reporting institutions must ensure that the audit report and necessary corrective measures undertaken are made available to FIED, BNM and the relevant supervisory authorities upon request.

In addition, MSB licensees are expected to be guided by other relevant requirements relating to internal audit report issued by the Money Service Business Regulation Department, BNM.