Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing, and Proliferation Financing
Para. 2.10Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
The Guide does not aim to encourage Financial Institutions to engage in unjustified de-risking, which is a practice whereby the Financial Institution terminates or restricts business relationships with customers or categories of customer in a comprehensive, excessive, and unjustified manner to avoid risks rather than manage them in accordance with a Risk-Based Approach. The Financial Institutions shall manage risks and apply Preventive and Risk Mitigation Measures that are commensurate with its level of Risk Appetite. 2.11 The Financial Institution must verify that the Business Risk Assessment meets all of the following criteria, at a minimum: a. It shall be written and approved by the board of directors or senior management, as the case may be. b. It shall encompass all factors and risks associated with the Financial Institution's business. c. It shall cover the risks for all elements specified in the Guide. d. It shall clearly distinguish between money laundering risks, terrorist financing risks, and proliferation financing risks. e. It shall take into account high-level external sources, such as national risk assessments and sectoral risk assessments. f. It shall identify priorities for risk treatment in accordance with their level of risk and their impact on business continuity. g. It shall be updated on an ongoing basis, at least once annually, unless a triggering event occurs in accordance with paragraph (2.5). Chapter Three: Stages of Business Risk Assessment 3.1. Stage One/ Data Collection 3.1.1. As part of the Risk assessment process, the Financial Institution shall assess Inherent Risks by collecting data and information from multiple external and internal sources. This stage shall be carried out in an integrated manner, with the participation of the relevant departments within the Financial Institution, to ensure a comprehensive understanding of potential sources of Risk. 3.1.2. The Financial Institution shall rely on reliable sources to collect data and information to ensure an accurate understanding of the Risks. Such sources shall include, by way of example and not limitation: - Relevant external sources: a. The Kingdom's national Risk assessment. b. Risks identified by the Anti-Money Laundering Permanent Committee (AMLPC) and the Permanent Counter Terrorism Committee (PCTC). c. Risk assessments conducted by supervisory authorities and competent authorities in the Kingdom. d. Instructions issued by SAMA. e. Circulars and guidelines issued by supervisory authorities and competent authorities. f. International guidelines, typologies, and assessments. g. Information issued by sectoral professional agencies. h. Blacklists, gray lists, and international sanctions lists. i. Thematic Risk assessments conducted by supervisory authorities or competent authorities. j. National Risk assessments in other regions that are relevant to the Financial Institution's business. - Relevant internal operational sources: a. Customer data: numbers, types, and geographic locations. b. Beneficial owner data of the Financial Institution's customers. c. Results of the analysis of unusual or suspicious transactions. d. Observations/findings of internal and external auditors. e. Volume of operations. f. Percentage of cash transactions. g. Scope and characteristics of products. h. Compliance, anti-money laundering, and combating terrorist financing function reports. i. Exposure to specific sectors/industries. j. Size of the legal entity operations. k. Reliance on third parties. l. Remote transactions conducted without the customer being physically present. 3.2. Stage Two/Inherent Risk Analysis:
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded