Money laundering legislation has grown exponentially since the creation of the Financial Action Task Force (FATF) at the Sommet de l’Arche in Paris in 1989. This growth has been not only in terms of geographical coverage around the world, but also in terms of the sophistication and complexity of the legislation. Indeed, it has become so complex that applying the same stringency to all situations would result in an unduly burdensome regime. This has led to the development of the risk-based approach – a plan to fit the defences to the threats.
Every commercial enterprise will need to be different from its competitors in order to demarcate itself and demonstrate unique selling points (USPs) to potential clients. The risk profile of each enterprise will, therefore, also be different, not only in terms of the specific threats faced but also the vulnerabilities of the enterprise. This article aims to give firms food for thought in the development of risk management steps to be taken under the risk-based approach. The guidance offered by governments and trade associations is usually not that detailed or helpful, so companies need to give considerable lateral thought to development of an anti-money laundering (AML) risk management structure that meets legal and regulatory requirements, and assures enterprises of the maximum commercial protection available.
‘Core obligations’ include:
- Putting in place appropriate systems and controls to reflect the degree of risk associated with the business and its customers.
- Putting in place appropriate risk-sensitive customer due diligence (CDD) measures, depending on the type of customer, business relationship, product or transaction.
- Taking into account situations that, by their nature, can present a higher risk of money laundering or terrorist financing (ML/TF). These specifically include: occasions where the customer has not been physically present for identification purposes; correspondent banking relationships; and business relationships and occasional transactions with PEPs (politically exposed persons).
Required actions, to be kept under regular review, are therefore to:
- Carry out a regular formal and regular ML/TF risk assessment, including market changes, and changes in products, customers and the ‘wider environment’.
- Ensure internal procedures, systems and controls, including staff awareness, adequately reflect the risk assessment.
- Ensure customer identification and acceptance procedures reflect the risk characteristics of customers.
- Ensure arrangements for monitoring systems and controls are robust and reflect the risk characteristics of customers.
The following steps should be taken:
- Identify the ML/TF risks relevant to the commercial enterprise.
- Assess the risks presented by the commercial enterprise’s particular customers, products, delivery channels, geographical areas of operation.
- Design and implement controls to manage and mitigate these assessed risks.
- Monitor and improve the effective operation of these controls.
- Record appropriately what has been done and why.
There should be documentation of what has been done, in order for a firm to demonstrate to a regulator or court:
- How it assesses threats/risks of being used in connection with ML/TF.
- How it agrees and implements the appropriate systems and procedures, including due diligence requirements, in the light of its risk assessment.
- How it monitors and, as necessary, improves the effectiveness of its systems and procedures.
- The arrangements for reporting to senior management on operation of its control processes.
The Risk Cycle
There is not much assistance given for developing a risk management methodology, so commercial enterprises are left to their own devices. A suggested cycle, as developed in industries where risk management is much more advanced, is:
- Establish the context.
- Identify risks.
- Analyse risks.
- Assess risks.
- Risk prioritisation.
- Risk planning.
- Implement the plan.
- Report.
- Mitigate.
- Monitor.
- Review.
- Reformulate.
It is vital to document the risk cycle, in order for it to be reviewed and reformulated as necessary.
Establish the context
This means planning the scope of the task, the identity and objectives of stakeholders (clients, shareholders, staff, management, etc), the basis of risk assessment (see below) and the agenda for identification and analysis. Certain policies need to be decided, for example:
- Accepting no unnecessary risk.
- Accepting risks where the benefits outweigh the costs.
- Reducing risks to an acceptable level rather than remove them altogether.
- Focusing on reducing probability of occurrence or severity of loss, or both.
Identify risks
Risks are events which, if they occur, will cause problems, so identification can start with the source of the problem, or the problem itself:
- Sources may be internal or external, e.g. staff, criminals, regulators.
- Problems are related to identified threats, such as losing money, reputation, etc.
Once these are known, the events behind them can be investigated. For example, regulators may decide to investigate, or employees may steal client information. It is relatively difficult to identify and assess specific measurable levels of ML/TF risk and their many sources. However, these can be identified by using the following techniques:
Source: FMLI
The following table sets out various methods used in risk identification and how they could be used:
Source: FMLI
Risks can be grouped and split into different levels. For example, Level 0 may relate to external risks; level 1 may relate to clients; level 2 may consider the various breakdowns of risks relating to clients, such as their location, ownership, solvency and vulnerability to financial crime; level 3 may break down client location factors further into risky jurisdictions from the perspective of drug trafficking, etc. This process of taking factors down through the levels helps to systematise the risk identification process and ensure none are left out. It can also help avoid risk blind spots or gaps, as well as double counting or duplication, indicating whether any further risk identification needs to take place. This process can be improved by use of various analytical techniques such as logic, brainstorming, morphological analysis, or competing hypotheses, and tools such as the Six Thinking Hats and Parlour’s Five Compliance Forces model. The assumption that the risk matrix is complete can be tested by including a category of ‘other risks’ and getting team members to focus on that as well.
Analyse Risks
Risk analysis is the most important step in the risk management process. Risks must be assessed as to probability of occurrence and potential impact. There are a number of different approaches possible, depending on the degree of sensitivity required:
- Basic: score both probability of occurrence and potential loss severity simply, as high, medium or low. This is the bare minimum, a blunt approach, but a good start.
- Medium: to give a more sensitive analysis, risk could be scored in four elements. This will give a more refined result than the basic approach, but also needs a refinement of the responses.
- Advanced: here, better sensitivity is achieved. An example as to how this may be approached is set out in the table below.
Source: FMLI
Source: FMLI
Assess Risks
The risks then need to be assessed, following whichever of the three approaches set out above is selected.
The simplest formula for risk quantification is: Risk = rate of occurrence*impact of event.
Basic approach
Source: FMLI
Medium approach
Source: FMLI
Advanced approach
Source: FMLI
E = Extreme
H = High
MH = Medium High
M = Medium
ML = Medium Low
L = Low
I = Insignificant
This is a suggested base model and policy may change the above. For example, it may be decided that any risk carrying a potentially catastrophic effect should be assessed as extreme, no matter what the probability of occurrence is.
Assessment should focus on area risks as well as individual risks. Collation of control and tool usefulness will help to identify which tools are the most useful in risk reduction, thereby giving maximum ‘bang for buck’ in terms of effectiveness. This will enable:
- Understanding the type of risk exposure.
- Exposing the most significant sources of risk.
- Revealing root causes of risk.
- Highlighting potential kingpin solutions and generic responses.
- Indicating areas of dependency or correlation between risks.
- Focusing risk response development on high risk areas.
The financial benefits of risk management are not so much dependant on the formula used, but that risk assessment is performed frequently and using simple methods if possible.
One of the other key components in risk analysis is comparison of risk assessment. For example the risks of lowering know your customer (KYC) procedures for ‘lower’ risk type client applicants must be balanced against the potential increase in security due diligence (SDD)/ enhanced due diligence (EDD) exercises if there were no reduction. One risk assessment alone is rarely sufficient to make an informed decision, but it is important to compare assessments to identify the lesser evil.