Chapter-5: IFSCA (Anti Money Laundering, Counter Terrorist Financing and Know Your Customer) Guidelines, 2022 (Part 2)

Chapter-5: IFSCA (Anti Money Laundering, Counter Terrorist Financing and Know Your Customer) Guidelines, 2022 Part 2: Risk-Based Approach (RBA) & Business Risk Assessment (BRA)

1. Section 5.3: Risk-Based Approach (RBA)

1.1 Core Philosophy & Foundation of RBA

The primary thrust of the IFSCA Guidelines is to enable every Regulated Entity (RE) to adopt a comprehensive Risk-Based Approach (RBA). The RBA serves as the essential foundation of an RE’s AML/CFT compliance culture, and it must trickledown from the level of Senior Management to the rest of the entire organisation.

Rather than treating compliance as a rigid, box-ticking exercise, the RBA requires an RE to dynamically identify, assess, and document the specific Money Laundering (ML) and Terrorist Financing (TF) risks to which it is exposed. This risk exposure depends heavily upon:

  • The nature, scale, and complexity of the RE's business.
  • Its involvement with or exposure to specific types of clients.
  • The countries or geographic areas in which it operates or with which it has business relations.
  • The specific products, services, transactions, or delivery channels it utilizes.

1.2 Triple Safeguard Rules of RBA

When designing and implementing a Risk-Based Approach, a Regulated Entity must satisfy three core statutory conditions to ensure the framework is legally sound and operationally effective:

No. Safeguard Key Principle Purpose
1 🎯 Objectivity & Proportionality AML-CFT measures should be proportionate to the actual risks identified. Avoid both under-control and excessive control.
2 🔎 Reasonable Grounds Risk assessments must be based on objective, factual, and reasonable information. Ensure decisions are evidence-based rather than arbitrary.
3 🔄 Periodic Review Cycle Risk assessments and controls should be reviewed and updated regularly. Keep the AML-CFT framework aligned with changing risks and circumstances.
  1. Objectivity and Proportionality: The RBA must be objective and directly proportionate to the actual risks identified within the entity's operations. Stricter controls must be reserved for higher risks, while simplified processes can be applied to lower-risk scenarios.
  2. Reasonable Grounds: The design and application of the RBA must be established on reasonable, defensible grounds, supported by data, regulatory findings, and logical risk analyses.
  3. Periodic Review and Updates: The RBA cannot remain static; it must be reviewed and updated at appropriate intervals to reflect evolving financial crime typologies and organizational shifts.

1.3 Scope of Risk Assessment: Enterprise-wide, Group-wide, and Customer-wide levels

An RE is required to assess ML/TF risks at multiple operational levels to prevent blind spots in its compliance framework:

  • Individual Customer Level: Assessing the specific risk profile presented by each individual client during onboarding and ongoing due diligence.
  • Enterprise-Wide Level: Identifying and assessing ML/TF risks across the entire institution. This requires a consolidated, macro-level assessment of risk factors existing across all of the RE's diverse business units, product lines, and delivery channels.
  • Financial Group-Wide and Group-Wide Level: Where applicable, if the RE is part of a larger group or financial conglomerate, the risk assessment must be integrated and consolidated at the Group-wide level.

1.4 Documenting Risk Assessments & External Information Inputs

The outcomes of an RE's risk assessments must be formalised in writing. This documentation serves as a critical audit trail and must include:

  • The detailed enterprise-wide AML/CFT risk assessment.
  • Concrete details showing how the RE's AML/CFT risk management systems and controls have been implemented and guided by the risk assessment.

Table: Authorized External Sources for Risk Assessments

To ensure the risk assessment is robust and aligned with global intelligence, the RE is expected to integrate information from several authorized international and domestic sources:

Source Type Primary Risk Materials to Incorporate Regulatory Utility
FATF Publications FATF Public Statements, Mutual Evaluation Reports, and published follow-up reports. Identification of non-cooperative jurisdictions and global money laundering trends.
FATF Guidance Notes Specialized reports and guidance notes on AML, CFT, and Proliferation Financing (PF). Understanding complex risk typologies (e.g., Trade-Based Money Laundering).
Authority Circulars Country-specific information, risk directives, and advisories circulated by domestic and international regulators. Compliance with localized risk alerts and immediate regulatory shifts.
UNSC Lists Regularly updated lists of natural and legal persons subjected to sanction measures under United Nations Security Council Resolutions. Strict adherence to targeted financial sanctions and counter-terrorist financing rules.

All risk assessment documentation must be maintained securely as per the record-keeping standards of the Guidelines and must be made immediately available to the IFSCA upon request.

1.5 Customer Risk Classification (Low, Medium, High)

The ultimate objective of conducting a customer-level risk assessment is to classify clients into distinct risk categories: Low Risk, Medium Risk, and High Risk.

The fundamental principle governing this classification is the proportionate application of due diligence measures:

  • High-Risk Customers: Mandatorily subject to Enhanced Due Diligence (EDD) measures and closer transactional scrutiny.
  • Low-Risk Customers: Eligible for Simplified Customer Due Diligence (SCDD) measures, allowing for streamlined onboarding processes.

1.6 Review Cycle, Triggers, and Governing Body Oversight

Risk assessments cannot be treated as one-time documents. To ensure they remain completely up-to-date, the Guidelines impose strict review timelines:

  • Minimum Frequency: The risk assessment must be reviewed and updated at least once every two years.
  • Trigger-Based Review: If a material trigger event occurs prior to the two-year mark, the risk assessment must be updated immediately. Examples of material triggers include significant changes in ownership, the launch of new business lines, or sudden regulatory updates.
  • Governing Body Oversight: The final outcome of the risk review exercise must be formally presented to the Governing Body of the RE (e.g., the Board of Directors) or to a designated committee of the RE to which such supervisory powers have been delegated.

2. Section 5.4: Business Risk Assessment (BRA)

2.1 Regulatory Mandate of BRA & Applicability to Exempted Entities

Under Chapter III of the Guidelines, every Regulated Entity is required to adopt a structured, enterprise-level Business Risk Assessment (BRA). The BRA requires the RE to evaluate the nature, size, and complexity of its business activities to identify its exposure to ML/TF risks.

The Non-Negotiable BRA Rule for Exempted Entities

A common misconception is that entities exempted from day-to-day AML/CFT/KYC compliance are entirely free from regulatory oversight. The IFSCA maintains strict rules regarding exemptions:

  • Exempted Entities: Certain specific entities, such as international branch campuses of foreign universities and intra-group service providers within the same financial group (provided they are not located in FATF high-risk jurisdictions), are exempt from direct, day-to-day AML/CTF/KYC compliance.
  • Mandatory BRA Requirement: Notwithstanding this exemption, all exempted financial institutions must still conduct and document a formal Business Risk Assessment (BRA) and maintain the relevant risk records and safeguards.
  • Reversion to Normal Compliance: If any ML/TF risks are identified during the course of the exempted entity's BRA, the exemption is immediately suspended, and normal, full compliance obligations under the PMLA and the IFSCA Guidelines resume without delay.

2.2 Core Risk Factors in a Business Risk Assessment (BRA)

When compiling and updating the BRA, the Regulated Entity must systematically analyze and document six core risk factors, to the extent they are applicable and relevant to its operations:

No. Risk Factor What to Assess
1 👤 Customer Profiles & Activities Customer type, profile, occupation/business activity, ownership structure, and associated risk.
2 🌍 Geographic Engagement Countries and jurisdictions involved in the relationship, including country-specific risk factors.
3 🏦 Product & Service Profiles Nature of products and services offered and their potential exposure to ML/TF risks.
4 💸 Transaction Complexity & Volume Transaction patterns, complexity, frequency, volume, and unusual transaction characteristics.
5 🤝 New Sales Practices & Partners Risks arising from new business models, sales channels, intermediaries, agents, and business partners.
6 💻 Emerging Technology & Platforms Risks associated with new technologies, digital platforms, delivery channels, and technological innovations.
  1. Customer Profiles and Activities: The specific types of customers the RE serves (e.g., individual investors, corporate entities, trusts) and the underlying nature of their business activities.
  2. Geographic Engagement: The countries or geographic jurisdictions with which the RE does business, including cross-border transaction hubs and regions exposed to higher financial crime.
  3. Product, Service, and Activity Profiles: The risk characteristics of the financial products and services offered, along with the channels used to deliver them to clients.
  4. Transaction Complexity and Volume: The operational scale, velocity, and architectural complexity of the transactions processed by the RE.
  5. New Products and Business Practices: The planned development of new products, delivery mechanisms, distribution channels, and business partnerships.
  6. Emerging and Developing Technologies: The introduction or operational use of new technologies for both new and pre-existing products.

Based on the explicit identification and assessment of these six factors, the RE must implement commensurate, robust mitigation measures to address any vulnerabilities.

2.3 New Products, Business Practices, and Developing Technologies (Section 5.4.1)

The introduction of innovative financial technologies or novel business models can create immediate, unmonitored compliance gaps. To mitigate this, Section 5.4.1 imposes a strict pre-launch risk assessment rule:

  • Scope of Assessment: The RE must proactively identify and assess the ML and TF risks that may arise from:
    1. The development of new products and business practices, including new delivery mechanisms.
    2. The implementation or use of new or developing technologies for both new and pre-existing products.
  • The "Prior to Launch" Rule: This risk assessment exercise must be completed prior to the launch or operational use of such products, practices, or technologies.
  • Actionable Mitigation: The RE must implement appropriate, targeted measures to manage and mitigate any technology-related risks identified during the assessment before releasing the product to the market.

2.4 AML/CFT Systems and Controls (Section 5.4.2)

The nature, depth, and scale of the AML/CFT systems and controls established by a Regulated Entity must be directly commensurate with the ML/TF risks identified through its enterprise-wide risk assessment.

The RE must use the specific findings of its BRA to:

  • Establish and maintain highly effective policies, procedures, systems, and controls designed to prevent ML/TF.
  • Verify and guarantee that the RE's active compliance frameworks are strong enough to adequately mitigate every identified risk.
  • Conduct regular, formal risk assessments evaluating the ongoing adequacy of the RE's AML/CFT systems and controls. This ensures the entity can continuously identify, assess, monitor, and manage operational risks.

2.5 Operationalizing Systems and Controls: Senior Management Review & PEP Determinations

To ensure the systems and controls are not merely passive policies, the Guidelines require the framework to include specific operational capabilities:

  • Senior Management Review Provision: The systems and controls must contain explicit provisions that enable Senior Management to regularly review information regarding the daily operations and overall effectiveness of the RE's AML systems and controls.
  • PEP Identification Capabilities: The systems must actively enable the RE to determine:
    1. Whether any customer or Beneficial Owner (BO) is a Politically Exposed Person (PEP).
    2. Whether a beneficiary of an insurance policy, or the Beneficial Owner of such a beneficiary, is a PEP (in cases where the RE provides life insurance or other investment-linked insurance policies).
  • Legislative Alignment: The systems must ensure full, uncompromised compliance with the IFSCA Guidelines and all other applicable AML/CFT legislations.

2.6 Senior Management Approval & Continuous Quality Improvement

  • Approval Authority: All AML/CFT policies, procedures, and internal controls must be formally approved by Senior Management. This ensures executive-level accountability for managing the risks identified by the RE or notified to it by the IFSCA.
  • Continuous Monitoring: The RE is legally obligated to constantly monitor the implementation of its approved policies and controls.
  • Iterative Improvement: If monitoring reveals operational weaknesses, changing risk environments, or system inefficiencies, the RE must proactively improve and refine its controls.

3. Key Exam-Relevant Terms & Definitions

  • Risk-Based Approach (RBA): A flexible, risk-proportionate methodology used to identify, assess, and mitigate money laundering and terrorist financing risks based on factual exposure.
  • Business Risk Assessment (BRA): An enterprise-wide, documented evaluation of an RE’s exposure to financial crime risks, taking into account its customers, geographic reach, products, transactions, and technologies.
  • Enterprise-Wide Risk: A holistic, consolidated risk view of an entire organization across all business units, product lines, and delivery channels.
  • Exempted Entity: An entity (such as a foreign university campus in the IFSC) exempt from day-to-day KYC procedures but still strictly required to document a BRA and maintain basic safeguards.
  • Politically Exposed Persons (PEPs): Individuals who are or have been entrusted with prominent public functions, whose accounts and beneficial ownerships require enhanced systems detection and senior management approval.

4. Important Takeaways for Students & Professionals

  1. Risk-Based Proportionality: The core of the IFSCA guidelines is proportionality. High-risk profiles require intense, resource-heavy Enhanced Due Diligence (EDD), whereas low-risk profiles allow for streamlined, cost-effective Simplified Due Diligence (SCDD).
  2. No BRA Loophole: There is absolutely no loophole for exempted entities when it comes to the Business Risk Assessment. Even if exempt from daily KYC filing, every IFSC entity must compile and maintain a documented BRA.
  3. Strict Technology Timeline: A Regulated Entity cannot launch a new product, partner with a new delivery mechanism, or implement a new technology and assess its risks later. The risk assessment must be finalized and documented prior to launch.
  4. Two-Year Review Hard Stop: Enterprise risk assessments cannot be archived and forgotten. They must undergo a formal, documented review at least once every two years, or immediately upon a material trigger event, and the board or delegated committee must review the outcome.

Practice with a Free Mock Test

Ready to test your NISM IFSCA 01: Anti Money Laundering and Counter Terrorist Financing Certification in the IFSC preparation? Start with Test 1 — no payment required.

Notify me when you update the Notes

Free account · No payment needed for Test 1

Create a free PassNISM account

Continue with Google to start a free NISM mock test (Test 1) for this subject, save scores, and compare attempts.

Continue with Google