+SECTION 1 Internal policies, procedures and controls, risk assessment and staff
---+Article 9 Scope of internal policies, procedures and controls
---+Article 10 Business-wide risk assessment
---+Article 11 Compliance functions
---+Article 12 Awareness of requirements
---+Article 13 Integrity of employees
---+Article 14 Reporting of breaches and protection of reporting persons
---+Article 15 Situation of specific employees
|
SECTION 1 Internal policies, procedures and controls, risk assessment and staff
SECTION 1 Internal policies, procedures and controls, risk assessment and staff
1. Übersicht
| Bezeichnung |
Regulierung |
|
Article 9 Scope of internal policies, procedures and controls
|
Article 9
Scope of internal policies, procedures and controls
1. Obliged entities shall have in place internal policies, procedures and controls in order to ensure compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor and in particular to:
|
(a)
|
mitigate and manage effectively the risks of money laundering and terrorist financing identified at the level of the Union, the Member State and the obliged entity;
|
|
(b)
|
in addition to the obligation to apply targeted financial sanctions, mitigate and manage the risks of non-implementation and evasion of targeted financial sanctions.
|
The policies, procedures and controls referred to in the first subparagraph shall be proportionate to the nature of the business, including its risks and complexity, and the size of the obliged entity and shall cover all the activities of the obliged entity that fall under the scope of this Regulation.
2. The policies, procedures and controls referred to in paragraph 1 shall include:
|
(a)
|
internal policies and procedures, including in particular:
|
(i)
|
the carrying out and updating of the business-wide risk assessment;
|
|
(ii)
|
the obliged entity’s risk management framework;
|
|
(iii)
|
customer due diligence to implement Chapter III of this Regulation, including procedures to determine whether the customer, the beneficial owner, or the person on whose behalf or for the benefit of whom a transaction or activity is being conducted, is a politically exposed person or a family member or person known to be a close associate;
|
|
(iv)
|
reporting of suspicious transactions;
|
|
(v)
|
outsourcing and reliance on customer due diligence performed by other obliged entities;
|
|
(vi)
|
record retention and policies in relation to the processing of personal data pursuant to Articles 76 and 77;
|
|
(vii)
|
the monitoring and management of compliance with such internal policies and procedures in accordance with point (b) of this paragraph, the identification and management of deficiencies and the implementation of remedial actions;
|
|
(viii)
|
the verification, proportionate to the risks associated with the tasks and functions to be performed, when recruiting and assigning staff to certain tasks and functions and when appointing agents and distributors, that those persons are of good repute;
|
|
(ix)
|
the internal communication of the obliged entity’s internal policies, procedures and controls, including to its agents, distributors and service providers involved in the implementation of its AML/CFT policies;
|
|
(x)
|
a policy on the training of employees and, where relevant, agents and distributors with regard to measures in place in the obliged entity to comply with the requirements of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor;
|
|
|
(b)
|
internal controls and an independent audit function to test the internal policies and procedures referred to in point (a) of this paragraph and the controls in place in the obliged entity; in the absence of an independent audit function, obliged entities may have this test carried out by an external expert.
|
The internal policies, procedures and controls set out in the first subparagraph shall be recorded in writing. Internal policies shall be approved by the management body in its management function. Internal procedures and controls shall be approved at least at the level of the compliance manager.
3. The obliged entities shall keep the internal policies, procedures and controls up-to-date, and enhance them where weaknesses are identified.
4. By 10 July 2026, AMLA shall issue guidelines on the elements that obliged entities should take into account, based on the nature of their business, including its risks and complexity, and their size, when deciding on the extent of their internal policies, procedures and controls, in particular as regards the staff allocated to the compliance functions. Those guidelines shall also identify situations where, due to the nature and size of the obliged entity:
|
(i)
|
internal controls are to be organised at the level of the commercial function, of the compliance function and of the audit function;
|
|
(ii)
|
the independent audit function can be carried out by an external expert.
|
|
|
Article 10 Business-wide risk assessment
|
Article 10
Business-wide risk assessment
1. Obliged entities shall take appropriate measures, proportionate to the nature of their business, including its risks and complexity, and their size, to identify and assess the risks of money laundering and terrorist financing to which they are exposed, as well as the risks of non-implementation and evasion of targeted financial sanctions, taking into account at least:
|
(a)
|
the risk variables set out in Annex I and the risk factors set out in Annexes II and III;
|
|
(b)
|
the findings of the risk assessment at Union level conducted by the Commission pursuant to Article 7 of Directive (EU) 2024/1640;
|
|
(c)
|
the findings of the national risk assessments carried out by the Member States pursuant to Article 8 of Directive (EU) 2024/1640, as well as of any relevant sector-specific risk assessment carried out by the Member States;
|
|
(d)
|
relevant information published by international standard setters in the AML/CFT area or, at the level of the Union, relevant publications by the Commission or by AMLA;
|
|
(e)
|
information on money laundering and terrorist financing risks provided by competent authorities;
|
|
(f)
|
information on the customer base.
|
Prior to the launch of new products, services or business practices, including the use of new delivery channels and new or developing technologies, in conjunction with new or pre-existing products and services or before starting to provide an existing service or product to a new customer segment or in a new geographical area, obliged entities shall identify and assess, in particular, the related money laundering and terrorist financing risks and take appropriate measures to manage and mitigate those risks.
2. The business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1 shall be documented, kept up-to-date and regularly reviewed, including where any internal or external events significantly affect the money laundering and terrorist financing risks associated with the activities, products, transactions, delivery channels, customers or geographical zones of activities of the obliged entity. It shall be made available to supervisors upon request.
The business-wide risk assessment shall be drawn up by the compliance officer and approved by the management body in its management function and, where such body exists, communicated to the management body in its supervisory function.
3. With the exception of credit institutions, financial institutions, crowdfunding service providers and crowdfunding intermediaries, supervisors may decide that individual documented business-wide risk assessments are not required where the specific risks inherent in the sector are clear and understood.
4. By 10 July 2026, AMLA shall issue guidelines on the minimum requirements for the content of the business-wide risk assessment drawn up by the obliged entity pursuant to paragraph 1, and on the additional sources of information to be taken into account when carrying out the business-wide risk assessment.
|
|
Article 11 Compliance functions
|
Article 11
1. Obliged entities shall appoint one member of the management body in its management function who shall be responsible for ensuring compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor (‘compliance manager’).
The compliance manager shall ensure that the obliged entity’s internal policies, procedures and controls are consistent with the obliged entity’s risk exposure and that they are implemented. The compliance manager shall also ensure that sufficient human and material resources are allocated to that end. The compliance manager shall be responsible for receiving information on significant or material weaknesses in such policies, procedures and controls.
Where the management body in its management function is a body collectively responsible for its decisions, the compliance manager shall be responsible for assisting and advising it and for preparing the decisions referred to in this Article.
2. Obliged entities shall have a compliance officer, to be appointed by the management body in its management function and with sufficiently high hierarchical standing, who shall be responsible for the policies, procedures and controls in the day-to-day operation of the obliged entity’s AML/CFT requirements, including in relation to the implementation of targeted financial sanctions, and shall be a contact point for competent authorities. The compliance officer shall also be responsible for reporting suspicious transactions to the FIU in accordance with Article 69(6).
In the case of obliged entities subject to checks on their senior management or beneficial owners pursuant to Article 6 of Directive (EU) 2024/1640 or under other Union legal acts, compliance officers shall be subject to verification that they comply with those requirements.
Where justified by the size of the obliged entity and the low risk of its activities, an obliged entity that is part of a group may appoint as its compliance officer an individual who performs that function in another entity within that group.
The compliance officer may only be removed following prior notification to the management body in its management function. The obliged entity shall notify the supervisor of the removal of the compliance officer, specifying whether the decision relates to the carrying out of the tasks assigned under this Regulation. The compliance officer may, on his or her own initiative or upon request, provide information to the supervisor concerning the removal. The supervisor may use that information to perform its tasks under the second subparagraph of this paragraph and under Article 37(4) of Directive (EU) 2024/1640.
3. Obliged entities shall provide the compliance functions with adequate resources, including staff and technology, in proportion to the size, nature and risks of the obliged entity for effective performance of their tasks, and shall ensure that the persons responsible for those functions are granted the powers to propose any measures necessary to ensure the effectiveness of the obliged entity’s internal policies, procedures and controls.
4. Obliged entities shall take measures to ensure that the compliance officer is protected against retaliation, discrimination and any other unfair treatment, and that decisions of the compliance officer are not undermined or unduly influenced by commercial interests of the obliged entity.
5. Obliged entities shall ensure that the compliance officer and the person responsible for the audit function referred to in Article 9(2), point (b), can report directly to the management body in its management function and, where such a body exists, to the management body in its supervisory function independently, and can raise concerns and warn the management body, where specific risk developments affect or may affect the obliged entity.
Obliged entities shall ensure that the persons directly or indirectly participating in implementation of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, have access to all information and data necessary to perform their tasks.
6. The compliance manager shall regularly report on the implementation of the obliged entity’s internal policies, procedures and controls to the management body. In particular, the compliance manager shall submit once a year, or, where appropriate, more frequently, to the management body a report on the implementation of the obliged entity’s internal policies, procedures and controls drawn up by the compliance officer, and shall keep that body informed of the outcome of any reviews. The compliance manager shall take the necessary actions to remedy in a timely manner any deficiencies identified.
7. Where the nature of the business of the obliged entity, including its risks and complexity, and its size justify it, the functions of the compliance manager and the compliance officer may be performed by the same natural person. Those functions may be cumulated with other functions.
Where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only, that person shall be responsible for performing the tasks under this Article.
|
|
Article 12 Awareness of requirements
|
Article 12
Awareness of requirements
Obliged entities shall take measures to ensure that their employees or persons in comparable positions whose function so requires, including their agents and distributors are aware of the requirements arising from this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and of the business-wide risk assessment, internal policies, procedures and controls in place in the obliged entity, including in relation to the processing of personal data for the purposes of this Regulation.
The measures referred to in the first paragraph shall include the participation of employees or persons in comparable positions, including agents and distributors, in specific, ongoing training programmes to help them recognise operations which may be related to money laundering or terrorist financing and to instruct them as to how to proceed in such cases. Such training programmes shall be appropriate to their functions or activities and to the risks of money laundering and terrorist financing to which the obliged entity is exposed, and shall be duly documented.
|
|
Article 13 Integrity of employees
|
Article 13
1. Any employee, or person in a comparable position, including agents and distributors, directly participating in the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall undergo an assessment commensurate with the risks associated with the tasks performed and whose content is approved by the compliance officer of:
|
(a)
|
individual skills, knowledge and expertise to carry out their functions effectively;
|
|
(b)
|
good repute, honesty and integrity.
|
The assessment referred to in the first subparagraph shall be performed prior to taking up of activities by the employee or person in a comparable position, including agents and distributors, and shall be regularly repeated. The intensity of the subsequent assessments shall be determined on the basis of the tasks entrusted to the person and risks associated with the function they perform.
2. Employees, or persons in comparable positions, including agents and distributors, entrusted with tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, shall inform the compliance officer of any close private or professional relationship established with the obliged entity’s customers or prospective customers and shall be prevented from undertaking any tasks related to the obliged entity’s compliance in relation to those customers.
3. Obliged entities shall have in place procedures to prevent and manage conflicts of interest that may affect the carrying out of tasks related to the obliged entity’s compliance with this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor.
4. This Article shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.
|
|
Article 14 Reporting of breaches and protection of reporting persons
|
Article 14
Reporting of breaches and protection of reporting persons
1. Directive (EU) 2019/1937 of the European Parliament and of the Council (41) shall apply to the reporting of breaches of this Regulation, Regulation (EU) 2023/1113 and any administrative act issued by any supervisor, and to the protection of persons reporting such breaches.
2. Obliged entities shall establish internal reporting channels that meet the requirements set out in Directive (EU) 2019/1937.
3. Paragraph 2 shall not apply where the obliged entity is a natural person or a legal person whose activities are performed by one natural person only.
|
|
Article 15 Situation of specific employees
|
Article 15
Situation of specific employees
Where a natural person falling within any of the categories listed in Article 3, point (3) performs professional activities as an employee of a legal person, the requirements laid down in this Regulation shall apply to that legal person rather than to the natural person.
|
1.1 Referenzen
1.2 Identifizierte Anforderungen
1.3 Related Standards
2. Identifizierte Anforderungen
Anforderungen
| Source |
Anforderung |
3. Related Standards
Standards
| Source |
Anforderung |
|