11.10.2013 Views

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

BANK SECRECY ACT, ANTI-MONEY LAUNDERING,<br />

AND OFFICE OF FOREIGN ASSETS CONTROL<br />

institution or its employees. Criminal penalties provide for<br />

imprisonment up to 30 years and fines ranging up to $10<br />

million.<br />

Furthermore, financial institutions are not permitted to<br />

transfer responsibility for OFAC compliance to<br />

correspondent banks or a contracted third party, such as a<br />

data processing service provider. Each financial institution<br />

is responsible for every transaction occurring by or through<br />

its systems. If a sanctioned transaction transverses several<br />

U.S. financial institutions, all <strong>of</strong> these institutions will be<br />

subject to the same civil or criminal action, with the<br />

exception <strong>of</strong> the financial institution that blocked or<br />

rejected the transaction, as appropriate.<br />

<strong>Examination</strong> Considerations<br />

Financial institutions should establish and maintain<br />

effective OFAC programs and screening capabilities in<br />

order to facilitate safe and sound banking practices. It is<br />

not the examiner’s primary duty to identify unreported<br />

accounts or transactions within an institution. Rather,<br />

examination procedures should focus on evaluating the<br />

adequacy <strong>of</strong> an institution’s overall OFAC compliance<br />

program and procedures, including the systems and<br />

controls in place to reasonably assure accounts and<br />

transactions are blocked and rejected.<br />

In reviewing an institution’s OFAC compliance program,<br />

examiners should evaluate the operational risks the<br />

financial institution is willing to accept and determine if<br />

this exposure is reasonable in comparison with the business<br />

type, department or product, customer base, and cost <strong>of</strong> an<br />

effective screening program for that particular institution,<br />

based on its risk pr<strong>of</strong>ile.<br />

The <strong>FDIC</strong> strongly recommends that each financial<br />

institution adopt a risk-focused, written OFAC program<br />

designed to ensure compliance with OFAC regulations. An<br />

effective OFAC program should include the following:<br />

• Written policies and procedures for screening<br />

transactions and new customers to identify possible<br />

OFAC matches;<br />

• Qualified individual to monitor compliance and<br />

oversee blocked funds;<br />

• OFAC risk-assessment for various products and<br />

departments within the financial institution;<br />

• Guidelines and internal controls to ensure the periodic<br />

screening <strong>of</strong> all existing customer accounts;<br />

• Procedures for obtaining and maintaining up-to-date<br />

OFAC lists <strong>of</strong> blocked countries, entities, and<br />

individuals;<br />

Section 8.1<br />

• Methods for conveying timely OFAC updates<br />

throughout the financial institution, including <strong>of</strong>fshore<br />

locations and subsidiaries;<br />

• Procedures for handling and reporting prohibited<br />

OFAC transactions;<br />

• Guidance for SAR filings on OFAC matches, if<br />

appropriate, such as when criminal intent or terrorist<br />

activity is involved;<br />

• Internal review or audit <strong>of</strong> the OFAC processes in<br />

each affected department; and<br />

• Training for all appropriate employees, including<br />

those in <strong>of</strong>fshore locations and subsidiaries.<br />

Departmental and product risk assessments are<br />

fundamental to a sound OFAC compliance program.<br />

These assessments allow institution management to ensure<br />

appropriate focus on high-risk areas, such as correspondent<br />

banking activities and electronic funds transfers. An<br />

effective program will filter as many transactions as<br />

possible through OFAC’s SDN and Blocked Persons List,<br />

whether they are completed manually or through the use <strong>of</strong><br />

a third party s<strong>of</strong>tware program. However, when evaluating<br />

an institution’s compliance program, examiners should<br />

consider matters such as the size and complexity <strong>of</strong> the<br />

institution. Adequate compliance procedures can and<br />

should be targeted to transactions that pose the greatest risk<br />

to an institution. Some transactions may be difficult to<br />

capture within a risk-focused compliance program. For<br />

example, a customer could write a personal check to a<br />

blocked entity; however, the only way the financial<br />

institution that the check is drawn upon could block those<br />

funds would be if it reviewed the payee on each personal<br />

check, assuming the information is provided and legible.<br />

Under current banking practices, this would be costly and<br />

time consuming. Most financial institutions do not have<br />

procedures for interdicting these transactions, and, yet, if<br />

such a transaction were to be processed by a U.S. financial<br />

institution, it is a violation <strong>of</strong> OFAC regulations and could<br />

result in CMPs against the bank.<br />

However, if a financial institution only screens its wire<br />

transfers through the OFAC SDN and Blocked Persons<br />

List and never screens its customer database, that is a much<br />

higher and, likely, unacceptable risk for the financial<br />

institution to assume in relation to the time and expense to<br />

perform such a review. Particular risk areas that should be<br />

screened by all financial institutions include:<br />

• Incoming and outgoing electronic transactions, such as<br />

ACH;<br />

• Funds transfers, including message or instruction<br />

fields;<br />

• Monetary instrument sales; and<br />

Bank Secrecy Act (12-04) 8.1-50 DSC <strong>Risk</strong> <strong>Management</strong> <strong>Manual</strong> <strong>of</strong> <strong>Examination</strong> <strong>Policies</strong><br />

Federal Deposit Insurance Corporation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!