Chapter 5: Comprehensive Guide to IFSCA AML, CFT, and KYC Guidelines 2022

Comprehensive Guide to IFSCA AML, CFT, and KYC Guidelines 2022

The International Financial Services Centres Authority (IFSCA) has established a robust regulatory framework to maintain the integrity of the IFSC ecosystem. The IFSCA (Anti Money Laundering, Counter Terrorist Financing and Know Your Customer) Guidelines, 2022 (abbreviated as IFSCA AML, CFT, and KYC Guidelines, 2022) are central to this mission, mandating that all regulated entities implement systems to detect, prevent, and report illicit financial activities.

1. Duties and Responsibilities of a Regulated Entity (RE)

A Regulated Entity is any unit or entity granted a license, registration, or authorisation by the IFSCA. Their primary duties include:

  • Policy Formulation: Every RE must create an AML-CFT policy and a KYC policy (as part of the former), which must be approved by the Governing Body or a delegated committee.
  • Key Principles: Policies must incorporate the core elements of the IFSCA guidelines.
  • Senior Management Accountability: Members of Senior Management are personally responsible for ensuring compliance and must exercise due skill, care, and diligence.

2. The Risk-Based Approach (RBA)

The RBA is the foundational principle of the IFSCA guidelines, ensuring that compliance measures are proportionate to the actual risks faced by the RE.

Key Requirements of the RBA:

  • Objectivity: The approach must be based on reasonable grounds and be documented.
  • Enterprise-Wide Assessment: REs must assess risks not just at the individual customer level but also at the enterprise, financial group, or group-wide level.
  • Risk Classification: Customers must be classified as Low, Medium, or High risk. This classification determines whether Simplified or Enhanced due diligence measures are applied.
  • Periodic Review: Risk assessments must be updated at least once every two years or upon a material trigger event, whichever is earlier.

 

3. Business Risk Assessment (BRA)

REs must conduct a BRA to identify their exposure to ML/TF risks based on the nature and complexity of their business.

Risk Factor Category Specific Considerations
Customer Base Types of customers and their specific activities.
Geography Business engagement with specific countries or geographic areas.
Products/Services Complexity and volume of transactions, delivery channels, and activity profiles.
Technology Use of new or developing technologies and delivery mechanisms.

New Products and Technologies: Before launching any new product, business practice, or technology, an RE must conduct a dedicated risk assessment and implement mitigation measures.

 

4. Identification and Reporting of Suspicious Transactions

Internal Reporting Mechanism

REs must establish systems where any employee who knows or suspects ML/TF activity promptly notifies the Principal Officer (PO) with all relevant details.

Four Steps to Identify Suspicion:

  1. Detect: Identify a suspicious indicator.
  2. Ask: Question the customer regarding the activity.
  3. Review: Examine the customer's historical records.
  4. Evaluate: Assess all gathered information to confirm suspicion.

Reporting to FIU-IND

All Suspicious Transaction Reports (STRs) must be furnished to the Director, Financial Intelligence Unit-India (FIU-IND).

  • Deadlines: STRs must be submitted promptly once a conclusion is reached. Non-Profit Organization Transaction Reports (NTRs) must be submitted by the 15th day of the succeeding month.
  • Confidentiality: REs and their employees are strictly prohibited from disclosing (tipping off) that an STR has been filed.

5. Correspondent Banking and Wire Transfers

Correspondent Banking

This refers to a bank (correspondent) providing services to another bank (respondent) to facilitate cross-border transactions.

  • Due Diligence: REs must gather information on the respondent’s management, reputation, and the quality of supervision in their home jurisdiction.
  • Shell Banks: REs are strictly prohibited from entering into relationships with Shell Financial Institutions.

Wire Transfers

REs must ensure that all electronic fund transfers carry accurate and meaningful information.

  • Cross-Border Threshold: For transfers exceeding USD 1,000, the message must include the originator's residential address, unique ID number, or date/place of birth.
  • Domestic Transfers: Both the ordering and beneficiary institutions are located within the IFSC. Messages must allow for the transaction to be traced back to the originator.

6. Internal Policies, Compliance, and Audit

The Principal Officer (PO)

The PO must be a management-level official with the seniority and authority to oversee the AML/CFT program.

  • Responsibilities: Includes reporting STRs, training employees, and informing Senior Management of compliance reviews.
  • Independence: The PO should be distinct from internal audit and business line functions to avoid conflicts of interest.

Audit and Training

  • Independent Audit: REs must maintain an adequately resourced audit function to periodically test the effectiveness of AML/CFT policies.
  • Ongoing Training: Relevant employees must receive periodic training tailored to the RE's specific products and risk profile.

7. Record Keeping Requirements

REs must maintain high-quality records to allow for the reconstruction of transactions and demonstrate compliance to authorities.

  • Retention Period: Records must be preserved for at least six years from the date the business relationship ends or the transaction is completed.
  • Types of Records: Includes CDD documents, transaction records, business correspondence, and internal findings on unusual transactions.
  • Accessibility: Data must be retrievable easily and quickly. If records are stored outside the IFSC, the RE must ensure they are immediately available for inspection by the Authority upon request.

Key Takeaways for Professionals

  • RBA is Mandatory: Every action must be grounded in a documented risk assessment updated every two years.
  • Zero Tolerance for Shell Banks: Relationships with shell financial institutions are prohibited.
  • Strict Reporting Deadlines: NTRs are due by the 15th of the following month.
  • Record Integrity: The six-year retention rule is a critical compliance benchmark.

Important Terms

  • Regulated Entity (RE): An entity licensed or authorized by the IFSCA.
  • Politically Exposed Persons (PEPs): Individuals entrusted with prominent public functions by a foreign country.
  • Beneficial Owner (BO): The natural person who ultimately owns or controls a customer.
  • FINGate 2.0: The primary portal used by REs to report suspicious transactions to FIU-IND.

Practice with a Free Mock Test

Ready to test your NISM-Series-24: AML and CFT Provisions in Securities Markets Mock Tests preparation? Start with Test 1 — no payment required.

Notify me when you update the Notes

Free account · No payment needed for Test 1

Create a free PassNISM account

Continue with Google to start a free NISM mock test (Test 1) for this subject, save scores, and compare attempts.

Continue with Google