Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing, and Proliferation Financing
Para. 3.2.5Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
When a Financial Institution uses automated technology and information systems to determine overall Risk ratings for the purpose of classifying business relationships or the size of operations, and these systems are provided by an external provider and are not developed internally, the Financial Institution must fully understand the Risk classification methodology proposed by the external provider and how it integrates Risk factors to arrive at an overall Risk classification. The methodology used must meet the Financial Institution's requirements for Risk assessment and the requirements for anti-money laundering, combating terrorist financing, and combating-proliferation financing in the Kingdom. The Financial Institution must ensure that the ratings are accurate and reflect its understanding of the Risks, without exempting the Financial Institution from the statutory regulatory requirements and conditions. 3.3. Stage Three/Analysis of Risk Mitigation Measures: 3.3.1 The Financial Institution must ensure that appropriate procedures, controls, and measures are in place to effectively manage and mitigate its identified Risks, including those identified at the national level, and that these procedures, controls, and measures are commensurate with the level of Risks identified by the Financial Institution and are subject to ongoing monitoring and review to ensure that they remain effective in managing and mitigating the identified level of Risk. 3.3.2 The Financial Institution shall take into account that the level of Inherent Risk directly affects the type and extent of controls, procedures, and measures applied, as well as the human and technical resources allocated to combating Risk. 3.3.3 The Financial Institution must verify the implementation of the approved controls, procedures, and measures for Risk mitigation and their consistency with the Financial Institution's daily operations. It shall assess the adequacy and effectiveness of the approved controls, procedures, and measures for Risk mitigation, and conduct ongoing monitoring to ensure proper implementation, evaluate effectiveness, and promptly address any deficiencies or gaps. 3.3.4 The Financial Institution shall continuously assess the level and adequacy of the approved controls for Risk mitigation, and the assessment process shall include, at a minimum, the following: a. The impact of Inherent Risk levels on the type and levels of controls and resources for anti-money laundering, combating terrorist financing, and combating proliferation financing. b. The controls and strategies adopted to mitigate Risks. c. Identification of the type of control (e.g., whether the control is automated or manual). d. Whether the control has been tested by an independent auditor. e. Identification of the level of control (e.g., whether the control is primary or secondary). f. Whether the control has been in place for more than a year. g. Identification of the nature of control (e.g., Whether the control is preventive, such as controls adopted by the Financial Institution to limit the possibility of its products or channels being used in a manner that could increase the Risks. This may include controls such as setting transaction limits, requiring administrative approval for high-Risk customers, products, or countries, and applying enhanced due diligence measures to specific customers. or a detective control, such as controls adopted by the Financial Institution for the purpose of monitoring customer activities related to products or channels, which may include information related to the manner in which products or channels are used, information related to transaction monitoring, and reporting of suspicious transactions). 3.4. Stage 4/Risk Response
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded