A functioning AML framework can be viewed as several connected layers.
1. Client Identification
The first layer establishes who the business is dealing with.
Depending on the client and activity, this can include identity verification, corporate information, beneficial ownership, business activity, authorised representatives and other information needed to understand who controls or benefits from the relationship.
This information creates the baseline against which future activity can be assessed.
2. Risk Assessment
The next layer evaluates the level and type of risk associated with the relationship.
FINTRAC's risk-based framework requires businesses to consider factors such as clients and business relationships, products and services, delivery channels and geographic exposure.
In practical terms, the business needs to understand what activity can reasonably be expected for different client groups and where additional controls may be required.
A domestic payment business, an international remittance provider and a virtual currency platform may all operate as MSBs while requiring different risk models.
3. Transaction Monitoring
Once activity begins, transactions need to be evaluated in the context of what is already known about the client.
Monitoring may consider:
- transaction amount and frequency;
- countries and payment corridors involved;
- counterparties and beneficiaries;
- changes in transaction behaviour;
- funding patterns;
- unusual transaction structures;
- activity inconsistent with the expected purpose of the relationship.
The purpose of monitoring is to identify activity that may require additional attention and provide enough context for further review.
4. Review and Escalation
Unusual activity does not automatically mean suspicious activity. A monitoring system therefore needs a decision layer where alerts can be reviewed, additional information considered and conclusions documented.
A Suspicious Transaction Report must be submitted when there are reasonable grounds to suspect that a completed or attempted transaction is related to money laundering or terrorist activity financing. There is no monetary threshold for this assessment.
This makes documentation important. The business should be able to explain what was reviewed, how the activity was assessed and why a particular decision was reached.
5. Reporting and Record Keeping
Depending on the activity, MSBs may have reporting obligations related to suspicious activity, large transactions and certain transfers of funds or virtual currency. They must also maintain prescribed client and transaction records.