SlideShare a Scribd company logo
1 of 4
Download to read offline
INDUSTRY
ADVISORY FROM
WASHINGTON, DC • NEW YORK, NY • DALLAS, TX
FinCEN Issues Final Rules on Customer Due 	 june 2016
Diligence Requirements for Financial Institutions 	 	
		
The Treasury Department’s Financial Crimes Enforcement Network (FinCEN) has issued final rules clarifying and
strengthening customer due diligence (CDD) requirements for banks and other financial institutions. The rules add a
fifth pillar to the anti-money laundering (AML) compliance model that is currently mandated under the Bank Secrecy
Act (BSA).
Background and Implications
In May 2016, FinCEN issued final BSA rules establishing a baseline for identifying individuals with equity ownership
ormanagementcontrolinfinancialinstitutions’businesscustomers.Therulesfurthertheinterestsofbothgovernment
and financial institutions by improving banks’ ability to assess and mitigate financial crime and regulatory risk. The
new rules apply to banks, brokers or dealers in securities, mutual funds, and futures commission merchants and
introducing brokers in commodities. The rules are effective July 11, 2016, and covered institutions must comply by
May 11, 2018.
Banks currently use widely divergent CDD practices to identify beneficial owners and controlling individuals in
corporations, partnerships, and other legal entity customers, according to FinCEN. FinCEN notes that financial
institutions are not currently required to know the identity of individuals who own or control legal entity customers,
enabling criminals, kleptocrats, and other bad actors to hide proceeds or illegal activities and access the financial
system anonymously.
The new rules will improve banks’ abilities to assist law enforcement with financial investigations, thereby advancing
counterterrorism and other national security interests and facilitating tax compliance. FinCEN asserts that the rules
will also enable financial institutions to perform transaction surveillance more efficiently by enhancing their ability
to tailor surveillance parameters to customers’ business characteristics. Another important contribution will be the
promotion of clear and consistent expectations and practices.
FinCEN claims that the costs of the final rules will not be unduly burdensome to financial institutions and will be
justified by reduction in illicit activity. For the most part, industry best practices require banks and other financial
institutions to maintain CDD requirements in excess of the minimum requirements of the new rules. By improving
clarity and consistency throughout the industry, the new rules could promote a level playing field and facilitate bank
management of financial crime and regulatory risk.
Reviewing Current CDD Practice
The purpose of CDD is to enable a bank to predict the types of transactions in which a customer is likely to engage,
so that banks can determine when transactions may be suspicious, according to the Federal Financial Institutions
Examination Council (FFIEC) BSA/AML Examination Manual (2014). CDD begins with verification of a customer’s
identity through a bank’s customer identification program (CIP) and assessment of risks associated with that
customer. CDD should be ongoing and higher risk customers should undergo enhanced CDD processes.
INDUSTRY
ADVISORY (CONTINUED)
WASHINGTON, DC • NEW YORK, NY • DALLAS, TX
The FFIEC’s 2014 manual states that a bank’s CDD policies should be commensurate with its BSA/AML risk profile
and that a bank should ensure that it possesses sufficient customer information to implement an effective suspicious
activity monitoring system. However, other than requiring CIP programs, the manual has not, to date, mandated
specific minimum CDD requirements. Notably, there has been little guidance regarding identification of beneficial
owners and controlling individuals of customers that use a corporate or other legal entity structure.
Tightening CDD
In addressing this gap, FinCEN has identified the key elements of CDD as:
	 - Identifying and verifying the identity of customers (CIP);
	 - Identifying and verifying the identity of beneficial owners of legal entity customers;
	 - Understanding the nature and purpose of customer relationships; and
	 -Conducting ongoing monitoring to maintain and update customer information and to identify and
report suspicious activity.
While existing CIP requirements adequately address the first element above, the final rules address the second
element with the beneficial ownership requirement. Amendments to existing requirements for understanding
customer relationships and for monitoring explicitly deal with the third and fourth elements, which are already
implicitly addressed by current suspicious activity reporting requirements.
The final rules explicitly reference the BSA’s existing “pillars” of an adequate AML program. CDD would constitute a
fifth pillar, FinCEN says, joining the other four (namely internal controls, independent testing, designated compliance
manager/s, and personnel training).
Establishing Beneficial Ownership and Control
The beneficial ownership requirement constitutes the only entirely new obligation in the final rules. FinCEN seeks
to incorporate the concept of ownership and effective control contained in the Financial Action Task Force (FATF)
definition of “beneficial owner” as “the natural person(s) who ultimately owns or controls a customer and/or the
person on whose behalf a transaction is being conducted,” as well as “those persons who exercise ultimate effective
control over a legal person or arrangement.” It is worth emphasizing that beneficial owners are defined as natural
persons rather than other legal entities.
In targeting beneficial ownership, the rules refer to two “prongs.” An “ownership prong” aims to identify individuals
with substantial equity ownership interests, and a “control prong” aims to identify individuals with managerial
control over the customer. Each prong is intended to provide an independent test. In total, however, the identification
of no fewer than one individual and no more than five will be required. The same individual could be identified under
the ownership prong and the control prong, if appropriate.
The ownership prong will require identification of each individual who directly or indirectly owns 25 percent or
more of the equity interests of a legal entity customer. The term “equity interests” is to be interpreted broadly to
encompass a wide variety of ownership interests including stock in a corporation and membership interest in a
limited liability company or partnership.
INDUSTRY
ADVISORY (CONTINUED)
WASHINGTON, DC • NEW YORK, NY • DALLAS, TX
The control prong requires the identification of one individual with significant responsibility to control, manage, or
direct the legal entity customer, including an executive or senior manager (e.g., chief executive officer, chief financial
officer, chief operating officer, managing member, general partner, president, vice president, or treasurer) or any
other person who regularly performs similar functions. The customer has broad discretion to identify any individual
who fits the definition.
The final rules define legal entity customers to include corporations, limited liability companies, partnerships, and
similar business entities (whether or not officially registered in one of the 50 states). They will not include trusts,
unless created through a filing with a secretary of state. Customers that are exempt from CIP (e.g., regulated financial
institutions, publicly held companies traded on certain U.S. stock exchanges, and domestic government entities) will
be exempt from the beneficial ownership requirements of the new rules. Other specified entities will also be exempt—
generally customers whose beneficial ownership information is publicly available. Further, existing customers as of
the implementation date of the regulation will not be subject to the beneficial ownership requirement.
How It Will Work
At the time an account is opened, financial institutions will be required to verify the identity of beneficial owners
of legal entity customers consistent with existing CIP practice either by obtaining the required information on a
standard certification form or by any other means that comply with the rules’ substantive requirements. Banks would
need to record the beneficial owner’s name, date of birth, address, and government-issued identification number (a
Social Security number for U.S. persons, or a passport number with country of issuance or similar identification
number for non-U.S. persons). The forms, as well as descriptions of supporting documentation and verification, will
have to be retained for five years after any account is closed.
FinCEN will not, however, require financial institutions to verify that the natural persons they have identified are
in fact the beneficial owners of the legal entity customer. FinCEN expects financial institutions to be able to rely
generally on customers’ representations, provided that they have no knowledge of facts that would reasonably call
into question the reliability of the information.
Understanding and Monitoring Customer Relationships
In erecting a fifth “pillar” of core AML compliance, the new rules will amend existing AML program requirements
to address the third and fourth CDD elements (above), explicitly linking a financial institution’s know your customer
(KYC) program with current BSA-mandated monitoring and reporting of suspicious activity.
Thethirdelementwillrequirebanksandotherfinancialinstitutionstounderstandthenatureandpurposeofcustomer
relationships in order to develop a customer risk profile. FinCEN expects a bank to gain an understanding of its
customer to assess the financial crime risk presented and to aid the bank in determining whether customer activity is
“suspicious.” A customer risk profile refers to information gathered at account opening and may include self-evident
information such as the type of customer or type of account and may include a system of risk ratings or categories
of customers. Banks will not necessarily be required to obtain statements from customers regarding the nature and
purpose of their relationships or to collect information not already collected pursuant to existing requirements.
INDUSTRY
ADVISORY (CONTINUED)
WASHINGTON, DC • NEW YORK, NY • DALLAS, TX
© May 2016 Treliant Risk Advisors, LLC. F0516
The fourth element will explicitly require banks to conduct ongoing monitoring to maintain and update customer
information and to identify and report suspicious activity. This element is also intended to be consistent with a
bank’s existing suspicious activity reporting requirements. FinCEN expects that when a financial institution becomes
aware of information that affects the assessment of risk presented by a customer, it will update the customer’s
profile accordingly. The updating requirement is event-driven, occurs as a result of normal monitoring, and is
not a categorical requirement to update customer information, including beneficial ownership information, on a
continuous or periodic basis.
Providing a Baseline
FinCEN emphasizes that the rules describe minimum due diligence expectations and are not intended to reduce
regulators’ expectations nor do they aim to undermine financial institutions whose own internal risk assessments
have resulted in stricter CDD practices.
In fact, many banks already conduct more stringent CDD—for example, requiring identification of individuals with
10 percent ownership interests for higher risk customers. Many require the identification of a customer’s board of
directors or senior executives. Further many banks require updating of customers’ CDD information on a periodic
basis, depending on the level of risk presented by the customer.
FinCEN has projected that it does not expect the rules to require significant new activities or other changes to bank
operations. That said, changes to written procedures may be necessary.

More Related Content

What's hot

Opening & Supervision Of Accounts
Opening & Supervision Of AccountsOpening & Supervision Of Accounts
Opening & Supervision Of AccountsASAD ALI
 
This assignment is related for a bank (SBP)
This assignment is related for a bank (SBP)This assignment is related for a bank (SBP)
This assignment is related for a bank (SBP)Amna Abrar
 
Volcker 2.0: Proposed Changes to the Volcker Rule
Volcker 2.0: Proposed Changes to the Volcker RuleVolcker 2.0: Proposed Changes to the Volcker Rule
Volcker 2.0: Proposed Changes to the Volcker RuleChristopher Pearson
 
How can we help your Bank?
How can we help your Bank?How can we help your Bank?
How can we help your Bank?NJordan97
 
Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...
Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...
Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...CBIZ, Inc.
 
Sia partners aml_and_hedge_funds.01
Sia partners aml_and_hedge_funds.01Sia partners aml_and_hedge_funds.01
Sia partners aml_and_hedge_funds.01Daniel Connor
 
Capital Infusion: Private Equity Update
Capital Infusion: Private Equity UpdateCapital Infusion: Private Equity Update
Capital Infusion: Private Equity UpdatePatton Boggs LLP
 
Final CDD Rule - How We Got Here and What To Do Now
Final CDD Rule - How We Got Here and What To Do NowFinal CDD Rule - How We Got Here and What To Do Now
Final CDD Rule - How We Got Here and What To Do NowNick Guest, CAMS
 
Atty. aquino prentation rbap
Atty. aquino prentation rbapAtty. aquino prentation rbap
Atty. aquino prentation rbapRBAPAT54
 
Vskills basel iii professional sample material
Vskills basel iii professional sample materialVskills basel iii professional sample material
Vskills basel iii professional sample materialVskills
 
FATCA: why is it so difficult even after so many years?
FATCA: why is it so difficult even after so many years?FATCA: why is it so difficult even after so many years?
FATCA: why is it so difficult even after so many years?HEXANIKA
 
The Volcker Rule: Its Implications and Aftereffects
The Volcker Rule: Its Implications and AftereffectsThe Volcker Rule: Its Implications and Aftereffects
The Volcker Rule: Its Implications and AftereffectsHEXANIKA
 
Trust Exchange and ICS Webinar on Cannabis Banking Compliance
Trust Exchange and ICS Webinar on Cannabis Banking ComplianceTrust Exchange and ICS Webinar on Cannabis Banking Compliance
Trust Exchange and ICS Webinar on Cannabis Banking ComplianceTrust Exchange
 
MBA Compliance Essentials Consumer Compliants Resource Guide
MBA Compliance Essentials Consumer Compliants Resource GuideMBA Compliance Essentials Consumer Compliants Resource Guide
MBA Compliance Essentials Consumer Compliants Resource GuideMBAMortgage
 
Financial sector in Kenya
Financial sector in KenyaFinancial sector in Kenya
Financial sector in KenyaMogaka Ariemba
 

What's hot (19)

Opening & Supervision Of Accounts
Opening & Supervision Of AccountsOpening & Supervision Of Accounts
Opening & Supervision Of Accounts
 
This assignment is related for a bank (SBP)
This assignment is related for a bank (SBP)This assignment is related for a bank (SBP)
This assignment is related for a bank (SBP)
 
Volcker 2.0: Proposed Changes to the Volcker Rule
Volcker 2.0: Proposed Changes to the Volcker RuleVolcker 2.0: Proposed Changes to the Volcker Rule
Volcker 2.0: Proposed Changes to the Volcker Rule
 
Volcker 2.0
Volcker 2.0 Volcker 2.0
Volcker 2.0
 
Volcker 2.0
Volcker 2.0 Volcker 2.0
Volcker 2.0
 
How can we help your Bank?
How can we help your Bank?How can we help your Bank?
How can we help your Bank?
 
Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...
Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...
Compliance Abhors a Vacuum - If the Void is Filled with Heightened BSA Scruti...
 
Jennifer Epperson | Wall Street Reform
Jennifer Epperson | Wall Street ReformJennifer Epperson | Wall Street Reform
Jennifer Epperson | Wall Street Reform
 
Sia partners aml_and_hedge_funds.01
Sia partners aml_and_hedge_funds.01Sia partners aml_and_hedge_funds.01
Sia partners aml_and_hedge_funds.01
 
Capital Infusion: Private Equity Update
Capital Infusion: Private Equity UpdateCapital Infusion: Private Equity Update
Capital Infusion: Private Equity Update
 
Final CDD Rule - How We Got Here and What To Do Now
Final CDD Rule - How We Got Here and What To Do NowFinal CDD Rule - How We Got Here and What To Do Now
Final CDD Rule - How We Got Here and What To Do Now
 
Atty. aquino prentation rbap
Atty. aquino prentation rbapAtty. aquino prentation rbap
Atty. aquino prentation rbap
 
Your Third-Party Vendor's Risk Is Your Risk, Too
Your Third-Party Vendor's Risk Is Your Risk, Too Your Third-Party Vendor's Risk Is Your Risk, Too
Your Third-Party Vendor's Risk Is Your Risk, Too
 
Vskills basel iii professional sample material
Vskills basel iii professional sample materialVskills basel iii professional sample material
Vskills basel iii professional sample material
 
FATCA: why is it so difficult even after so many years?
FATCA: why is it so difficult even after so many years?FATCA: why is it so difficult even after so many years?
FATCA: why is it so difficult even after so many years?
 
The Volcker Rule: Its Implications and Aftereffects
The Volcker Rule: Its Implications and AftereffectsThe Volcker Rule: Its Implications and Aftereffects
The Volcker Rule: Its Implications and Aftereffects
 
Trust Exchange and ICS Webinar on Cannabis Banking Compliance
Trust Exchange and ICS Webinar on Cannabis Banking ComplianceTrust Exchange and ICS Webinar on Cannabis Banking Compliance
Trust Exchange and ICS Webinar on Cannabis Banking Compliance
 
MBA Compliance Essentials Consumer Compliants Resource Guide
MBA Compliance Essentials Consumer Compliants Resource GuideMBA Compliance Essentials Consumer Compliants Resource Guide
MBA Compliance Essentials Consumer Compliants Resource Guide
 
Financial sector in Kenya
Financial sector in KenyaFinancial sector in Kenya
Financial sector in Kenya
 

Similar to Treliant_IndustryAdvisory_FinalCDDRules_June2016

Volcker-Rule-Complex-Compliance-Challenge-2014-FINAL
Volcker-Rule-Complex-Compliance-Challenge-2014-FINALVolcker-Rule-Complex-Compliance-Challenge-2014-FINAL
Volcker-Rule-Complex-Compliance-Challenge-2014-FINALKenneth A. Goodwin Jr., MBA
 
Compliance implications of crossing the $10 billion asset threshold
Compliance implications of crossing the $10 billion asset thresholdCompliance implications of crossing the $10 billion asset threshold
Compliance implications of crossing the $10 billion asset thresholdGrant Thornton LLP
 
FinCEN Statement on Providing Banking Services to Money Services Businesses
FinCEN Statement on Providing Banking Services to Money Services BusinessesFinCEN Statement on Providing Banking Services to Money Services Businesses
FinCEN Statement on Providing Banking Services to Money Services BusinessesRyan Renicker CFA
 
Accounting and-bookkeeping
Accounting and-bookkeepingAccounting and-bookkeeping
Accounting and-bookkeepingTechweek
 
Main presentation aml cft
Main presentation aml cftMain presentation aml cft
Main presentation aml cftAsad Hameed
 
Csr and-personal-banker
Csr and-personal-bankerCsr and-personal-banker
Csr and-personal-bankerTechweek
 
Reasonably Designed - BSA/AML Primer for TPPPs
Reasonably Designed - BSA/AML Primer for TPPPsReasonably Designed - BSA/AML Primer for TPPPs
Reasonably Designed - BSA/AML Primer for TPPPsJay Postma
 
Regulatory Focus - June 2018
Regulatory Focus - June 2018Regulatory Focus - June 2018
Regulatory Focus - June 2018Duff & Phelps
 
StubbsGazette Anti Money Laundering E Book
StubbsGazette Anti Money Laundering E BookStubbsGazette Anti Money Laundering E Book
StubbsGazette Anti Money Laundering E BookJames Treacy
 
StubbsGazette AML/CFT EBook for Credit Unions
StubbsGazette AML/CFT EBook for Credit UnionsStubbsGazette AML/CFT EBook for Credit Unions
StubbsGazette AML/CFT EBook for Credit UnionsStubbsGazette
 
Stubbs gazette handbook final version
Stubbs gazette handbook final versionStubbs gazette handbook final version
Stubbs gazette handbook final versionJames Treacy
 
Beneficial-Ownership.pptx
Beneficial-Ownership.pptxBeneficial-Ownership.pptx
Beneficial-Ownership.pptxSiniTizhe
 
Embracing the Consumer Duty Imperative: A Comprehensive Guide
Embracing the Consumer Duty Imperative: A Comprehensive GuideEmbracing the Consumer Duty Imperative: A Comprehensive Guide
Embracing the Consumer Duty Imperative: A Comprehensive GuideRNayak3
 
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia PartnersFinancial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia PartnersDaniel Connor
 
Regulations Overview.pptx
Regulations Overview.pptxRegulations Overview.pptx
Regulations Overview.pptxZOHAIBABBASI15
 

Similar to Treliant_IndustryAdvisory_FinalCDDRules_June2016 (20)

Client Alert: CFPB
Client Alert: CFPBClient Alert: CFPB
Client Alert: CFPB
 
Volcker-Rule-Complex-Compliance-Challenge-2014-FINAL
Volcker-Rule-Complex-Compliance-Challenge-2014-FINALVolcker-Rule-Complex-Compliance-Challenge-2014-FINAL
Volcker-Rule-Complex-Compliance-Challenge-2014-FINAL
 
ACAMs article
ACAMs articleACAMs article
ACAMs article
 
Compliance implications of crossing the $10 billion asset threshold
Compliance implications of crossing the $10 billion asset thresholdCompliance implications of crossing the $10 billion asset threshold
Compliance implications of crossing the $10 billion asset threshold
 
Payments 101
Payments 101Payments 101
Payments 101
 
FinCEN Statement on Providing Banking Services to Money Services Businesses
FinCEN Statement on Providing Banking Services to Money Services BusinessesFinCEN Statement on Providing Banking Services to Money Services Businesses
FinCEN Statement on Providing Banking Services to Money Services Businesses
 
Accounting and-bookkeeping
Accounting and-bookkeepingAccounting and-bookkeeping
Accounting and-bookkeeping
 
Marijuana banking
Marijuana bankingMarijuana banking
Marijuana banking
 
Main presentation aml cft
Main presentation aml cftMain presentation aml cft
Main presentation aml cft
 
Csr and-personal-banker
Csr and-personal-bankerCsr and-personal-banker
Csr and-personal-banker
 
Reasonably Designed - BSA/AML Primer for TPPPs
Reasonably Designed - BSA/AML Primer for TPPPsReasonably Designed - BSA/AML Primer for TPPPs
Reasonably Designed - BSA/AML Primer for TPPPs
 
Regulatory Focus - June 2018
Regulatory Focus - June 2018Regulatory Focus - June 2018
Regulatory Focus - June 2018
 
StubbsGazette Anti Money Laundering E Book
StubbsGazette Anti Money Laundering E BookStubbsGazette Anti Money Laundering E Book
StubbsGazette Anti Money Laundering E Book
 
StubbsGazette AML/CFT EBook for Credit Unions
StubbsGazette AML/CFT EBook for Credit UnionsStubbsGazette AML/CFT EBook for Credit Unions
StubbsGazette AML/CFT EBook for Credit Unions
 
Stubbs gazette handbook final version
Stubbs gazette handbook final versionStubbs gazette handbook final version
Stubbs gazette handbook final version
 
Beneficial-Ownership.pptx
Beneficial-Ownership.pptxBeneficial-Ownership.pptx
Beneficial-Ownership.pptx
 
Embracing the Consumer Duty Imperative: A Comprehensive Guide
Embracing the Consumer Duty Imperative: A Comprehensive GuideEmbracing the Consumer Duty Imperative: A Comprehensive Guide
Embracing the Consumer Duty Imperative: A Comprehensive Guide
 
CIP
CIPCIP
CIP
 
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia PartnersFinancial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
Financial Services Insight NYSDFS Whistleblowing Guidance - Sia Partners
 
Regulations Overview.pptx
Regulations Overview.pptxRegulations Overview.pptx
Regulations Overview.pptx
 

Treliant_IndustryAdvisory_FinalCDDRules_June2016

  • 1. INDUSTRY ADVISORY FROM WASHINGTON, DC • NEW YORK, NY • DALLAS, TX FinCEN Issues Final Rules on Customer Due june 2016 Diligence Requirements for Financial Institutions The Treasury Department’s Financial Crimes Enforcement Network (FinCEN) has issued final rules clarifying and strengthening customer due diligence (CDD) requirements for banks and other financial institutions. The rules add a fifth pillar to the anti-money laundering (AML) compliance model that is currently mandated under the Bank Secrecy Act (BSA). Background and Implications In May 2016, FinCEN issued final BSA rules establishing a baseline for identifying individuals with equity ownership ormanagementcontrolinfinancialinstitutions’businesscustomers.Therulesfurthertheinterestsofbothgovernment and financial institutions by improving banks’ ability to assess and mitigate financial crime and regulatory risk. The new rules apply to banks, brokers or dealers in securities, mutual funds, and futures commission merchants and introducing brokers in commodities. The rules are effective July 11, 2016, and covered institutions must comply by May 11, 2018. Banks currently use widely divergent CDD practices to identify beneficial owners and controlling individuals in corporations, partnerships, and other legal entity customers, according to FinCEN. FinCEN notes that financial institutions are not currently required to know the identity of individuals who own or control legal entity customers, enabling criminals, kleptocrats, and other bad actors to hide proceeds or illegal activities and access the financial system anonymously. The new rules will improve banks’ abilities to assist law enforcement with financial investigations, thereby advancing counterterrorism and other national security interests and facilitating tax compliance. FinCEN asserts that the rules will also enable financial institutions to perform transaction surveillance more efficiently by enhancing their ability to tailor surveillance parameters to customers’ business characteristics. Another important contribution will be the promotion of clear and consistent expectations and practices. FinCEN claims that the costs of the final rules will not be unduly burdensome to financial institutions and will be justified by reduction in illicit activity. For the most part, industry best practices require banks and other financial institutions to maintain CDD requirements in excess of the minimum requirements of the new rules. By improving clarity and consistency throughout the industry, the new rules could promote a level playing field and facilitate bank management of financial crime and regulatory risk. Reviewing Current CDD Practice The purpose of CDD is to enable a bank to predict the types of transactions in which a customer is likely to engage, so that banks can determine when transactions may be suspicious, according to the Federal Financial Institutions Examination Council (FFIEC) BSA/AML Examination Manual (2014). CDD begins with verification of a customer’s identity through a bank’s customer identification program (CIP) and assessment of risks associated with that customer. CDD should be ongoing and higher risk customers should undergo enhanced CDD processes.
  • 2. INDUSTRY ADVISORY (CONTINUED) WASHINGTON, DC • NEW YORK, NY • DALLAS, TX The FFIEC’s 2014 manual states that a bank’s CDD policies should be commensurate with its BSA/AML risk profile and that a bank should ensure that it possesses sufficient customer information to implement an effective suspicious activity monitoring system. However, other than requiring CIP programs, the manual has not, to date, mandated specific minimum CDD requirements. Notably, there has been little guidance regarding identification of beneficial owners and controlling individuals of customers that use a corporate or other legal entity structure. Tightening CDD In addressing this gap, FinCEN has identified the key elements of CDD as: - Identifying and verifying the identity of customers (CIP); - Identifying and verifying the identity of beneficial owners of legal entity customers; - Understanding the nature and purpose of customer relationships; and -Conducting ongoing monitoring to maintain and update customer information and to identify and report suspicious activity. While existing CIP requirements adequately address the first element above, the final rules address the second element with the beneficial ownership requirement. Amendments to existing requirements for understanding customer relationships and for monitoring explicitly deal with the third and fourth elements, which are already implicitly addressed by current suspicious activity reporting requirements. The final rules explicitly reference the BSA’s existing “pillars” of an adequate AML program. CDD would constitute a fifth pillar, FinCEN says, joining the other four (namely internal controls, independent testing, designated compliance manager/s, and personnel training). Establishing Beneficial Ownership and Control The beneficial ownership requirement constitutes the only entirely new obligation in the final rules. FinCEN seeks to incorporate the concept of ownership and effective control contained in the Financial Action Task Force (FATF) definition of “beneficial owner” as “the natural person(s) who ultimately owns or controls a customer and/or the person on whose behalf a transaction is being conducted,” as well as “those persons who exercise ultimate effective control over a legal person or arrangement.” It is worth emphasizing that beneficial owners are defined as natural persons rather than other legal entities. In targeting beneficial ownership, the rules refer to two “prongs.” An “ownership prong” aims to identify individuals with substantial equity ownership interests, and a “control prong” aims to identify individuals with managerial control over the customer. Each prong is intended to provide an independent test. In total, however, the identification of no fewer than one individual and no more than five will be required. The same individual could be identified under the ownership prong and the control prong, if appropriate. The ownership prong will require identification of each individual who directly or indirectly owns 25 percent or more of the equity interests of a legal entity customer. The term “equity interests” is to be interpreted broadly to encompass a wide variety of ownership interests including stock in a corporation and membership interest in a limited liability company or partnership.
  • 3. INDUSTRY ADVISORY (CONTINUED) WASHINGTON, DC • NEW YORK, NY • DALLAS, TX The control prong requires the identification of one individual with significant responsibility to control, manage, or direct the legal entity customer, including an executive or senior manager (e.g., chief executive officer, chief financial officer, chief operating officer, managing member, general partner, president, vice president, or treasurer) or any other person who regularly performs similar functions. The customer has broad discretion to identify any individual who fits the definition. The final rules define legal entity customers to include corporations, limited liability companies, partnerships, and similar business entities (whether or not officially registered in one of the 50 states). They will not include trusts, unless created through a filing with a secretary of state. Customers that are exempt from CIP (e.g., regulated financial institutions, publicly held companies traded on certain U.S. stock exchanges, and domestic government entities) will be exempt from the beneficial ownership requirements of the new rules. Other specified entities will also be exempt— generally customers whose beneficial ownership information is publicly available. Further, existing customers as of the implementation date of the regulation will not be subject to the beneficial ownership requirement. How It Will Work At the time an account is opened, financial institutions will be required to verify the identity of beneficial owners of legal entity customers consistent with existing CIP practice either by obtaining the required information on a standard certification form or by any other means that comply with the rules’ substantive requirements. Banks would need to record the beneficial owner’s name, date of birth, address, and government-issued identification number (a Social Security number for U.S. persons, or a passport number with country of issuance or similar identification number for non-U.S. persons). The forms, as well as descriptions of supporting documentation and verification, will have to be retained for five years after any account is closed. FinCEN will not, however, require financial institutions to verify that the natural persons they have identified are in fact the beneficial owners of the legal entity customer. FinCEN expects financial institutions to be able to rely generally on customers’ representations, provided that they have no knowledge of facts that would reasonably call into question the reliability of the information. Understanding and Monitoring Customer Relationships In erecting a fifth “pillar” of core AML compliance, the new rules will amend existing AML program requirements to address the third and fourth CDD elements (above), explicitly linking a financial institution’s know your customer (KYC) program with current BSA-mandated monitoring and reporting of suspicious activity. Thethirdelementwillrequirebanksandotherfinancialinstitutionstounderstandthenatureandpurposeofcustomer relationships in order to develop a customer risk profile. FinCEN expects a bank to gain an understanding of its customer to assess the financial crime risk presented and to aid the bank in determining whether customer activity is “suspicious.” A customer risk profile refers to information gathered at account opening and may include self-evident information such as the type of customer or type of account and may include a system of risk ratings or categories of customers. Banks will not necessarily be required to obtain statements from customers regarding the nature and purpose of their relationships or to collect information not already collected pursuant to existing requirements.
  • 4. INDUSTRY ADVISORY (CONTINUED) WASHINGTON, DC • NEW YORK, NY • DALLAS, TX © May 2016 Treliant Risk Advisors, LLC. F0516 The fourth element will explicitly require banks to conduct ongoing monitoring to maintain and update customer information and to identify and report suspicious activity. This element is also intended to be consistent with a bank’s existing suspicious activity reporting requirements. FinCEN expects that when a financial institution becomes aware of information that affects the assessment of risk presented by a customer, it will update the customer’s profile accordingly. The updating requirement is event-driven, occurs as a result of normal monitoring, and is not a categorical requirement to update customer information, including beneficial ownership information, on a continuous or periodic basis. Providing a Baseline FinCEN emphasizes that the rules describe minimum due diligence expectations and are not intended to reduce regulators’ expectations nor do they aim to undermine financial institutions whose own internal risk assessments have resulted in stricter CDD practices. In fact, many banks already conduct more stringent CDD—for example, requiring identification of individuals with 10 percent ownership interests for higher risk customers. Many require the identification of a customer’s board of directors or senior executives. Further many banks require updating of customers’ CDD information on a periodic basis, depending on the level of risk presented by the customer. FinCEN has projected that it does not expect the rules to require significant new activities or other changes to bank operations. That said, changes to written procedures may be necessary.