The EU regulators are consulting on draft regulations specifying how credit and financial institutions should manage money laundering and terrorist financing risks where a third country's law prevents the implementation in their group-wide policies and procedures
The European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA) and European Securities and Markets Authority (ESMA) have published draft regulatory technical standards (RTS) in a bid to foster a common approach to anti money laundering (AML) and countering the financing of terrorism in order to create a level playing field across the EU’s financial sector.
Credit and financial institutions have to put in place and maintain AML policies and procedures to assess and manage effectively the money laundering risks to which they are exposed. Where they are part of a group, these AML policies and procedures have to be applied at group-level. This can be challenging where branches or majority-owned subsidiaries are located in a third country, outside of the European Economic Area (EEA), with less stringent AML requirements.
In its analysis of the proposed new rules, the EBA says most third countries' legal systems will not prevent groups from implementing group-wide AML policies and procedures that are stricter than national legislation requires. However, the implementation of a third country's law may at times not permit the application of some or all parts of a group's AML policies and procedures. This can be the case, for example, when the sharing of customer-specific information within the group conflicts with local data protection or banking secrecy requirements and limits a credit or financial institution's ability to understand who their customers are.
The regulator says restrictions on obtaining and processing customer data can also facilitate tax crimes, as highlighted in the context of the ‘Panama Papers'.
In such cases, credit and financial institutions must take effective steps to handle the resultant money laundering risk. These include obtaining consent from customers to overcome restrictions on the ability to share and process customer data, carrying out enhanced reviews to be satisfied that branches and majority-owned subsidiaries in those jurisdictions are able to adequately assess and manage money launderin risk and restricting the ability of other entities in the same group to rely on customer due diligence measures carried out by a branch or majority-owned subsidiary in those jurisdictions.
The consultation runs until 11 July 2017.
Draft Joint Regulatory Technical Standards on the measures credit institutions and financial institutions shall take to mitigate the risk of money laundering and terrorist financing where a third country’s law does not permit the application of group-wide policies and procedures are here.