Sanctions Compliance in the AI and Quantum Technology Sector

Sanctions Compliance in the AI and Quantum Technology Sector

Introduction: Role of Compliance in Emerging Technologies

The Australian Sanctions Office (ASO), operating under the Department of Foreign Affairs and Trade (DFAT), issues guidance to help businesses, researchers, and industry professionals understand their obligations under Australia’s Sanctions framework. This article offers a practical overview of how sanctions apply to the fast-evolving fields of Artificial Intelligence (AI) and Quantum Technologies. While the Guidance Note outlines key principles, it is not intended to replace legal advice, and organisations remain responsible for ensuring their own compliance with sanctions law.

Sanctions compliance is a shared responsibility. The ASO collaborates closely with the regulated community to prevent misuse of advanced technologies and encourages initiative-taking engagement. This includes reporting suspected breaches, whether involving other entities or through self-disclosure. By promoting transparency and cooperation, the ASO underscores the critical role of businesses and individuals in safeguarding Australia’s national security interests while supporting responsible technological invention.

Regulatory Framework and Compliance Duties

The rapid advancement of AI and Quantum Technologies creates exciting opportunities but also brings complex sanctions risks. In particular, the transfer of assets, whether tangible or intangible, such as intellectual property, research data, and the provision of certain services, may fall within the scope of Australia’s sanctions law.

Oversight by the Australian Sanctions Office

The ASO is responsible for administering and enforcing sanctions law. While it offers resources and encourages reporting, the ultimate duty to comply rests with individuals and organisations themselves.

Responsibility of Businesses

Obligations for businesses and entities in Australia extend far beyond financial restrictions. Organisations must ensure appropriate reporting duties are fulfilled, not only for their own activities but also when becoming aware of potential breaches by others.

Seeking independent legal advice, conducting ongoing due diligence, and embedding compliance responsibilities into everyday practice are essential steps for mitigating risk while advancing innovation responsibly.

Key Sanctions Risks in AI and Quantum Technology

The rise of AI and Quantum research has introduced new layers of complexity to global compliance. Australian sanctions laws apply not only to the transfer of physical goods but also to intangible assets, such as intellectual property, software and more. For AI and Quantum sector, understanding these risks is vital to avoiding inadvertent breaches.

Controlled Assets: Intellectual Property, Software and Research Data

Australian sanctions prohibit dealing with designated persons, entities, and their assets to ensure such parties cannot access or benefit from them. An asset under the law is defined broadly, covering tangible or intangible property, including intellectual property, research, software, and electronic material.
Targeted Financial Sanctions (TFS) prohibit:
  • Providing, directly or indirectly, any asset to or for the benefit of a listed person or entity
  • Using, managing, or enabling the use of assets owned or controlled by a designated person or entity.

These assets are referred to as “frozen” by the ASO until the restrictions are lifted.

The DFAT maintains a Consolidated List of sanctioned persons and entities upon which TFS have been imposed. Checking this list is crucial for all businesses operating in Australia to reduce the risk of accidentally enabling restricted actors to access valuable technology and data.

AI and Quantum Tech: The Military End-Use Challenge

Australia’s sanctions laws restrict the supply, transfer, or sale of goods that could support military activity. For the AI and Quantum Technology sector, this risk is significant because tools built for civilian use may also be used for military purposes.
Under Australian sanctions laws, “arms or related material” can include:
  • Weapons, ammunition, and military vehicles
  • Equipment and spare parts
  • Paramilitary tools and accessories

Items not clearly listed may still fall under this definition. For example, AI-driven data analytics or advanced machine learning may be treated as “dual use,” given their potential in both civilian and military contexts.

To remain compliant, companies should apply the three-step test to assess whether their technologies could be classified as controlled material before export or collaboration.

Restricted Services Under Sanctions Laws

Australian sanctions laws restrict the provision of certain services that may contribute to sanctioned activities. While the prohibitions vary by framework, they commonly cover the supply of:
  • Technical advice, training, or assistance
  • Financial Assistance or services
  • Other forms of support
These restrictions apply when the service is linked to:
  • A sanctioned supply,
  • A military activity, or
  • The manufacture, maintenance, or use of export-sanctioned goods (such as dual-use technologies)

For technology companies, this often relates to providing expertise or knowledge that supports the development or use of “export sanctioned goods.” “Technology” in this context extends to detailed information about design, production, or use. The prohibitions may also apply where services are provided directly to a sanctioned country, entity or individual.

Additionally, certain sanctions frameworks impose country-specific restrictions on services, including those tied to Syria, Russia, Zimbabwe, North Korea (DPRK), and specified regions of Ukraine, particularly in scientific or technical cooperation.

Penalties and Liabilities for Sanctions Breaches

Breaching Australian sanctions laws attracts severe penalties:
  • For individuals:
    • Up to 10 years’ imprisonment, and/or
    • Fines of 2,500 penalty units (=$825,000 as of Nov 2024), or
    • Three times the value of the transaction, whichever is greater.
  • For corporations:
    • Fines of up to 10,000 penalty units (=$3.30 million), or
    • Three times the transaction value, whichever is greater.
These are strict liability offences for companies, meaning intent need not be proven. However, businesses may defend themselves if they demonstrate reasonable precautions and due diligence to prevent breaches.

Red Flags Every AI and Quantum Tech Firm Should Look Out For

AI and Quantum Technology companies face unique compliance challenges, especially when customers or partners might be linked to high-risk activities.
Identifying red flags early is critical to prevent sanctions breaches. Warning signs may include:
  • Mismatch of Industry Use- The end receiver operates in a sector that has no legitimate need for AI software or Quantum research.
  • Opaque Profiles- Customers (domestic or foreign) with limited online presence and vague business interests.
  • Suspicious Addresses- Use of generic postal locations, freight-forwarder addresses, or co-location with unrelated businesses.
  • Complex Ownership- Entities with opaque or layered Beneficial Ownership structures.
  • High-Risk Jurisdictions- Operations based in countries subject to sanctions or heightened monitoring.
  • Unusual Payments- Reliance on non-bank channels such as remittance networks, cryptocurrency, or unrelated third-party payees.
Recognising these signals helps firms apply stronger due diligence and avoid exposure to inadvertent sanctions.

Practical Measures to Strengthen Compliance in Emerging Technology

To navigate sanctions risks, AI and Quantum Technology firms must embed strong compliance measures into their operations. Effective due diligence includes:
  • Sanctions Screening to ensure customers are not individuals or entities listed under Australian or international sanctions.
  • Collecting and verifying customer details such as name, contact information, incorporation records, and Beneficial Ownership, to reduce identity risks.
  • Assessing the end user, intended use, and potential re-export of AI or Quantum products.
  • Ensuring products are not diverted to restricted sectors or sanctioned jurisdictions.
  • Using end user certificates and restricting access to customers in high-risk regions.
These steps strengthen sanctions compliance, protect business integrity, and ensure AI innovation remains within legal boundaries.

Key Takeaways and Practical Resources

Sanctions compliance in the AI and Quantum Technology sectors is not a one-off task but an ongoing responsibility. As global risks evolve, businesses must regularly reassess obligations under Australian sanctions law and strengthen internal safeguards. In practice, seeking independent legal advice helps organisations navigate complex cases, while official resources offer practical support.

Key tools include the Sanctions Compliance Toolkit, the Sanctions Risk Assessment Tool, DAFT Guidance Note for Universities. By actively using these resources, firms can manage AI sanctions compliance in Australia, address Quantum Technology sanctions challenges, and ensure responsible innovation while protecting business integrity.

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 9+ years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

Australia’s New AML/CTF Framework: Key Changes Under the 2025 Rules

Australia’s New AML/CTF Framework: Key Changes Under the 2025 Rules

Introduction: Purpose and Scope of the AML/CTF Rules 2025

The Anti Money Laundering and Counter Terrorism Financing Rules 2025 (AML/CTF Rules or 2025 Rules) mark a decisive turning point in Australia’s compliance framework. Issued under the Anti-Money Laundering and Counter Terrorism Financing 2006 (AML/CTF Act), the rules were finally signed on 29 August 2025 and will take effect from 31 March 2026. This transition period allows institutions to restructure systems, update governance practices, and prepare for expanded obligations.

Unlike earlier iterations, the 2025 Rules go beyond consolidation by extending regulatory scope. Alongside traditional reporting entities and remittance providers, the framework now directly encompasses Virtual Asset Service Providers (VASPs) and, for the first time, Real Estate transactions. They also formalise definitions of Domestic Politically Exposed Persons (PEPs), reflecting closer alignment with global best practices.

The new regime reflects AUSTRAC’s broader strategy, embedding accountability, raising compliance expectations and positioning Australia as a credible partner in the global fight against illicit finance. Far from a routine update, the Rules establish a forward-looking framework that balances regulatory strength with business adaptability.

Who All Will Be Regulated?

The AML/CTF Rules 2025 expand AUSTRAC’s authority, capturing new sectors and closing regulatory gaps. While retaining core obligations, the framework significantly broadens its scope and raises compliance expectations across diverse industries.

Current Reporting Entities

Reporting Entities remain at the centre of Australia’s AML/CTF framework. These include banks, financial institutions, and other designated service providers. While their core obligations are familiar, the 2025 Rules place sharper emphasis on governance structures and accountability mechanisms.

Domestic Politically Exposed Persons in Focus

The 2025 Rules also spell out clearer definitions for Domestic PEPs. By subjecting these clients to enhanced scrutiny, Australia strengthens its safeguards against political corruption risks and better aligns with international best practices for managing high-risk customers.

Regulation of Real Estate Dealings

One of the most notable shifts is the formal inclusion of Real Estate dealings within AML/CTF oversight. Property transactions, long recognised as attractive for illicit fund flows, now fall squarely under AUSTRAC’s remit, requiring compliance by agents, developers, and settlement professionals.

Remittance Providers and Virtual Asset Services

Remittance operators and VASPs are again in regulatory focus, reflecting the risks of fast, opaque cross-border transactions. These entities must now adopt stricter Customer Due Diligence and reinforce monitoring systems to address evolving Money Laundering threats.

Major Shifts Brought by the 2025 Framework

The AML/CTF Rules modernise Australia’s compliance framework, merging earlier obligations, bringing virtual assets and real estate under the regulations, and refining Customer Due Diligence (CDD). Collectively, these reforms strengthen governance and reflect evolving global standards in financial crime prevention.

Direct Oversight of Virtual Asset Services

VASPs are formally regulated through a new register, requiring disclosures on assets, wallets and customer channels. Programs must assess wallet types, licensing, and secure transfers, ensuring digital finance risks are addressed alongside traditional services.

Stronger AML/CTF Programs and Due Diligence

Compliance programs must now address Proliferation Financing, Targeted Sanctions, and Real Estate transactions. Refined CDD rules require deeper ownership checks, ongoing monitoring of high-risk clients, and stricter reliance provisions for third-party KYC, enhancing transparency and accountability.

Streamlined Regulatory Structure

Replacing the former framework, the 2025 Rules adopt twelve parts for clarity and accessibility. This streamlined framework reduces fragmentation, supports compliance, consistency, and provides entities until 31 March 2026 to align their systems with the updated structure.

Central Compliance Duties Under the 2025 Rules

The AML/CTF Rules establish a robust framework of compliance obligations designed to strengthen governance and accountability across Reporting Entities. The obligations are far more comprehensive than in earlier frameworks, reflecting both domestic priorities and international Financial Action Task Force (FATF) standards.

Requirements for Enrolment and Registration

All reporting entities must undergo an updated enrollment process, which captures detailed information on ownership, corporate structures, identifiers, business activities, and exposure to financial crime risks. VASPs for the first time, are required to obtain a formal registration, creating a greater transparency in relation to wallet management and delivery mechanisms.

Designing Robust AML/CTF Programs

Entities are expected to implement customised programs that directly address the risk of Money Laundering, Terrorist Financing, and Proliferation Financing. These programs must embed strong governance measures, including regular reporting from the Compliance Officer to the boards, independent reviews of effectiveness, and rigorous due diligence and training for employees.

Enhanced Customer Identification and Monitoring

The new framework expands verification obligations across individuals, corporates, trusts, and government agencies. Enhanced checks apply in high-risk contexts, including dealings with PEPs and Real Estate transactions. Entities must also conduct Ongoing Monitoring to ensure customer information remains accurate and up to date.

Obligations For Record Management

The 2025 Rules embed record-keeping as a cornerstone of compliance. Lead Entities must maintain updated registers of group membership, reliance agreements must assign clear documentation responsibilities, and entities acquiring customers from another provider must secure historical records. These requirements underpin transparency, support audits, and support investigative capacity when irregularities occur or any suspicious activity is detected.

Reporting Duties and Transaction Requirements

Obligations relating to Suspicious Matter Reports (SMRs), Threshold Transaction Reports (TTRs), and cross-border movement declarations have become more detailed and data-intensive. Transitional arrangements permit temporary reliance on earlier reporting formats, giving institutions a limited adjustment period before full compliance is enforced.

Correspondent Banking and Transfers of Value

Financial institutions are required to perform detailed due diligence before entering correspondent banking arrangements, with senior management overseeing them. Rules on transfer transparency now cover both traditional money transfers and virtual assets, requiring ordering, intermediary, and beneficiary institutions to capture and pass on complete transaction information.

Practical Challenges for Businesses

While the AML/CTF Rules 2025 establish a stronger compliance regime, they also create a far more demanding environment for businesses. Meeting these requirements need a substantial amount of investment in people, processes, and governance, technology, and skilled personnel, exposing entities to operational pressure and reputational risks.

Heavy Reporting Obligations

Reporting requirements for SMRs, TTRs, and cross-border movement disclosures now demand highly detailed data. The sheer volume increases compliance costs and data-management risks, while AUSTRAC’s public reporting of breaches exposes businesses to reputational damage if obligations are not met effectively.

Managing International and Third-Party Relationships

Relying on third parties for KYC verification or managing correspondent banking ties requires rigorous due diligence. Businesses must evaluate whether the overseas partners meet FATF standards and repeat such assessments regularly, an exercise that is resource-heavy and highly technical.

Ongoing Risk Monitoring and Assessments

Entities must maintain continuous oversight of Money Laundering or Terrorist Financing and Proliferation Financing Risks across products, delivery channels, and jurisdictions. Policies require rapid updates whenever independent reviews reveal weaknesses. For smaller institutions, this constant cycle of monitoring and adjustment can be especially burdensome.

Complex Data Collection and Verification Needs

The new framework expands CDD obligations, compelling institutions to gather detailed Know Your Customer (KYC) information across individuals, corporates, trusts, and government bodies. Providing Beneficial Ownership in layered or opaque structures is particularly difficult, especially where evidence is incomplete or subject to delayed verification.

Compliance Challenges for VASPs

VASPs encounter distinct challenges. They must identify custodial versus self-hosted wallets, confirm that controllers are properly licensed, and ensure secure handling of transaction data. The decentralised nature of Virtual Assets makes these tasks uniquely difficult.

Transparency and International Alignment

The AML/CTF Rules 2025 place a strong focus on transparency and global consistency. By mandating public disclosures, reinforcing payment traceability, and harmonising with the FATF framework, they bolster Australia’s domestic accountability while strengthening its standing in the international financial system.

Public Disclosure and Payment Transparency Measures

Listed public companies that are already bound by market disclosure rules are treated as transparent for Beneficial Ownership during CDD. In addition, the updated “Payment Transparency” obligations for Transfers of Value demand that both payer and payee information be verified and transmitted through the chain, reflecting FATF-strengthened recommendations.

Cross-Border Cooperation and Oversight Mechanisms

AUSTRAC is also empowered to share information with both domestic regulators and foreign counterparts, enhancing cooperation against financial crime. More importantly, registrations can be suspended or cancelled if providers are subject to adverse findings or sanctions, ensuring that international risks are factored into Australia’s oversight.

Alignment with FATF Global Standards

The Rules allow reliance on CDD already undertaken in FATF-compliant jurisdictions, as well as delayed verification in foreign branches where such regimes are recognised. For Virtual Asset transactions, service providers must confirm wallet controllers are licensed under laws consistent with FATF standards, otherwise services must proceed.

AUSTRAC’s Role in Promoting Openness

Under the Rules 2025, AUSTRAC must publish details from the Remittance Sector Register and the Virtual Asset Service Provider Register that are publicly accessible. This includes legal identifiers such as entity names, ABNs, registered addresses, and website domain names. Where conditions are attached to a registration, or where an entity faces suspension or cancellation, AUSTRAC is required to publish these outcomes to maintain openness.

The AML/CTF Rules 2025 represent a turning point in Australia’s approach to financial regulation. By weaving international best practices into local compliance obligations, the framework strengthens domestic safeguards while reinforcing Australia’s credibility on the global stage. Beyond meeting regulatory demands, these rules provide businesses with a chance to adopt more resilient systems, contributing to a safer and more transparent financial environment worldwide.

Key Takeaway

The AML/CTF Rules 2025 are more than just a compliance exercise; they represent a decisive recalibration of Australia’s regulatory landscape. By extending obligations to Real Estate, VASPs, and Domestic PEPs, the framework plugs long-standing gaps that criminals might have exploited. For businesses, the challenge lies in balancing the heavy operational burden of data collection, risk assessment, and reporting with the opportunity to build resilience and trust.

With the March 2026 deadline fast approaching, organisations that invest early in governance, technology and training will be better positioned not only to meet AUSTRAC’s standards but also to strengthen their competitive standing in a global marketplace where transparency and accountability increasingly define success.

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 9+ years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

How to File CNMR and PNMR on the goAML Portal Under TFS Guidance, 2025

How to File CNMR and PNMR on the goAML Portal Under TFS Guidance, 2025

How to File CNMR and PNMR on the goAML Portal Under TFS Guidance, 2025

This blog elaborates on the July 2025 updates to the Targeted Financial Sanctions (TFS) Guidance. These updates introduce sharper procedures, especially around screening and reporting, and call attention to nuanced revisions, such as:
  • Fund Freeze Report (FFR) changed to Confirmed Name Match Report (CNMR)
  • Clarified screening during weekends and public holidays
  • Updated procedures related to Partial Name Match Reporting
  • Additional examples on PNMR Reporting
  • Grievance procedures were deleted and published separately on the EOCN website.

The blog also includes a detailed explanation of what TFS obligations are, an in-depth understanding of CNMR and PNMR filing obligations and step-wise processes under TFS Guidelines 2025, and the best practices that Reporting Entities can incorporate into their AML framework to ensure Sanctions Compliance.

Apart from procedural updates, this blog also provides a step-by-step walkthrough for CNMR and PMNR filing using the goAML portal, helping AML compliance professionals and Regulated Entities to understand their core TFS compliance obligations.

Guidance on Targeted Financial Sanctions, July 2025: What Reporting Entities Must Know

In order to decode the provisions of the TFS Guidelines July 2025, reporting entities must develop a sound understanding of the basic concepts, such as:

What are Targeted Financial Sanctions (TFS) in the UAE?

“Targeted Financial Sanctions” refers to an obligation to freeze the funds or other assets of designated individuals or entities, and to restrict access to such funds, assets, or related services, either directly or indirectly.

The primary purpose of TFS is to prevent designated persons and entities from accessing financial resources, thereby disrupting the use of such resources for illicit purposes or transactions that may benefit individuals or organisations involved in terrorism, proliferation financing, or other criminal activities.

TFS Compliance Obligations

Article 21 of Cabinet Decision No. 74 of 2020 has set the main TFS compliance obligations on Reporting Entities, including DNFBPs, FIs, and VASPs:

Register

Reporting Entities must register for the EOCN Notification Alert System (NAS) to receive automated email notifications on any update to the Sanctions List. In terms of practical implementation, Regulated Entities using Sanctions Screening Software can ensure that the screening software is paired up with a sanctions screening API that gives real-time data and updates as to additions and deletions of names in:
  • The UAE Local Terrorist List that contains the names of all the sanctioned individuals, entities, or groups designated by the UAE Cabinet.
  • The UNSC Consolidated List that contains the names of all the sanctioned individuals, entities, or groups designated by the United Nations Sanctions Committees or directly by the UNSC.

Screen

The “when” and “whom” of sanctions screening is covered under paragraphs 30 and 31 of the latest guidance, which provide that Reporting Entities must undertake regular and ongoing screening on the latest Sanction Lists. Sanctions Screening must be undertaken mandatorily in the following circumstances:

  • Updates, i.e., additions, deletions, and revisions of names to Sanction lists
  • Prior to onboarding a new customer, i.e., a potential customer
  • Persons or entities party to any transactions or related to parties of any transaction, including names of persons with direct or indirect relationships with designated individuals, entities, or groups
  • Upon periodic KYC reviews or if there is any material change in the nature or ownership of the customer is identified
  • Daily screening of the existing customer database
  • Daily screening of the offboarded customers or previous customers with whom the Regulated Entity had prior business relationships and transactions
    • Reporting Entities need to be mindful that they are required to SCREEN all their previous or offboarded customers on an ongoing basis for a period of five (5) years after termination or cessation of the business relationship, even if there is no active business relationship or no assets are held with the Regulated Entity at present.
  • Before processing any transactions with a counterparty.

The “what” of the sanctions screening requirement is covered under paragraphs 32 and 33, which state the “key identifiers” and “other identifiers” required to be obtained by regulated entities from their customers to screen their names against those contained in the latest sanctions lists. These key identifiers and other identifiers are:

Once the key identifier details are available with the regulated entity, the Screening Analyst can proceed with conducting sanctions screening either manually or through screening software. The latest guidance on TFS requires regulated entities to have in place an adequate screening mechanism to help ensure TFS compliance.
The sanctions screening process generates screening outcomes, which can be disambiguated into four categories, such as:
  • Confirmed Name Match: The name of the customer matches with the sanctions screening outcome.
  • Partial Name Match: The name of the customer partially matches with the sanctions screening outcome.
  • False Positive: The name of the customer does not match with the screening outcome.
  • Negative Match: The name of the customer does not generate a screening outcome.
The occurrence of any of these four outcomes requires the personnel of the regulated entity to take appropriate steps, which are more elaborately discussed in the table below:
Sanctions Screening Outcomes and Resultant Reporting Requirements
Screening ResultTFS Measures

TFS Reporting Requirement

Record-Keeping Obligation

Perfect Match or Confirmed Name Match

  • Freezing of Funds or Other Assets without any delay (within 24 hours)
  • Prohibition from Making Funds or Other Assets or Services Available
  • If the confirmed name match is of a potential customer, transaction must be immediately rejected
    (TFS measures discussed more elaborately in step 3)

Confirmed Name Match Report (CNMR) to be filed within 5 days alongwith obligatory information

 

Paragraph 46 of the TFS Guidance updated in July 2025 prescribes to maintain records for the duration of atleast five (5) years, irrespective of the screening outcome.

Partial Match
  • Immediate suspension of transaction without any delay
  • Avoid offering funds or any other services
  • Scenario-wise requirements apply

Partial Name Match Report (PNMR) to be filed within 5 days alongwith obligatory information

False Positives or False Match

Not applicable

No reporting required

No Match or Negative Match

Implement TFS Measures

Reporting Entities must either freeze all funds and assets without delay, prohibit the provision of services/funds or reject the transaction. The core elements of TFS Measures prescribed by the Guidance on TFS include:
  • Asset Freezing without delay
  • Prohibition from making funds or other assets or services available
    • Financial Assets
    • Economic Resources
    • Any other assets.
The distinction between “Freezing Measures” in the case of a Confirmed Match and “Suspension Measures” in the case of a Partial Match is discussed in depth in further paragraphs of this AML UAE blog.

Report

The mechanism to report any TFS measures taken by the Reporting Entity must be after identifying a Confirmed or Partial Name Match, reporting to the relevant Supervisory Authority and submitting one of the following two reports via goAML:
  • Confirmed Name Match Report (CNMR)
  • Partial Name Match Report (PNMR)

The TFS Guidance also requires Reporting Entities to include and enclose mandatory and obligatory information along with the CNMR and PNMR filed.

In the context of CNMR, the RE is required to enclose ID documents of the person or legal entity whose name is found in the sanctions lists, resulting in a confirmed match during screening, as without possession of ID documents, the RE cannot conclusively confirm that the screening match found is a perfect match, requiring regulatory reporting. Examples of obligatory information for CNMR are:

  • The amount of funds or other assets frozen with documentary evidence, such as bank statements, transaction receipts, investment portfolios, title deeds, account summaries, etc
  • Detailed description of rejected transactions or services.
In the context of PNMR, the RE is required to enclose documents such as ID documents (if and when available) and the full name of the person or entity whose name is found to have partially matched during screening. The examples of obligatory information that REs can attach to PNMR are:
  • Funds or other assets that are suspended
  • Detailed description of rejected transactions or services.

How to File a Confirmed Name Match Report (CNMR) While Implementing TFS Measures

The step-wise process for filing CNMR requires a well-developed internal workflow to be followed by employees of a Regulated Entity. Timely filing of CNMR is only possible when the process from match identification to submitting the report on the goAML portal flows seamlessly from one department to another. Regulated Entities need to appoint an AML Compliance Officer and register themselves on the goAML portal. Registration on the goAML portal enables REs to file reports to the UAE FIU (Financial Intelligence Unit) to fulfil regulatory reporting requirements. The step-wise process for filing CNMR includes:
The subscription to the EOCN Notification Alert System (NAS) is a prerequisite that REs must tick off their to-dos once they commence business operations concerning covered activities under UAE’s AML/CFT regime. The subscription to NAS is a one-time exercise, which enables REs to access updated Sanctions Lists in real-time.

Identification of Confirmed Name Match During Sanctions Screening

REs can opt to screen their customers manually across the Sanctions Lists obtained through NAS or rely on a Sanctions Screening Software or unified AML Software that relies on efficient Screening APIs. Using one of these or a combination of software tools ensures that Sanctions Lists relied on for screening customers are updated in real time as published by the regulator, or EOCN, in the context of TFS compliance. The process of screening customers generates screening results or screening outcomes, which need to be disambiguated by the Screening Analyst.

Regulated Entities must remain mindful that they screen across their customer databases, which include potential, existing, and former customers, with whom they had a previous business relationship during the past five (5) years

When a Screening Analyst, while disambiguating screening results, identifies a perfect match or a confirmed match, they need to assess the screening outcome to confirm its accuracy.

Assessment of Confirmed Name Match Outcome

Assessment of a Confirmed Name Match or Perfect Match outcome is quite straightforward. In the case of potential, existing, and former customers, the frontline team or the Screening Analyst is required to carefully examine and cross-verify the customer’s key identifiers and the screening outcome’s attributes to assess whether the initial identification and disambiguation of the screening is accurate or erroneous. Once the Screening Analyst or the frontline team is sure of the match outcome assessment, they need to escalate the customer profile and screening outcome findings to the AML Compliance Officer for carrying out further steps.

Escalation by the Frontline Team or Screening Analyst to the AML Compliance Officer

The AML Compliance Officer needs to assess the customer profile forwarded by the frontline or screening team and assess whether the customer (potential, existing, or former) is indeed a confirmed match or there is any confusion or error on part of screening or frontline team in identifying the match results accurately and proceed further with imposition of TFS Measures and fulfilling CNMR filing formalities in a timely manner.

Impose Freezing Measures on Potential, Existing, and Former Customers

Once the AML Compliance Officer is sure that the confirmed match screening outcome is correct and accurate, he needs to act fast and impose freezing measures without delay (within 24 hours of the confirmed match). The extent and manner of imposing TFS Measures shall differ on the basis of the maturity of the business relationship, as elaborated below:

In case of a Potential Customer

  • Rejection of transaction or service immediately

In case of a Potential Customer

  • Freeze all funds/assets
  • Prohibition from making funds, other assets, or services available to such customer

In case of a Potential Customer

  • If the confirmed match is that of a former customer and the RE does not have any assets or funds available with them, they can still proceed with the CNMR filing process, stating that business relationship concluded and they are not in possession of any assets.

Preparation of Mandatory and Obligatory Information & Documents for CNMR in alignment with goAML Requirements

After imposing TFS Measures, the Compliance Officer then needs to ensure that he is equipped with all the mandatory and obligatory information pertaining to the customer against whom the CNMR is supposed to be filed. The ID documents (passport, Emirates ID, trade license) are assumed to be in possession of the RE and need to be submitted with CNMR. The examples of obligatory information are:
  • Asset value proof (bank statements, portfolio summaries, title deeds)
  • Description of rejected service or transaction.

Logging in on the goAML Portal to File CNMR

The AML Compliance Officer must log into their employer’s goAML portal account using RE’s log-in details to file CNMR.

Selecting Report Type as CNMR & Entering Information and Documents

The AML Compliance Officer needs to select CNMR from the list of options given in the dropdown menu on the goAML portal. The AML Compliance Officer can either upload the CNMR in an XML format or fill in the details regarding a confirmed name match in real-time by opting for the web-report option on the goAML portal.

Saving and Submitting CNMR

Once the details regarding the confirmed name match are entered on the goAML portal successfully, the AML Compliance Officer must save the CNMR details and submit the same. The AML Compliance Officer must be mindful of the requirement to complete the legal obligation filing of CNMR on the goAML portal within 5 days after applying freezing measures.

Maintaining Records of CNMR Filed for Five (5) Years

REs are required by law to maintain records of all screening results, including CNMRs, the identification, decision, freezing measures taken, and details of the CNMR filed on the goAML portal for the period of at least five (5) years.

How to File a Partial Name Match report (PNMR) While Implementing TFS Measures

The step-wise process of filing a PNMR broadly consists of the steps elaborated in further paragraphs. However, based on the maturity of the business relationship, i.e., whether the customer is a potential customer, an existing customer, or a former customer, the employees of the Reporting Entity, such as the frontline team, Screening Analysts, KYC Analysts, and AML Compliance Officer, must make sure that they collect necessary information about the customer to ensure accurate filing of PNMR. Timely filing of PNMR can be achieved through well-coordinated efforts by all personnel concerned.
Needless to say, the prerequisite of subscription to the EOCN Notification Alert System (NAS) is implied when it comes to having a well-defined and documented process to file PNMR in place. The Reporting Entity may screen its customers manually, through updated sanctions lists and notifications received after subscribing to EOCN NAS or can rely on a Sanction Screening Software or an AML Software with Sanctions Screening API.

Identification of Partial Name Match During Sanctions Screening

Regulated Entities must ensure that they screen across their customer databases, including potential, existing, and former customers, with whom they had a previous business relationship during the past five (5) years.

When a Screening Analyst, while disambiguating screening results, comes across screening results or outcomes where only some or few of the attributes of the customer profile, and they cannot conclusively confirm whether or not such a match is a confirmed match or a false positive, then in such a scenario, they are required to escalate the customer profile and screening outcome to the AML Compliance Officer for further assessment.

Assessing Partial Name Match Outcome

Assessment of Partial Name Match Outcome after screening needs to be done to rule out the possibility of the initial match disambiguation being inaccurate, false positive, or a confirmed name match instead. However, the issue with Partial Name Match outcomes is that the Screening Analyst or frontline team cannot conclusively decide whether it’s a false or a complete match due to factors such as:
  • Lack of adequate information and non-availability of the customer’s ID documents in case of potential customers
  • Lack of information in Screening Outcomes, i.e., screening results exist but don’t provide adequate information so as to conclude successful disambiguation
  • A high number of screening outcomes or results are generated by the screening software due to lower match percentage thresholds configured, leading to high disambiguation volume with non-existent substantial information for disambiguation.

In order to simplify the Partial Name Match Outcome’s accuracy assessment, the following factors must be considered by Reporting Entities, such as:

For Potential Customers: Obtaining ID documents must be attempted when ID documents are not available, leading to a lack of information on key identifier details, so that the match can be disambiguated by having a complete set of information prior to disambiguation for accurate results.

  • If ID is received within 10 days, the RE must conduct Screening with details contained in the ID obtained. Based on the screening outcome, if the RE finds that the match is indeed a Partial Match, they must continue/implement Suspension/Freezing Measures and proceed with the PNMR/CNMR filing process. If, after fresh screening, the RE finds that the screening outcome is a false positive or no match, they must proceed with establishing a business relationship.
  • If ID is not received within 10 days, the RE must Reject/Cancel Transaction and proceed with PNMR filing process
  • If ID is received after 10 days, the RE must conduct Screening based on the recently acquired ID and implement Suspension Measures accordingly, if a Partial Match is found, or proceed with CNMR if a Complete Match is found, or establish a business relationship if false or no match found.

Existing and Former Customers: The possession of a Customer ID is assumed

  • Suspend any transaction, refrain from offering any funds, assets, or services.

Escalation by the Frontline Team or Screening Analyst to the AML Compliance Officer

The AML Compliance Officer needs to assess the customer profile forwarded by the frontline or screening team and determine whether the customer (potential, existing, or former) is indeed a partial match or confirmed match or false match, based on which further actions can be taken.

Impose Suspension Measures on Potential, Existing, and Former Customers

Once the AML Compliance Officer is sure that the partial match screening outcome is correct and accurate, he needs to act fast and impose a suspension of the business relationship and refrain from or avoid providing any service, assets, or funds to such a customer without delay (within 24 hours of the partial match).
The extent and manner of imposing TFS Measures, i.e., suspension, shall differ on the basis of the maturity of the business relationship, as elaborated below:

In case of a Potential Customer

  • Cancel the Transaction and proceed with the PNMR filing process

Existing and Former Customers

  • Suspend any transaction, refrain from offering any funds, assets, or services.

Preparation of Mandatory and Obligatory Information & Documents for CNMR in alignment with goAML Requirements

After imposing TFS Measures, the Compliance Officer then needs to ensure that he is equipped with all the mandatory and obligatory information pertaining to the customer against whom the PNMR is supposed to be filed. The ID documents of existing and former customers (passport, Emirates ID, trade license) are assumed to be in possession of the RE and need to be submitted with PNMR. The ID documents of potential customers can be submitted if and when available. The examples of obligatory information are:
  • Asset value proof (bank statements, portfolio summaries, title deeds)
  • Description of suspended service or transaction
  • Description of rejected transaction or service (when no funds are held).

Logging in on the goAML Portal for PNMR Filing

The AML Compliance Officer must log into their employer’s goAML portal account using RE’s log-in details to file PNMR.

Selecting Report Type as PNMR & Entering Information and Documents

The AML Compliance Officer needs to select PNMR from the list of options given in the dropdown menu on the goAML portal. The AML Compliance Officer can either upload the PNMR in an XML format or fill in the details regarding a confirmed name match in real-time by opting for the web-report option on the goAML portal.

Saving and Submitting PNMR

Once the details regarding the confirmed name match are entered on the goAML portal successfully, the AML Compliance Officer must save the PNMR details and submit the same. The AML Compliance Officer must be mindful of the requirement to complete the legal obligation filing of PNMR on the goAML portal within 5 days after applying suspension measures.

Following EOCN Response

REs after filing a PNMR must await and follow the EOCN instructions and maintain suspension measures until further instructions are received.

The EOCN instructions in the context of PNMR concern the treatment of suspension measures, particularly in the case of existing and former customers. The Reporting Entity must submit PNMR along with all the necessary and obligatory customer information so that EOCN can verify the PNMR submitted and give further instructions to the RE. Either of the following steps must be taken by RE, based on EOCN response:

  • If EOCN concludes PNMR filed as a False Positive, RE must cancel TFS suspension measures and proceed with the business relationship
  • If EOCN validates PNMR as a Confirmed Match, REs must freeze funds and submit CNMR.
In the case of potential customers, if customer information and documents are lacking, then EOCN will not be able to verify the PNMR report submitted into Confirmed Match or False Positive.

Maintaining Records of PNMR Filed for Five (5) Years

REs are required by law to maintain records of all screening results, including PNMRs, the identification, decision, suspension measures taken, and details of the PNMR filed on the goAML portal for the period of at least 5 years.

Key Differences Between CNMR and PNMR: Comparative Table

Differences Between CNMR and PNMR

Distinguishing AspectsCNMR (Confirmed Name Match Report)PNMR (Partial Name Match Report)
Trigger EventIdentification of Confirmed Match during Sanctions ScreeningIdentification of Partial Match during Sanctions Screening
Immediate Action NeededFreezing Measures for TFS Compliance to be applied within 24 hoursSuspension Measures for TFS Compliance to be applied within 24 hours
Filing TimelinesWithin 5 days after imposing Freezing MeasuresWithin 5 days after imposing Suspension Measures
Documents RequiredComplete Customer ID + Documents of Freezing Measures/ Transaction RejectionComplete or Partial Customer ID + Documents of Suspension Measures
Post Filing MeasuresFreezing Measures to say in place. However lift Freezing Measures if Person/Entity is Delisted from Sanctions List or Freezing Cancellation Decision given by EOCNAwait EOCN Response, maintain Suspension Measures, may need to file CNMR or mark match as False Positive

Key Differences Between Freezing and Suspension Measures

Differences Between Freezing and Suspension of Funds

Distinguishing Aspects

Freezing MeasuresSuspension Measures

Sanctions Screening Disambiguation Outcome

Confirmed or Perfect MatchPartial Match

Report to be filed on GoAML Portal

CNMRPNMR

TFS Compliance Requirements

Freezing measures remain in place until person/entity is delisted from Sanctions List or Freezing Cancellation Decision given by EOCNSuspension measures remain in place until EOCN provides further instructions on the match’s status

General Do’s and Don’ts to Ensure TFS Compliance

Compliance with Targeted Financial Sanctions (TFS) is legally mandated under UAE law and reinforced by the 2025 TFS Guidance. These emphasize proactive, risk-based screening, reporting, and asset freezing for designated persons. The following do’s and don’ts guide Reporting Entities, i.e., DNFBPs, FIs, and VASPs in meeting TFS obligations, particularly for CNMR and PNMR submissions via goAML.

Dos to Ensure TFS Compliance

Do subscribe to the Executive Office mailing list or alert system

Regulated Entities (DNFBPs, VASPs, and FIs) are required to register on the goAML platform to submit STRs and SARs to the FIU. They must also use the platform to report CNMRs/PNMRs to the EOCN and the Supervisory Authority.

Do screen continuously, even on weekends and holidays

Reporting Entities must establish internal procedures for screening against the UAE Local Terrorist List and UNSC Consolidated List during weekends and public holidays, ensuring that access to funds or assets is restricted at all times. If no transactions or customer access occur during weekends or holidays, screening must begin immediately at the start of business activity, and freezing measures should be promptly applied.

Do Report and Disclose previous transactions or business dealings with Confirmed or Partial Name Matches.

Reporting Entities must submit CNMRs and PNMRs for all relevant transactions, business relationships, and accounts held within the past five years, including those closed before the designation, even if no current assets or ties exist. The report must explicitly state that no funds or assets are presently held, no ongoing relationship exists with the designated party, and that the account in question is closed.

Do Report Matches via Email to the EOCN if You’re Not a goAML User

For an entity not registered with goAML (that do not fall under the definition of FIs, DNFBPs, or VASPs and are therefore not under an obligation to register on goAML), CNMRs or PNMRs must be reported by emailing and providing a complete set of case details that clearly explain the identified match with all relevant supporting documents attached in the message.

Do Escalate Matches Found in Criminal or Unilateral/Multilateral Sanctions Lists

Reporting Entities must consult the relevant Supervisory Authority (SA) for guidance on handling matches found with unilateral or multilateral sanctions lists, or other criminal lists, and consider submitting an STR or SAR to the Financial Intelligence Unit (FIU) if such matches are confirmed. The Reporting Entity should not use CNMR/PNMR reports in goAML for matches found on other sanction or criminal lists like OFAC, EU, HMT, or INTERPOL. These reports are only for matches with the UAE Local Terrorist List and UN List.

Do understand the change in penalty for non-compliance and inform staff

Reporting Entities must equip themselves with the awareness of changes made to the penalty imposed on TFS violations and incorporate the changes, such as imprisonment for a period of one to seven years. REs must also understand that Administrative Sanctions might be applied to them, resulting in a warning for license cancellation.

Don'ts to Ensure TFS Compliance

Don’t overlook changes in ownership structures, as even minority holdings may evolve into controlling stakes.

Reporting Entities are required to impose freezing measures on any entity that is majority-owned (more than 50%) by designated persons or entities. During implementation, REs must determine whether a designated person owns or exercises control over more than 50% of the proprietary rights. If the designated individual holds only a minority stake (50% or less), the entity is not subject to freezing measures unless ownership shifts, and the designated person gains a majority stake or controlling interest. Furthermore, all funds or assets owed to designated individuals must be frozen and must not be made accessible under any circumstances.

Don’t notify customers before freezing measures, as doing so may be considered tipping off

Reporting Entities must avoid informing customers about freezing measures before they are applied, as this may constitute tipping off. Customers may be notified once the measures have been implemented.

Don’t Forget to Document False Positives

Reporting Entities do not need to report a False Positive result to the EOCN and may proceed with the business transaction. However, they must maintain internal records of the screening alert and all actions taken.

Don’t rely solely on third-party screening services to meet compliance obligations

Reporting Entities must not consider third-party screening services as a guarantee of compliance. Reporting Entities remain responsible and must assess the reliability and robustness of external systems before using them.

Don’t Rely on Assumptions or Unverified Links

When a Confirmed or Partial Name Match is identified, the Reporting Entity must obtain and review the customer’s identification documents. Following the review, appropriate freezing or suspension actions should be taken and properly documented.

Best Practices for CNMR and PNMR Filing on the goAML Portal to Ensure TFS Compliance

Filing of CNMRs and PNMRs via goAML portal is a key compliance requirement for Reporting Entities, including DNFBPs, FIs, and VASPs. By implementing the following best practices, Reporting Entities can ensure effective compliance with the UAE’s Latest Guidance Targeted Financial Sanctions (TFS):

Establish Comprehensive Sanctions Compliance Policies and Internal Controls

Reporting Entities must set and implement policies, procedures, and internal controls that align with the requirements of the latest TFS Guidance. These should ensure compliance with freezing obligations, include reasonable measures to identify beneficial owners, signatories, and strictly prohibit staff from disclosing freezing actions to customers or third parties. REs must allocate appropriate human and technical resources to fulfil TFS obligations effectively.

Using Sanctions Screening Software for Accuracy

REs must deploy Sanctions Screening Software that enables high-accuracy detection of designated individuals and entities across the UAE Local Terrorist List and the UNSC Consolidated List. The software should allow configurable thresholds to minimise false positives while ensuring true matches are not missed. The software must support real-time updates to watchlists, automatic batch screening, and ongoing monitoring of customer databases and transactions. These capabilities are critical for ensuring that CNMRs and PNMRs are identified without delay.

Providing Sanctions Compliance Training to Employees

REs must conduct regular and role-specific training for employees, especially those in compliance, operations, and client onboarding teams. The training must cover the detection and handling of CNMRs and PNMRs, the use of sanctions screening software, and the regulatory obligations outlined in the latest TFS Guidance. Training should also emphasise the importance of confidentiality (prohibition of tipping off) and include practical case scenarios to ensure readiness for real-life detection and reporting situations.

Group Oversight Across All Branches and Trade Zones

REs must establish Group Oversight to ensure consistent application of CNMR and PNMR processes across all branches and trade zones. This includes unified match thresholds, centrally managed screening tools, and standardised escalation procedures. Group Compliance must include overseeing implementation, conducting regular audits, and providing training to ensure effective and consistent Sanctions Screening. Central oversight ensures that potential matches are identified and resolved promptly, reducing the risk of sanctions breaches across the institution’s entire operational footprint.

Tamper-Proof Record-Keeping

REs must maintain tamper-proof record-keeping systems to ensure the integrity and security of data related to CNMR and PNMR activities. Records of screening results, match investigations, and escalation decisions must be securely maintained with access controls that restrict unauthorised viewing or editing. The system must include audit trails that log all user actions and prevent any undetected alterations or deletions.

Implementing Centralised Record Management Systems

REs must implement Centralised Record Management Systems to ensure consistent, secure, and traceable handling of data related to CNMR and PNMR processes. These systems should consolidate customer and transaction records across all business units and branches, enabling efficient access and retrieval during sanctions screening, investigations, and regulatory inspections. Centralisation ensures that relevant data is readily available as a single source of truth, supporting timely identification, review, and escalation of potential matches. Easy access to accurate records is essential for demonstrating compliance with TFS obligations and facilitating smooth regulatory visits.

Internal Reporting & Escalation Module

REs must establish a structured Internal Reporting & Escalation Module to manage alerts generated through CNMR and PNMR processes. This module should define clear roles, timelines, and procedures for the review, escalation, and resolution of potential sanctions matches. Automated workflows should support timely alert handling, while ensuring that all actions are logged for audit purposes. Effective internal reporting and escalation are essential for preventing delays, ensuring regulatory compliance, and facilitating prompt decision-making in line with TFS obligations.

Bringing It All Together: TFS Measures, Match Outcomes, and goAML Reporting

The advent of TFS Guidance, July 2025, calls for more than reactive and passive compliance measures; it requires proactive internal policies and procedures that take care of timely screening, clear escalation protocols, and accurate CNMR/PNMR reporting through the goAML portal and reposting to the relevant Supervisory Authority. Irrespective of dealing with confirmed or partial match in case of potential, existing, or former customers, regulated entities must implement appropriate freezing or suspension measures, document actions taken, and maintain records for a period of five (5) years.

Incorporating these practices into daily workflows helps ensure regulatory compliance while reinforcing operational resilience. With right Sanctions Screening Software, Role Specific AML Training, and governance, REs in UAE can go beyond reactive compliance and master proactive and risk-based TFS Compliance.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

Reach Out to Pathik

What is MENAFATF, and who are its members and observers?

What is MENAFATF, and who are its members and observers?

The Middle East and North Africa (MENA) region has its dedicated and focused FATF-Style Regional Body (FSRB), known as MENAFATF. This blog embarks upon a journey to introduce its members and overserves while providing a glimpse at MENAFATF’s mission, structure, governance, members, observers, and their key role in strengthening the region’s financial integrity.

What is MENAFATF, and who are its members and observers?

In a world highly interlinked with finance, trade, and technology, the risk associated with money laundering (ML) and the financing of terrorism (FT) has grown significantly. These activities pose a threat to economies, global security, and the integrity of financial systems. Recognising the threats posed by money laundering and terrorist financing operations to countries in the Middle East and North Africa Region, the Middle East and North Africa Financial Action Task Force (MENAFATF) stands out as a critical regional body dedicated to combating money laundering (ML) and financing of terrorism (FT).

The countries in the MENA region work conjointly to comply with MENAFATF’s standards that establish an effective system which countries need to implement in a way that does not contradict their cultural values, constitutional frameworks, and legal systems.

Establishment and Background of MENAFATF

MENAFATF was established in Manama, Bahrain, on 30th November 2004 at an inaugural Ministerial Meeting wherein the Governments of 14 countries decided to establish MENAFATF as a FATF Style Regional Body (FSRB).

MENAFATF operates as an independent body, distinct and separate from any other international body and regionally focused organisation which is designed to reflect the unique political, economic and social culture of the region, and follows the model of the Financial Action Task Force (FATF), the global organisation that sets standards for AML/CFT.

Objectives and Functions of MENAFATF

The primary function of MENAFATF is to combat money laundering (ML) and terrorism financing (TF) by promoting regional cooperation and ensuring that the member countries implement effective measures aligned with international standards, particularly the FATF 40 recommendations. MENAFATF Member countries strive towards achieving the following objectives:
  • To encourage member nations to set up and implement a comprehensive AML/CFT structure, according to the FATF recommendations, and ensure implementation of relevant UN treaties and agreements and the UNSCRs (United Nations Security Council Resolutions).
  • To conduct a mutual evaluation of member nations to assess their adherence to international AML/CFT standards and identify the gaps that need to be taken care of.
  • To provide guidance, training, and support to member nations in developing, implementing, and enhancing their legal, regulatory, and institutional AML/CFT structure.
  • To facilitate the sharing of information, typologies, and best practices among member nations and international partners.
  • To take measures throughout the region to combat money laundering and terrorist financing in a manner that respects the cultural values, constitutional frameworks, and legal systems of the member countries.

MENAFATF Structure And Governance

MENAFATF follows a well-defined governance structure that ensures both strategic and operational efficiency. Key components of this structure include two bodies, i.e., the Plenary Meeting of Representatives of member countries, also referred to as the Plenary for the sake of simplicity, and the Secretariat:

The Plenary

The plenary is the decision-making body consisting of the representatives from all member nations. The Plenary meets at least twice a year to discuss policies, approve evaluation reports, and oversee the organisation’s activities. It nominates the President and Vice President among the member countries.
  • President and Vice President: The president and vice president are elected among the members for a term of one year. The president and vice president represent the MENAFATF at international forums.
More details about the plenary session are discussed in the following paragraphs.

Secretariat

The Secretariat is responsible for the day-to-day activities of MENAFATF. It is in Bahrain and supports the implementation of plenary decisions, coordinates evaluations, and manages communication with member nations and observers.
The Secretariat performs the following functions:
  • Prepare the annual report, work plan, and estimated budget, and submit them to the Plenary.
  • provide technical and administrative preparation for convening the plenary, working groups, and any established committees;
  • implement and follow up on the work plan as approved by the Plenary;
  • Submit regular reports on MENAFATF work to the Plenary and the President.
  • manage the expenditure of the approved budget and carry out mutual evaluation exercises;
  • Identify the training and technical assistance needs of member states and facilitate the provision of such needs in consultation with these countries.
  • Monitor worldwide AML/CFT developments and provide appropriate information to the Plenary;
  • carry out any other tasks assigned by the Plenary.

Working Groups

MENAFATF has different specialised working groups that work on areas such as mutual evaluation, typologies, research, technical assistance, and training. These groups help to bring together the experts from member nations to collaborate on specific projects.

Members of MENAFATF

MENAFATF comprises 21 countries from the region of the Middle East and North Africa. Each member is required to implement the FATF 40 recommendations and actively participate in MENAFATF’s activities. The member countries are-
1. Algeria 2. Bahrain 3. Djibouti 4. Egypt 5. Iraq 6. Jordan 7. Kuwait 8. Lebanon 9. Libya 10. Mauritania 11. Morocco 12. Oman 13. Qatar 14. Palestine 15. Saudi Arabia 16. Somalia 17. Sudan 18. Syria 19. Tunisia 20. United Arab Emirates 21. Yemen
MENAFATF comprises 21 countries from the region of the Middle East and North Africa. Each member is required to implement the FATF 40 recommendations and actively participate in MENAFATF’s activities. The member countries are-

Observers of MENAFATF

In addition to the member nations, MENAFATF associates with several observers, including international organisations as well as countries. They participate in MNAFATF’s meetings, provide technical expertise, and contribute to the overall mission of effective regional AML/CFT efforts. The international organisations that are members of MENAFATF are:
1. International Monetary Fund 2. World Bank 3. Co-operation council for the Arab states of Gulf 4. Financial Action Task Force 5. Egmont Group of Financial Intelligence units 6. Asia/Pacific Group on Money Laundering 7. World Customs Organization 8. Arab Monetary Fund 9. Eurasian Group on combating money laundering and financing of terrorism 10. United Nations 11. European Commission 12. Russian Federation
The countries that are the observers of MENAFATF are:
1. France 2. United Kingdom 3. United states of America 4. Spain 5. Australia 6. Germany
The countries listed above often have bilateral partnerships with MENAFATF members and play a significant role in international AML/CFT initiatives.

Key Activities and Achievements of MENAFATF

Over the past few years, MENAFATF has made key progress in enhancing the AML/CFT framework across the region. The key activities and achievements of MENAFATF are:

Mutual Evaluation

MENAFATF conducts several rounds of mutual evaluation of the member nations to assess their AML/CFT compliance with FATF standards. These rounds of mutual evaluation are discussed in further paragraphs. These evaluations help nations identify areas for improvement in their AML/CFT frameworks.

Capacity Building

MENAFATF provides extensive training to government officials, regulators, law enforcement agencies, and financial intelligence units through workshops, seminars, and technical missions.

Typology reports

MENAFATF publishes reports on regional ML/TF trends and methods. These reports help member nations identify and mitigate emerging threats.

Global Collaboration

MENAFATF works closely with FATF and other organisations like the Asia-Pacific Group on Money laundering (APG).

Public Awareness

MENAFATF supports efforts to educate the public about AML/CFT obligations and the importance of these compliances.

The Role of MENAFATF Plenary

The Plenary in MENAFATF is the highest decision-making body and plays a significant role in contributing to MENAFATF’s mission. It comprises representatives from each member nation, typically experts in AML/CFT or senior officials from the Ministry of Finance, Central Banks, or Financial Intelligence agencies.

The Plenary assembles at least twice a year and may hold extraordinary meetings if necessary.

In a plenary meeting, a wide range of issues are discussed by the members as well as observers and decided upon, which includes:

  • The approval of mutual evaluation reports
  • Adoption of strategic plans
  • Discussion of typology findings
  • Endorsement of training programs
The Plenary approves the MENAFATF work program and performs the following functions:
  • establish and approve the policies of MENAFATF;
  • determine the rules and procedures of MENAFATF;
  • approve annual report, work plan, and estimated budget, and ratify the financial report and auditor’s report of MENAFATF;
  • appoint the Executive Secretary and independent auditor, and approve the Secretariat’s organisational structure and other functions;
  • decide upon new member countries and observers;
  • adopt any amendments to the Memorandum of Understanding (MOU) that may be significant in the future;
  • identify technical assistance needs of member States and coordinate delivery of technical assistance in consultation with such nations and in co-operation with countries as well as international and regional organizations providing such assistance, particularly those holding observer status;
  • consider and approve mutual evaluation reports of members’ compliance with FATF standards;
  • establish working groups and committees when needed to undertake special tasks;
  • consider any other subjects proposed by any of the member countries, the President, or the Secretariat.

The Plenary also elects president and vice-president, and annually reviews the organisation’s work plan and budget. The rules of the Plenary are designed to encourage transparency, inclusiveness, and effective decision-making.

Moreover, the Plenary provides a platform for observer organisations and countries to interact and participate in the discussions, although they do not have any voting rights. The Plenary is important for ensuring that MENAFATF remains dynamic, responsive, and aligned with the international AML/CFT framework.

Mutual Evaluation Working Group

The Mutual Evaluation Working Group (MEWG) is one of the important components of MENAFATF’s operational structure. It includes the task of managing and overseeing the process of mutual evaluation and follow-up reports of member nations. MEWG ensures that the evaluation is conducted in accordance with FATF standards, and the result reflects an accurate assessment of the country’s AML/CFT system.

MEWG focuses on two reports-

Mutual Evaluation Report

The mutual evaluation process involves an extensive peer review where a team of experts assesses the member country’s compliance with the FATF 40 recommendations. The evaluation includes both the technical and effectiveness compliance. Furthermore, this Evaluation Report is responsible for coordinating evaluations, selecting review teams, guiding on-site visits, and reviewing draft evaluation reports before they are submitted to the Plenary for approval. These reports highlight areas of strength, areas for improvement, and potential red flags. Once these reports are approved by the Plenary, the evaluation report will be accessible to the public.

Follow-up Report

Once a mutual evaluation is completed, the member nations initiate a follow-up process to ensure they take corrective measures. The MEWG monitors this progress by reviewing follow-up reports submitted by the nations.

These reports elaborate on the steps taken to address the areas of improvement identified in the mutual evaluation report. Depending on the level of progress, nations may be subject to enhanced follow-up or regular follow-up with the timelines for submitting these progress reports. MEWG reviews these reports and assesses whether the nation can exit the follow-up process or require further monitoring.

Therefore, MEWG plays a crucial role in maintaining accountability and promoting continuous improvement among its members. This rigorous evaluation and effective follow-up help strengthen the nation’s AML/CFT compliance in accordance with the FATF’s 40 recommendations.

Withdrawal and Suspension of Membership

MENAFATF includes the provision for the withdrawal or suspension of membership of a member nation.

A member, if voluntarily wants to withdraw, may submit a written notice of withdrawal to the Secretariat. This process takes effect after a stipulated period, generally six months from the date of notification, unless an earlier date is decided.

In certain cases where a member nation fails to fulfill its obligations, such as mutual evaluation, continuous non-compliance with the AML/CFT framework, or a lack of cooperation, that member may be subject to suspension by MENAFATF. The Plenary, with a two-thirds majority vote, makes the decision regarding suspension. The decision to suspend results in the loss of voting rights and the ability to influence decisions within the organisation until the issues leading to the suspension are resolved.

The withdrawal and suspension of membership provision of MENAFATF enables better accountability and engagement among members, and facilitates a hassle-free exit process or disciplinary actions in cases of persistent non-cooperation.

Challenges and Future Outlook

Challenges faced by MENAFATF

MENAFATF has achieved notable success in recent times, but even today, it faces several challenges:
  • Political Instability: The member nations can be affected by ongoing political conflicts and governance, which can hinder their AML/CFT framework.
  • Resource Constraints: Not all member nations have enough resources; some may face resource constraints with respect to financial and human resources, which can impact their AML/CFT framework.
  • Diverse Legal System: The varied legal system among different member nations can hinder the standard AML/CFT framework.
  • Technological Evolution: The rise of advanced technology leads to the rise of digital currencies and fintech, which requires constant updates to regulatory approaches that can hinder their AML/CFT standards.
The challenges listed above need to be addressed, and MENAFATF must continue to strengthen its partnerships, enhance technical assistance, and promote the adoption of new technologies.

Outlook for MENAFATF

MENAFATF is expected to
  • Enhance their research and typology to be aware of emerging threats.
  • Boost the Mutual Evaluation processes to ensure efficient ongoing compliance.
  • Deeper integration with the international financial system and standards.
  • Boost greater private sector engagement in the AML/CFT framework.

MENAFATF: The Watch Continues

MENAFATF plays a significant role in ensuring financial transparency and security in the Middle East and North Africa (MENA) region. It stands as a cornerstone of regional cooperation in the fight against Money laundering and financing of terrorism.

By aligning their efforts with international standards and tailoring them to address the challenges of the MENA region, organisations play a significant role in strengthening financial systems, enhancing legal frameworks, and promoting transparency. As financial crime continues to evolve, the MENAFATF’s role remains important not only as a monitor and advisor but also as a driver of sustainable reform. Through continued commitment and innovation, MENAFATF can further empower its members to build more resilient and secure economies.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

Reach Out to Pathik

Dissecting Hawala – Its Vulnerability and Misuse for Financial Crime

Dissecting Hawala – Its Vulnerability and Misuse for Financial Crime

What is Hawala?

Hawala Meaning

Hawala is an informal value transfer system in which one person transmits funds to another without using formal money transfer mechanisms, such as banking. It’s a system based on trust in which transmitting funds from one place to another is made possible without the actual movement of cash through a nexus of hawaladars facilitating such fund or value transfer for a fee or percentage.

Historical Context for Hawala Transactions

To understand the concept of hawala better, it’s important to understand that it started centuries ago. Traders and merchants intending to send funds home would make a deposit with a hawala broker at their location, and the broker would communicate within their nexus to let the designated recipient collect funds from a hawala broker located in that region.

Key Participants in Hawala Transactions

Remitter:

A person who wants to transfer funds to someone without using formal banking channels.

Hawaladars:

A Hawala transaction cannot take place without the involvement of a hawaladar. There could be one or more Hawaladars involved in a single transaction at the point of origin and the destination. Hawaladars receive and make payments on behalf of their clients and settle those transactions among themselves as trade transactions.

Beneficiary:

The intended recipient of the Hawala transaction.

Hawala Transaction Process

The hawala process generally has the following steps, as discussed.

Approach:

A person intending to transfer value to the recipient at another location, i.e., the originator, gets in touch with a hawaladar and finalises the terms of fund transmission. At this stage, the originator and recipient decide on the secret key or passcode type. This passcode or secret key is communicated to the hawaladar and the intended recipient of the funds.

Coordination:

The said hawaladar, i.e., the originator’s hawaladar, coordinates with other hawaladars in his network to identify who can disburse payment to the client’s intended recipient on his behalf while discussing other terms. At this stage, the originator hawaladar conveys the secret key or passcode to the hawaladar in the recipient’s region so that they can confirm the same prior to disbursing funds to the recipient.

Passcode or Secret Key Confirmation:

The recipient approaches the hawaladar in their region, which is responsible for disbursing payments, and gives the secret key or passcode that acts as a signal for the hawaladar to release funds. The hawaladars decide how they want to confirm or validate the fund originators’ and recipients’ identification based on the regulations, if any, in their jurisdiction.

Account Settlement:

The trust factor amongst hawaladars is the key component on which the entire hawala network and business exists. They trust one another adequately that the funds disbursed on the word of the other will be settled in time, along with their share of fees or commission as agreed. The entire business of hawala runs on mutual trust and understanding, where hawaladars settle each other’s accounts by way of trade transactions.

Legitimate Vs Illegitimate Uses of Hawala

Hawala, as an informal value transfer system, attracts legitimate as well as users with devious motives to launder or transfer illicit proceeds for funding illegal activities. Hawala has both legitimate and illegitimate uses, as discussed below.

Examples of legitimate uses of Hawala include:

  • Avoidance of bank fees for fund transfers
  • Lack of banking access in the remittance-receiving jurisdiction
  • Cultural preference
  • Lack of trust in formal banking.

Examples of illegitimate uses of Hawala include:

  • Transfer of funds for illicit purposes
  • Evasion of regulatory scrutiny about the source of funds
  • Sanctions and trade embargo or restriction evasion
  • Evade disclosure of the identities of actual beneficiaries of the transaction, which, if resorted to the formal banking system, would have required disclosure of Ultimate Beneficial Owners (UBOs)who might turn out to be sanctioned or Politically Exposed Persons (PEPs), triggering regulatory reporting or enhanced due diligence (EDD) measures, respectively.

Characteristics of Hawala Transactions

Some of the distinguishing characteristics of Hawala transactions are as follows:
  • There is No Physical Movement of Cash From Point A to Point B. It’s the hawaladar’s nexus that makes the funds available to the recipient as finalised between the sender and the hawaladar. The sender does give funds to the hawaladar, but those exact funds or currency are not disbursed or transferred. Those funds are rather settled by the mode of trade transactions among a nexus of hawaladars.
  • Hawala Transactions are Unregulated and hence circumvent the requirement of customer identification and verification, contrasting with formal value transfer systems.
  • There is No Element of Mandatory Regulatory Record-Keeping obligations that hawala transactions or hawaladars have to adhere to.
  • The Information of the Hawala Transaction is Coded: The subject matter of each transaction, such as sender, recipient, agreed-upon fees, secret passcode, etc., is transferred across in a coded manner that ensures the privacy and anonymity of the parties involved.
  • Geographical Spread: The geographical spread of hawala networks facilitates recipients’ receiving funds in any part of the world based on information or possession of documents containing identifiable and verifiable information that the hawaladar can confirm to disburse funds.

Why is Hawala Preferred Over Formal Banking Systems?

The very characteristics of the Hawala system that make it appear more appealing than the formal banking system are the lack of regulation, documentation, and compliance obligations.

Why Hawala Attracts Money Launderers?

Hawala system attracts money launderers due to its abovementioned characteristics, but the following two are the major reasons discussed as follows:
  • No paper trail: As launderers do not prefer to be linked to their transactions and are always trying to separate their illicit proceeds from their origin, hawala helps by quickly getting rid of large sums of cash that an unwitting hawaladar accepts, not knowing the origin of those illicit proceeds.
  • Anonymity: The Hawala system does not follow the stringent practice of ID verification and customer due diligence that regulated entities under AML obligations do. Hence, money launderers can almost anonymously send and receive funds across the world through the hawala network.

At Which Stages of ML Can Hawala Take Place?

Money laundering takes place in three stages: placement, layering, and integration. Hawala network can be misused by money launderers at any stage of the money laundering process. The hawala system can facilitate placement, as it readily accepts large sums of cash without knowing that those could be illicit proceeds. The same goes for the layering stage, where funds are structured and remitted to and fro, and the integration stage, where the funds come back to the launderer after placement and layering, making it impossible to trace the origin of such proceeds.

Why Hawala Attracts Terrorism and Proliferation Finance Actors?

Hawala attracts terrorism and proliferation financing (TF and PF) actors for similar reasons as money laundering. The element of anonymity and lack of a paper trail that can be traced back to the actual person makes the hawala system highly vulnerable to misuse for TF and PF.

At Which Stages of the TF/PF Can Hawala Take Place?

TF has stages such as collect, store, move, and use, and PF has stages such as program fundraising, disguising the funds, and procurement of proliferation-sensitive materials. The misuse of hawala can be done at the moving stage of TF. With regards to PF, hawala can be misused for concealing as well as making payments for procurement of proliferation-sensitive materials in a high-risk, blacklisted, or sanctioned country. The limited amount of scrutiny and the existence of unlicensed or unregistered hawaladars who do not keep up with regulatory obligations are prone to be misused by TF and PF actors.

ML, FT, and PF Typologies Associated with Hawala Transactions

Typologies related to hawala transactions:
  • Structuring: Criminals break down a large sum of illicit money into small sections and launder the funds through several hawala transactions to avoid any suspicion.
  • Back-to-Back Transfers: Matching one client’s need to send money to another’s need to receive money in the opposite direction creates a circular or offsetting mechanism that avoids any actual money movement.
  • Trade-Based Settlement: Settling Hawala debts through over- or under-invoicing of goods. Hawaladars may run import-export businesses and manipulate trade values to balance their books.
  • Use of Third Parties or Mules: Criminals use third parties or mules to transfer funds among countries. These third parties or mules are often unaware that they are being misused for illicit fund transfers.
  • Integration with Criminal Proceeds: Criminals use hawala transactions to legitimise their illicit proceeds by disguising them as legitimate payments.
  • Use of False Invoices and Shell Companies: False invoices are often used to legitimise the transfer of illicit funds, creating the appearance of genuine transactions to meet regulatory requirements. Shell companies may also be established solely for the purpose of laundering money, with illicit funds disguised as proceeds from legitimate business activities.
  • Charities and Non-Profit Organisations: Funds are sent through Hawala to support terrorist organisations or individuals in high-risk jurisdictions, often linking them to charitable organisations or seemingly legitimate donations.
  • Cross-border Value Transfer Without Currency Movement: Hawaladars never physically transfer money; rather, one hawaladar contacts another hawaladar in another jurisdiction to give the same amount of money to the recipient without actually moving it.
  • Reverse Hawala Flows: Hawaladars settle their accounts without physically moving money. They maintain running accounts of corresponding Hawaladars, offset the balances against other transactions, and, if needed, settle the accounts periodically.

Harnessing Technology for Mitigating ML, FT, and PF Risk Emanating from Hawala Transactions

FIs, DNFBPs, and VASPs can rely on technology, such as transaction monitoring powered by data analytics and artificial intelligence, to detect patterns indicating hawala activities and help identify and report illegal hawala activity to comply with AML/CFT and CPF obligations. Implementing robust transaction monitoring systems helps detect any illegal and unregulated hawala transactions.

Concept of Hawala: Concluding Remarks

Conducting or encouraging hawala transactions comes with the inherent risk of being linked to illegal activities and funds for ML, FT, or PF activities. Regulated Entities must exercise caution when dealing with customers who might be using funds from questionable origins. Seeking sources of funds and sources of wealth to corroborate a paper trail of funds helps mitigate ML, FT, and PF risks, particularly from hawala, to a great extent, followed by senior management approval and enhanced due diligence measures.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

Reach Out to Pathik

Mitigating “Tipping Off” Risk to Ensure AML/CFT Compliance

Mitigating “Tipping Off” Risk to Ensure AML/CFT Compliance

This blog discusses the intricate subject of tipping off in the context of AML Compliance by taking the reader through the topics covering the following:
  • What is Tipping Off
  • A nuanced analysis of the specific exemption from filing STRs available to professionals like Accountants, Independent Legal Auditors, Lawyers, and Notaries when providing privileged services
  • Obligation to file STR by complying with no-tipping-off requirements when performing services or activities coming under the purview of AML/CFT obligations.
  • Do’s and Don’ts to avoid tipping off
  • Best Practices to avoid tipping off
  • Suggestive Checklist to Avoid Tipping- Off Customers While Filing STR With UAE FIU.

What is Tipping Off in AML Compliance?

What Does The Word “Tip-Off” Mean?

The act of informing a person about an upcoming event, information, or any action against them so that they can take precautionary measures or prepare themselves for the consequences of such event, action, or information is known as tipping off.

Tipping Off in the Context of AML Compliance

Before delving into understanding tipping off in the context of AML/CFT and TFS compliance, a rewind or refresh of AML compliance and suspicious transaction reporting (STR) obligations is required. The Federal Decree Law No (20) of 2018 on AML/CFT requires the reporting entity (FIs, DFNBPs, or VASPs) to report to the FIU about the suspicious transaction without any delay, while ensuring confidentiality. This confidentiality requirement is two-pronged, requiring reporting entities to ensure confidentiality in two stages:
  • Not disclosing the information, contents, and subject matter of the STR to anyone, particularly the customer themselves, except the concerned team members (which include senior management, AML compliance officers, and other compliance team members) or personnel working on the particular case.
  • Not disclosing the act of reporting itself, except for the concerned team members, that regulatory reporting measures are being carried out for a particular customer regarding their transaction with the entity.
Any violation of this confidentiality requirement, particularly resulting in the customer being forewarned, informed, or given any hint or disclosure of impending or concluded reporting by the regulated entity to the authorities, is known as tipping off.
In simple words, when a customer is reported to the authorities, the regulated entity must ensure that such customer does not know through any staff member of the regulated entity that they are being or are reported, either intentionally or unintentionally.

Consequences of Tipping Off on Regulated Entities

If the customer gets to know about STR because of a lapse of confidentiality on the part of the regulated entity, then such a lapse would amount to tipping off and a consequential fine of not less than one hundred thousand (100,000) AED being capped at five hundred thousand (500,000) AED and imprisonment for a minimum of one year would be imposed on the regulated entity and its employee responsible for such a lapse. Tipping off affects the integrity of a regulated entity.

The goodwill or the reputation of a regulated entity gets affected in the eyes of customers as it undermines the trust and faith of customers by showing that the regulated entity is non-compliant with the legal requirements.

Balancing Act: Navigating Specific Exemption from Regulatory Reporting & STR Confidentiality Obligations For Professionals like Accountants, Independent Legal Auditors, Lawyers, and Notaries

Unlike other DNFBPs, professionals like Accountants, Independent Legal Auditors, Lawyers, and Notaries providing services such as the following:
  • Assessment of customer’s legal position
  • Defending or representing customers before the court of law or authorities
  • Assisting with or providing services such as arbitration or mediation
  • Providing legal advice or opinion in the context of legal proceedings
  • Consulting services for avoiding or commencing legal proceedings or their completion of such services

are exempt or waived from the responsibility of reporting and filing an STR with the FIU due to direct invocation of professional secrecy in order to avoid conflict of interest and safeguard the privacy of communications with the client, ensuring that the best interest of the clients is served through the professional services. To put it simply, reporting suspicious transactions is not required if the service rendered by these professionals comes directly under the purview of legal professional privilege.

Nevertheless, activities and services under the scope of AML compliance but outside the purview of direct professional privilege, having any suspicious element (pertaining to ML, TF, and PF) in transactions, must be reported to the UAE FIU without any delay. These activities and services are discussed more at length in further paragraphs. This portion of UAE AML/CFT compliance obligations is drawn in alignment with the Financial Action Task Force (FATF) Recommendation Nos. 20, 21 and 23 for Suspicious Transaction Reporting and Tipping Off.

Caution to be Exercised by Lawyers and Accountants to Prevent Tipping Off While Complying with UAE’s AML/CFT Regulatory Reporting Obligations

By virtue of specific exemption from reporting STRs granted to professionals like Accountants, Independent Legal Auditors, Lawyers, and Notaries, they need not file STR with the UAE FIU, apparently freeing them up from no tipping-off obligations with regard to services impacting the legal standing of the client as described earlier.

However, the catch exists as professionals like Accountants, Independent Legal Auditors, Lawyers, and Notaries need to file STR if they come across suspicious transactions when their service is outside the scope of the specific exemption, but under the purview of AML obligations. Examples of such services or activities include, but are not limited to, activities and services such as illustrated and enumerated:

  • Purchase/Sale of Real Estate
  • Management of Client Funds
  • Management of Bank Accounts, Savings Accounts, or Securities Accounts
  • Organising contributions for the establishment, operation or management of companies
  • Creating, or managing Legal Persons of Legal Arrangements
  • Purchase and Sale of Commercial Entities

Interestingly, dissuading or advising the client or customers against engaging in any activity or transaction pertaining to ML/TF does not amount to tipping off by professionals like Accountants, Independent Legal Auditors, Lawyers, and Notaries.

Professionals like accountants, independent legal auditors, lawyers, and notaries must exercise caution when formulating AML/CFT policies and procedures. Their AML/CFT Policies and Procedures must be crafted in such a way that the processes for customer due diligence (CDD) for activities within the scope of a specific exemption from reporting and those activities covered under AML/CFT compliance and resultant statutory reporting, such as STR should have distinct workflows, escalations and protocols in place so that there is no under or over-reporting or wrongful or missed reports on part of the accountants, independent legal auditors, lawyers, and notaries. This also helps eliminate the risk of the occurrence of tipping off event as there are distinct services where exempted services do not need reporting and the ones under the scope of AML compliance are reported accurately in the event of suspicious transaction in a timely manner, without the risk of breaching professional secrecy.

How Can All Regulated Entities Prevent Tipping Off

It is important to strike a balance between tipping-off prevention and complying with AML/CFT regulatory reporting obligations. Regulated Entities need to maintain this balance smartly. This section addresses how all Regulated Entities, including professionals like Accountants, Independent Legal Auditors, Lawyers, and Notaries, can prevent tipping off while ensuring compliance with reporting obligations.

The primary recourse available with the regulated entities is to delay the processing or conclusion of the suspicious transaction or the proposed transaction attempted by the subject customer of the SAR/STR.

  • Delay Processing of Transaction: Rejecting or terminating the business relationship with the reported customer may tip off the person. Thus, the regulated entities are required to avoid tipping off by delaying the transaction until the entity has received any recommendation, feedback, or additional information request from the Financial Intelligence Unit (FIU).
  • Delay Internal Approval Process: The regulated entities can delay the processing of the transaction by informing the customer that it is pending due to the internal approval process, rather than disclosing that the entity is awaiting feedback from FIU or that it is reconsidering the decision to engage with the person on account of observed red flag. For example, regulated entity may inform the customer that the delay has occurred due to the review of their transaction as part of the internal compliance process, which includes verifying the information and obtaining the necessary internal approval.
  • Increase Paperwork: The regulated entities can avoid tipping off by informing the customer that the paperwork has been misplaced and needs to be resubmitted. This process may take some time, during which the FIU may respond or provide further guidance around the reported suspicion.
  • Demand Additional Information: The regulated entities can ask for additional information or documents like more identification documents or bank documents for verification, thereby delaying the execution of the transaction or trying to create botheration for the customer, which may result in the customer withdrawing from the proposed transaction.
  • Any Other Reason: Apart from the above-mentioned reasons, regulated entities can make other excuses, such as the delay being caused by a technical glitch that might take some time to resolve or that the business relationship cannot be continued on account of commercial reasons or that the fees/charges need re-negotiation.

General Do’s and Don’ts to Avoid Tipping-Off

There are certain general Dos and Don’ts that all Regulated Entities can imbibe in their daily operations discussed below:

Do’s to Avoid Tipping Off

  • Report Suspicious Transactions Confidentially: Regulated entities are required to report suspicious transactions while maintaining the confidentiality of both the reporting act and the information being reported. This protects the essential purpose STR serves in combating financial crimes.
  • Formulation of Proper Protocols and Controls Within AML/CFT Policy and Procedures To Prevent Tipping Off: Regulated entities need to formulate the guiding principles, protocols, and controls regarding the confidentiality of STR within their AML/CFT Policy and Procedures. Moreover, policies should also talk about staff training, which needs to be documented and approved by senior management.
  • Training The First Line of Defence to Avoid Tipping Off: The first line of defence are the employees who directly interact with customers. Training them about cases of suspicious transactions, questions they have to ask the customers, and information that should not be disclosed helps minimise the risk of breaching the NO tipping off requirement.

Don’ts to Avoid Tipping Off

  • Disclose Customer About Ongoing Investigation: Disclosing information about the ongoing investigation to the customer results in the breach of no tipping-off obligation, resulting in the regulatory fine and/or imprisonment to the employees of the regulated entity and the regulated entity itself. For this, the Company must ensure that customer communication post reporting is handled by the expert compliance team member who understands the tipping-off risk.
  • Discuss AML Reports With Anyone: The information about STR should not be discussed with anyone unless such information is necessary for the recipient to discharge their official duties within DNFBPs or its affiliated groups entrusted with the identification and prevention of ML/FT and PF risk.

Best Practices to Avoid Tipping Off a Customer Through Strengthening Internal Controls Within the Regulated Entity

  • Establish AML/CFT policies, procedures and controls by identifying the situations that may lead to tipping off and applying the control measures to prevent it.
  • Maintain robust security practices, such as an electronic document storage system with strong password protection, to avoid information leakage and access to such confidential information by authorised personnel only.
  • Maintain the customer files and documents with digital user verification and password protection to avoid easy access to customer files by unauthorised personnel within the organisation, leaving an audit trail.
  • Apply internal controls appropriate for business, such as restricting the sharing of information to only those who have a genuine need to know.
  • Balance the obligations of data privacy and protection with the requirement to file STRs involving disclosure of only the necessary information to authorities while ensuring the protection of the customer’s personal data, as discussed in the context of lawyers and accountants.
  • When appointing a third party to undertake Customer Due Diligence (CDD) measures, the regulated entity should consider the internal controls deployed by the third party to prevent tipping off.
  • Formulate policies that outline the terms and conditions for sharing information with the customers by clearly identifying situations where sharing information could constitute tipping off and specifying the circumstances in which sharing of the specified information is restricted.
  • Provide staff training, particularly those in the first line of defence, on how to maintain the confidentiality of STR filings and the necessary steps to avoid tipping off.
  • Use legally enforceable agreements when disclosing confidential information to third-party employees.
  • Clearly define the penal consequences an employee may face in case of tipping off and communicate the same to all the employees within the organisation.

Suggestions to Avoid Tipping Off

Establishing robust AML compliance procedures requires DNFBPs to have a checklist to avoid tipping off. Any regulated entity’s AML Compliance Officer can refer to the suggestions mentioned below and use them as their checklist to rule out potential breaches of the tipping-off obligations by taking remedial measures.
  • Does the person handling the customer communication understand the requirement of “No Tipping Off”?
  • Whether any activity, event, or communication took place with the customer, which can be inferred as the AML compliance team has filed or is going to file STR?
  • Did any activity, event, or communication take place with the customer informing that the regulated entity received notice from the FIU for additional information?
  • Did any activity, event, or communication take place with the customer regarding suspicion of their involvement in ML/FT or PF-related transactions?
  • Does the customer-facing team and AML compliance team follow AML/CFT Policies and Procedures in place, having protocols to avoid tipping off?
  • Has the transaction processing been delayed with reasonable justification given to the customer or rejected on commercial grounds?

Tipping Off & Robust Regulatory Reporting: A Final Thought

Avoiding tipping off and establishing robust regulatory reporting is essential for complying with the AML/CFT obligations. By establishing clear policies and procedures and conducting proper training, regulated entities can ensure that they meet the regulatory requirements.
AML/CFT/CPF Training for staff of the Financial Institutions operating in capital markets ensures that each employee understands their role in the AML/CFT/CPF Program of the Financial Institutions and performs their responsibility properly.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

Reach Out to Pathik

Identity Verification Toolkit for Tranche 2 Entities

Identity Verification Toolkit for Tranche 2 Entities

In this article, we will explore the critical role of Identity Verification (IDV) in AML/CFT/CPF compliance. Financial crimes have an adverse impact on the economy and society at large. Governments across the globe have implemented AML/CFT/CPF laws and regulations to curb the menace of financial crimes like money laundering, terrorist financing, and proliferation financing. Know Your Customer (KYC) processes play a huge role in preventing and detecting financial crimes. One of the important aspects of KYC processes is to perform customer ID Verification.

What is ID Verification

ID Verification, also known as Identity Verification, is a regulatory obligation where a Reporting Entity identifies and verify the authenticity of the ID Documents provided by the individual customers as well as non-individual customers (such as companies, associates, trust, etc.). This verification helps Reporting Entities in Australia to establish the true identity of their clients before providing designated services to them, thereby reducing the risk of being exploited for illegal financial activities.

Regulatory Requirements for ID Verification

IDV is a regulatory obligation for all the Reporting Entities in Australia under the following legislations:
  • Anti-Money Laundering and Counter-Terrorism Financing Act 2006
  • Anti-Money Laundering and Counter-Terrorism Financing Rules 2007
  • Associated regulations, etc.
The proposed reform, the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024, introduces the requirement of the ID Verification for Tranche 2 Entities which will come into effect from July, 2026.

Role of in Tranche 2 Entity’s AML/CTF Framework

Knowing a customer’s profile gives insight into who a customer is and what the nature of their business is. Having knowledge of the customer and their business helps in detecting irregular activities or behavior. A business can monitor customer transactions and activities and detect abnormal or unusual transactions. It also helps in knowing the risks associated with customers.

Each customer is different and has different types of risks associated with them. For example, a PEP poses a higher risk than a non-PEP individual. In the same way, a customer from high jurisdictional risk poses more risk than a customer from low jurisdictional risk. Therefore, it is important to understand the customer for the right risk assessment.

Below are some of the key roles that IDV performs in mitigating ML/TF risk:

Reduction in Financial Crimes

Identity verification helps in the reduction of financial crimes. As Reporting Entities are required to perform Identity Verification procedures before entering into a business transaction, it discourages criminals from placing their illicit money into the legitimate economy and thereby reduces financial crimes and their adverse effects on the economy and society at large.

Enhanced Trust and Reputation

Businesses that are compliant with the ID verification procedures know who they are dealing with and can take a risk-based approach when performing their Customer Due Diligence (CDD) Procedures. If there is a slight suspicion as to the legitimacy of the ID Documents provided, more detailed KYC procedures can be applied. A compliant business creates an environment of trust among other businesses and thereby earns a reputation and a positive brand image.

Improved Regulatory Compliance

Identity Verification procedures ensure compliance with the regulatory requirements. If a Reporting Entity is consistently doing IDV before customer onboarding then if any suspicion arises with respect to Money Laundering, Terrorist Financing, or Proliferation Financing, it can be reported to the Australian Transaction Reports and Analysis Centre (AUSTRAC) within a reasonable time.

Streamlined Customer Onboarding Procedures

Identity Verification ensures uniform business-wide customer onboarding procedures. This results in proper Customer Due Diligence and risk assessment. The appropriate level of due diligence is carried out depending on the risks associated with the customer.

Steps for Identity Verification by Reporting Entities

All the Reporting Entities, including Tranche 2 entities, must continuously maintain and updating Applicable Customer Identification Procedures (ACIP) as part of a thorough and risk-sensitive approach to Customer Due Diligence:

Identifying the Timeframe

  • Reporting Entities are expected to complete customer identification procedures prior to delivering any designated service. This obligation applies regardless of whether the interaction involves a single transaction or forms part of an ongoing business arrangement.
  • In relation to beneficial ownership and Politically Exposed Person (PEP) status, the timing requirements are slightly more flexible. While it is preferable to determine these aspects before the designated service is provided or shortly thereafter, provided it is completed as soon as practicable within a risk-based framework.

Collecting and Verifying Customer’s ID Documents

Tranche II Reporting Entities must obtain reliable Identification Documents or data and verify their authenticity to confirm the customer’s identity. When verifying a customer’s identity, Reporting Entities must be relying on documents that are both trustworthy and independent. The reliable and independent documents in Australia include:

A. For Individuals

1. Primary Photographic Identification Documents: These are official documents that include a photograph of the individual and are generally issued by a government authority. Acceptable examples include:

  • Driver’s licence (physical or digital)
  • Australian passport
  • Australian-issued proof of age card
  • Passport issued by a foreign government or the United Nations
  • International travel document from a recognised authority
  • National identity card issued by a foreign government or the United Nations.

2. Primary Non-Photographic Identification Documents: Where a photograph is not available, the following original documents can be used to verify identity:

  • Australian birth certificate or
  • Australian citizenship certificate
  • Foreign birth or citizenship certificate
  • Concession card issued by the Australian government (such as a pensioner card, healthcare card, or seniors health care card).

3. Secondary Identification Documents: These documents provide supporting information and must include the customer’s name and residential address. Acceptable examples are:

  • Letter or notice from a government agency (e.g., the ATO or Centrelink) issued within the past 12 months
  • Utility bill or local council rates notice issued within the last 3 months (e.g., electricity, gas, or water bill)
  • For minors under 18:

    • Letter from a school principal issued within the last 3 months, showing the student’s name, residential address, and attendance details
    • Student identification card, if available.

Note: All documents used must be current. However, an Australian or foreign passport can be accepted if it has expired within the last two years.

B. For Legal Entities

  • Certificate of incorporation of a company from ASIC (Australian Securities and Investment Commission) and/or an annual statement including the amendments submitted to ASIC
  • Trust deed
  • Partnership agreement
  • Constitution and/or certificate of incorporation for an incorporated association
  • Constitution of a registered cooperative.

Identifying Beneficial Ownership

When the customer is a legal entity, the Reporting Entity must be:
  • Identifying the individuals who own 25% ownership or control the entity.
  • Verifying their identity using reliable and independent documents.
  • Understanding the ownership and control structure.

Performing Screening for Politically Exposed Persons (PEPs)

  • Tranche 2 Reporting Entities should determine if the customer or their beneficial owners are PEPs, which may elevate the risk profile.
  • Enhanced Due Diligence (EDD) is required if the individual is a PEP, due to elevated ML/TF risk.

Understanding the Business Relationship

  • Tranche 2 Reporting Entities should gather information on why the customer is engaging with their services.
  • Understanding the expected nature, purpose, and duration of the relationship.

Addressing Risk Based Factors

IDV Procedures of a Reporting Entity must be developed with regard to the specific risks relevant to their operations. Key factors to address include:
  • The size, scope, and complexity of the business activities
  • The nature and purpose of the customer relationship
  • The level and type of money laundering or terrorism financing (ML/TF) risks involved
  • Types of customers and their profiles, including their ownership and control structures
  • The sources of customer funds and wealth
  • The method of delivery of your services (face-to-face, digital, third-party, etc.)
  • The jurisdictions involved, especially where foreign exposure increases risk

Different Types of Customer Verification Procedures for Reporting Entities

Identity Verification Procedures vary based on the type of customer and their assessed level of Money Laundering (ML) and Terrorism Financing (TF) risk. Below is a breakdown of the customer verification approaches for individuals, companies, and trusts, particularly under simplified or ‘safe harbour’ provisions:

1. ‘Safe Harbour’ Verification Procedure

Reporting Entities may apply ‘safe harbour’ procedures when verifying the identity of individuals assessed as posing medium or low ML/TF risk. These procedures are less rigorous than those required for high-risk individuals but still mandate the collection and verification of key identifiers such as:
  • Full name, and
  • Either the date of birth or residential address.
Verification can be carried out using:
  • Reliable and independent documentation (originals or certified copies of primary or secondary identification documents), or
  • Electronic data sources, ensuring at least two independent and credible sources are used (e.g., databases from credit reporting agencies).

2. Simplified Verification Procedures

Reporting Entities may apply simplified verification procedures in low-risk cases:

For Companies: Verification is simplified if the company is:

  • Listed on an Australian stock exchange
  • A majority-owned subsidiary of a listed company
  • Licensed and regulated by a Commonwealth, State, or Territory authority
In these cases, Reporting Entity can verify through Stock exchange listings, Australian Securities and Investments Commission (ASIC) records, annual reports, or regulator databases.

For Trusts: Simplified checks apply if the trust is:

  • A registered managed investment scheme
  • An unregistered scheme for wholesale clients only
  • Supervised by a Commonwealth regulator
  • A government superannuation fund

Methods of Performing Identity Verification or Tranche 2 Entities

Verification of identity can be done in different ways, such as digital verification using biometrics or identity verification using identity cards. Following are multiple methods that Reporting Entities may adopt to verify the identity of individuals as well as entities:

Biometric Verification

Using technology to scan fingerprints, eye scans, and facial recognition and compare them against the central database provides more security, and this method is more reliable. It is difficult to fake this verification.

Document Verification

For individuals, verification typically includes checking official documents such as For companies, Australian Business Number (ABN) registration details or Australian Securities and Investments Commission (ASIC) records can be used.
Reporting Entities should verify the authenticity of customer ID Documents through both online and offline methods, which include:
  • ID Confirmation: Validate the document with issuing authorities such as the Department of Home Affairs (for Australian passports). ID Documents that are using electronic data can verify the data through Document Verification Service (DVS) which is a secure online system managed by the Department of Home Affairs.
  • ID Validation: Assess the genuineness of the document to detect any signs of forgery or tampering.
  • ID Number Match: Verify the document’s issue date and validity period to ensure the ID document is current and accurate.

Knowledge-Based Authentication (KBA)

Reporting Entities may enhance identity assurance by asking personalized security questions that only the genuine individual can answer. This method will add an extra layer of protection to fight against ML/TF risk.

Online verification with Biometrics and AI

Reporting Entities can authenticate IDs in real-time by prompting customers to upload selfies which is then matched against the image in their Identity Document using facial recognition and artificial intelligence.

Two-Factor Authentication (2FA)

Reporting Entities should use multi-layer security by adding a layer of security and asking users to confirm their identity through a second method like a code or One Time Password (OTP) sent to their phone or email along with the password.

Device Verification

Reporting Entities may assess the legitimacy of ID documents and the device used by the customer during onboarding or transactions to detect fraud and ensure security.

Challenges in IDV Process for Reporting Entities

Despite the clear regulatory requirements, Reporting Entities often face several challenges in effective implementation of the ID Verification process such as:

Uneven Jurisdictional Requirements

IDV systems face significant complexity when deployed across multiple jurisdictions. Each country may have distinct Know Your Customer (KYC) regulations, resulting in inconsistent record-keeping standards and verification requirements.

Data Privacy and Security Compliance

A major hurdle for IDV solutions is navigating stringent data privacy laws and biometric data regulations. Gaining valid consent and managing sensitive biometric information such as facial recognition or fingerprint data must be done in full compliance with regional laws (e.g., GDPR, Australia’s Privacy Act, 1988). Any misstep could lead to legal penalties and loss of user trust.

Exploitation Through Deepfakes and Cyber Threats

The remote nature of IDV particularly in digital onboarding exposes systems to sophisticated threats. Deepfake technology may be used to impersonate individuals, bypassing facial verification tools. Additionally, malware infections, phishing, and cyberattacks targeting IDV databases pose persistent risks to data integrity and authenticity.

Lack of System Integration

Not all IDV tools are designed for easy integration into a company’s existing infrastructure. This lack of interoperability can disrupt the onboarding workflow and lead to inefficiencies, as organisations are forced to manually bridge gaps between legacy systems and modern IDV platforms.

Resistance from High-Risk Customer Segments

Despite advanced IDV technologies, challenges persist in verifying high-risk customers such as Politically Exposed Persons (PEPs) or Ultimate Beneficial Owners (UBOs) with complex corporate ownership structures. These individuals may delay or withhold critical information, hindering timely completion of the IDV process and increasing exposure to compliance risk.

Best Practices for ID Verification

To meet global compliance expectations and reduce exposure to financial crime, Tranche two Entities should adopt the following best practices for implementing a robust IDV process:

Adopt a Risk-Based Approach

Reporting Entities must apply Identity Verification measures proportionate to the level of risk posed by each customer or transaction. A standardised approach for all customers fails to account for varying levels of money laundering risks. Therefore, a risk-based strategy should be incorporated by Reporting Entities which includes classifying customers into risk categories (low, medium, high) and adjusting verification procedures based on risk (e.g., enhanced due diligence for high-risk profiles).

Define Comprehensive IDV Policies and Procedures

Internal AML/CFT policies must clearly define the types of Identity Documents that are acceptable, and how these documents are verified. It should categorically define the steps that are required to handle non-face-to-face onboarding and remote verifications.

Incorporate Ongoing Monitoring

Identity verification is not a one-time task. Businesses must establish processes for monitoring for changes in customer information and Re-verifying Identities during periodic reviews or when risk profiles change.

Ensure Staff Competency Through Training

Reporting Tranche II entities should ensure that their employees who are responsible for conducting IDV such as KYC analysts, and Compliance Officers must be trained to detect forged or fraudulent document and identify red flags such as inconsistent information, false addresses, or outdated IDs.

Leverage Technology and Automation

Digital solutions are key to improving the speed, accuracy, and reliability of IDV. Reporting Tranche II entities should include tools such as facial recognition, biometric checks, and OCR, API-based integration with government databases and watchlists, etc. Automated verification reduces human error and speeds up onboarding while ensuring full audit trails.

Technologies Powering Identity Verification Software for Tranche 2 Entities

Identity verification software enables Reporting Entities to efficiently capture customer data and perform its verification against the relevant databases. It helps the Reporting Entities to overcome the challenges associated with the manual methods and provides an efficient, timesaving, less error-prone, systematic, and accurate way to perform the IDV of their clients. By automating the process, IDV software ensures a streamlined, accurate, and compliant approach to verifying customer identities, thereby enhancing regulatory adherence and customer onboarding experience.

Artificial Intelligence and Machine Learning

Artificial intelligence and machine learning are central to modern IDV systems. It helps analyze ID documents by identifying patterns, attributes, and potential anomalies. It will flag the documents if they appear to be forged.

Optical Character Recognition

Optical Character Recognition (OCR) helps in extracting data from documents, thereby saving time and ensuring a faster turnaround. It also minimizes manual data entry errors, improving operational efficiency.

Blockchain Technology

Blockchain provides an enhanced layer of security as it provides a temper-proof ID verification. It makes the entire process auditable, traceable, and verifiable.

Biometric Verification

Biometric IDV tools helps the Reporting Entities to verify customer identity by different methods such as facial recognition, fingerprint scanning, and iris detection, offer robust security and accuracy.

Electronic Know Your Customer (eKYC)

eKYC eliminates the need for physical documents by enabling digital Identity Verification using government-backed databases and secure APIs. It allows customers to complete KYC processes remotely, offering a faster, paperless, and cost-effective method of compliance, especially in digital banking and fintech platforms.

These advanced technologies collectively ensure that Identity Verification software remains an essential component of an effective AML/CTF compliance framework, improving risk management while enhancing user experience and regulatory compliance.

Let IDV Concerns Disappear in Your Rearview Mirror!

Verifying customer identity gives more knowledge about the customer and their business. Correct risk rating and due diligence can be done if the identification process is right. When doing Identity Verification, a business gains access to customers’ personal information. It is important to protect customer information from data breaches and fraud. Thus, a Reporting Tranche 2 Entity should identify the customer by having the right identification and verification program and protect customer data by having the right data management and protection tools.

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 9+ years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

Securing Capital Markets against Financial Crime Risks

Securing Capital Markets against Financial Crime Risks

Capital Markets provide platforms where buyers and sellers trade stocks, bonds, and other financial assets, fuelling economic growth by connecting businesses with investors. However, these markets are vulnerable to exploitation by financial criminals. In this blog, we will examine Anti-Money Laundering (AML), Combatting the Financing of Terrorism (CFT), and Counter Proliferation Financing (CPF) measures for securing capital markets against financial crime risks.

Let us begin by first understanding the meaning of capital markets.

What Are Capital Markets?

Capital Markets connect those who need capital and those who have capital and want to invest the same. Capital markets thus facilitate economic growth. Entities operating in the capital market sector offer various types of products and services, such as:
  • securities and commodities brokerage,
  • investment advice and management,
  • securities consultation and analysis,
  • fund service businesses,
  • exchanges, depository services, etc.

These products and services encourage investment. In UAE, the capital market sector is supervised by the Securities and Commodities Authority (SCA). It is the apex authority in-charge of overseeing and regulating the capital markets in the UAE. This includes monitoring the AML/CFT/CPF compliance of Financial Institutions operating within the UAE’s capital markets. However, there’s an exception to this – the Financial Services Regulatory Authority (FSRA) and the Dubai Financial Services Authority (DFSA) oversee the operations of the capital market players registered and operating from the Abu Dhabi Global Market (ADGM) and Dubai International Financial Centre (DIFC), respectively.

Now, let us discuss exactly what types of Financial Institutions operating in the capital market are subject to and regulated under AML/CFT/CPF regime of UAE.

Financial Institutions Operating in Capital Markets that Are Regulated under AML/CFT/CPF Regime of UAE

Under Cabinet Decision No. (10) of 2019, the following types of financial activities or operations are relevant in the context of Capital Markets:
  • Providing Monetary brokerage services
  • Engaging in securities transactions, issuing securities, providing financial services related to issuing of securities, finance, and finance leasing
  • Trading, making investments in, operating or managing:
    • Assets
    • Options contracts
    • Future financial contracts
    • Exchange and interest rate transactions
    • Financial derivatives
    • Negotiable financial instruments
  • Providing custody of funds services
  • Management of investment and other types of funds and portfolios
Further, the SCA provides to the following categories:

Category 1: Entities Dealing in Securities

This category includes trading and clearing brokers, global market trading brokers, trading brokers of OTC derivatives, OTC commodities contracts, currencies in spot market, financial products dealers, etc.

Category 2: Entities Dealing in Investments

These entities include those involved in investment fund management, family business investment management, portfolio management, fund administration, profit sharing investment account management, etc.

Category 3: Entities Dealing in Custody, Clearing, and Registration

These include custody, general clearing, issuer of covered warrants, depository bank of depository receipts, depository bank agents of depository receipt, registrar of private joint stock companies, etc.

Category 4: Credit Rating Agencies

Category 5: Entities Dealing in Arrangement and Advice

These include entities such as financial consulting, financial advisor, listing adviser, introducing services, promotion services, etc.

Category 6: Crowdfunding Platform Operators

Category 7: Virtual Assets Services Providers

This category includes entities engaged in virtual asset brokerage and custody of virtual assets. VASPs operate as a distinct category of regulated entities under AML, CFT, CPF and TFS regime of UAE, alongside Financial Institutions and Designated Non-Financial Businesses and Professions (DNFBPs).

Therefore, all Financial Institutions licensed by the SCA and providing any of the financial transactions or activities associated with the capital market listed under Cabinet Decision No. 10 of 2019 are regulated under AML/CFT/CPF regime of UAE.

Now, let us understand why capital markets are vulnerable to financial crimes, highlighting why Financial Institutions operating in the capital markets of UAE need strong AML/CFT/CPF compliance programs.

Why are Financial Institutions in the Capital Market Sector Vulnerable to Financial Crime Risks

Capital markets provide access to the financial system. Certain characteristics of the capital market make it susceptible to criminals seeking to commit financial crimes such as Money Laundering (ML) , Terrorism Financing (TF), and Proliferation Financing (PF) . These characteristics include the following:

Large Volume and Value of Transactions:

Financial Institutions operating in the capital markets process an enormous volume of transactions daily, often involving substantial sums of money. The large volume and value of transactions makes monitoring difficult, allowing illicit activities to sometimes go undetected.

Rapid Execution of Transactions:

Transactions in the capital market are executed at high speed, often within seconds or minutes. This rapid movement of funds makes it challenging for Financial Institutions to detect and intervene in real-time. Financial criminals often exploit this feature to quickly transfer dirty money before suspicious patterns are identified.

Involvement of Multiple Intermediaries:

Transactions conducted in the capital markets often involve a complex network of intermediaries, including brokers, investment funds, custodians, and clearing houses. This fragmentation of transactions provides anonymity to financial criminals, as no single intermediary has full visibility of the entire audit trail of the transaction. This lack of oversight enables illicit fund movements.

Complexity of Financial Transactions, Instruments, and Products:

Capital markets provide a wide range of financial products and services, such as derivatives, bonds, multiple types of securities, investment options, etc. Criminals exploit these sophisticated instruments offered by Financial Institutions to create intricate money trails that make it difficult to track and trace illicit funds

High Liquidity:

The high liquidity of the Financial Institutions in the capital market instruments allows assets to be quickly converted into cash or other financial instruments. This makes it easier for criminals to integrate illicitly gained funds into the formal economy.

Movement of Capital across Various Geographies:

The capital market is global, with funds moving across different jurisdictions and financial systems. Cross-border transactions make it difficult to detect ML/TF/PF risks, monitor suspicious activities, and adopt appropriate risk mitigation measures.

Pre-Emptive Detection of ML/TF/PF is Challenging

Financial criminals often structure transactions in a way that makes them appear legitimate at face value. This makes it difficult for Financial Institutions to proactively identify illicit activities before they occur. By the time suspicious patterns emerge, the funds may have already been moved.

Lack of Visibility of the Entire Chain of Transactions:

The sophisticated nature of capital market transactions, coupled with the use of intermediaries, makes it difficult to keep track of the entire chain of transactions. This lack of visibility hinders the detection of ML/TF/PF risks.

These characteristics make Financial Institutions in the Capital Market Sector in the UAE vulnerable to financial crime risks. Now, let us discuss the common financial crime typologies that criminals misuse to conduct ML/TF/PF through Financial Institutions.

Financial Crimes Through Capital Markets: Common Typologies

To effectively detect and prevent the misuse of capital markets for financial crimes, Financial Institutions operating in the capital market must stay informed about common and emerging ML/TF/PF typologies. These typologies include the following:

“Free of Payment” Movement of Securities:

Free of payment movement is essentially a transfer of securities and other capital market instruments without any corresponding payments. It is used to conduct ML/TF/PF by creating layers of transactions. For example, criminals may transfer securities between multiple trading accounts through the services of many brokers across different jurisdictions without any payment, making it difficult to trace the original source of funds. Each broker that facilitates these transactions may have limited visibility regarding the entire audit trail, making it difficult to detect the financial crime involved.

Cash-Based Money Laundering:

While capital markets are not usually considered a cash-intensive sector, financial criminals often try to place illicitly sourced cash in trading accounts and quickly move them through multiple securities trading accounts to avoid detection. Often trading accounts are held with different Financial Institutions, and therefore, they have limited visibility with respect to entire trail of transactions.

“Free of Payment” Movement of Securities:

While capital markets are not usually considered a cash-intensive sector, financial criminals often try to place illicitly sourced cash in trading accounts and quickly move them through multiple securities trading accounts to avoid detection. Often trading accounts are held with different Financial Institutions, and therefore, they have limited visibility with respect to entire trail of transactions.

Mirror Trading:

Mirror trading can be exploited for financial crimes by executing identical buy and sell transactions across different jurisdictions through two connected individuals. To brokers in separate countries, these individuals may appear unrelated. A criminal may deposit illicit funds into a brokerage account and simultaneously buy securities in one country while selling them in another (as only these two transactions match each other and are settled at the prices determined by these two connected parties). Since the trades cancel each other out, there is no market risk, but the money appears as a legitimate trade transaction. This technique effectively launders illicit funds across borders and disguises their origin.

Wash Trading:

In this typology, a trader buys and sells the same financial asset at nearly identical prices to give the trading activity an appearance of legitimacy. Despite the trading activity, no market risk is assumed, and the financial criminal’s market position remains unchanged.

Parking:

In this typology, a person transfers assets to another, often without any legitimate reason or economic rationale, with an understanding that the person will repurchase the same later.

Using Illiquid Securities:

Financial criminals often make use of illiquid securities to conduct financial crimes. Illiquid securities are those assets that do not have a real market, or are low volume, or are of obscure companies, etc. Illiquid securities are used because their prices can be easily manipulated. Trading in illiquid securities is conducted to move around illicitly gained funds.

The typologies discussed in the above section can be detected pre-emptively through red flags that indicate financial crime risks. Let us now discuss these red flags.

Red Flags Indicating Financial Crime Risks in Capital Markets

  • False or Misleading Information: The customer gives Financial Institutions false, misleading, or incorrect information
  • One Directional Transactions: The customer has some accounts mainly for deposits and other accounts primarily for outgoing payments in relation to securities trading activities
  • Customer Hesitant to Provide CDD Information: The customer is hesitant or declines to provide Financial Institutions with CDD information such as Source of Funds or Source of Wealth
  • Frequent and Small Deposits: The customer frequently deposits small amounts of cash, which are later used to buy a specific securities product that is quickly sold or redeemed
  • Third-Party Involvement: The customer’s account receives deposits from third parties, which corresponds to outgoing transfers to other third parties
  • Trading in Securities not in the Name of the Customer: The security, bonds, or any other capital market instrument that the customer seeks to trade, or deposit is not in the customer’s own name.
  • Parties to the Transaction are Interconnected: On each side of a trading transaction, the parties are interconnected, have the same UBOs, business transactions, personnel, etc.
  • No Economic Rationale: The trading strategies of the customer has no economic rationale, or logical reason. The transactions seem irrational. For example, the customer is making a loss, trading at a value below market price, redeeming long-term funds within a short span of time, etc.
  • Transactions in Quick Succession: Customers conduct transactions in quick succession in a short span of time
  • Circumventing De-Risking: Previous customers of the Financial Institutions seek to reapply and seek services of the entity through a different legal person in order to circumvent de-risking or client exit measures adopted by the Financial Institutions for those previous customers.
  • Misalignment with Known Customer Profile: The transaction does not match the customer’s profile, trading history, and trading position. Customer uses denominations or amounts of currencies that do not align with their profile
  • Rapid Change in Customer Details: There may be small but quick changes in CDD details of the customer such as address, directors, Ultimate Beneficial Owners (UBOs), etc.
  • Funding Patterns Are Abnormal: The customer’s account receives funds from third parties with no apparent connection to the customer, or the deposits are done through multiple payment methods, significant funds received in a short time, etc. For example, the customer deposits a significant sum of money in small-denomination currency to fund the account or purchase securities
  • Trading Account Linked by Many Devices: Trading account of the customer is accessed through multiple devices such as PC, different mobile handsets International Mobile Equipment Identity (IMEI) numbers, etc.
After having understood how capital markets are exploited by financial criminals, and how financial crimes can be detected, understanding the common typologies and red flags, let us now discuss AML/CFT/CPF measures Financial Institutions operating in the capital markets can take to strengthen their defence against financial crimes.

AML/CFT/CPF Measures for Financial Institutions Operating in Capital Markets: Challenges and Best Practices

Financial Institutions, DNFBPs, and VASPs are regulated under AML/CFT/CPF regime of UAE and need to adhere to certain compliance obligations. We have detailed these obligations, through an easy-to-understand infographic on AML Compliance Requirement in UAE.

Let us now discuss and focus on specific AML/CFT/CPF measures, challenges in their implementation, and best practices to conduct them effectively, specifically for financial institutions operating in the capital markets.

Enterprise-Wide Risk Assessment (EWRA)

Financial Institutions operating in the capital markets are exposed to financial crime risks – both directly through transactions undertaken by their customers, and indirectly, through ML/TF/PF risks emanating from customers themselves. EWRA helps in assessing these risks on an institutional level, facilitating adoption of proportionate and effective ML/TF/PF risk management system and controls, suitable to the nature and size of the business.

Challenges Contributing to the Ineffective Implementation of EWRA:

  • Adopting Generic EWRA: Financial Institutions may use generic or template EWRA or fail to fully assess the specific financial crime risks they face due to their specific business model. As a result, there may be a lack of awareness across the entity about how criminals could exploit them, leaving a few vulnerabilities unidentified and unattended.
  • Not Defining EWRA Methodology: Failing to define an EWRA methodology weakens a Financial Institution’s ability to identify and mitigate ML/TF/PF risks. Without a structured approach, EWRA may become inconsistent, emerging threats may go unnoticed, and resources invested in AML/CFT/CPF compliance processes may be misallocated.
  • Not Updating EWRA when ML/TF/PF Risk Exposure Changes: ML/TF/PF risk exposure of the Financial Institutions may change due to many reasons, such as the introduction of new financial products, expansion of business to other countries, etc. When Financial Institutions do not update their EWRA to incorporate ML/TF/PF risk exposure arising from their changed circumstances, it may lead to the adoption of inadequate risk mitigation measures, which in turn may lead to failure in preventing financial crimes.
  • Not Considering How EWRA Feeds into ML/TF/PF Controls: The risk assessed through EWRA must translate into risk controls adopted by the Financial Institution. When this is not done, the risk control measures adopted are not relevant or adequate to mitigate the specific ML/TF/PF risks the Financial Institutions is exposed.

Best Practices for Effective Implementation of EWRA:

  • Adopting Tailored and Relevant EWRA: EWRA should be customised to assess the actual ML/TF/PF risks a regulated entity is exposed to. It must take into consideration the ML/TF/PF risks emanating from the customer base of the Financial Institution, the geographies it operates in, its own products and services, the delivery channels used, the transactions it is exposed to, etc. It must also assess the financial crime typologies it is vulnerable to and adopt necessary controls accordingly. EWRA must also incorporate a red flag analysis to ensure that ML/TF/PF typologies are detected and dealt with.
  • Clearly Documenting EWRA Methodology: A clear, documented methodology ensures consistency and enhances ML/TF/PF risk detection capabilities of the Financial Institution. The methodology must include both qualitative and quantitative assessment parameters.
  • Defining Triggers and Updating EWRA when They Occur: Financial Institutions should define scenarios that would trigger a need to update their EWRA. Whenever these triggers occur, the financial crime risk exposure of the Financial Institutions changes, and therefore, EWRA must be updated to incorporate the ML/TF/PF risks emanating from such incidents. These triggers include incidents such as the Financial Institutions introducing new products, the Financial Action Task Force (FATF) updating its Grey List, etc.
  • Ensuring that ML/TF/PF Risks Assessed through EWRA is Mitigated through Appropriate Controls: Adopting proportional and relevant risk controls based on the particular risk exposure of a Financial Institution is the very essence of a risk-based approach. The risks assessed through the EWRA must be mitigated through the Financial Institution’s AML/CFT/CPF Policies, Procedures, and Controls.

Customer Due Diligence (CDD)

Customer Due Diligence (CDD) is the process of understanding the identity of a customer, the ML/TF/PF risks emanating from them, and adopting risk-based ML/TF/PF controls to manage these risks.

Challenges Contributing to the Ineffective Implementation of CDD:

  • Not Documenting Information on Expected Account Activity and Client’s Expectations: One of the challenges in implementing effective Customer Due Diligence (CDD) is the failure to document expected account activity and client expectations. Without a clear record of how an account is expected to function, Financial Institutions may struggle to identify unusual transactions that may indicate financial crime risks.
  • De-Risking in a Wholesale Manner without Considering ML/TF/PF Risks: Some Financial Institutions restrict services to entire customer groups without properly conducting ML/TF/PF risk assessment for them. Effective risk management requires a targeted, risk-based approach rather than broad de-risking measures. Simply cutting off services without sufficient rationale can lead to unintended consequences such as financial exclusion and regulatory non-compliance.
  • Not Re-conducting CDD when Customer’s Circumstances Change: CDD is not a one-time process, it must be dynamic and responsive to changes in a customer’s profile. If a customer’s CDD information undergoes changes, such as a change in ownership, business structure, transaction patterns, etc., but the Financial Institution does not conduct a fresh CDD review, it may lead to incomplete CRA, resulting in the adoption of inadequate ML/TF/PF control measures for the customer.
  • CDD Review is Conducted in an Alphabetical Manner and not a Risk-Based Manner: Some Financial Institutions may conduct periodic CDD reviews in a systematic but ineffective manner, such as reviewing customers alphabetically rather than based on the degree of ML/TF/PF risks they pose. This method does not prioritise high-risk clients, leaving potential financial crime risks undetected for extended periods.

Best Practices for Effective Implementation of CDD:

  • Collecting Adequate Information on Expected Account Activity and Client’s Expectations: Financial Institutions operating in capital markets usually offer financial services geared toward investments and trading in securities. Their clients may have certain expectations as to their account activity and expected returns. Financial Institutions should understand the same to ensure that any mismatch is identified in the future.
  • Creating a Matrix of AML Requirements for Each Customer Type Based on Risk-Based Approach: A one-size-fits-all approach is ineffective in AML/CFT/CPF compliance. Financial Institutions should develop a structured matrix, questionnaire, or checklist outlining specific AML/CFT/CPF tasks that need to be completed for each customer based on different customer types and their associated ML/TF/PF risk levels. This risk-based approach allows for improved efficiency and ensures the optimum allocation of resources.
  • Conducting Periodic Review of CDD in a Risk-Based Manner: Regular CDD reviews are important for maintaining up-to-date customer risk profiles. Financial Institutions should establish triggers for periodic reviews, such as extended periods of non-trading, changes in account activity, updates in regulatory requirements, Financial Action Task Force’s Grey List or Blacklist updates, etc. Further, for periodic reviews, risk-based approach should drive the review schedule, ensuring that high-risk customers receive more frequent and thorough CDD reviews than low-risk ones.
  • Clearly Defining CRA Parameters, Methodology for Calculating Risk Scores and Overrides: A well-defined Customer Risk Assessment methodology is important for consistency and accuracy in the evaluation of ML/TF/PF risks each customer poses to a Financial Institution. Therefore, they should establish clear parameters for assessing financial crime risk, document the methodology for calculating risk scores, and outline procedures for overriding default CRAs where justified.Further, Financial Institutions should tailor their CRA methodologies to include parameters specific to capital markets, such as trading behaviours and investment patterns. This enhances the effectiveness of ML/TF/PF risk management for Financial Institutions.

Transaction Monitoring and Reporting Suspicious Transactions

Financial Institutions operating in the capital markets need to report suspicious activities and transactions by filing Suspicious Activity Report (SAR) and Suspicious Transaction Report (STR) with UAE’s Financial Intelligence Unit (FIU).

Challenges Contributing to Ineffective Implementation of Transaction Monitoring and STR/SAR Reporting Mechanisms:

  • Conducting Transactions Monitoring Manually: Manual transaction monitoring poses challenges for Financial Institutions, including difficulty in assessing and applying relevant transaction monitoring rules and insufficient resources to review suspicious transactions effectively. These factors can lead to inefficiencies, increased operational costs, and potential compliance risks, which hinder the Financial Institution’s ability to manage large volumes of transactions.
  • Mismatch between Increase in Volume of Trade and Scalability of Transactions Monitoring Solution: A mismatch between transaction monitoring capacity and trade volumes undertaken by the Financial Institutions can create risks of AML non-compliance. Financial Institutions may fail to upgrade their transaction monitoring systems in line with their business expansion, leading to them being overloaded and causing delays in detecting suspicious transactions. This issue becomes aggravated when Financial Institutions rely on outdated technologies or systems that cannot handle large datasets efficiently.
  • Not Utilising Capital Market Specific Transaction Monitoring Rules: When Financial Institutions utilise generic transaction monitoring rules that do not give sufficient importance to capital market-specific risks, they reduce their suspicious transaction detection capabilities. Without industry-specific rules, Financial Institutions may fail to detect complex financial crime typologies that target capital markets.
  • Not Considering Contextual Information while Monitoring Transactions: Often, transactions may not appear suspicious when considering them on their own, without assessing them in the context of a customer’s KYC information, CRA profile, Screening results, changes in Ultimate Beneficial Owners (UBOs), etc. This results in suspicious transactions slipping notice.
  • Transactions Monitoring Systems are not Regularly Reviewed: Transaction monitoring systems require periodic reviews and vulnerability assessments to ensure they remain effective in detecting financial crime risks. Failure to assess the adequacy of transaction monitoring systems regularly may lead to outdated detection mechanisms that use ineffective rules and thresholds, produce excessive false positives, etc.
  • Knowledge Gained Through Transaction Monitoring Not Fed Back into EWRA, Controls, and Staff Training: A key challenge is the failure to integrate insights gained from transaction monitoring into EWRA internal controls, and staff training. Transaction monitoring generates valuable intelligence on patterns of financial crimes, their red flags, and typologies. If these insights are not used to refine the existing EWRA, financial crime controls, and staff training, AML/CFT/CPF measures adopted by the Financial Institutions will remain outdated, inefficient, and static, increasing the likelihood of financial crimes slipping through the cracks.
  • Not Documenting Transaction Monitoring Alerts in a Customer’s Profile: Whenever a suspicious transaction alert related to a customer is generated, it must be recorded in the customer’s profile. When alerts are not stored against customer profiles, Financial Institutions may find it difficult to track the history of red flags of suspicious behaviour over time.

Best Practices for Effective Implementation of Transaction Monitoring and STR/SAR Reporting Mechanisms:

  • Utilising Scalable and Customised Transaction Monitoring Software: Financial Institutions should invest in advanced transaction monitoring software that is scalable and tailored to the capital market sector. AI-driven and machine-learning enabled systems can help detect unusual patterns, even in complex transactions involving sophisticated financial instruments. These solutions should have the ability to scale with business growth and volume of transactions. Additionally, implementing real-time monitoring capabilities enables firms to detect suspicious transactions promptly and take immediate action on submitting STR or SAR.

  • Defining and Utilising Risk-Based Transaction Monitoring Triggers
    To improve detection capabilities, transaction monitoring rules should be customised based on the specific risks associated with different clients, products, and services. For example, customers engaging in high-frequency trading may require different monitoring parameters than customers opting for long-term investment funds.
  • Monitoring Transactions in a Contextual Manner: Effective transaction monitoring goes beyond simple analysis of transactions and investigating alerts, it requires evaluating activities in the broader context of customer risk profiles, historical behaviour, KYC data, screening results, etc. By doing so, Financial Institutions can improve their capabilities of detecting sophisticated financial crime typologies that may not be apparent on the face value from the transactions alone.
  • Regularly Reviewing Transaction Monitoring Software: Transaction monitoring systems should undergo periodic reviews and vulnerability assessments to assess the effectiveness of transactions monitoring rules and thresholds, and overall system performance. Updates should be made in response to new regulatory requirements, emerging financial crime typologies and red flags, change in Financial Institution’s financial crime risk exposure, etc.
  • Incorporating Knowledge Gained Through Transaction Monitoring Into EWRA, Controls, and Staff Training: Financial Institutions should establish a feedback loop that integrates insights and knowledge gained through transaction monitoring into their EWRA, internal controls, and staff training programs. By doing so, they can continuously improve the effectiveness of their AML/CFT/CPF Program. Transaction monitoring alerts and their resolution can also provide case studies as a way to train staff members on the practical aspects of detecting financial crime risks.
  • Documenting Transaction Monitoring Alerts in Customer’s Profile: Transaction monitoring alerts related to a customer should be documented in that customer’s profile. Systematically storing alerts, and the investigation conducted to resolve the same ensures that Financial Institutions create valuable data on customer behaviour. This helps tracking patterns of suspicious transactions over time. 

AML/CFT/CPF Staff Training

AML/CFT/CPF Training for staff of the Financial Institutions operating in capital markets ensures that each employee understands their role in the AML/CFT/CPF Program of the Financial Institutions and performs their responsibility properly.

Challenges Contributing to Ineffective Implementation of AML/CFT/CPF Staff Training:

  • Conducting Generic AML/CFT/CPF Training: One of the most prevalent deficiencies in AML/CFT/CPF training is the use of generic, one-size-fits-all training programs. Many Financial Institutions rely on broad-based modules that fail to address the specific financial crime risks faced by the Financial Institution.
  • Not Conducting Role-Based Training: Financial Institutions often fail to tailor their AML/CFT/CPF training to different employee roles and responsibilities. Effective training programs must differentiate between front-line employees, compliance officers, risk managers, senior management, and other stakeholders.
  • Not Compiling and Incorporating Near-Miss Data: A major oversight in AML/CFT/CPF training programs is the failure to analyse and incorporate near-miss incidents, cases where financial crimes almost occurred but were ultimately prevented. Near-miss data is a valuable resource for refining training strategies and improving employees/ ability to detect and respond to suspicious activities.
  • Not Regularly Testing the Effectiveness of Training: Even when AML/CFT/CPF training is conducted, Financial Institutions often neglect to assess its effectiveness. Without regular testing and evaluation, it is difficult to determine whether employees have truly learned key concepts and can apply them while performing their roles.

Best Practices for Effective Implementation of AML/CFT/CPF Staff Training

  • Tailoring Training to the Financial Institution’s Needs: Each Financial Institution has a different business model, ML/TF/PF risk exposure, products and services, size, customer-base, etc. Training should be tailored, keeping in mind the specific characteristics and needs of the business.
  • Conducting Role-Specific Training: Role-specific training ensures that each employee understands their specific responsibilities in the AML/CFT/CPF program of the Financial Institutions properly and executes the same effectively.
  • Using Near-Miss Data to Improve Training: A near-miss is an incident that could have resulted in issues such as non-compliance, missing the attempted ML/TF/PF activity, etc., but did not result in the same. These incidents must be reported to ensure continuous improvement in the AML/CFT/CPF compliance function of the Financial Institutions. Financial Institutions should ensure that data regarding these near-misses are incorporated into training material so that the likelihood of them occurring reduces or the possibility of their timely prevention by the staff increases.
  • Testing the Effectiveness of Training: The effectiveness of staff training should be checked through measures such as tests, quizzes, spot checks, feedback, etc.

AML/CFT/CPF Governance and Oversight

The AML/CFT/CPF measures discussed are important components of AML/CFT/CPF Policies, Procedures, and Controls. These measures need proper governance and oversight to ensure their proper functioning.

Challenges Contributing to Ineffective Implementation of Governance and Oversight Mechanisms

  • Not Inculcating a Culture of AML/CFT/CPF Compliance: Financial Institutions may struggle to instill a culture of AML/CFT/CPF compliance due to a lack of commitment from senior management, insufficient training, and failure to integrate AML/CFT/CPF compliance into everyday operations. This may result in risks of non-compliance.
  • Not Documenting Senior Management Decisions and Discussions: Financial Institutions may fail to document management discussions and decisions related to AML/CFT/CPF compliance. Without proper documentation, it becomes difficult to track compliance discussions, ensure accountability for decision-making, or communicate the decisions to the employees of the Financial Institutions. This lack of documentation can also result in an inability to audit past compliance actions effectively.
  • Not Having Open Communication Channels in Place: The absence of open communication channels hinders the timely escalation of ML/TF/PF risks. Employees may be hesitant to report suspicious transactions due to fear of retaliation or unclear reporting structures.
  • Not Having Proper Mechanisms to Address Possible Conflict of Interests: Conflicts of interest can undermine the integrity of AML/CFT/CPF measures. Financial Institutions that lack mechanisms to identify, report, and prevent conflicts of interest may find themselves vulnerable to ML/TF/PF risks. For example, if an employee of a Financial Institution is in any way related to a customer, such conflict of interest may be exploited by financial criminals and, therefore, is important to prevent.

Best Practices for Effective Implementation of Governance and Oversight Mechanisms

  • Setting an AML/CFT/CPF Compliance Culture: To establish a strong culture of AML/CFT/CPF compliance, senior management of the Financial Institution should lead by example by emphasising the importance of compliance through consistent messaging and actions. Such a culture leads to an atmosphere where AML/CFT/CPF compliance is prioritised throughout the organisational structure of the Financial Institution. Other methods, such as AML/CFT/CPF training for employees, AML/CFT/CPF program evaluations through regular audits, etc, also facilitate establishing a strong compliance culture.
  • Properly Documenting Senior Management Decisions and Approvals: Comprehensive documentation of Senior Management discussions and decisions related to AML/CFT/CPF compliance ensures internal accountability. This documentation serves as an audit trail, ensuring that decisions related to AML/CFT/CPF compliance are communicated and implemented effectively and can be reviewed when necessary.
  • Setting a Transparent Channel of Communication: Financial Institutions should establish clear and accessible communication channels for any concerns related AML/CFT/CPF compliance processes. Employees must have designated reporting structures and whistleblower protections to encourage the reporting of suspicious transactions without fear of retaliation.
  • Adopting Mechanisms to Address Conflict of Interests: Effective governance requires financial institutions to proactively identify and address conflicts of interest. Establishing clear policies on conflict disclosure, independent oversight committees, and regular audits can help minimise biased decision-making, reducing the risk of occurrence of ML/TF/PF. Employees should be required to declare potential conflicts of interest. For example, financial criminals may use their connections within the Financial Institutions to influence its AML/CFT/CPF compliance processes for that customer. Having conflict of interest disclosure requirements reduces this risk.

Customer Risk Assessment (CRA) Questionnaire: Sample Parameters That Financial Institutions Can Imbibe

Let us now discuss some Customer Risk Assessment (CRA) parameters that Financial Institutions operating in Capital Markets can incorporate. Giving due weightage to capital market sector-specific CRA parameters helps Financial Institutions operating in capital markets comprehensively and accurately analyse the ML/TF/PF risks emanating from their customers. These parameters can be used in conjunction with general CRA parameters.

Customer-Related CRA Parameters

CRA Parameter 

Yes/No

Observations 

Are there indicators that suggest an unconfirmed suspicion with respect to the customer’s KYC/CDD data?

 

 

Is the customer’s ownership structure complex or unclear?

 

 

Is the customer or legal person that is primarily established to hold or manage personal assets?

 

 

Does the customer have bearer shares issued or involve nominee shareholding structure? (Bearer shares makes ownership structures anonymous or untraceable)

 

 

Is the customer a cash-intensive company?

 

 

Is the customer’s organisational structure unusual or excessively complex relative to the nature of its business?

 

 

Is the customer a Politically Exposed Person (PEP) or related to a PEP?

 

 

Does the customer’s primary source of income originate from a high-risk country?

 

 

Geography-Related CRA Parameters

CRA Parameter

Yes/No

Observations

Is the country that the customer or transaction involves is a FATF Grey Listed Country?

 

 

Is the country that the customer or transaction involves is a FATF Blacklisted Country?

 

 

Has the country that the customer or transactions involves, been identified by reliable sources such as IMF, OECD, etc as having ineffective AML/CFT/CPF regime?

 

 

Has the country that the customer or transactions involve been identified by reliable sources to have high levels of corruptions, financial crimes, or drug trafficking? 

 

 

Is the country that the customer or transaction involves, subject to United Nations sanctions? 

 

 

Is the customer a securities provider, acting as an intermediary?

 

 

Products/Services Related CRA Parameters

CRA Parameter

Yes/No

Observations

Does the product/service have a feature that enables non-disclosure or anonymity of identity?

 

 

Are payments for products/services being received from unidentified individuals or third parties not associated with the customer?

 

 

Is the trading account, or products/services being operated or utilised for the benefit of a third person?

 

 

Is the client’s account coded or abbreviated?

 

 

Does the product/service have a geographical reach to high-risk jurisdictions?

 

 

Are the securities being purchased using cash?

 

 

Delivery Channels Related CRA Parameters

CRA Parameter

Yes/No

Observations

Has the customer been onboarded through non-face-to-face manner?

 

 

Is the customer engaging with the business through an agent or intermediary?

 

 

If intermediaries are involved, does the intermediary have adequate AML/CFT/CPF systems?

 

 

Is the customer acting on behalf of a third-party unrelated to the transaction? 

 

 

Transactions Related CRA Parameters

CRA Parameter

Yes/No

Observations 

Do the business relationships or transactions take place indirectly with the client through modern technologies like electronic signatures?

 

 

Does the transaction involve anonymous or fictitious accounts?

 

 

Does the transaction involve penny/microcap stocks?

 

 

Does the transaction involve payment through new technologies not usually used by the Financial Institution?

 

 

Is the transaction unusually complex? 

 

 

Securing Capital Markets against Financial Crime Risks: Concluding Remarks

Criminals exploit vulnerabilities in capital markets to engage in Money Laundering, Terrorism Financing, and Proliferation Financing, making it imperative for Financial Institutions to implement strong and effective AML/CFT/CPF compliance measures. By understanding financial crime typologies in capital markets, recognising red flags, and adopting best practices as discussed in the blog, Financial Institutions can strengthen their defences against financial crimes.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

Reach Out to Pathik

Mitigating TFS Risk Through Sanction Compliance Program: RACI Edition

Mitigating TFS Risk Through Sanction Compliance Program: RACI Edition

This article provides a detailed walkthrough of the legal framework in Australia governing Targeted Financial Sanctions (TFS)and its compliance, including:
  • Sanctions Regime in Australia
  • The Need for Sanctions Compliance Policy in Tranche 2 Entities to ensure alignment with the guidelines given by the Australian Sanctions Office (ASO), the Australian Sanctions Regulator.
    • Emphasising how the Compliance and Governance Function can leverage the RACI matrix to ensure smooth execution of roles and responsibilities to mitigate terrorism financing and proliferation financing risk
  • Consequences of Non-Compliance with TFS Obligations
  • Types of Sanctions Issued by Australia
  • Challenges encountered while implementing TFS measures and Best Practices to be incorporated for robust TFS Compliance
Including emphasis on processes to have in place for identifying designated persons and entities, assessing potential prohibited activities for TFS risk, and effective compliance measures to be implemented within the Sanctions Compliance Policy.

What are Targeted Financial Sanctions (TFS)?

Meaning of Sanctions:
In order to understand TFS, we first need to understand the meaning and intent behind sanctions. Sanctions are restrictive measures that a country or international organisation takes to respond to serious international concerns. Sanctions are imposed as restrictive measures to influence the behavior of individuals, groups, entities, or countries to compel desired behavior or stance.

Countries impose sanctions when there is an increase in violations of human rights, terrorism, proliferation financing, and other inhuman acts that are detrimental to society. Instead of using armed forces, governments use sanctions as a method to punish wrongdoers or delinquents and compel their compliance with government foreign policy requirements.

Meaning of Targeted Financial Sanctions (TFS)

TFS restricts the direct or indirect role in making an asset available to a designated person or entity and taking measures to freeze such assets, if in control, to prevent their use by designated persons or entities. In simple words, TFS strictly prohibits the supply of any assets to designated persons or entities. Australia maintains a Consolidated List, known as the Australian Sanctions Office (ASO) Consolidated List, which consists of names of designated individuals and entities subject to Targeted Financial Sanctions. This list includes details such as:
  • Names
  • Aliases
  • Dates of birth
  • Other identifying information.
Reporting Entities must compare names in TFS lists every time they onboard new customers and monitor existing business relationships to ensure compliance with sanctions regulations . Under the Australian Sanctions Regime, engaging in financial transactions with these designated persons or entities is prohibited.

Sanctions Regime in Australia

Australia enforces two primary categories of Sanction laws, which play a significant role in maintaining national security and aligning with international laws. To navigate this sanctions regime effectively, Reporting Entities should ensure that their Sanction Compliance Policies align with the legislative requirements to mitigate any consequences arising from non-compliance.

The two categories of Sanction laws enforced in Australia are given below:

United Nations (UN) Sanctions

These sanctions are imposed by the United Nations Security Council (UNSC). Australia implements these sanctions under the Charter of the United Nations Act, 1945 and its regulations, to which Australia adheres.

Autonomous Sanctions

These sanctions are imposed by the Australian authorities to address specific foreign policy concerns. These sanctions are administered by the Australian Sanctions Office (ASO) and are based on the following laws:
  • Autonomous Sanctions Act 2011
  • Autonomous Sanctions Regulations 2011.

In situations of international concern, Australia and the UNSC are applicable. These Sanctions frameworks are named after the targeted country, group, or thematic issue (e.g., ‘Iran sanctions’) to address specific circumstances and objectives. Sanctions frameworks are regularly updated by Australia to align with the foreign policy goals and international obligations.

Given below is the UNSC and Australian Autonomous Sanctions Framework:

Need for Sanctions Compliance Program in Tranche 2 Entities to Ensure TFS Compliance

In the evolving Sanctions regime landscape, Tranche 2 Reporting Entities such as Lawyers, Real Estate Agents, Accountants, Trust, and Company Service Providers need to align their TFS Compliance obligations with prevailing sanctions compliance requirements. In order to efficiently comply with these regulations and mitigate the risk of violating such sanctions, it is imperative for these Reporting Tranche 2 entities to develop, adopt, and implement a robust and well-crafted Sanction Compliance Program.

Key Elements that should be incorporated in the Sanction Compliance Program (SCP) are discussed below:

Simplifying Compliance and Governance Functions’ Roles and Responsibilities Using a RACI Matrix

Reporting Entities must establish a structured Sanctions Compliance Program (SCP) that sets out clear governance structures by defining roles, responsibilities, procedures, and internal controls to comply with Australian Sanctions laws. However, simply having a policy in place is not enough; the challenge lies in its effective implementation.

A crucial governance tool that helps the Tranche II entities to delineate the duties of their governance functions effectively is the incorporation of a RACI (Responsible, Accountable, Consulted, Informed) chart, also known as the Sanctions RACI matrix, into the Sanctions Compliance Program. It helps with a clear visual understanding of which employee in the organisation is responsible, accountable, consulted, or informed in the context of specific TFS compliance-related tasks, for instance:

What is a Sanctions RACI Chart

  • Responsible – Task Execution: For instance, the Screening Analyst is “Responsible” for carrying out the execution of the Sanctions Screening obligation.
  • Accountable – Define Outcome Ownership refers to building from the above example, the AML Compliance Officer is “Accountable” for the outcome generated during the screening exercise, and needs to decide further action, depending on the screening outcome.
  • Consulted – Input Provision refers to seeking relevant inputs, if any, from colleagues who are responsible for associated tasks, such as in the instance of screening, the Screening Analyst may be required to consult with the KYC Analyst to obtain key identifier details of the customer which need to be entered into Screening Software to carry out screening obligation.
  • Informed – Keep in the Loop refers to keeping relevant parties informed about the tasks in question.

Why is the Sanctions RACI Matrix Important for Sanctions Compliance?

The Sanctions RACI model clearly assigns who will perform tasks, who oversees them, and who needs to be consulted or informed, ensuring seamless operational execution of TFS compliance. This Matrix is helpful for Reporting Entities because it:
  • Clearly defines the responsibilities of Sanctions Compliance in an organisation.
  • Avoids duplication and gaps by assigning specific roles in sanctions-related workflows.
  • Enhances cross-functional coordination between various designated personnel of compliance, legal, and operations teams.
  • Supports audit readiness by providing a structured governance framework with accountability for sanctions compliance.

Suggestive Sanctions RACI Matrix Illustration

Given below is the Sanctions RACI chart mapping key sanctions compliance tasks to the internal governance function within a Tranche 2 Reporting Entity:

Mapping TFS Governance in Tranche 2 Entities Through RACI Matrix:

1. Understanding the Sanctions Regime
Sanctions are official measures imposed by governments or international bodies to achieve specific foreign policy or national security objectives. These measures can include restrictions on trade, financial transactions, or other economic activities with designated individuals, entities, or countries.

Boards and Senior Management of a Reporting entity should develop a written AML/CTF program by understanding the applicable sanction regime. Therefore, it becomes crucial for them to understand:

  • When to apply sanctions
  • Why are sanctions imposed
  • Who is responsible for Sanction Compliance
  • How to implement and monitor compliance procedures

2. Conducting Sanctions Risk Assessments
Risk plays a key factor in ensuring sanctions compliance. By gaining a clear understanding of the risks that an organization encounters at the overall operational level, it becomes possible for a Tranche 2 entities to create a more effective Sanctions Compliance Program.
The Boards and Senior Management of the Reporting Entities are responsible for conducting a comprehensive Risk Assessment to continuously assess their exposure to sanctions risks in terms of:

  • Nature of products and services offered
  • Customer and supplier base
  • Geographic regions of operation, etc.
By evaluating these elements, Reporting Entities can draft their SCP to address their unique risk profiles effectively.

3. Implementing Sanction Screening Software
Compliance Officer of Reporting Entities should implement robust Sanctions Screening Software for automating the process of checking transactions and counterparties against the sanctions list.

Such software should be finalized based on the Sanction Compliance framework and Risk Assessment of the Reporting Entity so that the software should be capable of integrating seamlessly with the existing system.

Regular updates and maintenance are necessary to ensure that the software remains effective with the update in the Sanction list.

4. Screening Transactions & Parties

Screening Analyst, in consultation with the compliance team, has the responsibility to systematically screen all customers, transactions, and third-party service providers against the following lists to detect any prohibited dealings against:

  • UN Sanctions list, and
  • Australian Autonomous Sanction list.
This process should be risk-based, focusing more resources on high-risk areas, such as transactions involving high-risk jurisdictions or sectors.

5. Analysing Sanctions Matches
When a potential match is identified during screening, it is essential for the Screening Analyst to analyse and disambiguate it thoroughly to determine if it is a:

  • Full Match
  • Partial Match
  • No Match
  • False Match.

6. Reporting Suspicious Matters to AUSTRAC
Reporting Entities should engage in conducting the Screening comprehensively against the Consolidated list and the UN list, and if they find any suspicion, then the Compliance Officer of the organization has the responsibility of filing a Suspicious Matter Report (SMR) to the AUSTRAC CEO within a reasonable time. At the same time, the Compliance Officer must ensure that customer-facing personnel, such as the frontline staff or other staff members, do not tip off the existing or potential customer regarding SMR in their name, if any. This can be achieved by ensuring that the information sharing in the context of suspicious matters is restricted and limited to relevant employees only.

7. Updating Sanctions Compliance Policies and Procedures
Sanctions regulations are dynamic, which undergo frequent updates and changes. Boards and Senior Management of the Reporting Entities should regularly review and update their internal policies and procedures to reflect the current legal landscape.
This may include several activities such as:

  • Revising compliance manuals
  • Updating training materials
  • Updating operational protocols to incorporate new sanctions regimes, etc.

8. Providing Role-Specific Training and Awareness Programs
The Compliance Officer has the responsibility to implement the internal policies and procedures effectively and regularly comply with the AML/CFT framework, and to do this, there needs to be an effective training and awareness program. The Reporting Entities should provide ongoing training to their employees regarding sanction compliance requirements. Training programs should be tailored to distinct roles within the organisation, ensuring that all staff understand their responsibilities and the importance of the Sanction Compliance Program as well as the risk of sanctions contraventions.

9. Ongoing Monitoring AML Compliance Officers of Reporting Entities should conduct day-to-day monitoring and periodic reviews to assess the effective implementation of the Sanctions Compliance Program (SCP). Ongoing monitoring may include activities such as:
  • Reviewing screening processes
  • Evaluating the handling of potential matches
  • Ensuring that policies are being followed correctly
  • Addressing weaknesses in the compliance framework
  • Identifying areas of improvement, etc.

10. Maintaining Records
The Compliance Officer of a Reporting Entity has a responsibility to ensure that the entity is complying with the AML/CTF Act and Rules. Therefore, in order to comply with such statutory obligation, the Compliance Officer should maintain detailed records of all the measures taken during the Sanction Compliance Policy to demonstrate diligence and readiness for audits and regulatory reviews. It is the obligation of the Reporting Entities to retain records of designated services and related customers for 7 years.

Benefits of the Sanctions RACI model in Sanctions Compliance and Governance

The Sanctions RACI model enhances Sanctions Compliance and Governance by clearly defining roles and responsibilities for critical tasks like screening, analysing, and reporting, and thereby reducing the ambiguity and duplication of efforts. It ensures that the compliance team of an organisation know who is Responsible, Accountable, to be consulted, and kept informed at each stage of the sanctions compliance process. This structured matrix improves coordination, streamlines decision-making, and strengthens regulatory adherence to the AML/CTF framework.

Identification of Applicable Sanction Regime

As an initial step in drafting an effective Sanction Compliance Policy (SCP) under the AML/CTF Program, Reporting Entities must make themselves aware of the relevant sanctions regime that their business needs to adhere to.
  • If sanctions requirements apply to the extent of imposing restrictions on trade or commercial activities, Reporting Entities should ensure that their Sanctions Compliance Policy includes a provision and procedure for conducting due diligence when such goods or services are offered to customers.
  • When Targeted Financial Sanctions are applicable to Reporting Entities, they need to have in place Sanctions Compliance Policies and Procedures which accurately provide for the identification of sanctioned individuals and entities. Such categories of persons or organisations designated under TFS may include Politically Exposed Persons (PEPs), entities linked to terrorism, or those acting on behalf of sanctioned countries.

Subscription to Relevant Regulators for Updates

Keeping up to date with the regulatory requirements is crucial for ensuring effective TFS compliance. Tranche 2 Reporting Entities should actively monitor the updates in Australia’s Sanctions framework by subscribing to the DFAT’s Mailing List.
  • Reporting Entities should subscribe to DFAT’s Mailing List to get timely updates on the following:
    • Changes to Australian sanctions laws
    • Revisions to existing regulations
    • Additions or removals from the Consolidated List of sanctioned individuals and entities.
  • If the proposed activity of the Reporting Entity is subject to sanctions and meets the criteria for a permit, then the Reporting Entity must register and apply through the PAX Portal.

Sanctions Screening

  • Reporting Entities should choose the appropriate Automated Screening Tool (AST) in their AML/CTF Compliance Program by integrating it into their internal due diligence process to screen persons, entities, and assets.
  • Reporting Entities should ensure real time checking against the Consolidated List as maintained by ASO. The Screening Process should be dynamic and updated regularly to capture new listings or delisting.

Performing Sanctions Due Diligence

To ensure compliance with the TFS measures and minimize the sanctions risk of their organization, Tranche two entities should incorporate some due diligence measures to comply efficiently with the Sanctions Compliance Policy. Due Diligence is a critical element in assessing the risk of engaging in prohibited activities and in identifying designated persons or entities.

1. Conducting Independent Checks

Reporting Entities should conduct independent checks on all persons or entities involved in the proposed activity. If a Reporting Entity is dealing with a company, it should understand its corporate structure. It should also look out for any indirect connections to designated persons or entities on Australia’s sanctions list.

2. Assessing the purpose and end use of Goods and services

Reporting Entities should ensure who will use the goods and services and what they will be used for. Reporting Entities should search the Australian Department of Foreign Affairs and Trade (DFAT) Consolidated List to verify whether any person or entity with which the Reporting Entity is dealing is subject to targeted financial sanctions.

3. Understanding Complex Business Structure & Beneficial Owners

When dealing with companies or any legal structures, Reporting Entities should assess the ownership and control of that organisation to identify the Ultimate Beneficial Owner (UBO), Director, Authorised Signatory, etc. that may be linked to sanctions target.

4. Performing Sanction Risk Assessment (SRA)

Reporting Entities should conduct a structured Sanctions Risk Assessment (SRA) in identifying and assessing whether the proposed activity is prohibited under TFS Compliance Regime. SRA forms a core component of an effective Sanction Compliance Policy.

A. Identifying Prohibited Activities

To ensure compliance with Targeted Financial Sanctions (TFS), obligated entities must adhere to strict prohibitions regarding interactions with the designated persons or entities. Following are the activities that are prohibited under TFS:

  • Provision of Assets: Reporting Entities are prohibited to provide assets directly or indirectly to, or for the benefit of, designated persons or entities.
  • Use of Controlled Assets: Asset holders must not use, deal with, or facilitate the use of assets owned or controlled by designated persons or entities. Such assets are considered ‘frozen’ by the ASO and cannot be accessed or utilized in any manner by the Reporting Entities.
Reporting Entities must ensure that their Sanctions Compliance Policy include a clearly defined assessment procedure for evaluating whether a proposed activity is prohibited under TFS. The Reporting Entity should examine:
  • Whether the proposed activity involves any direct or indirect provision of assets to a designated person or entity, or whether it benefits them in any way. If so, the activity may constitute a breach of TFS obligation and must be flagged for further review or reported to AUSTRAC CEO.
  • Whether the activity involves the use of or dealings with any assets that is owned or controlled by a designated person or entity. If so, the activity will be prohibited under TFS.
If neither of the elements is present, the proposed activity will fall outside the purview of prohibited activities and Reporting Entities can continue with the business relationship.

SCP Training & Internal Awareness

As part of their obligation to comply with the Sanctions Compliance Policy, Reporting Entities should prioritize staff training and internal awareness. Tranche 2 entities should implement regular training programs to help their employees:
  • Building awareness on the Australian Sanctions framework
  • Identifying restricted persons/assets
  • Knowing actions to take when a designated entity or asset is flagged
  • Acknowledging their responsibility to contact ASO in case of uncertainty.

Review of Sanctions Compliance Measures

To ensure continued compliance with the SCP:
  • Reporting Entities should perform periodic sanctions health checks
  • Reporting Entities should implement timely remediation measures based on the findings from the evaluations
  • Reporting Entities should identify compliance gaps and take corrective actions to make improvements in their current policies and framework.

Control Framework for TFS Compliance

To ensure that Tranche 2 entities remain compliant with the Sanctions laws, it is essential to understand the specific Sanction measures. Key Sanction measures often include:
  • Freezing of assets: Sanctions may require Reporting Entities to block access to funds, bank accounts and freezing of physical or digital assets owned by the blacklisted individuals or entities.
  • Travel Bans: Travel restriction prevents designated individuals from entering or passing through Australia.
  • Trade Restriction: These measures include banning the sale or purchase of specific goods or services between the countries.
  • Business Limitations: Stopping companies from investing, buying shares, forming joint ventures, or transferring intellectual property with the targeted party.
These measures can be used for different purposes. Sometimes it may be used to prevent a harmful situation from continuing. In some cases, the measures can also be used as a tool to control damage caused by any crisis.

Consequences of Non-Adherence to Sanctions Compliance Requirements

Reporting Entities should establish and maintain a robust SCP to ensure adherence to applicable Sanctions laws. If they do not comply or contravene with the applicable sanctions’ compliance laws, then they may have to face the following penalties:

For Individuals: If the contravening party is an individual, then they will be liable for an imprisonment of up to 10 years or a fine of up to 2500 Penalty Units or three times the value of the transaction (whichever is greater), or both.

For a Body Corporate: If contravention is done by the body corporate, then it will be punishable by a fine of up to 10,000 Penalty Units or three times the value of transaction (whichever is greater).

Note: The term “Penalty Unit” refers to a standard monetary amount used in Australian legislation to calculate fines for various offences. As of 1 July 2024, the value of a penalty unit is set at Australian $330.
From 1 July 2026, the Australian Dollar amount of a Penalty Unit is replaced by the amount calculated using the following formula:

Penalty Unit Value = (Indexation Factor × Previous Penalty Unit Value)

Types of Sanctions in Australia

Sanctions are of distinct types, each designed to address specific issues. Apart from TFS, the following are some of the other types of Sanctions:

Sectoral Sanctions

These sanctions focus on specific sectors of the economy. It does not block everything, but places limits on some financial activities within a sector to slow down growth in those areas.

Comprehensive Sanctions

These sanctions are the most wide-ranging. It prohibits all forms of trade and financial interaction with a targeted nation.

Challenges Faced by Regulated Entities While Complying with TFS Requirements

Ensuring risk-based compliance with TFS may present several challenges for Regulated Entities, including Tranche 2 Entities. To effectively uphold their SCP, Reporting Entities must recognize and address the following challenges:

1. Suppliers and International Branch Offices: Operating across multiple jurisdictions means navigating varying sanctions laws and enforcement practices. This complexity can lead to inconsistencies in compliance efforts across different regions.
2. Reporting and Alert Management: Regulatory bodies and requirements, such as ASO and Australian sanctions laws, often require prompt reporting of matches or suspicious activities. Delays or inaccuracies in reporting can lead to penalties. Sometimes, inaccurate, or incomplete data can result in missed matches or false positives, undermining the effectiveness of the compliance process.
3. Sanctions Evasion Tactics: Sanctioned individuals and entities continuously develop new methods or emerging technologies to circumvent the restrictions; therefore, it becomes a challenging task for the Reporting Entities to have ongoing vigilance and continuous monitoring of the current compliance strategies.
4. Automated Screening Complexities: Automated systems can generate numerous alerts that require manual review, consuming significant resources and potentially delaying legitimate transactions. Implementing automated screening solutions that seamlessly integrate with current IT infrastructure and workflows is often complex and resource intensive for the Reporting Entities.

Best Practices for Regulated Entities to Ensure Robust TFS Compliance

To ensure robust compliance with Targeted Financial Sanctions, Regulated Entities should adopt the following best practices in their SCP to mitigate risks and penalties:

1. Effective Management of Sanction Alerts: Reporting Entities should make sure that relevant personnel are trained to interpret and manage alerts that are generated by the sanctions screening systems.
2. Timely Reporting and application of TFS Measures: Upon identifying a confirmed match, Reporting Entities should promptly apply necessary TFS measures, such as freezing assets and prohibiting transactions.
3. Conducting Sanctions Risk Assessment: Reporting Entities should regularly conduct risk assessments to identify and evaluate potential sanctions risk associated with the organization’s operations.
4. Ongoing Training and Awareness Programs: Reporting Entities should provide ongoing education and training to their employees about sanctions regulations and the organization’s compliance obligations.
5. Implementing Internal Controls to Mitigate Sanctions Risk: Reporting Entities should implement robust policies and procedures to prevent and detect Targeted Financial Sanctions violations in their organization.
6. Establishing Sanctions Compliance Committee: Reporting Entities should establish a Sanctions Compliance Committee to oversee the implementation and effectiveness of the Sanctions Compliance Program in their organisation. This Committee should play a key role in ensuring proper governance and continuous improvement of the compliance framework.

Don’t Leave TFS Compliance to Chance!

Regulated entities, including Tranche 2 Entities, must have a Sanctions Compliance Policy as an integral part of their Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) obligations. Ensuring adherence to TFS not only safeguards the entity from significant legal and financial risks but also strengthens the integrity of Australia’s financial system.

By implementing comprehensive risk assessments, robust internal controls, timely reporting mechanisms, and continuous staff training, Tranche II Entities can confidently navigate the complex sanctions landscape in Australia.

Embedding sanctions compliance that aligns firmly with the AML/CTF framework demonstrates a proactive commitment to regulatory expectations and contributes to global efforts against financial crimes and terrorism financing. Ultimately, a well-structured SCP is essential for sustainable compliance, operational resilience, and maintaining the trust of regulators and stakeholders alike.

About the Author

Jyoti Maheshwari

CAMS, ACA

Jyoti has over 9+ years of hands-on experience in regulatory compliance, policymaking, risk management, technology consultancy, and implementation. She holds vast experience with Anti-Money Laundering rules and regulations and helps companies deploy adequate mitigation measures and comply with legal requirements. Jyoti has been instrumental in optimizing business processes, documenting business requirements, preparing FRD, BRD, and SRS, and implementing IT solutions.

Reach Out to Jyoti

AML/CFT Learning and Development Strategies for DNFBPs

AML/CFT Learning and Development Strategies for DNFBPs

AML/CFT Learning and Development Strategies for DNFBPs

In accordance with AML/CFT laws in UAE, the Designated Non-Financial Businesses and Professions (DNFBPs) are required to have adequate policies, procedures, and controls in place to conduct and impart employee training to ensure AML/CFT Compliance. This goal can be achieved with the help of a well-formulated AML/CFT Learning & Development (L&D) Strategy. Some of its elements are as discussed hereunder:
  1. Analysis of AML/CFT Training Needs
  2. Specification of AML/CFT Learning Objectives
  3. Formulation of AML/CFT Training Module Design
  4. AML/CFT L&D Monitoring & Evaluation
Let us discuss each of the elements in further detail:

Analysis of AML/CFT Training Needs

Identifying Organisational Needs:

Identifying Organisational Needs based on:

  • Size of the DNFBP
  • Sector of the DNFBP
  • ML/FT Risk to which the Business is exposed to
  • Degree, extent, and efficacy levels of AML/CFT Control Measures as defined in the Enterprise-Wide Risk Assessment (EWRA)

Mapping Skills at the Functional Level and Defining their AML/CFT L&D Needs:

These functions include but are not limited to the following:
  • Front Office Staff facing clients such as the sales team to identify ML/FT red flags
  • Screening Analyst: In the context of their knowledge and experience regarding:
    • When and how to Screen DNFBP’s customers across Relevant and applicable Sanctions Lists such as UAE Local Terrorist Lists, UNSC Consolidated List, etc.
    • Proficiency with the use of Screening Tools or Software
    • Proficiency with Batch or Bulk Screening and Matches Disambiguation
    • Distinction in individual and corporate screening requirements
  • KYC Analyst: In the context of their knowledge and experience regarding:
    • Customer Document Handling
    • Extracting and Interpreting Useful Information from KYC Documents
    • Questions to be included in the KYC Questionnaire and their implications
    • Entering KYC information into KYC Registers and its maintenance in alignment with UAE’s regulator-specific Record-Keeping requirements such as DIFC, ADGM, VARA, and SCA

AML/CFT Risk Analyst: In the context of their knowledge and experience regarding:

    • Conducting Customer Risk Assessment (CRA)
    • Developing Customer Profile and assigning appropriate Risk Rating/Scoring
    • Risk Rating Matrices Development, Meeting Record-Keeping Requirements, and maintaining Risk Registers
    • Knowledge of Inherent, Residual, Gross/Net Risk in consonance with DNFBPs EWRA

Transaction Monitoring Analyst: In the context of their knowledge and experience regarding:

    • Ability to assist with Scenario Development, Ongoing Monitoring, and Transaction Monitoring
    • Handling Rule Management, Alerts Prioritization, Review & Investigation
    • Case Management and Record-Keeping
    • Implementation and Compliance with Designated Transaction Reporting Requirements such as DPMSR and REAR

AML Compliance Officer (AML CO) or Money Laundering Reporting Officer (MLRO)

    • Preparation and Implementation of DNFBP’s AML/CFT Policies, Procedures, & Controls
    • Proficiency in preparation and filing of AML/CFT Semi-Annual Report
    • Proficiency with Inhouse AML/CFT Compliance Department Management
    • Internal SAR/STR investigation & Regulatory Reporting to UAE FIU through goAML Portal for filing reports such as SAR/STR, FFR, PNMR, HRC, HRCA, and Designated Transaction reports such as REAR (for Real Estate sector) or DPMSR (for Precious Metals and Stones sector)
    • Obtaining Senior Management Approval

Senior Management

    • Proficiency in Reviewing AML/CFT Reports
    • Appointment of AML CO or MLRO
    • Approving and Signing off AML/CFT Policies, Procedures, and Control Measures
    • Understanding High-Risk Customers to approve their onboarding
    • AML/CFP Policies, Procedures, and Controls Update and Remediation

Identifying Individual Performance-Driven Needs:

  • Performance Reviews
  • Developing Performance Metrics to identify proficiency in handling AML/CFT Compliance tasks
by identifying KPIs for relevant functions such as:
    • Screening Analyst
    • KYC Analyst
    • AML/CFT Risk Analyst
    • Transaction Monitoring Analyst
    • AML CO or MLRO
    • Senior Management

Specification of AML/CFT Learning Objectives

Aimed to fulfill the gap between the existing skill level of relevant functions and desired skill, proficiency, and performance output expected from relevant functions to meet organizational goals in achieving AML/CFT compliance excellence through the strengthening by L&D of relevant personnel. This can be achieved by considering factors such as:
  • Outcomes of topical risk assessment and UAE’s National Risk Assessment (NRA)
  • Making the right selection of screening and other automation tools and their compatibility with employee skills
  • Identifying internal and external sources for L&D strategy implementation and formulation of AML/CFT training module design

Formulation of AML/CFT Training Module Design:

Aimed to connect with and impart AML/CFT L&D to relevant functions through organizing and finding the right balance with the following elements to suit DNFBP’s organizational needs:
  • Guest Lectures/ Workshops
  • Experiential Activities such as Case Studies, Scenario Building, Role Playing in Situational Simulations
  • Job Shadowing for lateral as well as linear knowledge transfer for improved decision-making across different AML/CFT compliance roles
  • Mentoring by the second and third lines of defense to their subordinates

AML/CFT L&D Monitoring & Evaluation:

Aimed to evaluate and link AML/CFT L&D Program Learning Outcomes with Personnel Performance Outcomes to ensure that the L&D Program delivers the desired outcome for achieving AML Compliance excellence.

AML/CFT L&D Strategy acts as a tool to feed two birds with one scone!

  • The First Bird is the Regulator, requiring the DNFBP to adhere to AML/CFT Compliance requirements by ensuring adequate AML/CFT training of its employees to avoid noncompliance fines and penalties and
  • The Second Bird is the problem of filling the knowledge and skill gap of employees to meet organizational AML/CFT compliance goals.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

Reach Out to Pathik