AML Scenario Gap Finder

High-risk customer segment

Which scenarios run with lower lines for the customers rated high risk, rather than the same lines as everyone?

A scenario that places here

example

"High-risk customers: lower thresholds on all outgoing payments"

Read this scenario

Channels it applies to

4 of the 20 in the dictionary

CSH ACH WDM WIN

Cash, branch and ATM, ACH and direct entry, domestic wires and international wires: one sector each on the coverage chart, hatched where no scenario reaches it.

Obligations

3 regimes
RegimeObligation
Bank Secrecy Act and its regulations (31 CFR Chapter X)BSA BSA-AML-15 Transaction Monitoring · BSA BSA-CDD-4 Enhanced Due Diligence (EDD)
FATF 40 RecommendationsFATF R.10 Customer due diligence
Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)AUSTRAC AMLCTF-PartA-TxnMon Transaction Monitoring · AUSTRAC AMLCTF-PartB-ECDD Enhanced Customer Due Diligence

The obligations, quoted

BSA BSA-AML-15 Transaction Monitoring

Automated and manual transaction monitoring shall identify unusual or suspicious activity using risk-based scenarios and thresholds.

What an examiner asks to see: TM scenario inventory; Threshold tuning documentation; Above-the-line/below-the-line testing; Model validation reports
Where programmes usually fall short: No model validation; Scenarios not aligned to risk assessment
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
BSA BSA-CDD-4 Enhanced Due Diligence (EDD)

Higher-risk customers (PEPs, foreign correspondents, private banking) require enhanced due diligence including additional information collection, source of funds/wealth, senior management approval, and enhanced ongoing monitoring (31 U.S.C. 5318(i), 31 CFR 1010.610, 1010.620).

What an examiner asks to see: AML program documentation; KYC and CDD records; Transaction monitoring scenarios and tuning; SAR/STR filing register; Independent AML audit reports
Where programmes usually fall short: Beneficial ownership data incomplete; Monitoring scenarios not tuned to risk
Source: Bank Secrecy Act and its regulations (31 CFR Chapter X)
FATF R.10 Customer due diligence

Financial institutions may not keep anonymous accounts or accounts in obviously fictitious names and must, by a principle set out in law, undertake customer due diligence when establishing a business relationship, carrying out an occasional transaction above USD or EUR 15,000 or a payment or value transfer covered by INR.16, when money laundering or terrorist financing is suspected, or when they doubt previously obtained identification data: identify and verify the customer from reliable independent sources; identify the beneficial owner and take reasonable measures to verify that identity, understanding the ownership and control structure of legal persons and arrangements; understand and where appropriate obtain information on the purpose and intended nature of the relationship; and conduct ongoing due diligence and transaction scrutiny consistent with the customer's profile including, where necessary, the source of funds. The extent of each measure follows a risk-based approach; verification takes place before or during establishment of the relationship, or as soon as reasonably practicable after it where risks are managed and business would otherwise be interrupted; an institution that cannot complete CDD does not open the account or perform the transaction, or terminates the relationship, and considers a suspicious transaction report; the requirements apply to new customers and, on materiality and risk, to existing ones. The Interpretive Note sets the risk-based approach, enhanced and simplified measures, the specific measures for legal persons, arrangements and beneficiaries of life insurance, reliance on prior verification and the timing rules.

What an examiner asks to see: CDD policy and procedures with triggers and thresholds; Customer files with identity, beneficial ownership, purpose and risk rating; Ongoing monitoring and periodic review records
Where programmes usually fall short: Beneficial owner identified but never verified; Ownership and control structure of corporate customers not understood
Source: FATF 40 Recommendations
AUSTRAC AMLCTF-PartA-TxnMon Transaction Monitoring

Systems and controls for monitoring customer transactions for unusual or suspicious activity.

What an examiner asks to see: Transaction monitoring system & rules; Alert investigation records
Where programmes usually fall short: No transaction monitoring
Source: Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)
AUSTRAC AMLCTF-PartB-ECDD Enhanced Customer Due Diligence

Enhanced CDD must be applied in high-risk scenarios with additional identification, verification and monitoring steps.

What an examiner asks to see: ECDD procedures for high-risk customers / SMR triggers
Where programmes usually fall short: No ECDD for high-risk customers
Source: Anti-Money Laundering and Counter-Terrorism Financing Act (Australia)

Other typologies in peps, private banking and correspondents