11.10.2013 Views

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

BANK SECRECY ACT, ANTI-MONEY LAUNDERING,<br />

AND OFFICE OF FOREIGN ASSETS CONTROL<br />

Automated Clearing House Transactions and<br />

Electronic Initiation Systems<br />

Additionally, the National Automated Clearing House<br />

Association (NACHA) has provided standards which<br />

mandate the use <strong>of</strong> security measures for automated<br />

clearing house (ACH) transactions initiated through the<br />

Internet or electronically. These guidelines include<br />

ensuring secure access to the electronic and Internet<br />

systems in conjunction with procedures reasonably<br />

designed to identify the ACH originator.<br />

Interagency guidance on authenticating users <strong>of</strong> technology<br />

and the identity <strong>of</strong> customers is further discussed in <strong>FDIC</strong><br />

FIL-69-2001, “Authentication in an Electronic<br />

Environment.” This FIL not only identifies the risk <strong>of</strong><br />

access to systems and information, it also emphasizes the<br />

need to verify the identity <strong>of</strong> electronic and/or Internet<br />

customers, particularly those who request account opening<br />

and new services online.<br />

MONITORING BANK SECRECY ACT<br />

COMPLIANCE<br />

Section 8(s) <strong>of</strong> the Federal Deposit Insurance Act, which<br />

implements 12 U.S.C. 1818, requires the <strong>FDIC</strong> to:<br />

• Develop regulations that require insured financial<br />

institutions to establish and maintain procedures<br />

reasonably designed to assure and monitor compliance<br />

with the BSA;<br />

• Review such procedures during examinations; and<br />

• Describe any problem with the procedures maintained<br />

by the insured depository institution within reports <strong>of</strong><br />

examination.<br />

To satisfy Section 8(s) requirements, at a minimum,<br />

examiners must review BSA at each regular safety and<br />

soundness examination. In addition, the <strong>FDIC</strong> must<br />

conduct its own BSA examination at any intervening<br />

Safety and Soundness examination conducted by a State<br />

banking authority if such authority does not review for<br />

compliance with the BSA. Section 326.8 <strong>of</strong> the <strong>FDIC</strong>’s<br />

Rules and Regulations establishes the minimum BSA<br />

program requirements for all state nonmember banks,<br />

which are necessary to assure compliance with the financial<br />

recordkeeping and reporting requirements set forth within<br />

the provisions <strong>of</strong> the Treasury regulation 31 CFR 103.<br />

Part 326.8 <strong>of</strong> the <strong>FDIC</strong>’s Rules and<br />

Regulations<br />

Minimum Requirements <strong>of</strong> the<br />

BSA Compliance Program<br />

Section 8.1<br />

The BSA compliance program must be in writing and<br />

approved by the financial institution’s board <strong>of</strong> directors,<br />

with approval noted in the Board minutes. Best practices<br />

dictate that Board should review and approve the policy<br />

annually. In addition, financial institutions are required to<br />

develop and implement a Customer Identification Program<br />

as part <strong>of</strong> their overall BSA compliance program. More<br />

specific guidance regarding the CIP program requirements<br />

can be found within the “Customer Identification Program”<br />

discussion within this section <strong>of</strong> the DSC <strong>Risk</strong><br />

<strong>Management</strong> <strong>Manual</strong> <strong>of</strong> <strong>Examination</strong> <strong>Policies</strong> (DSC<br />

<strong>Manual</strong>).<br />

A financial institution’s BSA compliance program must<br />

meet four minimum requirements, as detailed in Section<br />

326.8 <strong>of</strong> the <strong>FDIC</strong>’s Rules and Regulations. The<br />

procedures necessary to establish an adequate program and<br />

assure reasonable compliance efforts designed to meet<br />

these minimum requirements are discussed in detail below:<br />

1. A system <strong>of</strong> internal controls. At a minimum, the<br />

system must be designed to:<br />

a. Identify reportable transactions at a point where<br />

all <strong>of</strong> the information necessary to properly<br />

complete the required reporting forms can be<br />

obtained. The financial institution might<br />

accomplish this by sufficiently training tellers and<br />

personnel in other departments or by referring<br />

large currency transactions to a designated<br />

individual or department. If all pertinent<br />

information cannot be obtained from the<br />

customer, the financial institution should consider<br />

declining the transaction.<br />

b. Monitor, identify, and report possible money<br />

laundering or unusual and suspicious activity.<br />

Procedures should provide that high-risk<br />

accounts, services, and transactions are regularly<br />

reviewed for suspicious activity.<br />

c. Ensure that all required reports are completed<br />

accurately and properly filed within required<br />

timeframes. Financial institutions should consider<br />

centralizing the review and report filing functions<br />

within the banking organization.<br />

d. Ensure that customer exemptions are properly<br />

granted, recorded, and reviewed as appropriate,<br />

including biennial renewals <strong>of</strong> “Phase II”<br />

exemptions. Exempt accounts must be reviewed<br />

at least annually to ensure that the exemptions are<br />

still valid and to determine if any suspicious or<br />

unusual activity is occurring in the account. The<br />

DSC <strong>Risk</strong> <strong>Management</strong> <strong>Manual</strong> <strong>of</strong> <strong>Examination</strong> <strong>Policies</strong> 8.1-31 Bank Secrecy Act (12-04)<br />

Federal Deposit Insurance Corporation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!