Settlement Agreement between the Central Bank of Ireland and Ulster Bank Ireland DAC (formerly Ulster Bank Ireland Limited)

Similar documents
Settlement Agreement between the Central Bank of Ireland and Intesa Sanpaolo Life dac

Re: Compliance with the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010 ( CJA 2010 )

Anti-Money Laundering Update Domestic and European developments

Settlement Agreement between the Central Bank of Ireland and Bank of Montreal Ireland p.l.c.

Criminal Justice (Money Laundering and Terrorist Financing) (Amendment) Act 2018

FINAL NOTICE. Abbey National plc. Abbey National House 2 Triton Square Regent's Place London NW1 3AN. Date: 9 December 2003

Anti-Money Laundering and Counter Terrorism

FINAL NOTICE. Ground Floor, 10 Chiswell Street, London, EC1Y 4UQ

AML / CFT Anti-money laundering and countering financing of terrorism. Designated Business Group Scope Guideline Updated in December 2017

HANDBOOK FOR FINANCIAL SERVICES BUSINESSES ON COUNTERING FINANCIAL CRIME AND TERRORIST FINANCING

Intermediary Times. Welcome to the Intermediary Times Special Edition. Issue Special Edition

Enforcement Action. The Central Bank of Ireland. and. PartnerRe Ireland Insurance dac Partner Reinsurance Europe SE

PART VI MUTUAL FUNDS AND MUTUAL FUNDS ADMINISTRATORS SECTOR SPECIFIC AML/CFT GUIDANCE NOTES

Regulatory Update. MAS Circular to FMCs on Enhancing AML/CFT Measures ( CMI 03/2015 ) 9 November Overview

ANNEX III Sector-Specific Guidance Notes for Investment Business Providers, Investment Funds and Fund Administrators

AML/CTF and Sanctions Policy

Settlement Agreement between the Central Bank of Ireland. and. Springboard Mortgages Limited trading as Springboard Mortgages

GENERAL SCHEME OF A CRIMINAL JUSTICE (MONEY LAUNDERING AND TERRORIST FINANCING) (AMENDMENT) BILL

CONSULTATION PAPER P June Proposed Amendments To The Monetary Authority Of Singapore Act And Trust Companies Act

CONTINENTAL REINSURANCE ( C Re ) ANTI-MONEY LAUDERING/COUNTERING THE FINANCING OF TERRORISM (AML/CFT) POLICY

TRUST COMPANY BUSINESS

JOINT RESOLUTION OF THE GOVERNOR OF BANK OF MONGOLIA AND CHAIR OF THE FINANCIAL REGULATORY COMMISSION

Discontinuing Your Business Relationship with AML Deficient Investors

Financial Crime Governance, Risk and Compliance Fund Managers & Fund Administrators. Thematic Review 2017

R.S.A. c. P98 Anti-Money Laundering and Terrorist Financing Code R.R.A. P98-5. Revised Regulations of Anguilla: P98-5

HANDBOOK FOR FINANCIAL SERVICES BUSINESSES ON COUNTERING FINANCIAL CRIME AND TERRORIST FINANCING. 15 December 2007 (updated July 2016)

Attachment: References for formulating a list of countries/regions with higher risks of money

Ministerial Regulation on Customer Due Diligence B.E (2013)

Number 26 of Criminal Justice (Money Laundering and Terrorist Financing) (Amendment) Act 2018

STATUTORY INSTRUMENTS. S.I. No. 60 of 2017 CENTRAL BANK (SUPERVISION AND ENFORCEMENT) ACT 2013 (SECTION 48(1)) (INVESTMENT FIRMS) REGULATIONS 2017

TRUST COMPANY BUSINESS

ANTI-MONEY LAUNDERING IN

FINAL NOTICE. Sonali Bank (UK) Ltd, Osborn Street, London E1 6TD. (1) imposes on Steven Smith a financial penalty of 17,900; and

Webinar 01: AML/CFT Requirements Overview. 4 th July 2018

THE GAZETTE PUBLISHED BY AUTHORITY

STATUTORY INSTRUMENTS. S.I. No. 604 of 2017 CENTRAL BANK (SUPERVISION AND ENFORCEMENT) ACT 2013 (SECTION 48(1)) (INVESTMENT FIRMS) REGULATIONS 2017

EAA issues guidelines on compliance of anti-money laundering and counter-terrorist financing requirements for the estate agency sector

FINANCIAL SERVICES. Transposition of the Fourth AntiMoney Laundering Directive. by Damien Barnaville

July 2017 CONSULTATION DRAFT. Guidelines on. Anti-Money Laundering. and. Counter-Terrorist Financing for Professional Accountants

Decree No. 67/2018 Coll.

FINANCIAL CRIME GUIDE (AMENDMENT NO 3) INSTRUMENT 2015

(Revised: 7 December 2016)

SFC reprimands and fines Ping An of China Securities (Hong Kong) Company Limited $6 million over internal control failures

ANTI-MONEY LAUNDERING POLICIES, CONTROLS AND PROCEDURES

TRUST COMPANY BUSINESS

CAYMAN ISLANDS MONETARY AUTHORITY

AML/CFT Phase II. Kate Reid NZLS CLE live stream 28 November /11/2017. Check it out by logging in at:

DIRECTIVE NO.DO1-2005/CDD

Guidelines on Anti-Money Laundering and Countering Financing of Terrorism

COMMISSION DELEGATED REGULATION (EU) /... of

Anti-Money Laundering & Countering the Financing of Terrorism (AML/CFT) - Deirdre. Lowry/Suzanne Geraghty/Orna McNamara

HANDBOOK FOR LEGAL PROFESSIONALS, ACCOUNTANTS AND ESTATE AGENTS ON COUNTERING FINANCIAL CRIME AND TERRORIST FINANCING

The Handbook. Sator Regulatory Consulting Limited. Helen M Hatton, Managing Director

AUSTRAC Guidance Note. Risk management and AML/CTF programs

Policy on Anti Money Laundering and Countering Terrorist Financing

Anti-Money Laundering and Countering the Financing of Terrorism Guidelines for the Financial Sector

FATF Mutual Evaluation of Ireland 2017

FINAL NOTICE You confirmed on 27 August 2004 that you do not intend to refer the matter to the Financial Services and Markets Tribunal.

ANTI-MONEY LAUNDERING ( AML ) POLICY OF BullM Global Limited

United Republic of Tanzania Financial Intelligence Unit Anti Money Laundering and Counter Terrorist Financing Guidelines to Insurers

VIRGIN ISLANDS ANTI-MONEY LAUNDERING AND TERRORIST FINANCING CODE OF PRACTICE, 2008

gamevy Anti- Money Laundering Detecting and Preventing Financial Crime Training for Gamevy

Financial Crime update. 12 September 2017

AML/CFT IMPLEMENTATION IN THE ESAAMLG REGION

FINAL NOTICE Alpari confirmed on 22 April 2010 that it would not refer the matter to the Upper Tribunal (Tax and Chancery Chamber).

SUMMARY Seychelles National Risk Assessment Report for Money Laundering & Terrorist Financing 2017

Guidance on Assessment of Money Laundering and Terrorism Financing Risks and Formulation of Related Control Programs by Futures Commission Merchants

Anti-Money Laundering Policy June 2017

OPERATING POLICIES AND PROCEDURES Chapter 12 Due Diligence Policy and Procedures. Effective from 28 November 2016

Anti-Money Laundering and Countering the Financing of Terrorism Guidelines for the Financial Sector

TRUST COMPANY BUSINESS

Guidelines for Electronic Retail Payment Services (ERPS 2)

Intermediary Times. Issue 5. Welcome to the Intermediary Times. December Welcome to the final edition of the Intermediary Times for 2018.

VIRGIN ISLANDS ANTI-MONEY LAUNDERING AND TERRORIST FINANCING CODE OF PRACTICE, 2008 ARRANGEMENT OF SECTIONS PART I

SUBSIDIARY LEGISLATION

Anti-money laundering and countering the financing of terrorism the Reserve Bank s responsibilities and approach

FEDERAL DEPOSIT INSURANCE CORPORATION WASHINGTON, D.C. ) ) ) ) ) ) ) ) ) )

Anti-Money Laundering and Counter Financing of Terrorism (AML/CFT) Digital Currencies (Sector 6) Exposure Draft

Strict implementation of laws, improving vigilance and enhancing due diligence

THE GAZETTE PUBLISHED BY AUTHORITY

FINAL NOTICE. St James s Place International plc. St James s Place House, Dollar Street, Cirencester, Gloucestershire, GL7 2AQ. Date: 24 November 2003

FINAL NOTICE. Nomura House, 1 St Martin s-le-grand, London EC1A 4NP

financial intelligence centre REPUBLIC OF SOUTH AFRICA Financial Intelligence Centre FAIS Workshop Presented by The Financial Intelligence Centre

FINAL NOTICE You have confirmed that you do not intend to refer the matter to the Financial Services and Markets Tribunal.

JC/GL/2017/ September Final Guidelines

AML/CFT TRAINING FOR ACCOUNTANTS AND AUDITORS

GUIDELINES ON RISK-BASED APPROACH (RBA) FOR THE PURPOSE OF ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM (AML/CFT)

ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM HANDBOOK JANUARY 2018

CONSULTATION PAPER NO.120

OVERVIEW OF THE QFC AML REGIME

Al Rajhi Bank Malaysia Anti-Money Laundering Questionnaire

F o l l o w - Up R e p o r t. Anti-money laundering and counter-terrorist financing measures. Uganda

FINCEN GUIDANCE. Under 31 CFR , an MSB s AML program must, at a minimum:

The Risk Factors Guidelines

Note on the application of the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017

GUIDELINES TO MAS NOTICE 314 ON PREVENTION OF MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM

ANTI-MONEY LAUNDERING REGULATIONS, 2011 ARRANGEMENT OF REGULATIONS

Regulatory Investigations and the Consumer Protection Risk Assessment

GUIDELINES ON ANTI-MONEY LAUNDERING AND COUNTER FINANCING OF TERRORISM (AML/CFT) INSURANCE AND TAKAFUL SECTORS

NOTICE TO BANKS MONETARY AUTHORITY OF SINGAPORE ACT, CAP. 186

Transcription:

Settlement Agreement between the Central Bank of Ireland and Ulster Bank Ireland DAC (formerly Ulster Bank Ireland Limited) Ulster Bank Ireland DAC fined 3,325,000 by the Central Bank of Ireland in respect of anti-money laundering and terrorist financing failures The Central Bank of Ireland (the Central Bank ) fined Ulster Bank Ireland DAC ( Ulster Bank Ireland ) and reprimanded it for breaches of the Criminal Justice (Money Laundering & Terrorist Financing) Act 2010 (the CJA 2010 ). The breaches have been admitted by Ulster Bank Ireland. The CJA 2010 requires credit and financial institutions to adopt and implement adequate policies and procedures appropriate to their business to prevent and detect the commission of money laundering and terrorist financing. The breaches occurred over a six year period, from enactment of the CJA 2010 on 15 July 2010 until 2016. The breaches identified significant failings in Ulster Bank Ireland s anti-money laundering/countering the financing of terrorism ( AML/CFT ) framework and procedures in respect of: Outsourcing: governance and control of AML/CFT outsourcing Risk Assessment: assessment of money laundering/terrorist financing ( ML/TF ) risks specific to its business and the relevant mitigating systems and controls Customer due diligence: identification and verification of existing customers who predated the Irish AML/CFT laws effected in May 1995 ( Pre-95 customers ) 1

The Central Bank also identified areas of non-compliance in respect of trade finance procedure manuals, adherence to internal procedures, AML/CFT training of non-executive directors and reliance on third parties in respect of customer due diligence ( CDD ). Director of Enforcement, Derville Rowland, said: Robust frameworks, systems and controls must be the cornerstone of credit and financial insititutions compliance with anti-money laundering legislation. Weaknesses in anti-money laundering controls expose the Irish and global financial system to abuse and threaten to undermine its stability. In today s global environment, the threat of money laundering and terrorist financing requires credit and financial institutions operating in Ireland to rise to the challenge of managing and mitigating these risks. It is incumbent upon our retail banks to counter the threat of money laundering through robust antimoney laundering frameworks, systems and controls. Retail banks are the lifeblood of the Irish financial system, providing essential banking and financial services for millions of consumers and businesses daily. The sheer volume and range of transactions processed exposes the Irish retail banking sector to an increased threat of money laundering and terrorist financing. Retail banks must counter this increased threat head on. Ulster Bank Ireland s breaches are especially concerning as they point to unacceptable weaknesses in key aspects of its anti-money laundering framework, systems and controls over an extended period of time. As one of the largest retail banks in Ireland, Ulster Bank Ireland provides a gateway to the financial system for more than one million customers through its extensive network of branches, online and telephone banking. Therefore, it is imperative that it vigorously applies the highest levels of anti-money laundering compliance in order to protect, not only itself, but its customers and the wider financial system. Firms play a vital role in assisting An Garda Síochána and the Revenue Commissioners in their investigation of money laundering and terrorist financing through the detection and reporting of suspicious activity. This case also highlights that firms who outsource must have in place appropriate controls to oversee outsourced activity, which must be documented and clear. This is even more critical where the outsourcing is within the group because these situations tend to foster a misplaced sense of 2

complacency regarding regulatory compliance. contingent upon a firm s commitment to observing them. Of course, the effectiveness of such controls is When the Central Bank identifies a failure to deal with these risks we will not hesitate to enforce compliance. The fine imposed on Ulster Bank Ireland demonstrates that the Central Bank will take action where anti-money laundering frameworks and controls are not sufficiently robust. The enforcement of anti-money laundering governance and controls is and will continue to be a priority for the Central Bank. BACKGROUND Ulster Bank Ireland is authorised to carry on banking business in Ireland under Section 9 of the Central Bank Act 1971. It is one of the largest banks in Ireland with over 110 branches and 1.1 million customers. Its principal activities consist of retail and commercial banking. Since 15 July 2010, Ulster Bank Ireland has been required to comply with the CJA 2010. The Central Bank has responsibility for securing the compliance of credit and financial firms with the CJA 2010. During 2012 and 2013, the Central Bank conducted a review of Ulster Bank Ireland s compliance with the CJA 2010. This review identified of a number of issues in respect of Ulster Bank Ireland s compliance with the CJA 2010. During this period, Ulster Bank Ireland also self-reported a number of issues of non-compliance with the CJA 2010. In December 2013, the Central Bank initiated engagement with Ulster Bank Ireland in respect of remediation efforts in areas where noncompliance with the CJA 2010 had been identified. On 20 March 2015, the Central Bank notified Ulster Bank Ireland of its decision to commence an investigation into suspected breaches of the CJA 2010. PRESCRIBED CONTRAVENTIONS The Central Bank s investigation identified 8 breaches of the CJA 2010, namely: Poor controls over AML/CFT outsourcing Ulster Bank Ireland is part of a group of companies headed by Royal Bank of Scotland plc ( RBS ) as the ultimate holding company. Ulster Bank Ireland outsources 25 AML/CFT activities mainly to other 3

entities in the RBS group. The outsourced activities involve a wide range of key AML/CFT obligations under the CJA 2010. The Central Bank identified two significant failings in respect of Ulster Bank Ireland s governance and oversight of those outsourced AML/CFT activities between 15 July 2010 and 15 October 2016. Firstly, Ulster Bank Ireland failed to put an outsourcing policy in place from 15 July 2010 until June 2011 (an 11 month period). Secondly, Ulster Bank Ireland failed to put a service level agreement ( SLA ) in place for 19 of the 25 outsourced activities when the outsourcing commenced, as required by its internal policy. Of the 19 activites which were not covered by SLAs, the average duration of the gap was 2 years, with 13 of those 19 activities not covered for a period of 3 years and longer. Given Ulster Bank Ireland s extensive reliance on AML/CFT outsourcing, the absence of these two important controls over outsourcing exposed it to an unacceptable risk that an outsourcing failure would prevent it from meeting its CJA 2010 obligations. An outsourcing policy is a key control that sets out the governance of outsourcing arrangements in order to ensure that a firm has the necessary oversight and control, including how the arrangement is set up and monitored, who is responsible for monitoring, and what happens in the case of an expected or unexpected termination of the services. SLAs provide further control in the form of a framework or contract for an individual outsourcing relationship that sets out the rights and duties of the parties and usually specifies agreed performance levels. Failure to conduct ML/TF risk assessment A thorough assessment of ML/TF risk exposure is fundamental to a robust AML/CFT framework as it allows a firm to identify the particular ML/TF risks to which it is exposed as a result of its business model and to inform the development of appropriate AML/CFT policies and procedures, and the design of proportionate systems. The risk assessment must be proportionate to the nature, scale and complexity of a firm s activities. Insufficient or absent ML/TF risk management policies, procedures and processes exposes firms to significant risks, including not only financial, but also reputational, operational and compliance risks. Ulster Bank Ireland failed to conduct an assessment of the ML/TF risks of its business for a period of over 2 years. Furthermore, until April 2014, Ulster Bank Ireland s risk assessment was inadequate in that it failed to provide any quantitative and/or qualitative evaluation of its exposure to the identified risk factors. 4

Customer due diligence The CJA 2010 requires firms to complete CDD to identify and verify customers at certain times, including when firms take on new customers and where they have concerns relating to documents previously obtained for the purposes of identifying and verifying customers. The CDD process is at the heart of AML compliance and ML/TF prevention in financial services and is designed to ensure that firms know their customer and are able to predict typical customer behaviour. This critical information allows firms to properly fulfil their obligations to monitor, identify and report unusual and potentially suspicious activity. The Central Bank identified a number of failings in Ulster Bank Ireland s procedures and systems in respect of CDD, namely: Section 33(1)(d) of the CJA 2010 requires firms to complete CDD where there are reasonable grounds to doubt that existing customer documents and information are accurate and adequate for the purposes of verifying or confirming customer identity. When the CJA 2010 was introduced, Ulster Bank Ireland needed to formally review and confirm the adequacy of the documents and information it held for Pre-95 customers to determine if Section 33(1)(d) required completion of CDD, however, Ulster Bank Ireland failed to do this; Ulster Bank Ireland provided new products to 64,900 Pre-95 customers without completing CDD in circumstances where section 33(1)(d) of the CJA applied; Customer identification markers which indicated that customers were exempt from CDD remained on Ulster Bank Ireland s system contrary to documented procedures; and Ulster Bank Ireland relied on a third party to conduct CDD where the contractual arrangement in place did not satisfy the conditions in Section 40 of the CJA 2010. Section 40 permits firms to rely on third parties to conduct CDD, but only if there is an arrangement in place which stipulates that the firm may rely on the third party to conduct CDD and the firm is satisfied that, when requested, the third party will forward the documents or information obtained when conducting CDD to the firm as soon as practicable. 5

Guidance in relation to identification of suspicious activity Detection and prevention of ML/TF depends on the timely identification and subsequent reporting of suspicious activity. It is vital that all employees and officers in the financial sector, including board members, are provided with training on the law relating to AML/CFT and their legal duty to report suspicious activity. In this regard, the Central Bank identified the following specific failings in Ulster Bank Ireland s procedures: Ulster Bank Ireland failed to demonstrate that training was provided to its non-executive directors on the CJA 2010 until 2013, and in particular, it failed to provide any training to its non-executive directors on identifying suspicious transactions and activities until March 2014. This failure occurred despite the issue of a Dear CEO letter by the Central Bank in October 2012, in which the Central Bank noted that it had identified deficiencies in AML/CFT training across firms, including that of board members and senior management; and Ulster Bank Ireland failed to have adequate policies and procedures specific to trade finance and in particular, until February 2015 it failed to include guidance in the procedure manuals for its trade finance business on the identification of potentially suspicious activity in that business i.e. trade finance red flags. PENALTY DECISION FACTORS In deciding the appropriate penalty to impose, the Central Bank considered the following matters: Seriousness with which the conduct is viewed, particularly given the Firm s central role in the financial services system and the high risk nature of the Firm s business in terms of ML/TF. The extended period of time over which the breaches occurred, spanning the period 15 July 2010 up until 2016 and the fact that the duration of the contraventions on average persisted for more than 4 years. The co-operation of the Firm during the investigation and in settling at an early stage in the Central Bank s Administrative Sanctions Procedure. The actions taken by the Firm to remediate the breaches. The fact that all bar 1 breach continued post the enhancement of the Central Bank s sanctioning powers under the Central Bank (Supervision and Enforcement) Act 2013. 6

The Central Bank confirms its investigation into Ulster Bank Ireland in respect of this matter is closed. - End - 7

NOTES TO EDITORS The fine reflects the application of the maximum percentage settlement discount of 30%, as per the Early Discount Scheme set out in the Central Bank s Outline of the Administrative Sanctions Procedure which is here. 8