Alqanoni

Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing, and Proliferation Financing

Para. 2.1
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

The Financial Institution shall conduct a Business Risk Assessment as a key element of its Risk-Based Approach. This assessment shall enable the Financial Institution to systematically assess the risks associated with its business activities, customer base, products, services, geographic exposure, and service delivery channels in order to identify, measure, and understand the Inherent and Residual Risks it faces. 2.2 The Financial Institution shall document the Business Risk Assessment and rely thereon as a key element that assists it in understanding the risks to which it may be exposed in its business, determining how to effectively mitigate risks through internal control systems, identifying Residual Risks and any gaps in controls that shall to be addressed, and determining its Risk Appetite and priorities accordingly. 2.3 The Financial Institution must ensure that the Business Risk Assessment has been developed specifically in accordance with the nature of its activities and the size of its operations, and that due consideration is given to the factors and risks specific to the Financial Institution's business context and those risks associated with the countries in which it operates. Any general Business Risk Assessment that is not developed and adapted to the nature and needs of the Financial Institution's business, and that does not take into account the key elements set out in the Guide shall not meet the minimum requirements for the Financial Institution. 2.4 The Financial Institution may identify and assess risks in a variety of ways and methods, including, but not limited to, assessing the likelihood of an event occurring, assessing both the likelihood and potential consequences, assessing based on vulnerabilities, threats, and impact, or assessing based on an analysis of the impact of uncertainty about the event. Regardless of the methodology chosen, the Financial Institution must be able to demonstrate to SAMA that its methodology is appropriate and effective, and that it is suitable and appropriate for its needs and the nature of its business. 2.5 The Financial Institution shall update its Business Risk Assessment immediately upon the emergence of any new or increasing risk element, including material changes in customer segments, products, services, transactions, delivery channels, business practices, technologies, regulatory requirements, or material weaknesses in Preventive and Risk Mitigation Measures. 2.6 The Financial Institution shall subject the Business Risk Assessment to an ongoing independent audit conducted by an independent auditor at least once annually. The audit shall include an assessment of the methodology, data quality, and the effectiveness of controls and preventive measures, and the results of the audit shall be submitted to the board of directors or senior management, as the case may be, for discussion and for addressing deficiencies and areas for improvement. 2.7 The Financial Institution shall provide the SAMA with a written Business Risk Assessment upon request, including an executive report and detailed appendices commensurate with the nature of its activities, the size of its operations, and its level of risk exposure. 2.8 The Financial Institution that is part of a group shall also conduct an individual assessment of its own risks and shall not rely solely on the group-level Business Risk Assessment. 2.9 The board of directors or senior management, as applicable, of the Financial Institution shall review the business risk report on an annual basis to ensure that it is consistent with the Financial Institution's Risk Appetite and the human and technical resources allocated thereto, without prejudice to other relevant SAMA's instructions, including the requirements relating to the submission of a quarterly report on the risks of the Financial Institution.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.