• Home
  • About
    • Fintech Family
  • Authorisations
    • CASP (MiCAR)
    • Buying & Selling
    • Payments & Emoney >
      • Support Material
  • Crowdfunding
  • Services
    • Regulatory Licences
    • Interim Solutions
    • Training
  • Brexit
    • Brexit Updates
  • Blogs & Insights
  • News
  • Team
  • Contact
  • Fintech Ireland
  • Client Login
  • Home
  • About
    • Fintech Family
  • Authorisations
    • CASP (MiCAR)
    • Buying & Selling
    • Payments & Emoney >
      • Support Material
  • Crowdfunding
  • Services
    • Regulatory Licences
    • Interim Solutions
    • Training
  • Brexit
    • Brexit Updates
  • Blogs & Insights
  • News
  • Team
  • Contact
  • Fintech Ireland
  • Client Login
CompliReg
  • Home
  • About
    • Fintech Family
  • Authorisations
    • CASP (MiCAR)
    • Buying & Selling
    • Payments & Emoney >
      • Support Material
  • Crowdfunding
  • Services
    • Regulatory Licences
    • Interim Solutions
    • Training
  • Brexit
    • Brexit Updates
  • Blogs & Insights
  • News
  • Team
  • Contact
  • Fintech Ireland
  • Client Login

Blogs & Insights

    Author

    Peter Oakes is an experienced anti-financial crime, fintech and board director professional.

    He has served in senior roles at central banks (Ireland & Saudi Arabia) and financial regulators (UK and Australia).

    Peter is an experienced board director of regulated finserv & fintech firms and advisor to regtech firms.

    Archives

    July 2026
    April 2026
    October 2025
    January 2025
    December 2024
    July 2024
    May 2024
    April 2024
    February 2024
    October 2023
    July 2023
    June 2023
    May 2023
    April 2023
    February 2023
    January 2023
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    December 2021
    November 2021
    September 2021
    July 2021
    June 2021
    May 2021
    April 2021
    February 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    June 2020
    May 2020
    February 2020
    January 2020
    December 2019
    June 2019

    Categories

    All
    ACAMS
    AIB
    AML
    Anti Money Laundering
    Anti-money Laundering
    AUSTRAC
    Authorisation
    Bank Of England
    Bank Of Ireland
    Bank Of Lithuania
    BIS Innovation Hub
    Bitcoin
    Blockchain
    Brexit
    Capital Requirements
    CBDC
    Central Bank Of Ireland
    Chambers And Partners
    Compliance
    Consultation
    COVID-19
    Crypto
    CRYPTOASSETS
    Culture
    Cybercrime
    Cyberfraud
    Cyberrisk
    Cyprus
    Data Protection
    Dear CEO Letter
    Digital Assets
    Digital Currencies
    Digital Euro
    EBA
    EBS
    ECB
    EML
    Emoney
    Enforcement
    Equivalence
    ESMA
    FCA
    Financial Conduct Authority
    Financial Crime
    Finolita Unio
    FinTech
    FintechUK.com
    Fitness & Probity
    FIU Ireland
    FTX
    GDPR
    Individual Accountability
    Insider Dealing
    Insider Trading
    KBC Bank
    Law
    Lithuania
    Map
    MiCA
    MiFID
    Moneycorp
    Money Laundering
    Open Banking
    Payments
    Payments System Regulator
    RegTech
    Risk Management
    Sam Bankman-Freid
    Sandbox
    SARs
    SEAR
    Square
    STRs
    Terrorist Financing
    Tracker Mortgage
    Tracker Mortgages
    VASP
    Virtual Assets
    Westpac
    Wirecard

Back to Blog

Peter Oakes, Founder of Fintech Ireland recognised Leading Fintech Consultant: Chambers & Partners 2021

13/2/2021

 
Picture
CompliReg's Peter Oakes has again being recognised as a leading fintech consultant for 2021 following his listing in 2020. 

Chambers and Partners released its Fintech Rankings for Ireland in January 2021.  Peter is the only individual / boutique professional services firm (CompliReg) to be ranked along side some of Ireland's largest consulting firms.

In research carried out by Chambers and Partners, Peter's clients and fintech industry experts informed the researchers that:
  • Peter is high-profile, he has very strong governance capabilities and is very good for a regulated FinTech company.
  • his area of expertise is in licensed applications with the Central Bank. He can explain what is required in black and white from the regulator but also what is left unsaid.
  • Peter would be my first port of call for any FinTech looking to obtain an e-money licence.
  • Peter's reputation really helps; he's top of the list of local Dublin-based regulatory consultants.

Reach to Peter for assistance and advice via the details on our contact page.

Further reading:
  • See Peter's entry at Chambers & Partners here
  • See Peter's entry alongside larger consulting brands here
  • See details of Peter's 2020 recognition here ​
0 Comments
Read More
Back to Blog

Ireland for Finance Action Plan Published by Minister Fleming

11/2/2021

 
Picture
Ireland's Minister of State for Financial Services, Credit Unions, and Insurance Seán Fleming TD today (Thursday 11th February) launches the Ireland for Finance Action Plan for 2021 following Cabinet approval.

The 2021 Action Plan has four priority areas; Sustainable Finance, Diversity, Regionalisation, and Digital Finance. It contains 16 new measures to build on the resilience shown by the IFS sector over the last year. 

​Read Fintech Ireland's Blog here
0 Comments
Read More
Back to Blog

What does Tesla's and Elon Musk's investments in bitcoin mean for digital assets? (RTE News)

11/2/2021

 
Picture
CompliReg's Peter Oakes talks on the hot topic of #bitcoin and #cryptoassets / #digitalassets for Fintech Ireland with Will Goodbody of RTE - Video and Post here
0 Comments
Read More
Back to Blog

"Dear CEO" Letter on Anti-Money Laundering & Counter Financing of Terrorism (Central Bank of Ireland)

16/12/2020

 
Picture
Central Bank publishes “Dear CEO” letter to Schedule 2 firms on low level of compliance with Anti-Money Laundering and Counter Financing of Terrorism obligations

  • Findings include overall lack of compliance by Schedule 2 Firms with AML/CFT obligations
  • Boards fail to demonstrate responsibility for ensuring the implementation and ongoing oversight of AML/CFT control framework
  • Central Bank will use all means to identify unregistered firms and take appropriate action

The Central Bank has today (16 December 2020) published the outcome of supervisory engagements undertaken in respect of Schedule 2 Firms to assess compliance with their obligations under Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 (CJA 2010).

The "Dear CEO" letter*, outlines the Central Bank’s expectations of firms in relation to Anti-Money Laundering/Counter Financing of Terrorism (AML/CFT) and Financial Sanctions (FS) requirements and details follow-up actions to be taken by CEOs and Boards in response to the findings outlined.

The examination, which comprised of both inspections and review meetings, found an overall lack of compliance across all areas of the AML/CFT control framework. There is also poor understanding of the requirements from Board and senior management levels, including at those firms who outsourced their AML/CFT and FS activities to third parties.

The examination identified a number of failings across Schedule 2 Firms, including:
  1. Board Oversight and Governance - failure to demonstrate Boards had taken responsibility for the implementation and ongoing oversight of AML/CFT and FS in a number of firms. In many instances, AML/CFT and FS was only included on the Board’s agenda following notification from the Central Bank of the upcoming supervisory engagement exercise.
  2. Money Laundering/Terrorist Financing Risk Assessment - lack of ongoing and comprehensive assessment and documentation of ML/TF risks that are specific to each firm’s consumers and business activities. In a number of instances, this was exacerbated by reliance on ‘off the shelf’ risk assessment frameworks.
  3. Anti-Money Laundering/Counter Financing of Terrorism Policies and Procedures - failure to put in place and implement firm-specific AML/CFT and FS policies and procedures, and failure to review and update these on an ongoing basis.

Director of Enforcement & Anti-Money Laundering, Seána Cunningham said: “The Central Bank expects all firms to be alert to the risks that money laundering and criminal financial activities may pose to their customers and business, and the wider integrity of the Irish financial system. This requires CEOs and Boards to have in-depth knowledge and understanding of their Anti-Money Laundering and Counter Financing of Terrorism obligations. It is also essential to have the necessary control framework in place to ensure protection of their business and customers.

“Our supervisory engagements revealed a low level of compliance with the AML/CFT control framework requirements. The culture and tone of any organisation is set from the top. It therefore rests with the Board of these firms to ensure that the necessary AML/CFT governance, risk assessment, policies and procedures, training and awareness are embedded throughout the organisation. While some firms may choose to outsource AML/CFT activities to third party service providers, Boards cannot outsource the responsibility for compliance.

“We will continue to engage directly with those firms where compliance weaknesses and failures have been identified to ensure that they are addressed. We also require all firms to review the content of this letter to ensure that they assess their own compliance with the issues identified.

“We are also taking this opportunity to remind all firms to assess their activities to determine if they are required to register with us under Schedule 2. Firms who fail to register are at risk of significant criminal and/or administrative sanctions. In 2021, the Central Bank will use all means available to identify those firms not registered and take appropriate action.”

ENDS
Notes to Editor
  • The Central Bank of Ireland is the competent authority for monitoring the compliance of credit and financial institutions with Part 4 of the CJA 2010, and with taking measures that are reasonably necessary to secure such compliance. Entities engaged in activities outlined under Schedule 2 of the CJA 2020, herein referred to as ‘Schedule 2 Firms’ have been obliged to comply with Part 4 of the CJA 2010 since its implementation in 2010. On 26 November 2018, Section 108A of the CJA 2010 introduced a statutory requirement for Schedule 2 Firms to register with the Central Bank, where such firms are not otherwise authorised or licensed to carry on business by the Central Bank. Details on the registration process is available on the Central Bank website.
  • The definition of “financial institutions” in the CJA 2010 includes entities that carry out one or more of the activities specified in Schedule 2 of the CJA 2010, hereto referred to as Schedule 2 Firms, Subject to limited exceptions as set out in the definition of “financial institution” in s24, and in s25(4) of the CJA 2010. Firms engaged in such activities are required to register with the Central Bank pursuant to section 108A of the CJA 2010.

Further information
Media Relations: [email protected] / 01 224 6299
Ewan Kelly: [email protected] / 01 224 6269


Read More
Back to Blog

Brexit & Equivalence for Payments and Electronic Money (emoney) - the facts

28/11/2020

 
Picture
Some choice headlines in the papers about Brexit in the past week as we - according to Brexit Ireland's countdown to Brexit clock - just little more than 33 days before 11p.m. (UK time) on Thursday 31st December 2020 when the Brexit transition period ends with no deal on financial services in sight.

This week sees the EU negotiating team returning to London after face-to-face talks came to end more than a week ago after Mr Bariner's team was hit by a case of Covid.  They will be greeted by headiness such as: ​UK dismisses ‘derisory’ EU fishing offer ahead of last-ditch trade talks; 
Europe’s finance sector hits ‘peak uncertainty’ over Brexit; and The City braces for Brexit.
Picture
There is no equivalence regime provided for within either EMD2 (electronic money institutions) or PSD2 (payments services institutions)!
One thing we are still very surprised by is the many in #fintech, #techfin and indeed #finserv (and scarily their advisers) who think that recent news on 'equivalence' deals are applicable to all UK #finserv which passport across the European Union / EEA.

The announcement on Monday 23rd November by the European Commission was simply and specifically about European regulators finalising a late change seeking to avoid chaos in £15tn of derivatives contracts held between UK and EU counterparties. Then on Wednesday 25th, they insisted outposts of EU banks in London would have to trade certain derivatives in the EU.

Back in August 2020 the European Parliament reminded that "Equivalence decisions are a unilateral decision by the Commission. The Commission ultimately exercises its discretion as conferred upon it by the “empowerment” given in EU sectoral legislation.'' BUT MORE IMPORTANTLY "The Commission also enjoys discretion to withdraw equivalence decision. The equivalence frameworks in force do not provide as such specific procedures for monitoring, reviewing or amending equivalence decisions."

There are no equivalence provisions in EU bank, payments nor electronic money directives, and the equivalence provision in MiFiD doesn't apply to retail investment services. See the below table on the 'Role of equivalence in key EU banking and financial services legislation' for confirmation.

The upshot is that if you are a UK authorised payments institution or electronic money intuition, come Thursday 31st December 2020 when your ability to passport across the whole of European Economic Area comes to an end, so too does your business model unless you have obtained an authorisation in an EU/EEA state.  There are are other options available but we'll leave that for another article. 

​If you are a regulated fintech looking for a home post #brexit contact https://complireg.com/authorisations.html.  Read our Fintech Authorisation Guides published jointly by CompliReg and Fintech Ireland on the authorisation process.  And check out the 'Why Ireland for Fintech' brochure.

Why Ireland for your regulated fintech? 
  • tax effectiveness
  • common law legal system
  • similarities to the UK in Irish approach to business
  • access to world leading talent in financial services and technology
  • reputation of the Central Bank / regulator 
  • growing recognition of Ireland as an international fintech hub thanks to the work of the Irish government, its agencies and groups like Fintech Ireland. 
“From January 1st, EU rules will apply to UK firms wishing to operate in the EU. UK firms will lose their financial passport: it’ll be anything but business as usual for them. This means they will have to adhere to individual home-state rules in each and every member state,” the official said.
Picture
Further reading:

​26 November 2020 - Move to EU or face disruption, City of London is warned
  • British financial firms must set up shop in the European Union or expect disruption on January 1st, the European Commission has warned, as it is unlikely to grant the required equivalency permit to ease access to the bloc’s customers by the end of the year.


27 August 2019 - "Third country equivalence in EU banking and financial regulation"
  • This briefing provides an insight into the latest developments on equivalence in EU banking and financial regulation both in terms of governance and decision making (Section 1) and in terms of regulatory and supervisory frameworks that governs the access of third countries firms to the internal market (Section 2). The briefing also gives an overview on the possible role of equivalence regimes in the context of Brexit (Section 3) together with Brexit-related supervisory and regulatory issues (Section 4). This briefing is an updated version of a briefing published in April 2018. 

29 July 2019 - Financial services: Commission sets out its equivalence policy with non-EU countries

​12 July 2017 - "Third-country equivalence in EU banking legislation"
  • This briefing focuses on the concept of equivalence in EU banking legislation and notably on the difference between “passporting” rights and “third-country equivalence” rights. It gives an overview of existing equivalence clauses in some key EU banking and financial legislation and of equivalence decisions adopted by the European Commission to date.
Read More
Back to Blog

Fitness & Probity Thematic Inspections: what the Central Bank thinks about state of compliance (the good, the bad & the ugly)

17/11/2020

 
Picture
Today, 17th November 2020, the Central Bank of Ireland released a Dear CEO Letter on "Thematic Inspections of Compliance by Regulated Financial Service Providers with their Obligations under the Fitness and Probity Regime".  Readers are probably aware that the Central Bank issued a previous Dear CEO Letter on 8th April 2019 on "Compliance by Regulated Financial Service Providers with their Obligations under the Fitness and Probity Regime".

If you need assistance with understanding or implementing the requirements, please contact the Team at CompliReg.

  • 17th November 2020 Dear CEO Letter 
  • 8th April 2019 Dear CEO Letter 


What does the Dear CEO Letter of 17th November 2020 say?

Background:
The Central Bank undertook thematic onsite inspections across a sample of firms in the insurance and banking sectors [Ed- No reference to MiFID, payments, emoney, intermediaries nor the funds industry] in order to assess the level of compliance with the Fintess and Probity (F&P) requirements.   This was on foot of its Dear CEO Letter on the topic of F&P back in April 2019.  The inspections did not examine the fitness and probity of particular individuals, but rather evaluated the processes in place to manage compliance with the requirements of the F&P Regime.

The inspections focused on the following areas:
  • Awareness and understanding within firms of their compliance obligations;  
  • Initial and ongoing due diligence processes;  
  • Oversight and control where Pre-Approval Controlled Function (“PCF”) roles or
  • Controlled Function (“CF”) roles have been outsourced; 
  • Processes and channels for effective engagement with the Central Bank; and  
  • Role of the Compliance Function with regard to the F&P Regime.

The Central Bank towards the end of the letter reminds that the F&P Regime is a cornerstone of the regulatory framework in Ireland, applying not only to individuals but also firms.  Firms must ensure that any individual who is engaged to carry out a CF role has the requisite fitness and probity to do so. 

The Central Bank’s Dear CEO letter of April 2019 emphasised the importance of compliance by firms and identified areas where compliance was inadequate.  As is noted below and in the November 2020 letter, the Central Bank believes that the range of findings from thematic onsite inspections following the April 2009 letter "indicates that many firms do not have due regard to their obligations under the F&P Regime".  The Central Bank is also concerned by the number of firms which did not take action, following the April 2019 letter, to perform a formal ‘gap analysis’ of their  policies, processes and procedures.  Its position seems clear "[i]t is wholly unacceptable that such shortcomings continue to exist in circumstances where the F&P Regime was introduced almost ten years ago."


What did the Central Bank find?:
In summary, the inspections highlighted a number of common issues and shortcomings, resulting in the release of the Dear CEO letter.  The letter sets out key findings and observations from the inspections together with the expectations of the Central Bank, which it believes need to be brought to the attention of the wider financial services industry.  

Helpfully, the Central Bank also set examples of good practices which had been implemented in a number of firms (see Appendix 1 of the Dear CEO Letter November 2020 and set out below).

A significant number of findings were identified in relation to the role of the Board, the conduct of due diligence and the outsourcing of CF roles.  While not all of the issues outlined in the Dear CEO November 2020 letter arose in each firm inspected, the Central Bank reckons that they are representative of the findings across the sample of firms. 

What are the key points arising from the findings?:
(a) role of the Board in the F&P Process:
  • the level of awareness by Board members of their fitness and probity obligations was poor. 
  • Board appointments were generally not subject to the same level of scrutiny or formality as other PCF/ CF appointments.  There was a notable lack of interview notes and suitability assessments available to support Board appointments, and succession plans generally did not meet expectations and were not used in practice. In a number of cases there was no evidence of Board approval, discussion or challenge of proposed PCF appointments.
  • instances of the CEO screening potential Board candidates is inappropriate given the conflict of interest between the respective responsibilities of directors and the executive. 
  • it is essential that Board members recognise the importance of the F&P framework and their responsibilities within it, not only for the firm, but also for the Board itself.   The Central Bank expects that the same high standards and rigour be observed and applied to board appointments as to those elsewhere within a firm. [Ed- important to review and include the above into the terms of reference for the Board of Directors and - as appropriate - relevant committees, such as Audit, Risk, Compliance, Remuneration, Nomination committees]

(b) Conducting Due Diligence:
  • due diligence was the most consistently weakest area across the majority of firms
  • initial and ongoing due diligence undertaken was not sufficiently robust to evidence compliance with the requirements of the F&P Standards.   
  • there was a lack of evidence of qualifications, reference checks and suitability searches. 
  • shortcomings in ongoing due diligence processes were particularly poor and often limited to an annual self-declaration without any ongoing due diligence screening to check if a change in circumstances had impacted an individual’s F&P. [Ed- Note that shortcoming were also found during the initial due diligence of individuals too]
  • in the context of initial due diligence, the Central Bank reminds of the process of PCF application Individual Questionnaires (“IQs”).  These are ultimately endorsed and submitted to the Central Bank by the firm.  The firm must declare in the IQ that it has carried out all necessary due diligence enquiries. It is at this point the firm should disclose all information relevant and potentially relevant to the Central Bank’s assessment of a proposed appointee’s F&P.  Full and frank disclosure is required.  Adverse information in relation to the candidate should be brought to the attention of the Central Bank and the firm should explain why this does not affect the individual’s suitability for the role proposed.  Where a firm has a doubt as to the materiality of a piece of information in this regard, this should be disclosed and explained.  The Central Bank takes non-disclosure seriously, especially where there  is an apparent attempt to mislead.  This may call into question not only the individual’s suitability but also the firm’s decision to propose the individual in question.
  • as regards ongoing due diligence, firms have ongoing obligations under Section 21 of the 2010 Act to ensure that they do not allow a person to perform a CF role unless they are “satisfied on reasonable grounds” that the person: (i) complies with the applicable standards of F&P; and (ii) has agreed to abide by those standards.  An annual self-declaration by PCF and CF role holders is the minimum expected. Where a firm becomes aware that there may be concerns regarding the fitness and probity of a person performing a CF role, the Central Bank expects the firm to investigate such concerns and take action as appropriate without delay. 

c) Outsourcing of Roles subject to the F&P Regime
 [Ed- the area of outsourcing is important for large, small, complex and non-complex firms alike]
  • where PCF or CF roles are outsourced to unregulated Outsource Service Providers (“OSPs”), the majority of firms had not, as part of their due diligence in appointing CF role holders, obtained the required documentation nor made any inquiries as to the OSP’s process for assessing fitness and probity. In addition, firms did not have a process whereby outsourcing arrangements were analysed to verify whether PCF or CF roles were being performed.  
  • firms’ obligations with respect to fitness and probity apply irrespective of whether the PCF or CF role is performed within the firm or outsourced to an unregulated OSP.  Firms are required to have appropriate processes and procedures to ensure compliance in both scenarios.

d) Engagement with the Central Bank
  • in the majority of firms the processes related to engagement with the Central Bank on fitness and probity issues, including the IQ submission process, have not been adequately developed, documented or embedded. 
  • many firms did not have robust processes in place to identify, escalate  and notify the Central Bank in a timely manner of potential concerns regarding the fitness and probity of a CF or PCF holder.  
  • lack of engagement with the Central Bank is also a reflection of the passive approach taken by firms to their ongoing due diligence requirements.   The Central Bank expects firms to be proactive in identifying fitness and probity issues as part of its ongoing due diligence and in reporting as appropriate to the Central Bank without delay. 

e) Role of the Compliance Function
  • the majority of firms had compliance frameworks, policies and procedures in place.
  • it is clear that many firms are not undertaking robust compliance testing of their fitness and probity processes and procedures. 
  • F&P process should be subject to comprehensive oversight by the Compliance Function and periodic independent review by the Internal Audit Function to ensure it is fit for purpose. [Ed- important to review and include the above into the terms of reference for both the compliance and internal audit functions]
 
Conclusion of the Central Bank:
  • Central Bank expects that all firms take appropriate action to address the significant issues outlined in this letter and be able to evidence same to the Central Bank, where requested. 
  • the November 2020 letter should be read in conjunction with the April 2019 letter, the F&P Standards and the associated fitness and probity guidance.    
  • failure by a firm to comply with its ongoing obligations can result in an investigation under the Central Bank’s Administrative Sanctions Procedure, leading to potential sanctions for firms and individuals.  
  • the Central Bank will continue to engage with firms to assess the robustness of their application of the F&P Regime and will initiate necessary supervisory responses to any weaknesses identified.  [Ed- there is no reference to any firm subject of the thematic F&P inspection will be subject to enforcement]

Appendix 1: Key Findings Identified by the Thematic Inspections

a) Levels of awareness and understanding of the F&P Regime

Role of the Board / Nomination Committee (“NomCo”) in Fitness and Probity Process

1. The level of awareness of fitness and probity obligations was weak throughout many of the firms, with Board awareness of its obligations particularly poor.

2. Board appointment procedures were generally not subject to the same level of scrutiny or formality as other CF and PCF appointments. In most cases, there was a lack of interview notes or suitability assessments available to support Board appointments.

3. In a number of instances there was no evidence of Board approval of the PCF appointment, Board approval of the appointment took place after approval by the Central Bank and/or there was no evidence of discussion or challenge by Board members of the proposed appointment.

4. Instances of the Chief Executive Officer (“CEO”) screening potential Board candidates were noted in a small number of firms. This is inappropriate given the conflict of interests that arise as between the respective responsibilities of directors and the executive.

5. The quality of succession plans for the Board and executive team generally did not meet expectations. Anumber of these succession plans did not set out the skills, competencies and experience required for the various roles and/or how the proposed successor would demonstrate/acquire those. However, some firms had developed their own Board Skills Matrix, which set out the key areas of experience required. This matrix was used to identify gaps in the combined experience of the Board.
 
Functional Responsibility for the F&P Regime

6. Management of the fitness and probity process varied significantly across the firms. Where there were clear, prescribed roles and responsibilities along with appropriate segregation of duties, the due diligence conducted in these firms was of a higher standard than those without clearly articulated and assigned responsibilities.

7. The quality of policies and procedures in relation to fitness and probity varied from firm to firm. Elements of good practice were observed in the form of ‘How To’ guides, establishment of Fitness & Probity Steering Committees, checklists, and clearly documented roles and responsibilities in relation to the fitness and probity process in the firm. However, good practice was not evident in most firms; the majority had disjointed processes that did not clearly outline the roles and responsibilities of the various functions performing fitness and probity related tasks.

Analysis and Mapping of Roles

8. There were instances where no register of employees performing PCF or CF roles was maintained. In addition, the process of regular review of individuals whose role changed, resulting in their coming within the remit of the F&P Regime, was lacking. Good practices identified included a documented requirement to review the job description when a vacancy arises to determine if the role is CF or PCF in nature, and guidelines setting out the key principles and rationale for the general interpretation of the CFs across the firm.

b) Conducting Due Diligence
Initial Due Diligence

9. In the majority of the firms inspected, the initial due diligence undertaken was not sufficiently robust to evidence compliance with the requirements of the F&P Standards. Issues highlighted by the inspections included: a lack of evidence of academic qualifications; lack of references from previous employers; a notable absence of interview notes across the majority of firms inspected; and no evidence of a documented assessment as to the suitability of the candidate.

10. Issues were also identified in a number of instances with a lack of judgement searches, regulatory searches, directorship searches and adverse media searches, including adverse media searches regarding previous employers that could assist with identifying potential fitness and probity concerns to be examined further.

11. Firms assessed as performing better had defined processes in place for conducting initial due diligence, including documented policies and procedures; an understanding of the allocation of responsibilities among the various functions (e.g. Human Resources, Company Secretary and Compliance Function); performed due diligence searches and conducted and retained interview notes.

Ongoing Due Diligence

12. Under Section 21 of the 2010 Act, firms are required to conduct due diligence on an ongoing basis to ensure that employees performing CFs continue to comply with the F&P Standards.

13. All firms had in place a requirement for each PCF and CF role holder to annually certify their compliance with the F&P Standards and their agreement to abide by the F&P Standards. An annual self-declaration by PCF and CF role holders is the minimum expected by the Central Bank.

14. However, the ongoing due diligence process in most firms is limited to the annual self-declaration. Firms should proactively conduct ongoing due diligence screening of staff to ensure there has been no change in circumstance that may affect the fitness or probity of the individual. In one firm they conducted ongoing due diligence searches on an annual basis for all PCF role holders and on a sample basis for CFs.
 
c) Outsourcing of Roles subject to the F&P Regime
15. Where CF roles are outsourced to unregulated OSPs, the majority of firms had not, as part of their due diligence in appointing CF role holders, obtained the required documentation nor made any inquiries as to the OSP’s process for assessing fitness and probity.

16. Firms did not have a process whereby outsourcing arrangements were analysed to verify whether PCF or CF roles were being performed. This gives rise to the risk that relevant individuals at OSPs may not be identified and subjected to the F&P Standards.

17. In addition to obligations under the Central Bank’s F&P Regime, the Solvency II Regulations impose requirements on insurance firms with respect to the outsourcing of critical or important functions. Under these Regulations, firms are obliged to verify that all staff of the service provider who will be involved in providing the outsourced functions or activities are sufficiently qualified and reliable. There was generally a low awareness of Solvency II obligations in this regard and these had not been included in applicable policies and procedures.
 
d) Engagement with the Central Bank
18. Firms did not have clearly defined procedures covering the various stages of the IQ process including initiation, compilation, completion, review, approval and submission of the IQ application. In addition, there was a lack of clarity in relation to what could be regarded as a material fact for inclusion in the IQ.

19. Firms did not have robust processes in place to identify, escalate and notify an appropriate individual or function, within the firm in a timely manner, of potential concerns regarding the fitness and probity of a CF or PCF holder. Additionally, there was a distinct lack of policies or procedures to support these escalations (i.e. investigation of concerns and the taking of timely action as appropriate) or to ensure timely notification of actions taken to the Central Bank.

20. Overall, the processes related to engagement with the Central Bank on fitness and probity issues, including IQ submission process, have not been adequately developed, documented or embedded.

e) Role of the Compliance Function
21. The majority of firms had compliance frameworks, policies and procedures in place. There was a good understanding of fitness and probity obligations by the Compliance Function in a number of the firms inspected. However, in some cases there was an over reliance placed on the Compliance Function, thereby creating potential key person risk.

22. Many firms are not undertaking robust compliance testing of their fitness and probity processes and procedures. The fitness and probity process should be subject to periodic independent review by the third line of defence.



​If you need assistance with understanding or implementing the requirements, please contact the Team at CompliReg.
  • 17th November 2020 Dear CEO Letter 
  • 8th April 2019 Dear CEO Letter 



0 Comments
Read More
Back to Blog

Spain - Collapse of half a billion euro money laundering and seizure case

10/10/2020

 
Picture
Here's one for the #moneylaundering typology case studies for #MLROs as part of regulatory training requirements!
 
Relates to the collapse of major investigation into the Kinahan cartel and more than half a billion euros- particularly €500,000,000 stash of cars, properties & cash handed back to the accused by a Spanish judge after collapse of money laundering case.
 
Can understand that staff and MLROs at financial institutions and other obliged entities which do a lot of the initial legwork in identifying suspicious transactions may feel underwhelmed (to say the least) when a case like this collapses.
 
We should train on all types of cases, regardless if there is a criminal outcome or not. Staff (and boards) need to appreciate that not all suspicious transactions reports will 'result' in a criminal outcome, but that doesn't excuse obliged entities and their staff from complying with the legal requirement to report suspicious transactions. A skill MLROs and trainers need to focus upon is motivating staff, themselves and the senior executive to stay the course.
 
https://www.linkedin.com/posts/peteroakes_moneylaundering-mlros-financialcrime-activity-6719937607700135936-jZUH
 
#antimoneylaundering #financialcrime #mlros #suspicioustransactions #lawenforcement

Check out the linkedin post with link to news article.
​
1 Comment
Read More
Back to Blog

ECB confident it can create a digital euro

4/10/2020

 
Picture

ECB confident it can create a digital euro.

With ECB officials concerned that the Chinese central bank is potentially a couple of years away from launching its own digital renminbi after it conducted large-scale experiments, it has identified several scenarios that would require it to launch a digital euro.

Two scenarios are:
  1. 1) centralised: The ECB will record all digital euro transactions in the central bank’s own ledger.
  2. 2) decentralised: The ECB would set the rules for transactions to be settled and recorded by supervised intermediaries.

Either way, some serious #regtech and #suptech will be required.

Despite a 55-PAGE REPORT, the question is whether the ECB can stay ahead of the rapidly changing world of #digitalcurrencies and #payments.

Central bankers are increasingly interested in the relatively new world of digital currencies, particularly since Facebook announced a plan to launch one called Libra that has the potential to overhaul the way money works. 
 
ECB officials believe the Chinese central bank is potentially a couple of years ‘ away from launching its own digital renminbi after it conducted large-scale experiments. 

In an interesting development, Bloomberg reported on 1 October 2020, that the European Central Bank has applied to trademark the term “digital euro” as officials prepare to release an assessment of the benefits and drawbacks of creating a digital version of the currency.  The application was filed on 22 September by the ECB’s legal representatives Bock Legal, according to the website of the European Union Intellectual Property Office. An ECB spokesman confirmed the filing.

The ECB outlined potential scenarios “that would require the issuance of a digital euro”. These include higher demand for electronic payments that creates a greater need for a “risk-free digital means of payment”, as well as the potential that a cyber attack or pandemic disrupts the existing payment system and requires a digital euro to serve as a back-up.

Another scenario is a further sharp drop in cash usage that leaves some people financially excluded.

Finally, it examined the potential rapid adoption of other private or public digital currencies including those issued by foreign central banks that ‘could “threaten European financial, economic and, ultimately, political sovereignty”. The ECB said a digital euro “also poses challenges, but by following appropriate strategies in the design of the digital euro the Eurosystem can address these”.

My Linkedin Post here

Sources: 
  • https://www.ft.com/content/b6f0c233-0b35-45d1-896f-1c6599558d9b
  • https://www.bloomberg.com/news/articles/2020-10-01/ecb-applies-for-digital-euro-trademark-amid-feasibility-study 
  • https://www.ecb.europa.eu
0 Comments
Read More
Back to Blog

Banks Should Review Client Onboarded Remotely During Pandemic: Moneyval

25/9/2020

 
Picture
Peter Oakes, fintech and financial crime expert talks to Gabriel Vedrenne of ACAMS MoneyLaundering.com about European financial institutions that switched to onboarding all new clients remotely at the height of COVID-19 lockdowns should review their customer files to ensure that adequate due diligence was conducted as per the European anti-money laundering standard setter warned.
​
​CLICK HERE
0 Comments
Read More
Back to Blog

Westpac to be fined $1.3bn for money laundering breaches including associated with possible child exploitation

24/9/2020

 
Picture
"the settlement sends a strong message to industry that AUSTRAC will take action to ensure our financial system remains strong so it cannot be exploited by criminals" AUSTRAC 24 September 2020
Source: AUSTRAC
Press Release 24 September 2020


Westpac and AUSTRAC have today agreed to a AUD$1.3 billion dollar proposed penalty over Westpac’s breaches of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). Westpac and AUSTRAC have agreed that the proposed penalty reflects the seriousness and magnitude of compliance failings by Westpac.

The Federal Court of Australia will now consider the proposed settlement and penalty. If the Federal Court determines the proposed penalty is appropriate, the penalty order made will represent the largest ever civil penalty in Australian history. 

In reaching today’s agreement, Westpac has admitted to contravening the AML/CTF Act on over 23 million occasions, exposing Australia’s financial system to criminal exploitation.
In summary, Westpac admitted that it failed to:
  • Properly report over 19.5 million International Funds Transfer Instructions (IFTIs) amounting to over $11 billion dollars to AUSTRAC.
  • Pass on information relating to the origin of some of these international funds transfers, and to pass on information about the source of funds to other banks in the transfer chain, which these banks needed to manage their own ML/TF risks.
  • Keep records relating to the origin of some of these international funds transfers.
  • Appropriately assess and monitor the risks associated with the movement of money into and out of Australia through its correspondent banking relationships, including with known higher risk jurisdictions.
  • Carry out appropriate customer due diligence in relation to suspicious transactions associated with possible child exploitation.

In reaching the agreement, Westpac has also admitted to approximately 76,000 additional contraventions which expand the original statement of claim. These new contraventions relate to information that came to light after the civil penalty action was launched last year and relate to additional IFTI reporting failures, failures to reasonably monitor customers for transactions related to possible child exploitation, and two further failures to assess the money laundering and terrorism financing risks associated with correspondent banking relationships.

AUSTRAC’s Chief Executive Officer, Nicole Rose PSM said the settlement sends a strong message to industry that AUSTRAC will take action to ensure our financial system remains strong so it cannot be exploited by criminals.

“Our role is to harden the financial system against serious crime and terrorism financing and this penalty reflects the serious and systemic nature of Westpac’s non-compliance,” Ms Rose said.
“Westpac’s failure to implement effective transaction monitoring programs, and its failure to submit IFTI reports to AUSTRAC and apply enhanced customer due diligence in relation to suspicious transactions, meant AUSTRAC and law enforcement were missing critical intelligence to support police investigations.”

Ms Rose said such a large number of breaches over several years was unacceptable and could have been avoided with better assurance and oversight processes to identify ongoing reporting failures.
AUSTRAC works in partnership with the businesses we regulate through a comprehensive industry education program.

“We have been, and will continue to work collaboratively with Westpac and all businesses we regulate to support them to meet their compliance and reporting obligations to ensure this doesn’t happen again in the future.”

Westpac continues to partner with AUSTRAC to assist AUSTRAC and law enforcement agencies to stop financial crime, including as a member of AUSTRAC’s private-public partnership the Fintel Alliance.

About AUSTRACAUSTRAC (the Australian Transaction Reports and Analysis Centre) is the Australian Government agency responsible for detecting, deterring and disrupting criminal abuse of the financial system to protect the community from serious and organised crime.

Through strong regulation, and enhanced intelligence capabilities, AUSTRAC collects and analyses financial reports and information to generate financial intelligence.
​
Learn more about AUSTRAC: https://www.austrac.gov.au/about-us/austrac-overview 
Media contactEmail: [email protected] 
Phone: (02) 9950 0488  
0 Comments
Read More
<<Previous
Forward>>
© CompliReg.com   Dublin 2, Ireland  ph +353 1 639 2971 
|  www.complireg.com  |  officeATcomplireg.com [replace AT with @]

Picture
Photo from Got Credit