General Components of AML Policies, Controls, and Procedures

General Components of AML Policies, Controls, and Procedures

Establishing and maintaining Anti-Money Laundering (AML) policies, controls, and procedures to mitigate Money Laundering, Terrorist, and Proliferation Financing (MLTPF) risks is a regulatory obligation for Relevant Persons in UK. Our latest infographic discusses the components of AML Policies, Controls, and Procedures as stipulated in the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017). These components include the following:

Risk Management Practices under Anti-Money Laundering Regulations in UK

The AML Policies, Controls, and Procedures should include the appropriate risk management systems and practices that Relevant Persons have put in place. These risk management practices must be proportionate to the nature and size of the business and the MLTPF risk exposure of the Relevant Person. The MLTPF risk exposure of a Relevant Person is assessed through the Business-Wide Risk Assessment.  

Internal Controls as a Part of Anti-Money Laundering Policies

The AML Policies, Controls, and Procedures should detail the internal controls, such as the appointment of a member of the Board of Directors or senior management as the officer responsible for compliance with the Anti-Money Laundering, Counter-Terrorist Financing, and Counter Proliferation Financing (AML/CTF/CPF) regulations.  Establishing employee screening procedures, independent audit functions, systems for responding to regulatory inquiries, and training for relevant employees and agents are some of the other internal controls that should form part of the regulated entity’s Anti-Money Laundering policy and procedures

Customer Due Diligence

The AML Policies, Controls, and Procedures should specify the Customer Due Diligence (CDD) measures that the Relevant Persons should perform at the time of establishing a business relationship, carrying out occasional transactions exceeding an amount specified in the regulations, which can be considered as a transfer of funds, in the event any MLTPF suspicion arises, if there are any doubts as to the veracity of adequacy of information/documents previously obtained during identification or verification, etc.

AML Policies, Controls, and Procedures for Reliance on Third Parties

AML Policies, Controls, and Procedures should determine the scope of reliance on third parties in accordance with the conditions given in MLR 2017, the extent of liability of the Relevant Persons and the third party they rely on, along with the due diligence measures to be applied when relying on a third party for AML/CTF/CPF compliance.

Record-Keeping Policies for AML Regulatory Obligations UK

AML Policies, Controls, and Procedures should specify the documents, information, and supporting records obtained by the relevant persons or their intermediary that must be maintained by the relevant persons for such time period as may be prescribed in MLR 2017.

Management and Monitoring of Compliance with AML Policies, Controls, and Procedures

AML Policies, Controls, and Procedures must also include measures for management and monitoring of compliance with such AML Policies, Controls, and Procedures.

Such management and monitoring measures may include periodic assessment of the adequacy of systems and controls, application of a Risk-Based Approach, responsibility of the senior management, compliance with the legal and regulatory requirements, adequacy of resources available, internal review mechanisms and internal audit functions.

Internal Communication of AML Policies, Controls, and Procedures

Relevant Persons must also have AML Policies, Controls, and Procedures with regard to internal communication of such policies and procedures. This includes staff training, staff awareness, and staff alertness on the money laundering, terrorist financing, and proliferation financing risks, the legal position of the Relevant Person and the adoption of a Risk-Based Approach to AML/CTF/CPF.

Identification and Scrutiny of Complex or Unusual Transactions in High-Risk MLTPF Situations

Relevant Persons must deploy adequate policies and procedures for the identification and scrutiny of complex transactions and unusual activity or transactions. For instance, if transactions are larger than usual, if the transaction pattern does not align with the customer’s day-to-day activities, or if the Relevant Person is unable to establish a sound reason or legitimate purpose of a transaction or if the Relevant Person doubts the veracity of the information provided by the customer, then the AML Policies, Controls, and Procedures should specify the enhanced measures that the Relevant Person must take.

Additional Measures for Preventing the Use of Products and Transactions Which May Not Favour Transparency for the Purpose of MLTPF

AML Policies, Controls, and Procedures should also elaborate upon the additional measures that the Relevant Person will take when required, to prevent products or transactions which may not favour transparency from being used for MLTPF purposes.

For example, in case of non-face-to-face contact with a customer, Relevant Persons in UK must deploy additional measures to determine if the customer is knowingly avoiding face-to-face contact.

Preparatory Measures before and During the Adoption of New Products, Business Practices, or Technologies for Assessment and Mitigation of MLTPF Risks

AML Policies, Controls, and Procedures must include provisions for ensuring that if and when new products or business practices, like new delivery mechanisms or technologies are introduced by the Relevant Persons, adequate preparatory measures surrounding risk mitigation of such products, business practices, or technologies against financial crimes are also adopted.

For instance, before introducing any new products, business practices, or technologies an MLTPF risk assessment must be conducted to determine the level of risk such a new product, business practice, or technology may pose.

Compliance with Obligations Stipulated in the Terrorism Act 2000 and Proceeds of Crime Act 2002 by Employees, Staff Members, or Associated Persons in the Event of MLTPF Suspicion

The Proceeds of Crime Act 2002 and the Terrorism Act 2000 provide for disclosure requirements in the event of grounds for suspicion that a person is engaged in money laundering or terrorist financing.

In this regard, the AML Policies, Controls, and Procedures should include procedures for the members of the staff to report to the Relevant Person’s nominated officer or such officer with equivalent designation any suspicion of MLTPF they encounter. The nominated officer must consider such an internal report, investigate the same, and file an external report to the Financial Intelligence Unit of UK.

Key Takeaways on General Components of AML Policies, Controls, and Procedures by AML Consultants UK

Inclusion of the above-mentioned components in a Relevant Person’s AML Policies, Controls, and Procedures ensures that the Relevant Persons are compliant with the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017.