Developing a Risk-based Approach

Money laundering legislation has grown exponentially since the creation of the Financial Action Task Force (FATF) at the Sommet de l’Arche in Paris in 1989. This growth has been not only in terms of geographical coverage around the world, but also in terms of the sophistication and complexity of the legislation. Indeed, it has become […]

Author
Richard Parlour Date published
July 28, 2009 Categories

Money laundering legislation has grown exponentially since the creation of the Financial Action Task Force (FATF) at the Sommet de l’Arche in Paris in 1989. This growth has been not only in terms of geographical coverage around the world, but also in terms of the sophistication and complexity of the legislation. Indeed, it has become so complex that applying the same stringency to all situations would result in an unduly burdensome regime. This has led to the development of the risk-based approach – a plan to fit the defences to the threats.

Every commercial enterprise will need to be different from its competitors in order to demarcate itself and demonstrate unique selling points (USPs) to potential clients. The risk profile of each enterprise will, therefore, also be different, not only in terms of the specific threats faced but also the vulnerabilities of the enterprise. This article aims to give firms food for thought in the development of risk management steps to be taken under the risk-based approach. The guidance offered by governments and trade associations is usually not that detailed or helpful, so companies need to give considerable lateral thought to development of an anti-money laundering (AML) risk management structure that meets legal and regulatory requirements, and assures enterprises of the maximum commercial protection available.

‘Core obligations’ include:

Required actions, to be kept under regular review, are therefore to:

The following steps should be taken:

There should be documentation of what has been done, in order for a firm to demonstrate to a regulator or court:

The Risk Cycle

There is not much assistance given for developing a risk management methodology, so commercial enterprises are left to their own devices. A suggested cycle, as developed in industries where risk management is much more advanced, is:

It is vital to document the risk cycle, in order for it to be reviewed and reformulated as necessary.

Establish the context

This means planning the scope of the task, the identity and objectives of stakeholders (clients, shareholders, staff, management, etc), the basis of risk assessment (see below) and the agenda for identification and analysis. Certain policies need to be decided, for example:

Identify risks

Risks are events which, if they occur, will cause problems, so identification can start with the source of the problem, or the problem itself:

Once these are known, the events behind them can be investigated. For example, regulators may decide to investigate, or employees may steal client information. It is relatively difficult to identify and assess specific measurable levels of ML/TF risk and their many sources. However, these can be identified by using the following techniques:

Table 1: Techniques for Identifying Sources of Risk

Source: FMLI

 

The following table sets out various methods used in risk identification and how they could be used:

Table 2: Risk Identification Methods

Source: FMLI

Risks can be grouped and split into different levels. For example, Level 0 may relate to external risks; level 1 may relate to clients; level 2 may consider the various breakdowns of risks relating to clients, such as their location, ownership, solvency and vulnerability to financial crime; level 3 may break down client location factors further into risky jurisdictions from the perspective of drug trafficking, etc. This process of taking factors down through the levels helps to systematise the risk identification process and ensure none are left out. It can also help avoid risk blind spots or gaps, as well as double counting or duplication, indicating whether any further risk identification needs to take place. This process can be improved by use of various analytical techniques such as logic, brainstorming, morphological analysis, or competing hypotheses, and tools such as the Six Thinking Hats and Parlour’s Five Compliance Forces model. The assumption that the risk matrix is complete can be tested by including a category of ‘other risks’ and getting team members to focus on that as well.

Analyse Risks

Risk analysis is the most important step in the risk management process. Risks must be assessed as to probability of occurrence and potential impact. There are a number of different approaches possible, depending on the degree of sensitivity required:

  1. Basic: score both probability of occurrence and potential loss severity simply, as high, medium or low. This is the bare minimum, a blunt approach, but a good start.
  2. Medium: to give a more sensitive analysis, risk could be scored in four elements. This will give a more refined result than the basic approach, but also needs a refinement of the responses.
  3. Advanced: here, better sensitivity is achieved. An example as to how this may be approached is set out in the table below.
Table 3: Probability of Occurrence

Source: FMLI
Table 4: Rating of Impact

Source: FMLI

Assess Risks

The risks then need to be assessed, following whichever of the three approaches set out above is selected.

The simplest formula for risk quantification is: Risk = rate of occurrence*impact of event.

Basic approach
Table 5: Risk Assessment – Basic Approach

Source: FMLI

 

Medium approach
Table 6: Risk Assessment – Medium Approach

Source: FMLI
Advanced approach
Table 7: Risk Assessment – Advanced Approach

Source: FMLI

E = Extreme
H = High
MH = Medium High
M = Medium
ML = Medium Low
L = Low
I = Insignificant

This is a suggested base model and policy may change the above. For example, it may be decided that any risk carrying a potentially catastrophic effect should be assessed as extreme, no matter what the probability of occurrence is.

Assessment should focus on area risks as well as individual risks. Collation of control and tool usefulness will help to identify which tools are the most useful in risk reduction, thereby giving maximum ‘bang for buck’ in terms of effectiveness. This will enable:

The financial benefits of risk management are not so much dependant on the formula used, but that risk assessment is performed frequently and using simple methods if possible.

One of the other key components in risk analysis is comparison of risk assessment. For example the risks of lowering know your customer (KYC) procedures for ‘lower’ risk type client applicants must be balanced against the potential increase in security due diligence (SDD)/ enhanced due diligence (EDD) exercises if there were no reduction. One risk assessment alone is rarely sufficient to make an informed decision, but it is important to compare assessments to identify the lesser evil.

Exit mobile version