1. Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall identify, understand, manage, and assess their crime risks in a manner proportionate to the nature and size of their business, taking into account the risk-based approach and the results of the National Risk Assessment, and shall comply with the following: a. Consider all relevant risk factors, such as Customer risks, countries and geographic risk, product, service, transaction, and delivery channel risks, prior to determining the overall level of risk and the appropriate level of risk mitigation measures to be applied. b. Document the processes for identifying and assessing risks and the information related thereto, retain the relevant study, update it on an ongoing basis, and provide it to the concerned authorities upon request. 2. Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall mitigate the crime risks identified pursuant to Clause (1) of this Article, taking into account the risk-based approach, the results of the National Risk Assessment, and sectoral assessments, and shall comply with the following: a. Establish internal policies, controls, and procedures approved by Senior Management, enabling them to manage and mitigate the identified risks, and review and update them on an ongoing basis. b. Ensure that such internal policies, controls, and procedures are proportionate to the nature and size of their business, and monitor their implementation, assess their effectiveness, and enhance them where necessary, in accordance with Article (21) of this Resolution. c. Apply Enhanced Due Diligence measures for the management and mitigation of identified risks, including, by way of example: 1) Obtaining and verifying additional information, such as information on the Customer’s identity and occupation, the Beneficial Owner, the amount of funds, and information available through public databases and open sources; 2) Obtaining additional information on the purpose of the Business Relationship or the reasons for expected Transactions or Transactions that have actually been carried out; 3) Updating Customer Due Diligence information on the Customer and the Beneficial Owner more regularly; 4) Taking Reasonable Measures to identify the source of funds and wealth of the Customer and the Beneficial Owner; 5) Increasing the degree and level of ongoing monitoring of the Business Relationship to determine whether it appears unusual or suspicious, and selecting Transaction patterns requiring further scrutiny and review; 6) Carrying out the first payment through an account in the Customer’s name held with a Financial Institution subject to equivalent Due Diligence standards; 7) Obtaining approval from Senior Management to commence or continue the Business Relationship with the Customer. 3. Financial Institutions, DNFBPs, and Virtual Asset Service Providers may, upon fulfilling the requirements set out in Clauses (1) and (2) of this Article, and in coordination with the Supervisory Authority, apply Simplified Due Diligence measures to manage crime risks where low risks are identified, unless there is a suspicion that a crime has been committed. Such Simplified Due Diligence measures shall be proportionate to the elements of low risk and shall ensure full implementation of the instructions issued by the Executive Office or other Competent Authorities in relation to Targeted Financial Sanctions, and may include, by way of example, the following: a. Verifying the identity of the Customer and the Beneficial Owner after the commencement of the Business Relationship; b. Updating Customer data at longer intervals; c. Reducing the frequency of ongoing monitoring and Transaction scrutiny; d. Inferring the purpose and nature of the Business Relationship from the type of Transaction or the Business Relationship established, without the need to collect information or undertake specific procedures. 4. Where high risks related to Proliferation Financing are identified, Financial Institutions, DNFBPs, and Virtual Asset Service Providers shall take proportionate measures to manage and mitigate such risks. This includes, by way of example, the following: a. Adopting enhanced internal controls aimed at detecting and preventing potential violations of, non-implementation of, or circumvention of instructions of the Executive Office or other relevant Competent Authorities relating to Targeted Financial Sanctions, and conducting ongoing enhanced scrutiny of the Business Relationship to ensure full compliance; b. Maintaining documented records of the measures taken and making them available to the competent authorities upon request; c. Conducting periodic reviews of internal controls in line with changes in the level of risk.
Interpretation and application must be checked against the official text and current version.
+7 (495) 221 31 46