11.10.2013 Views

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

BANK SECRECY ACT, ANTI-MONEY LAUNDERING,<br />

AND OFFICE OF FOREIGN ASSETS CONTROL<br />

inadequate to meet regulatory requirements and sound<br />

customer due diligence.<br />

Part 326.8(c)(1) <strong>of</strong> the <strong>FDIC</strong> Rules and Regulations<br />

Part 326.8(c)(1) states, in part, that the compliance<br />

program shall, at a minimum, provide for a system <strong>of</strong><br />

internal controls to assure ongoing compliance.<br />

<strong>Management</strong> has not provided for an adequate system <strong>of</strong><br />

internal controls to assure ongoing compliance. Examiners<br />

identified the following internal control deficiencies:<br />

• Incomplete BSA and AML policies for a bank with a<br />

high-risk pr<strong>of</strong>ile.<br />

• Insufficient identification systems for CTR reporting.<br />

• Late CTR filings.<br />

• Insufficient reporting mechanisms for identification <strong>of</strong><br />

structured transactions and other suspicious activity.<br />

• Weak oversight over high-risk customers.<br />

• Insufficient customer identification program and<br />

customer due diligence.<br />

Due to the financial institution’s high-risk pr<strong>of</strong>ile,<br />

management should go beyond minimum CIP requirements<br />

and do a sufficient level <strong>of</strong> due diligence that provides for<br />

a satisfactory evaluation <strong>of</strong> the customer. <strong>Management</strong><br />

must provide for adequate reporting mechanisms to<br />

identify large cash transactions as well as suspicious<br />

activity. Timely completion and review <strong>of</strong> appropriate<br />

reports, in conjunction with a sufficient level <strong>of</strong> due<br />

diligence, should allow for the accurate and timely<br />

reporting <strong>of</strong> CTRs and SARs.<br />

Part 326.8(c)(2) <strong>of</strong> the <strong>FDIC</strong> Rules and Regulations<br />

Part 326.8(c)(2) states that the compliance program shall<br />

provide for independent testing for compliance to be<br />

conducted by an outside party or bank personnel who have<br />

no BSA responsibility or oversight.<br />

The financial institution’s BSA policies provide for<br />

independent testing. However, the financial institution has<br />

not received an independent review for over three years.<br />

An annual review <strong>of</strong> the BSA program should be<br />

completed by a qualified independent party. This review<br />

should incorporate all <strong>of</strong> the high-risk areas <strong>of</strong> the<br />

institution, including cash-intensive accounts and<br />

transactions, sales and purchases <strong>of</strong> monetary instruments;<br />

customer exemption list; electronic funds transfer<br />

activities, and compliance with customer identification<br />

procedures.<br />

Part 326.8(c)(3) <strong>of</strong> the <strong>FDIC</strong> Rules and Regulations<br />

Section 8.1<br />

Part 326.8(c)(3) states that the compliance program shall<br />

designate an individual or individuals responsible for<br />

coordinating and monitoring day-to-day compliance.<br />

The board <strong>of</strong> directors has named Head Teller Ben Bison<br />

as the BSA <strong>of</strong>ficer. While Mr. Bison has a basic<br />

understanding <strong>of</strong> CTR filing, he does not have any training<br />

on detecting and reporting suspicious activity.<br />

Furthermore, Ben Bison does not have policy-making<br />

authority over the BSA function. <strong>Management</strong> needs to<br />

appoint someone with policy-making authority as the<br />

institution’s BSA Officer.<br />

Part 326.8(c)(4) <strong>of</strong> the <strong>FDIC</strong> Rules and Regulations<br />

Part 326.8(c)(4) states that the compliance program shall<br />

provide training for appropriate personnel.<br />

Example 1:<br />

While BSA training programs are adequate, management<br />

has trained less than half <strong>of</strong> the appropriate operational<br />

personnel during the last calendar year. <strong>Management</strong> must<br />

ensure that all appropriate personnel, including the board<br />

<strong>of</strong> directors and <strong>of</strong>ficers, receive adequate BSA training a<br />

minimum <strong>of</strong> once per year and ongoing for those whose<br />

duties require constant awareness <strong>of</strong> the BSA requirements.<br />

Example 2:<br />

BSA training needs improvement. While regular BSA<br />

training sessions are developed and conducted for branch<br />

operations personnel, the training programs do not address<br />

internal BSA policies and, more importantly, BSA and<br />

anti-money laundering regulations. <strong>Management</strong> must<br />

ensure that comprehensive BSA training is provided to all<br />

directors, <strong>of</strong>ficers, and appropriate operational personnel.<br />

Training should be provided at least annually, and must be<br />

ongoing for those whose duties require constant awareness<br />

<strong>of</strong> BSA requirements. The training must be commensurate<br />

with the institution’s BSA risk-pr<strong>of</strong>ile and provide specific<br />

employee guidance on detecting unusual or suspicious<br />

transactions beyond the detection <strong>of</strong> cash structuring<br />

transactions.<br />

Part 353.3 <strong>of</strong> the <strong>FDIC</strong> Rules and Regulations and 31<br />

C.F.R. 103.18<br />

Part 353.3(a) and 31 C.F.R. 103.18 state, in part, that<br />

Suspicious Activity Reports (SARs) should be filed when:<br />

• Insider abuse is involved in any amount;<br />

DSC <strong>Risk</strong> <strong>Management</strong> <strong>Manual</strong> <strong>of</strong> <strong>Examination</strong> <strong>Policies</strong> 8.1-53 Bank Secrecy Act (12-04)<br />

Federal Deposit Insurance Corporation

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!