International Financial Services Centres Authority (Anti Money Laundering, Counter-Terrorist Financing and Know Your Customer) Guidelines, 2022
X X X X Extracts X X X X
X X X X Extracts X X X X
....n and reporting of Suspicious Transactions 68-74 11. Chapter-XI Compliance obligations under International Agreements and domestic laws 75-79 12. Chapter-XII Groups, Branches and Subsidiaries 80-81 13. Annexure- I Guidance on CDD Procedure 82-87 14. Annexure-2 CDD requirements for Indian nationals 88-93 INDEX OF ABBREVIATIONS Sl. No. Abbreviation Full form 1. AML/CFT Anti-Money Laundering/Countering of Terrorist Financing (also used for Combating the financing of terrorism) 2. BF Business facilitator 3. BO Beneficial Owner 4. CDD Customer Due Diligence 5. CKYCR Central Know Your Customer Records Registry 6. CRS Common Reporting Standards 7. ECDD Enhanced Customer Due Diligence 8. FATCA Foreign Account Tax Compliance Act 9. FATF Financial Action Task Force 10. FIU-IND Financial Intelligence Unit- India 11. KYC Know Your Customer 12. IFSCs International Financial Services Centres 13. IFSCA International Financial Services Centres Authority 14. ML/TF Money Laundering/Terrorist Financing 15. NP....
X X X X Extracts X X X X
X X X X Extracts X X X X
...."Control" shall include the right to appoint majority of the directors or to control the management or policy decisions including by virtue of their shareholding or management rights or shareholders agreements or voting agreements; (b) Where the customer is a partnership firm, the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical person, has/have ownership of/entitlement to more than fifteen per cent. of capital or profits of the partnership; (c) Where the customer is an unincorporated association or body of individuals, the beneficial owner is the natural person(s), who, whether acting alone or together, or through one or more juridical person, has/have ownership of or entitlement to more than fifteen per cent. of the property or capital or profits of the unincorporated association or body of individuals; Explanation: The term 'body of individuals' includes societies. Where no natural person is identified under (a) to (c) above, the beneficial owner is the relevant natural person who holds the position of senior managing official. (d) Where the customer is a trust, the identificati....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ayment" means a wire transfer that combines a payment message sent directly by the ordering institution to the beneficiary institution with the routing of the funding instruction (the cover) from the ordering institution to the beneficiary institution through one or more intermediary institutions. 1.3.10. "Cross-border wire transfer" means any wire transfer (including a chain of wire transfers) where either the ordering institution or the beneficiary institution is located in IFSC. 1.3.11. "Customer" or "Client" for the purpose of these Guidelines shall mean a person who is engaged in a financial transaction or activity with a Regulated Entity and includes a person on whose behalf the person engaged in the transaction or activity, is acting. 1.3.12. "Designated Director" means a person designated by the Regulated Entity to ensure overall compliance with the obligations imposed under Chapter IV of the Act, the Rules and these Guidelines. 1.3.13. "Digital KYC" means the capturing live photo of the customer and officially valid document or the proof of possession of Aadhaar, where offline verification cannot be carried out, along with the latitude a....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... or anybody who controls and manages the affairs of such unincorporated association or a body of individuals (consisting of more than one person); (f) In relation to a Regulated Entity established as a branch, a committee constituted at the branch level with the authorization of the Governing Body of the parent entity of the Regulated Entity. 1.3.21. "International Financial Services Centre" shall have the meaning assigned to it under clause (g) of subsection (1) of Section 3 of the IFSCA Act, 2019 (50 of 2019). 1.3.22. "Intermediary Institution" means the financial institution in a serial payment or cover payment chain that receives and transmits a wire transfer on behalf of the ordering institution and the beneficiary institution, or another intermediary institution. 1.3.23. "International Organisation PEP" means a person who is or has been entrusted with prominent function by an international organisation. Explanation: This may include members of Senior Management or individuals who have been entrusted with equivalent functions, i.e., directors, deputy directors and members of the board or equivalent functionaries. An international or....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... documents shall also be deemed to be 'officially valid document': - (a) identity card with applicant's photograph issued by Central/State Government Departments, Statutory/ Regulatory Authorities, Public Sector Undertakings, Scheduled Commercial Banks, and Public Financial Institutions; (b) letter issued by a gazetted officer, with a duly attested photograph of the person. Provided also that, where the simplified measures are applied for verifying the limited purpose of proof of address of the customer, where a prospective customer is unable to produce any proof of address, the following document shall also be deemed to be Officially Valid Document: (i) utility bill which is not more than two months old of any service provider (electricity, telephone, post-paid mobile phone, piped gas, water bill); (ii) property, Municipal tax receipt, city council tax receipt, or such other equivalent document; (iii) Post Office savings bank account statement or statement of a bank account including of a foreign bank; (iv) pension or family Pension Payment Orders (PPOs) issued to retired employees by Government Departments or Public S....
X X X X Extracts X X X X
X X X X Extracts X X X X
....vernment, senior politicians, senior government, judicial or military officials, senior executives of state-owned corporations, important political party officials or International Organisation Politically Exposed Person. Explanation: The definition of Politically Exposed Person is not intended to cover middle ranking or more junior individuals in the definition. 1.3.35. "Regulated Entity" means a unit/entity which has been granted license, recognition, registration or authorisation by the Authority. 1.3.36. "Senior Management" means: (a) In relation to a Regulated Entity, (i) for an incorporated entity in International Financial Services Centre in India, every member of the Regulated Entity's Governing Body; (ii) for a branch, the person or persons who control the day-to-day operations of the Regulated Entity in an IFSC and may include such other persons as may be designated by the Regulated Entity. (b) In relation to a customer, that is a legal person, every member of its Governing Body and the person or persons who control its day-to-day operations. 1.3.37. "Serial Payment" means a direct sequential chain of....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ols, determined by the payment service provider in accordance with the protocols of the payment and settlement system or messaging system used for the wire transfer, which permits the traceability of the wire transfer. 1.3.43. "Video based Customer Identification Process" or "V-CIP" means an alternate method of customer identification with facial recognition and customer due diligence, by an authorised official of the Regulated Entity, by undertaking seamless, secure, live, informed &consent based audio-visual interaction with the customer to obtain identification information required for Customer Due Diligence purpose, and to ascertain the veracity of the information furnished by the customer through independent verification and maintaining audit trail of the process. Explanation: - Such processes complying with prescribed standards and procedures shall be treated on par with face-to-face customer identification procedure for the purpose of these Guidelines. 1.3.44. "Wire Transfer" means any transaction carried out on behalf of a Wire Transfer Originator through a financial institution by electronic means with a view to making an amount of funds availabl....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ty while adopting RBA shall ensure that: (i) The RBA is objective and proportionate to the risks; (ii) The RBA is based on reasonable grounds; and (iii) The RBA is reviewed and updated at appropriate intervals. (b) The RBA shall be appropriate to the nature and size of the business. While implementing the RBA, the Regulated Entity shall consider all relevant risk factors before deciding overall risk. Based on the risk assessment, the Regulated Entity shall monitor, manage, and mitigate the risks it is exposed to by applying effective, appropriate and proportionate measures. (c) In addition to assessing the ML/TF risks presented by an individual customer, a Regulated Entity shall also identify and assess ML/TF risks at an enterprise-wide level, wherever applicable. This shall include a consolidated assessment of the Regulated Entity's ML/TF risks perception that exist across all its business units, product lines and delivery channels. Explanation: FATF Public Statement, the reports and guidance notes on AML/CFT/PF issued by FATF and any country specific information that is circulated by relevant authorities from time to time, as well as the update....
X X X X Extracts X X X X
X X X X Extracts X X X X
....g new delivery mechanisms, channels and partners; and (vi) the use of new or developing technologies for both new and pre-existing products; (c) based on the assessment and risk identification made at Clause (a) and (b) above, the Regulated Entity shall undertake commensurate mitigation measures. 3.2. New products, business practices and technologies (a) A Regulated Entity shall identify and assess the ML and TF risks that may arise in relation to: - (i) the development of new products, business practices, including new delivery mechanisms; and (ii) the use of new or developing technologies for both new and pre-existing products. (b) The Regulated Entity shall undertake the above risk assessment exercise, prior to the launch or use of such products, practices and technologies and shall take appropriate measures to manage and mitigate the risks. Guidance Note: - (1) One of the key reasons for undertaking the exercise of business risk assessment is that it will aid the Regulated Entity to better understand its exposure to ML/TF risks and then take appropriate measures to prevent its business being used for the purposes of....
X X X X Extracts X X X X
X X X X Extracts X X X X
....dentified by it or notified to it by the Authority or other relevant authorities. Further, the Regulated Entity shall constantly monitor the implementation of the policies, procedures and controls, and improve them, if necessary. Guidance Note (1) A Regulated Entity's ML/TF risk assessment serves as a guide to the allocation of AML/CFT resources within it. (2) In the context of Clause (a) (iii) (bb) (2) above, a beneficiary may be a natural person, legal person, legal arrangement, or category of persons who will be paid the policy proceeds when an insured event occurs, that is covered by the policy. CHAPTER-IV CUSTOMER RISK ASSESSMENT Risks identified while assessing the business risks shall be used for the customer risk assessment. The customer risk assessment shall be performed while taking into consideration the parameters, or the process as specified below. The outcome of the Customer risk assessment shall be used to assign the risk rating of the customer as high, medium or low, proportionate to the ML/TF risks. 4.1. Assessing customer AML risks (a) A Regulated Entity shall: (i) undertake a risk-based assessment of every customer; and ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ountry or Geographic risk (i) Whether the countries or jurisdictions the Regulated Entity is exposed to, either through its own activities (including where its branches and subsidiaries operate in) or the activities of its customers (including the Regulated Entity's network of correspondent account relationships) have relatively high levels of corruption, organized crime or inadequate AML/CFT measures, as identified by the FATF; (ii) Whether the countries or jurisdictions are identified by any credible body as having significant levels of corruption, terrorism financing or other criminal activities; (iii) Whether the countries or jurisdictions are identified by credible sources, such as mutual evaluation or detailed assessment reports or published follow-up reports, as not having adequate AML/CFT systems; (iv) Whether the countries or jurisdictions do not have effective systems to counter ML/TF; or not implementing the AML/CFT measures that are consistent with FATF Recommendations; (v) Whether the countries or jurisdictions are subject to sanctions, embargos or similar measures issued by International Organisations or India; (vi....
X X X X Extracts X X X X
X X X X Extracts X X X X
....gistered in a geographical area of low risk; (b) product, service, transaction or delivery channel risk factors, including whether the product or service is: (i) a Contract of Insurance that is non-life insurance; (ii) a Contract of Insurance that is a life insurance product with no investment return or redemption or surrender value; (iii) an insurance policy for a pension scheme that does not provide for an early surrender option and cannot be used as collateral; (iv) a Contract of Insurance which is a reinsurance contract that is ceded by an insurer which is a regulated financial institution; (v) a pension, superannuation or similar scheme that satisfies the following conditions: (aa) the scheme provides retirement benefits to employees; (bb) contributions to the scheme are made by way of deductions from wages; and (cc) the scheme rules do not permit the assignment of a member's interest. (vi) a product where the ML/TF risks are adequately managed by other factors such as transaction limits or transparency of ownership; and (vii) financial products or services that provide appropria....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... customer who has been assigned 'high risk'; and, (iii) undertake Simplified Customer Due Diligence measures as detailed under Clause 5.7 by modifying Customer Due Diligence process detailed under Clause 5.4, in respect of a customer who has been assigned 'low risk'. 5.2. Timing of CDD (a) Except as otherwise provided in Clause 5.3 and 5.4, a Regulated Entity shall undertake the Customer Due Diligence of a customer: - (i) at the time of establishing business relationship, as mandated under Clause 5.4.1 (a) to (c); and, (ii) after establishing a business relationship, as mandated under Clause 5.4.1.(d). (b) A Regulated Entity shall also undertake Customer Due Diligence if, at any time: (i) in relation to an existing customer, it doubts the veracity or adequacy of documents, data or information obtained for the purposes of Customer Due Diligence; (ii) it suspects ML/TF; or, (iii) there is a change in risk-rating of the customer, or it is otherwise warranted by a material change in circumstances of the customer. 5.3. Establishing business relationship before verification (a) A Regulated Entity may e....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... veracity or adequacy of documents, data or information previously obtained, could be where there is a suspicion of ML/TF in relation to that customer, or where there is a material change in the manner the customer's account is operated, which is not consistent with the customer's business profile, or where it appears to the Regulated Entity that a person other than the customer is the real customer. (2) Examples of the types of circumstances where it would be permissible for verification to be completed after the establishment of the business relationship, because it would be essential not to interrupt the normal conduct of business, may include: (i) Non-face-to-face business. (ii) Securities transactions. In the securities market, companies and intermediaries may be required to perform transactions without delay depending upon market conditions, and in such circumstances, the execution of the transaction may be required before verification of identity is completed. Similar circumstances may occur where the customer seeks immediate insurance cover. (3) In case the Regulated Entity is not able to complete customer due diligence as requir....
X X X X Extracts X X X X
X X X X Extracts X X X X
....wing information: (i) Full name, including any aliases; (ii) Unique Identification Number (such as an Identity card number, passport number, etc.); (iii) Date of birth; (iv) Nationality; (v) Legal domicile; (vi) Current residential address; (other than a post office box address); (vii) Contact details such as personal, office or work telephone numbers. (b) If a customer is a legal person or legal arrangement, a Regulated Entity shall obtain at least the following information: (i) The full name and any trading name; (ii) Unique identification Number (i.e., Tax identification number or equivalent where this exists, incorporation number or business registration number); (iii) Registered or business address, and if different, its principal place of business; (iv) Date of establishment, incorporation or registration; (v) Place of incorporation or registration. (c) Further, in cases where the customer is a legal person or legal arrangement, a Regulated Entity shall, also identify the legal form, constitution and powers that regulate and bind the legal person or le....
X X X X Extracts X X X X
X X X X Extracts X X X X
....t. These may include government-issued identity cards or current valid passport, reports from independent company registries, published or audited annual reports and other reliable sources of information. The rigor of the verification process should be commensurate with the customer's risk profile. (c) In verifying the identity of a customer, a Regulated Entity may obtain the following documents: In case of Natural Persons - (i) any of the OVD specified under these Guidelines that contains photograph of the customer, name, unique identification number, date of birth and nationality; and (ii) residential address based on OVD or recent utility bill, bank statement or such other documents specified under the definition of OVD. In case of Legal persons or Legal Arrangements- (i) Name, legal form, proof of existence and constitution: - the verification for the same can be obtained from certificate of incorporation, certificate of good standing, partnership deed/agreement, trust deed, constitutional document, certificate of registration or any other document from a reliable independent source; and (ii) Powers that regulate an....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ion documents and retain a copy of the same. However, in complying with Clause 5.4.1, (i.e., undertaking customer due diligence), at times, if a customer is unable to produce, or it might not be possible for customer to submit original documents for verification (e.g., in situations where Regulated Entity has no physical contact with the customer or the onboarding of customer is done through non-face to face mode), a Regulated Entity should obtain a copy of the document that is certified to be a 'true copy' and such certification may be carried out by person specified in Clause 1.3.7 of these Guidelines. (7) The Regulated Entity shall ensure that documents obtained for performing CDD, as required under these Guidelines, are clear and legible. This is important for the establishment of a customer's identity, particularly in situations where business relations are established through non-face to face mode. (8) Except for high-risk customers, the following mode of verifications are also considered as sufficient to satisfy the requirements of Clause 5.4.3: - (i) downloading publicly available information from an official source (such as a regulator's or other....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ble, independent sources. For the identification and verification of Identity of Beneficial Owner, the Regulated Entity should consider the following in relation to: (a) Customers that are legal persons (i) The identity of the natural person(s) (whether acting alone or together) exercising control over the legal person through ownership or who ultimately owns the legal person; (ii) To the extent that there is doubt as to whether the natural persons who ultimately own the legal person are the beneficial owners or where no natural persons ultimately own the legal person, identify the natural person(s) (if any) who ultimately control the legal person or have ultimate effective control over the legal person. (b) Customers that are legal arrangements (i) Where the customer is a trust, the identification of beneficial owner(s) shall include identification of the author of the trust, the trustee, the beneficiaries with fifteen per cent. or more interest in the trust and any other natural person exercising ultimate effective control over the trust through a chain of control or ownership. (ii) In all other types of legal arrange....
X X X X Extracts X X X X
X X X X Extracts X X X X
....he identity of any shareholder or beneficial owner of a customer in the following - Where the client or the owner of the controlling interest is an entity listed on the stock exchange in India, or it is an entity resident in jurisdictions notified by the Central Government and listed on stock exchanges in such jurisdictions notified by the Central Government, or it is a subsidiary of such listed entities and such other entities who have been excluded from the requirements regarding identifying and verifying beneficial owners of a customer under the Act and Rules. 5.4.8. As per the proviso of rule 9(1)(b) of the Rules, in cases where a customer is subscribing or dealing with depository receipts or equity shares issued or listed in jurisdictions notified by the Central Government, of a company incorporated in India, and it is acting on behalf of a beneficial owner who is resident of such jurisdiction, the determination, identification and verification of such beneficial owner, shall be as per the norms of such jurisdiction and nothing in sub-rules (3) to (9) of the rule 9 of the Rules shall be applicable for due-diligence of such beneficial owner. Guidance ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....p and control structure, before opening an account. 5.4.9. Identifying and verifying beneficiary of a life insurance policy For life or other investment-related insurance business, Regulated Entity shall, in addition to the CDD measures required for the customer and the beneficial owner, conduct the following CDD measures on the beneficiary(ies) of life insurance and other investment related insurance policies, as soon as the beneficiary(ies) are identified/designated: (i) A Regulated Entity shall, as soon as a beneficiary of a life policy is identified as a specifically named natural person, legal person or legal arrangement, obtain the full name, including any aliases, of such beneficiary; (ii) For beneficiary(ies) that are designated by characteristics or by class (e.g., spouse or children at the time that the insured event occurs) or by other means (e.g., under a will) - the Regulated Entity shall obtain sufficient information concerning the beneficiary(ies) to satisfy itself that it will be able to establish the identity of the beneficiary(ies) at the time of the payout. Guidance Note: - (1) For both the cases referred to i....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... customer; (iii) Obtain approval from its Senior Management before opening an account of a PEP or making any payout under the life insurance or other similar policy to the PEP; (iv) In the event of an existing customer or the beneficial owner of an existing account subsequently becoming a PEP, obtain the Senior Management's approval to continue the business relationship; (v) Increase the degree and nature of ongoing monitoring of the business relationship, to determine whether the customer's transactions or activities appear unusual or suspicious. (vi) Carry out the additional Customer Due Diligence for circumstances specified in sub-clauses (i) to (v) above, before making any payout under the life insurance or other similar policy. (c) A Regulated Entity may adopt a risk-based approach in determining whether to perform enhanced CDD measures or the extent of enhanced CDD measures to be performed for:- (i) PEP, their family members and close associates; (ii) International Organisation PEP, their family members, and close associates; or (iii) PEP who have stepped down from their prominent public functions, taking....
X X X X Extracts X X X X
X X X X Extracts X X X X
....m the customer, commercial databases or other open sources. (6) Verification of source of wealth can be carried out by various measures including obtaining independent corroborating evidence such as share certificates, publicly available registers of ownership, information and documents such as evidence of title, copies of trust deeds, bank or brokerage account statements, probate documents, audited accounts and financial statements, salary details, tax returns, news items from a reputable source and other similar evidence. For instance: (i) for a legal person, this might be achieved by obtaining its financial or annual reports published on its website or news articles and press releases that reflect its financial situation or the profitability of its business; and (ii) for a natural person, this might include documentary evidence which corroborates answers given to questions on the source of wealth in an application form or customer questionnaire. For example, if a natural person attributes the source of his wealth to inheritance, he may be asked to provide a copy of the relevant will or grant of probate. In other cases, a natural person may be asked to ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....decided on case-to-case basis. (2) Circumstances where a customer presents or may present a high probability of ML/TF risk may include, but are not limited to the following: (i) where a customer or any beneficial owner of the customer is from or in a country or jurisdiction in relation to which the FATF has called for countermeasures; and (ii) where a customer or any beneficial owner of the customer is from or in a country or jurisdiction known to have inadequate AML/CFT measures, as determined by the Regulated Entity for itself or notified to Regulated Entity generally by the Authority or other relevant domestic authorities in India or other foreign regulatory authorities. (3) For establishing an account-based relationship with high-risk customers, the approval may be given by Senior Management or committee of senior managers or an individual member who has been authorised by the Senior Management in this behalf. (4) In cases where a customer uses complex legal structures and/or trusts, private investment vehicle, the Regulated Entity shall satisfy itself that it is used for a legitimate and genuine purpose. (5) The Regulated E....
X X X X Extracts X X X X
X X X X Extracts X X X X
....D (SCDD) measures shall not be conducted where there is a suspicion of ML/TF. Guidance Note: - (1) Where a Regulated Entity applies SCDD measures, it is still required to perform ongoing monitoring of business relations as specified under Clause 5.8. (2) A Regulated Entity is not required to identify or verify Beneficial Owners for retail investment funds which are widely held and for investment funds where the investor invests via pension contributions. (3) The Regulated Entity may also use other measures to conduct CDD in accordance with the customer risks. 5.8. Ongoing customer due diligence While undertaking the ongoing customer due diligence, as required under Clause 5.4.1.(d), the following requirements shall be complied with by a Regulated Entity: - (i) The Regulated Entity shall monitor its business relations with the customer on an ongoing basis. (ii) The Regulated Entity during the course of business relations with a customer, shall observe the conduct of the customer's account and scrutinize transactions undertaken throughout the course of business relations, to ensure that the transactions are consistent with Regulat....
X X X X Extracts X X X X
X X X X Extracts X X X X
....customer's Officially Valid Documents if these have expired), as part of its periodic CDD review, or upon the occurrence of a trigger event as deemed necessary by the Regulated Entity, whichever is earlier; and (ii) for all other risk categories of customers, a Regulated Entity should obtain updated CDD information upon the occurrence of a trigger event. (3) A Regulated Entity shall undertake a review under sub-clause (v) and (vii) of Clause 5.8, both periodically and at other appropriate times, including when: (i) the Regulated Entity changes its CDD documentation requirements; (ii) an unusual transaction with the customer is expected to take place; (iii) there is a material change in the business relationship with the customer; or (iv) there is a material change in the nature or ownership of the customer. 5.9. Ongoing sanctions screening A Regulated Entity shall review its customers, their business and transactions against United Nations Security Council sanctions lists and also against any other relevant sanctions list when complying with Clause 5.4.1 (d). 5.10. Failure of Regulated Entity to conduct or complete customer d....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... the customer in this regard may be obtained through mobile number registered with the Regulated Entity or through digital channels (such as online banking / internet banking, e-mail or mobile application of Regulated Entity). (ii) Change in address: (aa) In case of a change only in the address details of the customer, a self-declaration of the new address may be obtained from the customer through customer's email-id registered with the Regulated Entity, customer's mobile number registered with the Regulated Entity, digital channels (such as online banking internet banking, e-mail or mobile application of the Regulated Entity). The declared address shall be verified through positive confirmation within two months, by means such as address verification letter, contact point verification, deliverables etc. (bb) Further, a Regulated Entity shall obtain a copy of OVD or the equivalent e-documents thereof for the purpose of proof of address declared by the customer at the time of periodic updation. Such requirement, however, shall be clearly specified by the Regulated Entity in its internal KYC policy, duly approved by its Governing Body. (b) Customer....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ning Body. (v) A Regulated Entity shall adopt a risk-based approach with respect to periodic updation of CDD. Any additional and exceptional measures, which otherwise are not mandated under the above instructions, adopted by the Regulated Entity (such as requirement of obtaining recent photograph, requirement of physical presence of the customer, requirement of periodic updation of CDD only where account is maintained, a more frequent periodicity of CDD updation than the minimum specified periodicity etc.), shall be clearly specified in its approved internal KYC policy. (vi) A Regulated Entity shall ensure that its internal KYC policy and processes on updation / periodic updation of CDD are transparent and adverse actions against the customers should be avoided, unless warranted by specific regulatory requirements. CHAPTER-VI THIRD PARTY RELIANCE 6.1. For the purposes of these Guidelines, "Third Party" shall mean- (a) A financial institution which is subject to and supervised by a financial regulator; or (b) In relation to a Regulated Entity, its branches, subsidiaries, parent entity, the branches and subsidiaries of the parent entity, a....
X X X X Extracts X X X X
X X X X Extracts X X X X
....with the regulations and circulars/guidelines issued by Authority from time to time; and, (i) The Regulated Entity is ultimately responsible for client due diligence and undertaking enhanced due diligence measures, as applicable. Guidance Note: - (1) In a Third-Party reliance scenario, the Third Party will typically have an existing relationship with the customer that is independent of the relationship to be formed by the customer with the relying Regulated Entity. The third party will therefore perform the CDD measures on the customer according to its own AML/CFT policies, procedures and controls. (2) Obtaining records or information of the client due diligence under sub-clause (a) above, means obtaining all relevant CDD information, and not just basic information such as name and address. (3) For the avoidance of doubt, it is clarified that a Regulated Entity is not required automatically to obtain the underlying certified documents used by the third party to undertake its CDD. A Regulated Entity shall, however, under sub-clause (b) above, ensure that the certified documents are readily available from the third party on request. (4) The Regulated Entity sh....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ion; and, (iii) assess the respondent bank's AML/CFT controls and ascertain whether they are adequate and effective, having regard to the AML/CFT measures of the country or jurisdiction in which the respondent bank operates; (b) the responsibilities of each bank with whom correspondent banking relationship is established shall be clearly documented. (c) obtain approval from the Senior Management before providing correspondent banking or similar services to a respondent bank. (d) in the case of payable-through-accounts, the correspondent bank shall be satisfied that the respondent bank has verified the identity of the customers having direct access to the accounts and is undertaking ongoing 'due diligence' on them. (e) The correspondent bank shall ensure that the respondent bank is able to provide the relevant customer identification data immediately on request. (f) Correspondent relationship shall not be entered into with a bank which is a Shell Financial Institution. (g) It shall be ensured that the correspondent banks do not permit their accounts to be used by bank which is a Shell Financial Institution. ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....e entities, where both the originator and the beneficiary are Regulated Entities acting on their own behalf. (2) Clause 7.2. shall apply when a credit, charge, debit or prepaid card is used as a payment system to effect a person-to-person wire transfer. In such a case, the necessary information should be included in the message for such transactions. 7.7. Responsibility of the Ordering Institution 7.7.1. Identification and Recording of Information Before effecting a wire transfer, every bank that is an ordering institution shall: - (a) identify the wire transfer originator and verify his or its identity; and (b) record adequate details of the wire transfer so as to permit its reconstruction, including but not limited to, the date of the wire transfer, the type and amount of currency transferred and the value date. 7.7.2. Cross-Border Wire Transfers Below or Equal To USD 1000 In a cross-border wire transfer where the amount to be transferred is below or equal to USD 1000, every bank which is an ordering institution shall include in the message or payment instruction that accompanies or relates to the wire transf....
X X X X Extracts X X X X
X X X X Extracts X X X X
....er originator's residential or registered or business address or principal place of business (if registered and business addresses are different), as applicable; (bb) the wire transfer originator's unique national identification number (such as an identity card number, birth certificate number or passport number, or where the wire transfer originator is not a natural person, the incorporation number or business registration number); (cc) the date and place of birth, incorporation or registration of the wire transfer originator (as applicable). (b) Include only the wire transfer originator's account number (or unique transaction reference number where no account number exists), provided: - (i) that these details will permit the transaction to be traced back to the wire transfer originator and wire transfer beneficiary; (ii) the ordering institution shall provide the wire transfer originator information set out in Clause 7.7.4. (a) above, within 3 business days of a request for such information by the beneficiary institution, by the Authority or other relevant authorities; and (iii) the ordering institution shall provide the wire ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....IT AND TRAINING 8.1. Internal Policies A Regulated Entity shall develop and implement adequate internal policies, procedures, and controls, taking into consideration its ML/TF risks and the size of business, to help prevent ML/TF, and communicate these to its employees. Guidance Note: As internal policies and procedures serve to guide employees, officers and representatives in ensuring compliance with AML/CFT laws and regulations, it is important that a Regulated Entity updates its policies and procedures in a timely manner, to take into account new operational, legal and regulatory developments and emerging or new ML/TF risks. 8.2. Compliance (a) A Regulated Entity shall develop appropriate compliance management, including appointing or designating a Principal Officer at the management level and shall also develop compliance framework. (b) A Regulated Entity shall ensure that the Principal Officer, as well as any other persons appointed to assist him, is suitably qualified and, has adequate resources and timely access to all customer records and other relevant information which he may require to discharge his functions. (c) A Regulated Ent....
X X X X Extracts X X X X
X X X X Extracts X X X X
....dits. Such audits should be performed not just on individual business functions but also on a Regulated Entity-wide basis. Auditors should assess the effectiveness of measures taken to prevent ML/TF. This would inter-alia include ― (i) Determining the adequacy of the Regulated Entity's AML/CFT policies, procedures and controls, ML/TF risk assessment framework and application of risk-based approach; (ii) Reviewing the content and frequency of AML/CFT training programmes, and the extent of employee's, officer's and representative's compliance with established AML/CFT policies and procedures; and (iii) Assessing whether instances of non-compliance are reported to Senior Management on a timely basis. The frequency and extent of the audit should be commensurate with the ML/TF risks presented and the size and complexity of the Regulated Entity's business. 8.4. Training and awareness The Regulated Entity shall: - (a) provide AML/CFT training to all relevant employees, periodically; (b) ensure that its AML/CFT training enables its employees to: (i) comprehend the applicable laws relating to ML/TF, including the Act and Rules....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... to enable standalone transactions to be reconstructed; and (iii) internal findings and analysis relating to a business transaction or other transactions, where the transaction or business may be unusual or suspicious, whether or not it results in a Suspicious Transactions Report; (c) notifications made under Clause 10.1. (b); (d) Suspicious Transactions Reports and any relevant supporting documents and information, including internal findings and analysis; (e) any relevant communications, if made with the FIU; (f) the documents referred to in Clause 9.4; and (g) any other matter that the Regulated Entity may be expressly required to record and maintain, under these Guidelines. 9.2. The Regulated Entity shall preserve all necessary records, for at least six years or for such period as prescribed under the applicable laws, from the date on which business relationship has ended or transaction is completed. 9.3. The Regulated Entity shall provide to the Authority or any law enforcement agency immediately on request, a copy of a records maintained by it under these Guidelines. 9.4. Risk Assessment Document....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ferred to in Clause 9.1, by the Regulated Entities, the Authority or the law enforcement agencies of India; and (b) where such law exists, obtain without delay, the certified copies of the relevant records and keep such copies in a jurisdiction which allows access by those persons referred in Clause (a) above. 9.7. The Regulated Entities shall be able to convey that they have complied with the training requirements in Chapter VIII through appropriate measures, including the maintenance of relevant training records. CHAPTER-X PROCESS OF IDENTIFICATION OF SUSPICIOUS TRANSACTIONS 10.1. Internal reporting requirements (a) A Regulated Entity shall establish and maintain policies, procedures, systems and controls in order to monitor and detect suspicious transactions with respect to potential ML/TF. (b) A Regulated Entity shall put in place such policies, procedures, systems and controls which ensure that whenever any of its employee, acting in the ordinary course of his employment, either: (i) knows; (ii) suspects; or (iii) has reasonable grounds for knowing or suspecting; that a person is engaged in or att....
X X X X Extracts X X X X
X X X X Extracts X X X X
....determine whether there is a reasonable explanation for that observed indicator. (ii) The Regulated Entity shall ensure that when asking such questions, they do not "tip-off" the customer. Instead, questions could be asked using a service approach. (c) Review Customer's Records The next step is to determine whether the suspicious indicators identified earlier is justifiable given what is known about the customer. To achieve this, a Regulated Entity shall review its customer's records and consider all information that is already known to it about the customer. This may include: (i) the customer's usual occupation, business or principal activity; (ii) the customer's transaction history; (iii) the customer's risk profile; (iv) the customer's income level; (v) the customers source of income as stated during account opening or initial engagement; (vi) reasons for the transactions as provided by the customer; (vii) the "relationship" of the customer with the sender or beneficiary of funds; (viii) the frequency of transactions; (ix) the size and complexity of the transaction; (x) the i....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... it shall report the attempted transaction to the FIU-IND as a suspicious transaction. REPORTING OF SUSPICIOUS TRANSACTIONS 10.3. Reporting Requirements to Financial Intelligence Unit - India A Regulated Entity shall furnish to the Director, Financial Intelligence Unit-India (FIU-IND), the required information referred to in rule-3 of the Rules and in accordance with the terms of rule-7 thereof. Guidance Note: - 1) The reporting formats and comprehensive reporting format guide prescribed or released by FIU-IND and Report Generation Utility and Report Validation Utility developed to assist Regulated Entities in the preparation of prescribed reports shall be taken note of. The editable electronic utilities to file Suspicious Transaction Reports (STR) which FIU-IND has placed on its website, shall be made use of by Regulated Entities which are yet to install/adopt suitable technological tools for extracting STR from their live transaction data. 2) While furnishing information to the Director, FIU-IND, delay of each day in not reporting a transaction or delay of each day in rectifying a mis-represented transaction beyond the time limit as specified in the Rule shall c....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... disclosure to an officer, employee or agent of the Regulated Entity for any purpose connected to the performance of that person's duties; (ii) disclosure to a lawyer for the purpose of obtaining legal advice on the matter; (iii) disclosure to a supervisory authority (to enable it to carry out its supervisory role); or (iv) disclosure in compliance with the court order. (c) The Regulated Entities and its employees are protected from any civil, criminal or disciplinary action taken against them for reporting a suspicious transaction in good faith. Guidance Note: 1) No Nil reporting needs to be made to FIU-IND in case there are no suspicious/ non - profit organization transactions to be reported. The Regulated Entities shall not put any restrictions on operations in the accounts where an STR has been made. The Regulated Entities and their directors, officers and employees (permanent and temporary) shall be prohibited from disclosing ("tipping off") the fact that a STR or related information is being reported or provided to the FIU-IND. 2) This prohibition on tipping off extends not only to the filing of the STR and/ or related information ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ces/xsl/en/taliban-r.xsl (b) Details of accounts resembling any of the individuals/entities mentioned in the above lists, shall be reported to FIU-IND apart from advising Ministry of Home Affairs as required under UAPA Order bearing file no.14014/01/2019/CFT dated February 2, 2021, issued by the CTCR Division of the Ministry of Home Affairs, Government of India, which is available at https://www.mha.gov.in/sites/default/files/ProcedureImplementationSection51A_30032021.pdf (c) In addition to the above, other UNSC Resolutions circulated by the IFSCA in respect of any other jurisdictions/ entities from time to time, shall also be taken note of for necessary compliances. 11.2. Freezing of Assets under Section 51A of Unlawful Activities (Prevention) Act, 1967 The procedure laid down in the UAPA Order bearing file no.14014/01/2019/CFT dated February 2, 2021, issued by the CTCR Division of the Ministry of Home Affairs, Government of India, shall be strictly followed and compliance with the Order shall be ensured. The list of Nodal Officers for UAPA is available on the website of Ministry of Home Affairs. 11.3. Jurisdictions that do not or insufficiently apply th....
X X X X Extracts X X X X
X X X X Extracts X X X X
....Reporting requirement under Foreign Account Tax Compliance Act (FATCA) and Common Reporting Standards (CRS) Under FATCA and CRS, a Regulated Entity shall adhere to the provisions of Income Tax Rules 114F, 114G and 114H and determine whether it is a Reporting Financial Institution as defined in Income Tax Rule 114F and if so, shall take following steps for complying with the reporting requirements: (a) Register on the related e-filling portal of Income Tax Department as Reporting Financial Institutions at the link: https://incometaxindiaefiling.gov.in/ post login > My Account --> Register as Reporting Financial Institution; (b) Submit online reports by using the digital signature of the 'Designated Director' by either uploading the Form 61B or 'NIL' report, for which, the schema prepared by Central Board of Direct Taxes (CBDT) shall be referred to. Explanation: A Regulated Entity shall refer to the spot reference rates published by Foreign Exchange Dealers' Association of India (FEDAI) on their website at https://fedai.org.in/ for carrying out the due diligence procedure for the purposes of identifying reportable accounts in terms of Rule 114H. ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....d to be verified; and, (iii) the Regulated Entity considers it necessary in order to verify the identity or address of the customer, or to perform enhanced due diligence or to build an appropriate risk profile of the client. Guidance Note Under rule 9A of the Rules, a Regulated Entity is required to submit KYC Records to the Central KYC registry, in case of the Indian nationals. However, this requirement shall not be applicable in case of foreign nationals. CHAPTER-XII GROUPS, BRANCHES AND SUBSIDIARIES 12.1. Obligation to develop and ensure implementation of KYC/AML-CFT standards (a) A Regulated Entity incorporated in an IFSC, shall develop a group policy on AML/CFT to meet the requirements of these Guidelines and extend the same to all of its branches and majority owned subsidiaries. The group policies should include: (i) the development of internal policies, procedures and controls, including appropriate compliance management arrangements, and adequate screening procedures to ensure high standards when hiring employees; (ii) an ongoing employee training programme; and (iii) an independent audit function to test the syste....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... Annexure-I Guidance on CDD Procedure (Refer Clause 5.4.3) Part-I Guidance for identification of the customers For onboarding customers, the Regulated Entity may obtain such information as may be required under these Guidelines, in addition to that is required under the Act and Rules. The Illustrative list of information to be obtained for onboarding customers is provided below: - (1) For Individual (i) Full name, including any aliases; (ii) Unique Identification Number (such as an Identity card number, passport number, etc.); (iii) Date of birth; (iv) Nationality; (v) Legal domicile; (vi) Current residential address; (other than a post office box address); (vii) Contact details such as personal, office or work telephone numbers. (viii) Occupation or profession, name of employer and location of activity; (wherever applicable) (ix) Information regarding the nature of the business to be conducted; (wherever applicable) (x) Information regarding the origin of the funds; and (wherever applicable) (xi) Information regarding the source of wealth or income. (wherever ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....uations where Regulated Entity has no physical contact with the customer, or the onboarding of customer is done through non-face to face mode); a Regulated Entity should obtain a copy of the OVD that is certified to be a 'true copy' and such certification may be carried out by any one of the following: - (i) Authorised official of a bank located in a Financial Action Task Force (FATF) compliant jurisdiction with whom the individual has banking relationship; (ii) Notary Public (outside India); (iii) Court Magistrate (outside India); (iv) Judge (outside India); (v) Certified public or professional accountant (outside India); (vi) Lawyer (outside India); (vii) The Embassy/Consulate General of the country of which the non-resident individual is a citizen; or (viii) any other authority as may be specified by the Authority. (5) The person certifying the OVD should be contactable. (6) Where certification of an OVD is done by the authorised officer of the Regulated Entity, such certified copy should be dated, signed and marked with 'original sighted/verified'. (7) Where the simplified measures are applied for ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... (c) PAN or equivalent document prevalent in the home jurisdiction of the partnership firm; (d) Such OVDs as are required for verification of the identity of the beneficial owners, managers, officers or employees, or power of attorney holders, as the case may, who are authorised to transact on behalf of the partnership firm; (e) Such other documents as may be required by the Regulated Entities to collectively establish the existence of such partnership firm. (iii) In case of Trust (a) Registration certificate; (b) Trust deed; (c) PAN or equivalent document prevalent in the home jurisdiction of the trust; (d) Such OVDs as are required for verification of the identity of the beneficial owners, managers, officers or employees, or power of attorney holders, as the case may, who are authorised to transact on behalf of the Trust. (iv) In case of Unincorporated Associations/ Bodies (a) Resolution of the managing body of such association/body; (b) PAN or equivalent prevalent document in the home jurisdiction; (c) Power of attorney granted to transact on its behalf; (d) Such OVDs a....
X X X X Extracts X X X X
X X X X Extracts X X X X
....tomers which are non-natural persons. (b) Updation/Periodic updation of KYC for eligible customers. 1.2. Regulated Entities opting to undertake V-CIP, shall adhere to the following minimum standards: 1.2.1.V-CIP Infrastructure (i) A Regulated Entity shall comply with the minimum baseline cyber security and resilience framework as may be specified, as updated from time to time as well as other general guidelines on IT risks. The technology infrastructure should be housed in own premises of the Regulated Entity and the V-CIP connection and interaction shall necessarily originate from its own secured network domain. Any technology related outsourcing for the process should be compliant with the standards as may be specified. (ii) A Regulated Entity shall ensure end-to-end encryption of data between customer device and the hosting point of the V-CIP application, as per appropriate encryption standards. The customer consent should be recorded in an auditable and alteration proof manner. (iii) The V-CIP infrastructure / application should be capable of preventing connection from IP addresses outside India or from spoofed IP addresses. ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....resh session initiated. (iii) The sequence and/or type of questions, including those indicating the liveness of the interaction during video interactions shall be varied in order to establish that the interactions are real-time and not pre-recorded. (iv) Any prompting, observed at the end of customer shall lead to rejection of the account opening process. (v) The fact of the V-CIP customer being an existing or new customer, or if it relates to a case rejected earlier or if the name appearing in some negative list should be factored in at appropriate stage of workflow. (vi) The authorised official of the Regulated Entity performing the V-CIP shall record audio-video as well as capture photograph of the customer present for identification and obtain the identification information using any one of the following: (a) Offline Verification of Aadhaar for identification; (b) KYC records downloaded from CKYCR using the KYC identifier provided by the customer; (c) Equivalent e-document of Officially Valid Documents (OVDs) including documents issued through Digilocker. (vii) A Regulated Entity shall ensure to redact or b....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ngs of V-CIP shall be stored in a system / systems located in the territory of India. The Regulated Entities shall ensure that the video recording is stored in a safe and secure manner and bears the date and time stamp that affords easy historical data search. The extant instructions on record management, as stipulated in these Guidelines, shall also be applicable for VCIP. (b) The activity log along with the credentials of the authorised person of the Regulated Entity performing the V-CIP shall be preserved. PART-B DIGITAL KYC PROCESS FOR INDIAN NATIONALS 2.1. For undertaking CDD of Indian nationals, the Regulated Entities shall obtain the following from an individual while establishing an account-based relationship or while dealing with the individual who is a beneficial owner, authorised signatory or the power of attorney holder related to any legal entity: (a) the Aadhaar number where: - (i) the customer decides to submit his Aadhaar number voluntarily to a bank or any Regulated Entity notified under first proviso to sub-section (1) of section 11A of the Act; or (aa) the proof of possession of Aadhaar number where offline verificatio....
TaxTMI