AML/ KYC (Anti-Money Laundering / Know your customer) in Retail Banking

Published by

on

Why is AML/ KYC important 

AML is the collection of policies, processes, systems and controls used by banks to prevent criminals from using the banking system to either fund crime or use funds from a crime. The objective is to prevent criminals from using banking systems for crime. 

KYC is one of the policies & processes used for AML. It’s the assessment of who a customer is and whether they present a financial crime risk.

High level process flow for KYC

1. Trigger -> 2. KYC review/ assessment (CDD (Customer due diligence) -> Risk assessment -> EDD (Enhanced due diligence) (if high risk)) -> 3. Post review action (Retain or Exit customer)

  1. Trigger

KYC assessment is done at Onboarding for NTB (New to bank) customers and its usually done based on 3 trigger conditions for ETB (Existing to bank) customers. 

  1. On-going review (OGR) – Periodic EDD for High risk customers (eg. Annual or bi-annual)
  2. On-going due deligence (ODD) – Trigger an EDD when a Low or medium risk customer becomes a High risk customer eg. Due to a profile change (eg. change of Nationality)
  3. Investigation (eg. UAR/ STR (Unusual activity report / Suspicious transaction report)) – a transaction monitoring on unusual banking transactions (transactions not aligned with customer’s profile) may lead to a UAR (internal investigation) which then leads to an STR (filing the unusual activity with regulator). 

2. KYC assessment

A. CDD

For NTB customers in personal banking, CDD is done first by collecting CDD or base profile data and doing a risk assessment based on this data and if it’s a High risk customer, an EDD is done. In private banking, an EDD is always done at onboarding for NTB customers. 

E.g. of CDD data – ID details, Personal details (eg. Name, Nationality, DOB, Address), Occupation (Employment/ Business ownership details), Financial details (Income, source of funds), Purpose of account opening.

B. Risk assessment based on CDD

Examples of CDD data and other risk factors used for Risk rating – Nationality, Residential and Mailing address, Occupation, AUM (Assets under Management) with bank, PEP/ RCA (Politically exposed person/ Relatives or close associates) screening, Sanction screening, Adverse news screening

C. EDD

3 steps:

  1. SOW (Source of wealth) collection – SOW refer to details on how customer accumulated his/her wealth over time. It involves identifying drivers/sources of customer’s assets and income from each driver. 5 drivers of SOW are Employment, Business ownership, Property, Investments, Inheritance/ Gifts.
  2. SOW plausibility assessment (SOW assessment) – Assessment of whether the customer’s accumulated wealth is credible, consistent, and supported by objective evidence, and whether there are any indicators that the wealth may be derived from criminal activity
  3. Wholistic risk rating 

SOW collection & assessment

  1. Declaration of each of the driver from customer – Details of driver (eg. For Employment – Name of company, Role, start and end year of employment, Industry, country of employment), Income from driver and Seed fund (i.e. initial seed capital or funding required to start that driver, applies for Business, Investment and Property drivers only)
  2. Assess plausibility of each of the driver (i.e. Existence of the driver, Income from the driver) via
    1. Public search – Are there publicly available information that can be used to assess plausibility
    2. Benchmarking assessment – Is the income declared for the driver consistent with the income for a similar role in a similar industry
    3. Corroboration (for Highest risk customers only) – Ask for documents that can assess plausibility eg. Income statement
  3. SOF check for each seed fund – At a high level, assess the Source of Fund provider or plausibility of the seed fund. 
  4. For Inheritence/ Gift driver, it may involve another SOW collection & assessment (at high level) of the Giftor.
  5. Calculate Net worth from each driver – Total savings from the driver + Market value (only applies to Investments or Property) – Seed fund
  6. Calculate Total Net Worth from all drivers 
  7. 3 checks
    1. Total Net Worth from all drivers > AUM with bank
    2. Assessment of adequacy of seed fund – At each point of a seed fund, Total savings from all driver – Total Seed fund > Seed fund to be assessed
    3. Red flags assessment
      1. Documentation (eg. Forged or Missing documents)
      2. Customer Behaviour (Refuses to explain wealth or changes explanations)
      3. Financial Behaviour (Wealth inconsistent with occupation, Large unexplained cash deposits, Rapid movement of funds, Transactions that are not consistent with SOW or which cannot be linked to a SOW etc.)

Wholistic risk rating

Examples of EDD data and other assessment used for Wholistic Risk rating

  1. Risk rating from CDD
  2. For the SOW drivers
    1. Country of operations of each driver 
    2. PEP/ RCA screening
    3. Sanction screening
    4. Adverse news screening 

3. Post review actions

For onboarding trigger, the post review action is to either Onboard or Reject the customer.

For ETB customers, a post review action of Retain may involve Risk mitigation with controls. A post review action of Exit customer involves Closing accounts, putting DNO (Do not onboard) flag to prevent customer from opening account again in future. 

Examples of risk mitigation with controls

  1. Risk adjustment – Change customer risk rating to the wholistic RR which should then trigger a periodic review (i.e. OGR)
  2. Hold code on account (prevents credit or debit of account)
  3. Enhanced transactions monitoring 
  4. Product restrictions
  5. Grey list (add to a list for monitoring the risk identified after 6 ms) 

Leave a comment