When businesses complete an AML/CTF Risk Assessment, one of the first areas they need to consider is the products and services they provide.
But simply listing your designated services isn’t enough.
The more important question is:
How could the products and services we provide potentially be misused for money laundering, terrorism financing or proliferation financing?
This is where an AML/CTF Risk Assessment becomes more than a compliance document. It becomes a practical tool for identifying products and services risk, understanding where your business may be vulnerable, and determining what AML/CTF controls you need to put in place.
For Australian businesses subject to the AML/CTF regime, understanding the risks associated with your designated services is an important part of developing an effective, risk-based AML/CTF compliance framework.
Start With Your Designated Services
AUSTRAC requires reporting entities to identify and assess the money laundering, terrorism financing and proliferation financing risks they may reasonably face when providing designated services.
Your AML/CTF Risk Assessment needs to consider the kinds of designated services you provide, including relevant new and emerging technologies.
Importantly, your AML/CTF risk assessment should also consider designated services you plan to provide, particularly where the proposed service could increase your ML/TF risk.
The starting point is therefore relatively simple:
What designated services do we provide, and how could someone misuse them?
Understanding your designated services is essential to identifying products and services risk. Different services can create different vulnerabilities, and those vulnerabilities should be reflected in your AML/CTF Risk Assessment.
How Products and Services Create AML/CTF Risk
There isn’t one standard products and services risk that applies across every industry.
The vulnerabilities associated with a registered club can differ greatly from those associated with real estate, bullion, or professional services.
Your AML/CTF Risk Assessment should therefore reflect the actual products and services your business provides, rather than relying on a generic risk assessment.
Registered Clubs
A club might consider risks associated with areas such as:
- gaming-related transactions
- cash handling
- payouts and movement of funds
- high-value transactions
- transactions that appear inconsistent with normal gaming behaviour
- services or processes that could allow someone to disguise the source of funds
The question isn’t simply whether the club provides gaming services.
The club should consider how those services could potentially be exploited and whether those vulnerabilities create additional money laundering risk or terrorism financing risk.
The findings should then be documented in the club’s AML/CTF Risk Assessment and reflected in its controls.
Real Estate
Real estate presents a different products and services risk profile.
AUSTRAC identifies real estate as an asset type that can be exploited to integrate illegal funds into the legitimate economy and store the proceeds of crime.
A real estate business may therefore need to consider risks associated with:
- the nature and value of the transaction
- movement of significant amounts of money
- ownership structures
- complex arrangements
- circumstances where the true source of funds or wealth may be difficult to establish
These factors should be considered when completing an AML/CTF Risk Assessment and determining appropriate AML/CTF controls.
Bullion and Precious Metals
Again, the products and services risk is different.
AUSTRAC identifies the ability to convert illicit cash into stable, high-value assets as a potential vulnerability associated with buying and selling bullion.
Those assets can potentially be transported, transferred or resold.
This means a bullion dealer needs to understand the characteristics of its products and transactions that could make them attractive to someone attempting to disguise, move or integrate criminal proceeds.
The business should then consider whether its existing AML/CTF controls adequately address the identified risk.
Professional Services
Accountants, lawyers, conveyancers and other professional service providers may face AML/CTF risks when their services involve establishing or managing structures, handling or controlling assets, assisting with transactions, or providing other designated services.
Some legal structures and arrangements can potentially be used to obscure ownership or disguise the source of funds or wealth.
Professional service providers should therefore consider how their specific services could be misused and document those risks as part of their AML/CTF Risk Assessment.
The key point is that your products and services risk assessment must reflect what your business actually does.
How to Identify Products and Services Risk
When completing an AML/CTF Risk Assessment, it is important to look beyond the name of the service and consider the characteristics of the product or service.
For each designated service, ask:
- Does it involve high-value transactions?
- Does it involve significant amounts of cash?
- Can value be moved or transferred quickly?
- Could ownership or the source of funds be difficult to establish?
- Could a customer use a company, trust or other structure to make ownership less transparent?
- Could the service allow someone to convert cash into another asset?
- Are new technologies changing how the service operates?
- Does the service involve customers, transactions or jurisdictions that may increase ML/TF risk?
These questions can help a business identify its products and services risk and determine whether additional controls are required.
AUSTRAC specifically identifies high-value transactions and structures or arrangements that can assist customers to remain anonymous or disguise the source of wealth or funds as important considerations when identifying ML/TF risks.
Your AML/CTF Risk Assessment should document the relevant vulnerabilities and explain how the business manages those risks.
Using AML/CTF Risk to Determine Your Controls
Once you’ve identified how a product or service could potentially be misused, you can determine what AML/CTF controls are appropriate.
For example, an identified risk might lead your business to introduce or strengthen:
- Customer Due Diligence
- Transaction Monitoring
- Source of Funds and Source of Wealth enquiries
- Enhanced Customer Due Diligence
- Staff Training
- Management Review
- Suspicious Matter Reporting
Not every product or service requires the same level of control.
That’s the purpose of a risk-based approach to AML/CTF compliance.
A higher-risk service may require stronger or more frequent controls, while a lower-risk service may require less intensive measures.
Your AML/CTF Risk Assessment should therefore explain the relationship between the identified risk and the controls implemented by the business.
AUSTRAC’s regulatory expectations emphasise understanding the risks facing your business, documenting those risks and putting appropriate controls in place.
The objective is not to apply identical controls to every customer, service or transaction. The objective is to ensure that your AML/CTF controls are proportionate to the risks identified in your AML/CTF Risk Assessment.
Assessing Risk When Introducing a New Service
Your AML/CTF Risk Assessment shouldn’t be something you prepare once and then forget about.
Before introducing a new designated service, ask:
Could this change our ML/TF risk?
An effective AML/CTF compliance framework should consider both designated services currently provided and designated services the business plans to provide.
Planned designated services that could increase ML/TF risk should be assessed before implementation.
The same thinking should apply when you materially change how an existing service operates.
For example, you might introduce:
- a new transaction method
- a new technology
- a different payment process
- a new type of customer
- a new way of delivering the service
- operations involving another country or jurisdiction
These changes may alter your products and services risk profile.
A good internal process is therefore:
- Proposed Change
- Assess AML/CTF Risk
- Identify Required Controls
- Update AML/CTF Risk Assessment and Program
- Train Relevant Workers
- Implement
- Monitor
This is much stronger than introducing the change first and considering AML/CTF risk afterwards.
A Practical AML/CTF Risk Assessment Example
Imagine a business has assessed one of its designated services as Medium Risk in its AML/CTF Risk Assessment.
The business then changes how the service operates and customers can undertake larger transactions using a new delivery method.
Rather than assuming the previous Medium Risk rating still applies, the business should reassess its products and services risk and ask:
- Has the likelihood of misuse changed?
- Has the potential consequence changed?
- Are our existing AML/CTF controls still appropriate?
- Do we need additional Customer Due Diligence?
- Does transaction monitoring need to change?
- Do staff need additional AML/CTF training?
- Has the change created any new money laundering or terrorism financing risks?
The outcome might still be Medium Risk.
Or it might increase.
The important thing is that the business has considered the change, reassessed the AML/CTF risk, and documented its decision.
This demonstrates how an AML/CTF Risk Assessment should be used as a practical risk management tool rather than simply a compliance document.
How to Document Products and Services Risk
For small and medium businesses, your products and services risk assessment doesn’t need to become unnecessarily complicated.
For each designated service, document:
- Service
- How could it be misused?
- Potential ML/TF risk
- Risk level
- Existing AML/CTF controls
- Additional controls required
- Residual risk
This provides management and the AML/CTF Compliance Officer with a clear picture of why particular controls exist.
It also helps demonstrate how the business identified, assessed and managed its AML/CTF risks.
Most importantly, it connects your AML/CTF Risk Assessment to what happens within the business.
Need Help With Your AML/CTF Risk Assessment?
Understanding your products and services risk is an important part of building an effective AML/CTF compliance framework.
If you’re unsure whether your current AML/CTF Risk Assessment adequately reflects your designated services, changes to your business or emerging ML/TF risks, professional guidance can help.
CHD Partners can assist businesses with AML/CTF Risk Assessments, AML/CTF compliance frameworks and practical risk management.
Contact CHD Partners to discuss how we can support your AML/CTF compliance requirements.
The Key Message
Don’t just ask:
“What designated services do we provide?”
Ask:
“How could someone misuse the products and services we provide?”
Once you understand your products and services risk, it becomes much easier to determine the AML/CTF controls your business needs.
Your AML/CTF Risk Assessment should identify the risks associated with your designated services, consider how those services could be misused, and document the controls used to manage those risks.
When you introduce a new designated service or significantly change an existing service, assess the AML/CTF risk before implementation rather than waiting until the next annual review.
Understand the risk attached to the service before deciding what controls you need.
References
#CHDPartners #CIRT #RTO #WHS #WorkHealthAndSafety #Training #RiskManagement #SecurityAndSafetyCompliance #SME #SmallBusiness #MichaelHuggett #AUSTRAC #AMLCTFAnnualComplianceReports #AMLCTFCompliance #AMLCTF #AntiMoneyLaundering
