AML Risk Assessments Under Scrutiny - Pitfalls, Enforcement & Lessons Learned
Speaker
Introduction
AML risk assessments are receiving increasing scrutiny across regulated sectors.
Supervisory authorities routinely examine firm-wide risk assessments, policies, controls and procedures, customer or client risk assessments and supporting records as part of their inspections, monitoring and enforcement activity.
Yet recurring weaknesses continue to appear. These include generic or outdated firm-wide assessments, risk assessments completed retrospectively, unsupported risk ratings, insufficient source-of-funds and source-of-wealth enquiries and a failure to reassess risk when circumstances change.
Regulatory reviews and enforcement action across the legal, accountancy and financial services sectors demonstrate that simply having a risk-assessment document is not enough.
Businesses must be able to show that risks have been properly identified, assessed and managed -and that their conclusions are supported by a clear audit trail.
Presented by Jo Morris, this new virtual classroom seminar will examine common mistakes, difficult issues that arise in practice and lessons that can be learned from regulatory findings and enforcement action.
Ideal for MLROs, compliance officers and others responsible for AML compliance in regulated businesses, this session will use case studies and practical scenarios to explore whether a risk assessment is defensible, whether the proposed controls are sufficient and what action should be taken next.
What You Will Learn
This live and interactive session will cover the following:
- The regulatory framework:
- Regulation 18 - firm-wide risk assessments
- Regulations 28(12) and 28(13) - customer and transactional risk assessments
- Relevant guidance, warning notices and publications from supervisory authorities
- What might a supervisory authority examine during an inspection, review or compliance visit?
- Common firm-wide risk-assessment failures:
- No assessment in place
- An assessment prepared only after the supervisory authority requests it
- Generic, copied or templated wording
- Failure to reflect the business’s actual activities and customer base
- Missing mandatory risk categories
- Failure to consider relevant national and sectoral risk assessments
- Failure to address proliferation-financing risk
- No evidence of regular review or senior-management approval
- No clear distinction between inherent and residual risk
- Common customer, client and transactional risk-assessment failures:
- No documented assessment
- Assessments completed after the relationship or transaction has commenced
- Every customer, client or transaction classified as low or standard risk
- Tick-box answers without reasons
- Customer risk considered but product, service or transaction risk overlooked
- Risks identified without appropriate mitigating action
- No ongoing reassessment
- The relationship between:
- The firm-wide risk assessment
- Policies, controls and procedures
- Customer, client and transactional risk assessments
- Customer due diligence
- Enhanced due diligence
- Ongoing monitoring
- Compliance monitoring and independent audit
- Difficult risk-rating decisions:
- When might one risk factor result in a high-risk classification?
- How should multiple moderate risk factors be assessed?
- When is enhanced due diligence mandatory?
- Can mitigating measures change the residual risk rating?
- What is the difference between inherent and residual risk?
- Source of funds and source of wealth:
- What is the difference?
- When are enquiries required?
- How much evidence is enough?
- Can receipt of funds from a UK-regulated bank be treated as sufficient?
- Gifts, loans, third-party funding and unusual payment arrangements
- Tricky customer, client and transactional scenarios:
- Politically exposed persons
- High-risk third countries
- Complex and offshore ownership structures
- Nominee directors and shareholders
- Cash-intensive businesses
- Cryptoasset-derived funds or wealth
- Remote relationships and digital identification
- Intermediaries, agents and family offices
- Pooled funds and multiple contributors
- Unusual or unnecessarily complex transactions
- Customers, beneficial owners or funds connected to sanctions risks
- Changes during a business relationship or transaction:
- A new funder or beneficial owner
- Changes to the purpose or nature of the relationship
- Unexpected payments or payment routes
- Changes in transaction value or structure
- New adverse information
- A change in sanctions, PEP or geographical exposure
- When should you:
- Obtain further information or evidence?
- Apply enhanced due diligence?
- Increase ongoing monitoring?
- Seek MLRO or senior-management approval?
- Decline or terminate the relationship?
- Delay or refuse a transaction?
- Consider an internal disclosure or SAR?
- Lessons from regulatory reviews and enforcement action across regulated sectors
- Individual accountability and the responsibilities of senior management
- How to create a clear and defensible audit trail
- Interactive case studies - would your risk assessment withstand regulatory scrutiny?
Recording of live sessions: Soon after the Learn Live session has taken place you will be able to go back and access the recording - should you wish to revisit the material discussed.