Alqanoni

Guidance on Assessing Business Risks Related to Money Laundering, Terrorist Financing, and Proliferation Financing

Para. 3.4.1
Status unknownSaudi ArabiaRegulation

Issued by Saudi Central Bank (SAMA) Rulebook

The Financial Institution must verify that the previous three stages result in the identification of the Residual Risks. Regardless of the effectiveness of the Preventive and Risk Mitigation Measures adopted by the Financial Institution, it is reasonably foreseeable that Risks may persist and cannot be entirely eliminated, in view of external factors and evolving and ongoing threats. 3.4.2 At this stage, the Financial Institution must assess whether the Residual Risks it faces are consistent with its Risk Appetite in the context of its operations, ensure that it does not assume Risks beyond its capacity and capabilities, and introduce the necessary adjustments to strengthen controls, where required. 3.4.3 After identifying and assessing the Inherent Risks, Preventive and Risk Mitigation Measures, the Financial Institution should prepare a comprehensive action plan that sets out concrete steps to address any gaps in controls and measures, enhance Risk management processes, and reinforce compliance measures where the Residual Risks exceed its acceptable limits. 3.4.4 The Financial Institution should regularly review and update the action plan to ensure that Emerging Risks are promptly identified and effectively managed within its overall framework for anti-money laundering, combating terrorist financing, and combating proliferation financing. 3.4.5 The review process for the action plan adopted by the Financial Institution may include the following steps: a. Strengthening or introducing new controls in line with the provisions of the relevant regulations and instructions. b. Strengthening or updating the approved Internal Control Systems. c. Strengthening human or technical resources. 3.5. Stage 5/Endorsement 3.5.1 The Financial Institution shall document the Business Risk Assessment and action plan, endorse them, and review them on continuously in accordance with the provisions of the Guide and the provisions of Paragraph (2.11 ) at a minimum. 3.5.2 The Financial Institution shall inform its employees and all its staff of the results of the Business Risk Assessment through a continuous training program to raise their awareness of the key Business Risks to which the Financial Institution is exposed, enabling them to implement the Internal Control Systems adopted by the Board of Directors or Senior Management, as applicable, to effectively mitigate those Risks. 3.6. Stage 6/Follow-up and Review of the Business Risk Assessment 3.6.1 The Financial Institution must subject the Business Risk Assessment to continuous review, taking into account the ongoing change and evolution of Risks. If the Financial Institution is aware of the emergence of a new Risk or the exacerbation of an existing Risk, it must reflect the matter in the Assessment as soon as possible and notify SAMA thereof. The Financial Institution should assess the information obtained as part of the ongoing monitoring of the business relationship and consider whether it affects the assessment. 3.6.2 Financial Institutions should ensure that regulations and controls are in place to keep the Business Risk Assessment up to date, including, for example, setting a date for the next Business Risk Assessment to ensure that changing, new, or Emerging Risks are included. When reviewing the Business Risk Assessment, the Financial Institution should take into account updated quantitative and qualitative information, consider any new insights derived from national and/or sectoral Risk assessments, review Risks associated with products, services, and Delivery Channels, review regulatory updates, and consider any region-specific updates. 3.6.3 Financial Institutions should develop an internal list of events that may warrant an unscheduled review of the Business Risk Assessment, including new products, services, or Delivery Channels; the implementation of new technologies; a change in customer segment; material supervisory changes; or a significant increase in the level of Risk.

The Arabic text is the legally binding version. The English translation is provided for guidance only.

Freshness not yet recorded

Checking your watch…

Related articles

Citing judgments

No judgments citing this article have been indexed yet.

Amendment timeline

No amendment history recorded.