Effective Bank Secrecy Act/ Anti-Money Laundering Audits Presented by K.D. Mehra, CAMS, CRCM Managing Director September 22, 2011.

Slides:



Advertisements
Similar presentations
MONITORING OF SUBGRANTEES
Advertisements

Module N° 4 – ICAO SSP framework
HIGH-RISK: FOREIGN CORRESPONDENT BANKING
At Hyderabad December 29, 2010 Kunnel Prem. ICP 27 on Insurance Frauds and ICP 28 on AML/CFT.
Effective Internal Control, Establishing an Internal Audit Function, and Compliance Plans 2014 Governmental Accounting For Local Public Health September.
1 Financial Crimes Enforcement Network “FinCEN” Anna Fotias Senior Regulatory Compliance Specialist Office of Regulatory Policy
Anti-Money Laundering and OFAC Compliance for Transfer Agents SSA Annual Conference July 25, 2008.
1 Supplement to the Guideline on Prevention of Money Laundering Hong Kong Monetary Authority 8 June 2004.
THE ANTI-MONEY LAUNDERING ASSOCIATION AML SYSTEMS -- DATA VALIDATION OCTOBER 20, 2011 Kristen J. Stogniew, Shareholder Saltmarsh, Cleaveland & Gund.
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
AML/BSA Certification Program Level I
Quality evaluation and improvement for Internal Audit
Office of Inspector General (OIG) Internal Audit
Internal Control. COSO’s Framework Committee of Sponsoring Organizations 1992 issued a white paper on internal control Since this time, this framework.
Euseden INTERNAL AUDIT & ASSURANCE SERVICES.
E XAMINATION AND E NFORCEMENT I SSUES : B EYOND T HE P ILLARS The AMLA Third Annual Full Day BSA/AML Conference October 4, 2013 Presented by: John M. Geiringer.
Elements of Internal Controls Preventing Fraud, Waste, and Abuse in Urban and Rural Transit Systems.
February 10, 2012 Michelle Hemerley Director, Compliance Consulting
Vendor Risk: Effective Management is Essential
Internal Auditing and Outsourcing
Top 10 Things a New BSA Officer Must Know. What is Associated Risk Group? Premier provider of BSA/AML regulatory best practices to financial institutions.
Compliance System Validation - An Audit Based Approach December 2012 Uday Gulvadi, CPA, CIA, CISA, CAMS Director - Internal Audit, Risk and Compliance.
Revisions to the FFIEC BSA/AML Examination Manual and Federal Reserve Board BSA/AML Examination Findings and Issues Timothy P. Leary Senior Special AML.
1.  The views expressed are those of the speaker and do not necessarily reflect the views of the Federal Reserve Board of Governors, or the Federal Reserve.
Pre-Exam Process  Scope visitation  Prepare request letter  Review prior examination report and workpapers  Access BSA-reporting databases and other.
Regulatory Requirements & Compliance: Ensuring Effective Outcomes Presented By: John E. Palmer, CPA Managing Director/Principal.
Bank Secrecy Act Staying One Step Ahead of Your BSA Examiner September 2009 AMLA Chicago Chapter Event.
Risk Assessments/Risk Appetite Judith Gruenbaum 1.
Basics of OHSAS Occupational Health & Safety Management System
SMS Operation.  Internal safety (SMS) audits are used to ensure that the structure of an SMS is sound.  It is also a formal process to ensure continuous.
Bank Secrecy Act (BSA) Office of Foreign Assets Control (OFAC)
Fiduciary & Investment Risk Management Association
Portfolio Committee Presentation Government printing Works Audit and Compliance 07 May 2013 Presented by: Chief Executive Officer.
Chapter 7 Auditing Internal Control over Financial Reporting McGraw-Hill/Irwin ©2008 The McGraw-Hill Companies, All Rights Reserved.
DEPARTMENT OF MANAGEMENT SERVICES OFFICE OF INSPECTOR GENERAL.
Best Practices for Banking MSBs
Financial Crimes Enforcement Network (FinCEN) Institute of International Bankers Annual Seminar on Regulatory Examination, Risk Management and Compliance.
Private & Confidential1 (SIA) 13 Enterprise Risk Management The Standard should be read in the conjunction with the "Preface to the Standards on Internal.
The views expressed in this presentation do not necessarily reflect those of the Federal Reserve Bank of New York or the Federal Reserve System Association.
Strengths & Weaknesses noted in recent examinations September 16, 2016.
Evaluation of Internal Control System. Learning Objective 1 Contrast management’s need for internal control with the auditor’s need to consider internal.
On-site and Off-site Supervision
Enterprise AML Program Assessment
1 CIVIL AND CRIMINAL PENALTIES FOR MONEY LAUNDERING AND BSA VIOLATIONS  Money Laundering 20 years in prison $500,000 fine Forfeiture of property including.
Effective Bank Secrecy Act/ Anti-Money Laundering Audits Presented by K.D. Mehra, CAMS, CRCM Managing Director September 22, 2011.
BSA PROGRAM REQUIREMENTS.  Written, approved by the board of directors, and noted in the board minutes.  Based on the risk assessment  Fully implemented.
1 A Presentation for Members of the Bank Compliance Association of Connecticut (BCAC) June 12, 2008 Rebecca Williams FDIC Case Manager (Special Activities)
Challenges and Opportunities in the Caribbean Financial Services Sector Rudolph F. Zepeda, Jr. Federal Reserve Bank of Atlanta Miami Branch.
ANTI-MONEY LAUNDERING COMPLIANCE PROGRAM FCM TRAINING
Enterprise Risk Management for US Operations of International Banks Communication and Education.
McGraw-Hill/Irwin © 2003 The McGraw-Hill Companies, Inc., All Rights Reserved. 6-1 Chapter 6 CHAPTER 6 INTERNAL CONTROL IN A FINANCIAL STATEMENT AUDIT.
Agenda  Background and Purpose  Money Laundering and Terrorist Financing  BSA Program Requirements  Risk Based Program Management  Suspicious Activity.
Copyright © 2006 by The McGraw-Hill Companies, Inc. All rights reserved. McGraw-Hill/Irwin 7-1 Chapter Seven Auditing Internal Control over Financial Reporting.
AML Compliance Findings & Observations Wyn Clark U.S. Treasury.
AML O FFICER STR working Committee. S UBJECTS Technical aspects Aspects of day-to-day compliance AML Officer duties & responsibility Challenging facing.
Internal/External Audit and Internal Controls February 23, 2000 David Dudley Federal Reserve Bank of NY.
World Bank International Standards and their Measures for Financial Institutions and Non-Financial Businesses and Professions to Prevent Money Laundering.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Steps in the Transition to an Impact- Focused Audit Function Modifying Procedures, Audit Practices, and Reports to Address Risk Gert van der Linde, World.
Internal Audit Section. Authorized in Section , Florida Statutes Section , Florida Statutes (F.S.), authorizes the Inspector General to review.
Bank Secrecy Act Training For Volunteers
Judy Graham, Program Officer
Hans Nieuwlands CIA CGAP CCSA CEO IIA Netherlands
Compliance Management Systems
The Importance of an AML Programme
Financial Service Centers of America
Legislative Compliance Management Insurance Industry Workshop 1 – 2 November 2005 Bangkok, Thailand Kim Norris Managing Director International Advisory.
How to Survive an External Quality Assessment
Internal Audit’s Role in Preventing Fraud and Corruption
Presentation transcript:

Effective Bank Secrecy Act/ Anti-Money Laundering Audits Presented by K.D. Mehra, CAMS, CRCM Managing Director September 22, 2011

Effective BSA/AML Audits Page Effective Audit Program3 Efficient & Effective Planning5 Audit Frequency7 Areas to Test8 Workpaper Documentation 15 Communicating Results16 Tracking & Monitoring Corrective Actions17 Key Audit Deficiencies18 Audit Resources and Auditor’s Expertise19 Questions?20 TABLE OF CONTENTS 2

Effective Audit Program Appropriate for the bank’s risk profile Cover all applicable regulations and guidance Effective scoping and planning Ensure adequate transaction testing No gaps in the program - program covers all appropriate areas Well-organized workpapers Establish clear paper trails Extracts from a regulatory exam report: Audit did not include steps that would provide appropriate testing, especially of …………. the BSA/AML Program (of the bank) is deemed inadequate……..violation of regulations… Extracts from a regulatory exam report: Audit did not include steps that would provide appropriate testing, especially of …………. the BSA/AML Program (of the bank) is deemed inadequate……..violation of regulations… 3

Effective Audit Program (cont’d) Communicate exceptions effectively –Identify violations and explain risks –Recommend appropriate corrective action Communicate results to Board of Directors/Audit Committee and senior management Document resolution of audit observations not carried to audit report. Track corrective action Extracts from a regulatory exam report: While the BSAIAML audit report was issued to the General Manager, who forwarded a copy to Head Office…. Audit did not report its findings to the board of directors or its audit committee……Consistent with FFIEC guidance, audit results should be reported to the board of directors or a designated committee in a timely manner. Extracts from a regulatory exam report: While the BSAIAML audit report was issued to the General Manager, who forwarded a copy to Head Office…. Audit did not report its findings to the board of directors or its audit committee……Consistent with FFIEC guidance, audit results should be reported to the board of directors or a designated committee in a timely manner. 4

Efficient & Effective Planning Document your understanding of the AML risk profile Identify high risk services, products and clients Identify new regulations and regulatory guidance issued since prior audit Consider results of the most recent audit and regulatory examinations Consider results of other independent or self compliance reviews Identify resolution of past recommendations 5

Efficient & Effective Planning (cont’d) Consider other factors that have changed since prior audit, such as: –Changes to Bank’s risk profile since last audit –Changes in the compliance function since prior audit –IT enhancements introduced –Changes in monitoring parameters –Changes in key compliance and operation staff –New products or services 6

Audit Frequency Not defined in any statute FFIEC BSA/AML Examination Manual incorporates that a ‘sound practice’ is to conduct independent testing every months, ‘commensurate with the BSA/AML risk profile’ Industry practice - annually 7

Areas To Test Adequacy of policies and procedures –Fully addresses all elements of regulations and regulatory guidance –Provides sufficient guidance/instruction –Granular; includes process Ensure comprehensive test procedures –Cover the “other” three pillars of AML Program –Assess the integrity of specific processes/controls/systems/MIS –Assess framework for reporting exceptions to policies/control breakdowns –Test all requirements of applicable regulations 8

Areas To Test (cont’d) Effectiveness of the Bank’s Customer AML Risk Rating Methodology Adequacy of High Risk Customer identification Adequacy of Customer Due Diligence (CDD), and compliance with documented Policies and Procedures Adequacy of Enhanced Due Diligence (EDD), and compliance with documented Policies and Procedures Adequacy of Customer Identification Program (CIP) Adequacy of Internal Controls and Reporting Technical correctness of Suspicious Activity Reporting Appropriateness of SAR sharing with Head Office Record Keeping 9

Areas To Test (cont’d) Investigation and suspicious activity monitoring process –Effectiveness of monitoring system –Automated or manual system –Effectiveness of alerts, filters, rules and routines –Documentation of investigation results –Effectiveness of escalation procedures AML monitoring of Trade Finance activities AML monitoring of Remote Deposit Capture activities AML monitoring of International ACH transactions Compliance with Unlawful Internet Gambling Enforcement Act (UIGEA) 10

Areas To Test (cont’d) Funds Transfer recordkeeping and Travel Rule compliance USA PATRIOT Act - Test for compliance with: –314(a) and 314(b) –311 –312 –313/319 Ensure adequate Transaction Testing Validate corrective action taken to address last audit and examination findings Extracts from a regulatory exam report: Other than obtaining USA PATRIOT Act certifications, ……….risk rating and CDD/EDD were not uniformly applied to Foreign Correspondent Bank…... Extracts from a regulatory exam report: Other than obtaining USA PATRIOT Act certifications, ……….risk rating and CDD/EDD were not uniformly applied to Foreign Correspondent Bank…... 11

Areas To Test (cont’d) Evaluate BSA & OFAC training curriculum and its administration Determine if BSA Officer responsibilities are adequately defined Determine if the OFAC Officer’s responsibilities are adequately defined Extracts from a regulatory exam report: Management has assigned considerable responsibility to the BSA Officer to oversee the execution of the branch's BSAI AML and OFAC programs… management has not introduced measures to monitor the performance of the Officer….. nor adequately defined the performance standards within the job description. Extracts from a regulatory exam report: Management has assigned considerable responsibility to the BSA Officer to oversee the execution of the branch's BSAI AML and OFAC programs… management has not introduced measures to monitor the performance of the Officer….. nor adequately defined the performance standards within the job description. 12

Areas To Test (cont’d) Bank Risk Assessment –Suitability for the bank’s profile –Identification of all key AML risks –Incorporate mitigating factors and controls –Includes all products and services –Includes both qualitative and quantitative analysis –Has been reviewed and approved –Appears to be reasonable Extracts from a regulatory exam report: The branch's BSAIAML and OFAC risk assessment documents do not address the level of inherent risk ….. and are not well-supported by analysis. Descriptive terms such as a "few" are used …. discussion about the quality of mitigating controls is largely absent. Consequently, the risk assessments do not provide meaningful insight. Extracts from a regulatory exam report: The branch's BSAIAML and OFAC risk assessment documents do not address the level of inherent risk ….. and are not well-supported by analysis. Descriptive terms such as a "few" are used …. discussion about the quality of mitigating controls is largely absent. Consequently, the risk assessments do not provide meaningful insight. 13

Areas To Test (cont’d) Cash activities, exemption procedures,CTRs, Monetary Instruments Recordkeeping requirements OFAC –Policy and Procedures –Bank Risk Assessment –Screening of all relationships/activities –Periodic scrub –Adequacy of rationale/documentation for waivers –Integrity and updating of OFAC Filters CMIR and FBAR 14

Workpaper Documentation Maintain adequate documentation to support test work conducted: –Identify total population and your sample –Document the sampling methodology –Document the justification for sample size –Identify attributes tested –Record test results –Reconcile test work with conclusions 15

Communicating Results Discuss materiality of issues uncovered –Violations, exceptions to P&P, deficiencies….. Discuss likely cause(s) of the exceptions/control gaps identified Prioritize audit findings according to materiality Ensure that time frames for corrective actions align with the materiality of the issues concerned Repeat issues should be appropriately highlighted Audit rating should align with the significance of the audit issues/recommendations noted 16

Track & Monitor Corrective Actions Track all actionable issues Document responsibility for resolution of issues Validate closure of audit issues Maintain adequate support on all closed issues Where the corrective action involves the implementation of a new system, validate successful implementation and test for data integrity 17

Key Audit Deficiencies Failure in planning –Serious deficiencies can result in a violation of independent testing component Frequent deficiencies –Insufficient transaction testing –System/ MIS Integrity not tested –Documents reviewed had deficiencies, which audit failed to identify –Observations/findings unresolved – not in report –Failure to require appropriate corrective action –Delayed issuance of audit reports 18

Audit Resources & Auditor’s Expertise Independent Audit within the bank Head office audit Outside audit firm Audit staff should possess the expertise to assess compliance with BSA and OFAC regulations –Technical expertise/ Certification –Specialized training –Familiar with new regulations/guidance –Attendance at industry forums/conferences 19

Questions? K.D. Mehra, CAMS, CRCM Managing Director Accume Partners accumepartners.com Office: Cell: Fax: K.D. Mehra, CAMS, CRCM Managing Director Accume Partners accumepartners.com Office: Cell: Fax: Thank you