EBA欧洲银行-Joint-Guidelines-to-prevent-terrorist-financing-and-money-laundering-in-electronic-fund-transfers-28JC-GL-2017-1629_40页_613kb
报告摘要
Summary of Joint Guidelines under Article 25 of Regulation (EU) 2015/847
1. Core Content
These Joint Guidelines are issued by the European Supervisory Authorities (ESAs) under Article 25 of Regulation (EU) 2015/847, which entered into force on 26 June 2015. The Regulation aims to align European legislation with FATF Recommendation 16 (2012), focusing on the detection of missing or incomplete information in fund transfers and the procedures to manage such transfers to prevent abuse for money laundering (ML) and terrorist financing (TF) purposes.
The guidelines are intended to promote a common understanding among payment service providers (PSPs) and competent authorities across the EU on how to effectively detect and manage transfers lacking required information. They also support the implementation of restrictive measures and ensure that relevant authorities have prompt access to information.
2. Main Objectives
- To help PSPs and IPSPs identify and manage transfers of funds with missing or incomplete information on the payer or payee.
- To enable competent authorities to assess the adequacy and effectiveness of PSPs' and IPSPs' procedures.
- To ensure consistent application of EU law across member states.
- To support the AML/CFT regime by making it more difficult to abuse fund transfers for illicit purposes.
3. Key Requirements for PSPs and IPSPs
3.1 Determining the Role in a Transfer
PSPs must determine whether they act as the PSP of the payer, PSP of the payee, or intermediary PSP (IPSP). This determines the information obligations and the procedures they must follow.
3.2 Monitoring and Detection Procedures
- Real-time monitoring must be applied before the funds are credited to the payee's account, or before they are made available to the payee if they do not have an account.
- Ex-post monitoring is used after the funds have been credited or made available.
- PSPs and IPSPs must implement effective procedures to detect missing information or inadmissible characters.
3.3 Handling of Missing or Incomplete Information
- Meaningless information (e.g., random characters, nonsensical designations) should be treated as missing information.
- High-risk indicators should trigger alerts, including:
- Transfers exceeding a value threshold.
- Transfers involving PSPs or IPSPs from high-risk countries.
- Transfers from PSPs or IPSPs with a negative AML/CFT compliance record.
- Transfers where the payer or payee name is missing.
3.4 Actions on Transfers with Issues
- Rejection: If a transfer is rejected, the PSP or IPSP should notify the prior PSP and state the reason for rejection.
- Suspension: If a transfer is suspended, the PSP or IPSP must notify the prior PSP and request missing information or admissible characters within a reasonable timeframe (typically 3 working days for EEA transfers, 5 days for non-EEA transfers).
- Execution: If a transfer is executed, the PSP or IPSP must request missing information from the prior PSP and document the reason for execution.
4. Compliance and Implementation
- The guidelines are not exhaustive, and PSPs and IPSPs should consider other relevant factors and measures.
- The guidelines apply to Articles 7, 8, 11, and 12 of Regulation (EU) 2015/847, and similar considerations apply to Articles 9 and 13.
- They do not apply to transfers subject to the European sanctions regime (e.g., Regulation (EC) No 2580/2001, (EC) No 881/2002, (EU) No 356/2010).
5. Risk-Based Approach
PSPs and IPSPs must apply a risk-based approach to their procedures. This involves:
- Assessing ML/TF risk based on:
- Type of customers.
- Nature of products and services.
- Jurisdictions served.
- Delivery channels used.
- Complexity of payment chains.
- Transaction volume and value.
- Referring to the Risk Factors Guidelines for assessing ML/TF risk.
- Ensuring that their monitoring and procedures are proportionate to the identified risk levels.
6. Exemptions and Derogations
- Certain transfers may be exempt or derogated from information requirements.
- PSPs and IPSPs must ensure that exemptions are applied correctly, using systems and controls to verify compliance with the conditions for these exemptions.
- If exemptions cannot be applied, full compliance with Regulation (EU) 2015/847 is required.
7. Reporting and Compliance
- Competent authorities must notify the respective ESA of their compliance status within two months of the guidelines' issuance.
- Failure to notify by the deadline is considered non-compliance.
- A notification template is available on the ESAs' websites.
- All relevant staff must be trained and aware of the guidelines and their application.
8. Applicability and Scope
- The guidelines apply to PSPs and IPSPs that handle transfers at least partly by electronic means.
- They do not apply to restrictive measures under EU sanctions laws.
- The ESAs' view is that these guidelines should be incorporated into supervisory practices by competent authorities.
9. Additional Considerations
- PSPs and IPSPs should regularly review their procedures and update them as necessary.
- Ex-post reviews should be conducted on a random sample of all processed transfers.
- High-risk scenarios should always be monitored in real time.
- If the prior PSP does not provide the missing information, the PSP or IPSP should consider internal high-risk monitoring and future treatment of the prior PSP for AML/CFT compliance.
试读结束,高清完整版pdf/doc/ppt,请点下载