Chapter 4 · Countering Money Laundering — The Preventive Framework

15 of 50 exam questions (~30%) — THE HEAVIEST CHAPTER · RBA · CDD/EDD/SDD · BO · PEPs · SARs · MLRO · monitoring
← Back to quiz
Why this chapter matters. 15 of 50 exam questions (~30% — the biggest chapter by far). If you only revise one CFC chapter, revise this one. This is the OPERATIONAL CORE of a firm's AML programme. Trap zones: CDD trigger thresholds (€15,000 occasional / new relationship / suspicion / doubt about data), BO threshold is 25% ownership OR control (FATF baseline; lower for higher-risk), EDD is MANDATORY for PEPs, high-risk 3rd countries, correspondent banking, complex/unusual, non-face-to-face (though tech has softened this), PEP status persists ≥12 months after leaving office, SDD requires ongoing risk validation — not a "set and forget", MLRO has SOLE authority to file SARs (staff report internally). Ch 4 is where the exam turns into practical operational muscle-memory.

4.1 RBA — the operational core

RBA in practice — the foundational principle syllabus 1.1

Under the FATF-endorsed risk-based approach, a firm must:

  1. Identify + assess its ML/TF risks (customers, geographies, products, delivery channels, transactions)
  2. Design controls proportionate to those risks
  3. Document + evidence the risk assessment + control mapping
  4. Review + update periodically (annually + on trigger events)

See [[Ch 1]] for the RBA cascade (FATF → NRA → sector → firm → customer).

Firm-wide risk assessment (FWRA) syllabus 1.2

Every regulated firm must document a FWRA covering:

  • Customer risk factors
  • Geographic risk factors
  • Product / service risk factors
  • Delivery channel risk factors
  • Transaction risk factors

Feeds directly into the firm's policies, controls + customer risk-rating models. Not a compliance box-tick — supervisors expect it to genuinely drive control design.

The four core risk-factor categories syllabus 1.3-1.5

CategoryHigher-risk indicators
CustomerPEPs · complex ownership · cash-intensive business · sanctioned nationality · adverse media
GeographicFATF grey/black list · sanctioned jurisdictions · Corruption Perceptions Index low · offshore/secrecy jurisdictions
Product / servicePrivate banking · correspondent banking · trade finance · high-value goods · crypto
Delivery channelNon-face-to-face · via 3rd-party intermediary · anonymous instruments
Trap: candidates memorise "customer risk" only. All four dimensions must be assessed for a complete FWRA + individual customer rating.

4.2 Standard CDD — the four components

Standard CDD — the four required components syllabus 2.1

Standard Customer Due Diligence has four components (FATF Rec 10):

  1. Identify the customer
  2. Verify the customer's identity using reliable, independent source data
  3. Identify + verify the beneficial owner (see §4.3)
  4. Understand purpose + intended nature of the business relationship

Plus ongoing monitoring throughout the relationship (see §4.6).

CDD timing — the trigger events syllabus 2.2

CDD must be applied when:

  • Establishing a new business relationship
  • Occasional transaction ≥ €15,000 (or equivalent — the FATF baseline)
  • Wire transfer ≥ €1,000 (with Travel Rule info)
  • Suspicion of ML/TF
  • Doubt about previously obtained identification data

Verification must generally be complete BEFORE establishing the relationship (some limited exceptions for continuity of business where interrupted verification wouldn't work, subject to controls).

Trap: €15,000 is the OCCASIONAL transaction threshold, not the CDD threshold generally. New relationships trigger CDD regardless of amount.

"Reliable, independent source" — what qualifies syllabus 2.3

Identity data must be verified from a source that is:

  • Reliable — trustworthy, low risk of manipulation
  • Independent — not created or controlled by the customer

Common qualifying sources:

  • Government-issued passport / national ID
  • Driving licence
  • Certified extract from a credit bureau
  • Utility bill (last 3 months) for address
  • Companies House / equivalent for corporate customers
  • Trusted digital identity schemes (UK GOV.UK Verify, EU eIDAS)

Non-face-to-face verification syllabus 2.4

Historically flagged as higher-risk (impersonation risk). Modern position:

  • Still a risk factor to consider in overall customer rating
  • Mitigation: video ID verification, biometric matching, liveness checks, government digital ID
  • Regulators (FCA, EU) now recognise robust remote verification as equivalent to in-person

Firms rely heavily on RegTech providers (Onfido, Jumio, iProov, Yoti) for automated remote verification at scale.

4.3 Beneficial ownership

Beneficial owner — the definition syllabus 3.1

The beneficial owner is the natural person who ultimately owns or controls the customer, or on whose behalf a transaction is conducted.

Two limbs:

  1. Ownership — direct or indirect shareholding above threshold
  2. Control — even without ownership, controlling directors, veto rights, dominant influence

Always a natural person — never a company or trust structure.

BO threshold — the 25% benchmark syllabus 3.2

FATF baseline: identify natural persons owning or controlling 25% or more of the customer entity (directly or indirectly).

Key caveats:

  • 25% is a default — firms should apply a LOWER threshold for higher-risk cases (per their RBA)
  • Some jurisdictions set lower defaults (e.g. certain sensitive sectors)
  • UK PSC register uses 25% for the notification threshold
Trap: 25% is NOT a hard ceiling. It's a default that firms can + should lower where risk indicators warrant it.

When no natural person can be identified syllabus 3.3

Where no natural person meets the ownership threshold AND no controlling individual can be identified, firms should:

  1. Consider whether the ownership structure has been deliberately obscured (red flag)
  2. As a fallback, treat senior managing official(s) as beneficial owners
  3. Document the analysis + rationale

Never leave a corporate customer without an identified beneficial owner — the file must show either the BO or a documented reason why the senior managing official is being used instead.

BO in trusts syllabus 3.4

Trusts have multiple parties, ALL of whom are beneficial owners for AML purposes:

  • Settlor — the person who created the trust
  • Trustee(s) — the person(s) holding legal title
  • Protector — where one exists
  • Beneficiaries — named beneficiaries or class
  • Any other individual exercising ultimate effective control

UK: Trust Registration Service (TRS) — HMRC register requiring most trusts (including many non-taxable) to register + disclose these parties. In force since 2017, extended by 5MLD from 2020.

Complex ownership structures syllabus 3.5

Multi-layered ownership (parent → sub → sub → …) requires calculating indirect BO across the chain. Techniques:

  • Multiply through the chain (50% × 50% = 25%)
  • Consider control separately from ownership (voting rights, board appointments)
  • Watch for nominee arrangements — the nominee is legal owner, not BO
  • Watch for bearer shares — historically anonymous (banned in many jurisdictions post-2015)

4.4 Enhanced Due Diligence (EDD) + PEPs

EDD — the mandatory trigger categories syllabus 4.1

EDD is mandatory for:

  • PEPs (foreign + domestic + international organisation)
  • Customers established in high-risk third countries (FATF grey/black list; EU Commission list)
  • Correspondent banking relationships (see [[Ch 3]])
  • Complex or unusually large transactions
  • Transactions with no apparent economic or lawful purpose
  • Higher risk identified by firm's RBA

Plus discretionary EDD for any relationship the firm rates high-risk on its own metrics.

EDD measures — what "enhanced" means syllabus 4.2

EDD typically includes:

  1. Additional identity information beyond standard CDD (source of funds, source of wealth)
  2. Enhanced adverse-media + sanctions screening
  3. Senior management approval to establish or continue the relationship
  4. More frequent CDD refresh (annually or more)
  5. Enhanced ongoing monitoring — lower alert thresholds, more manual review
  6. On-site verification for corporate customers where appropriate

Source of wealth vs source of funds: SoW = how the customer accumulated total assets (career, inheritance); SoF = where a specific transaction's money came from. Both required for EDD.

PEP — the definition syllabus 4.3

A politically exposed person is a natural person who is or has been entrusted with a prominent public function. Categories:

  • Foreign PEP — non-domestic prominent public function
  • Domestic PEP — in your own jurisdiction (broadened by 4MLD)
  • International organisation PEP — UN, IMF, WTO senior officials

Prominent functions include: heads of state, senior ministers, senior judiciary, senior military, senior state-enterprise executives, ambassadors, senior political-party officials.

Family members + close associates of a PEP are also subject to EDD.

Domestic vs foreign PEPs syllabus 4.3

Historically only foreign PEPs required EDD (assumption: domestic corruption easier to detect). 4MLD (2015) extended EDD to domestic PEPs too.

Modern practice: both categories screened; risk-rating may still differ based on jurisdiction, role, adverse media.

PEP status duration syllabus 4.4

PEP status persists for at least 12 months after the person leaves office. Beyond 12 months, firms may de-classify but only after a risk assessment — some individuals remain higher-risk indefinitely (former heads of state, individuals still influential in politics).

UK FCA guidance (FG17/6): apply a proportionate approach — most former PEPs need not be treated the same as active PEPs after de-classification.

Trap: candidates think PEP status ends the day the person leaves office. Wrong — minimum 12 months, potentially longer based on risk.

4.5 Simplified Due Diligence (SDD)

SDD — when it applies syllabus 5.1

Simplified Due Diligence is permitted where the firm has determined the relationship or transaction presents lower risk. Examples of lower-risk factors:

  • Listed companies subject to disclosure requirements
  • Domestic public authorities
  • Regulated firms in equivalent jurisdictions
  • Products with low ML risk (e.g. certain life insurance, low-value e-money)
  • Customers resident in low-risk jurisdictions

SDD is not a CDD exemption — the four CDD components still apply, but the depth and frequency of verification can be lower.

SDD requires ongoing risk validation syllabus 5.2

SDD is not "set and forget." If risk indicators change (customer moves to a higher-risk jurisdiction, adverse media surfaces, unusual transaction pattern), the firm must upgrade to standard or enhanced CDD.

4.6 Ongoing monitoring + refresh

Ongoing monitoring — two arms syllabus 6.1

Ongoing monitoring has two arms:

  1. Transaction scrutiny — analysing transactions to ensure consistency with what the firm knows about the customer + business/risk profile
  2. CDD refresh — periodic review + update of customer information + risk rating

Typical refresh cadence: low-risk every 3-5 years, standard 2-3 years, high-risk annually or more.

Transaction monitoring systems syllabus 6.2

Firms deploy transaction monitoring systems (TMS) that:

  • Score transactions against typology scenarios (structuring, wire circulation, TBML patterns)
  • Generate alerts for human review
  • Feed disposition data back to tune scenarios

Modern hybrid: rules + ML models (see [[Ch 7]]). Alert false-positive rates are historically 90%+ — a major cost driver.

4.7 SARs + the MLRO role

SARs — the reporting mechanism syllabus 7.1

Suspicious Activity Report (SAR) — a report filed by a regulated firm to the national FIU when the firm knows / suspects / has reasonable grounds to suspect ML or TF.

Naming conventions vary:

  • UK / Australia: SAR
  • US: SAR (via FinCEN) + CTR (Currency Transaction Report — mandatory for cash transactions ≥$10,000)
  • Continental Europe: STR (Suspicious Transaction Report)
  • UAE: STR (to FIU-UAE)

Filed to the national FIU: UK NCA, US FinCEN, France TRACFIN, UAE FIU, etc.

DAML — Defence Against ML request syllabus 7.2

A specific type of SAR that also seeks consent to proceed with a transaction that would otherwise be a POCA principal offence. See [[Ch 2 §2.6]] for the timing rules.

Practical: consent regime lets firms comply with POCA while continuing business — but NCA's consent notice does not immunise the firm from other regulatory issues.

MLRO — the operational role in Ch 4 syllabus 7.3

MLRO's operational duties:

  1. Receive internal disclosures from staff
  2. Assess whether external report warranted
  3. Submit SARs / DAMLs to national FIU
  4. Maintain records of internal + external reports
  5. Annual MLRO report to senior management + board
  6. Liaise with regulators + law enforcement
  7. Ensure staff training + awareness

Sole authority to file SARs — staff report internally to the MLRO, who alone decides whether an external SAR is filed. Sits under SMCR as SMF17 (MLRO) in UK.

Trap: individual employees cannot bypass the MLRO and file a SAR directly. The MLRO is the single choke point for external reports.

4.8 Training, record-keeping, governance

Training — the "reasonable steps" requirement syllabus 8.1

Regulated firms must ensure staff:

  • Are aware of the ML/TF laws + firm policies
  • Understand red flags for their role
  • Know how to make an internal disclosure
  • Are trained at induction + refreshed periodically (annually is typical)

Failure to provide adequate training is itself a regulatory breach + a potential aggravating factor in enforcement.

Record-keeping — 5-year rule syllabus 8.2

Records to retain:

  • CDD documentation (identity data, verification evidence, BO analysis)
  • Transaction records
  • Correspondence with customer
  • Internal disclosures + MLRO decisions
  • SARs + related documents
  • Training records
  • Risk assessments

Retention period: minimum 5 years from end of the business relationship or one-off transaction (FATF Rec 11 / UK MLR 2017). Some records (SARs) may be required longer.

AML governance — the three lines syllabus 8.3

Modern AML governance uses the three lines of defence:

  1. First line — business + customer-facing staff (do CDD, spot red flags, make internal disclosures)
  2. Second line — Compliance + Financial Crime (policy, oversight, MLRO, monitoring)
  3. Third line — Internal Audit (independent assurance on effectiveness)

Board + senior management ultimately accountable — SMCR imposes personal duty of responsibility on Senior Managers.

4.9 Ch 4 cheat sheet

All the numbers + names

ItemAnswer
Standard CDD components (4)Identify · verify · BO · purpose & nature
Ongoing monitoringTransaction scrutiny + CDD refresh
CDD triggersNew relationship · occasional ≥€15k · wire ≥€1k · suspicion · doubt
BO threshold25% ownership OR control (default — lower for higher-risk)
BO alwaysA natural person
Trust BO partiesSettlor · trustee · protector · beneficiaries · controllers
UK Trust Registration ServiceHMRC · in force since 2017 · extended 2020 (5MLD)
EDD triggersPEPs · high-risk 3rd countries · correspondent · complex/unusual
EDD SoW vs SoFSoW = total wealth origin · SoF = specific txn origin
PEP scope (4MLD+)Foreign + domestic + int'l org
PEP status durationMin 12 months after leaving office (risk-based thereafter)
PEP family + close associatesAlso EDD
PEP onboardingSenior management approval REQUIRED
SDDLower risk · CDD components still apply · not "set and forget"
SAR (UK)Filed to NCA
STR (elsewhere)Filed to national FIU
US CTR thresholdCash ≥$10,000 · mandatory report
DAML deemed consent7 working days
DAML moratorium (refused)31 days (extendable)
MLRO UK SMFSMF17
MLRO SAR authoritySole — staff report internally
Records retentionMinimum 5 years (FATF Rec 11 / UK MLR 2017)
3 lines of defenceBusiness · Compliance/FC · Internal Audit
FATF Rec 10Standard CDD
FATF Rec 12PEPs
FATF Rec 13Correspondent banking (see [[Ch 3]])
This chapter alone is 30% of the CFC exam. Print this cheat sheet + drill the exam-hitter questions on the quiz. Next: Ch 5 — Terrorist Financing.