4.1 RBA — the operational core
▼RBA in practice — the foundational principle syllabus 1.1
Under the FATF-endorsed risk-based approach, a firm must:
- Identify + assess its ML/TF risks (customers, geographies, products, delivery channels, transactions)
- Design controls proportionate to those risks
- Document + evidence the risk assessment + control mapping
- Review + update periodically (annually + on trigger events)
See [[Ch 1]] for the RBA cascade (FATF → NRA → sector → firm → customer).
Firm-wide risk assessment (FWRA) syllabus 1.2
Every regulated firm must document a FWRA covering:
- Customer risk factors
- Geographic risk factors
- Product / service risk factors
- Delivery channel risk factors
- Transaction risk factors
Feeds directly into the firm's policies, controls + customer risk-rating models. Not a compliance box-tick — supervisors expect it to genuinely drive control design.
The four core risk-factor categories syllabus 1.3-1.5
| Category | Higher-risk indicators |
|---|---|
| Customer | PEPs · complex ownership · cash-intensive business · sanctioned nationality · adverse media |
| Geographic | FATF grey/black list · sanctioned jurisdictions · Corruption Perceptions Index low · offshore/secrecy jurisdictions |
| Product / service | Private banking · correspondent banking · trade finance · high-value goods · crypto |
| Delivery channel | Non-face-to-face · via 3rd-party intermediary · anonymous instruments |
4.2 Standard CDD — the four components
▼Standard CDD — the four required components syllabus 2.1
Standard Customer Due Diligence has four components (FATF Rec 10):
- Identify the customer
- Verify the customer's identity using reliable, independent source data
- Identify + verify the beneficial owner (see §4.3)
- Understand purpose + intended nature of the business relationship
Plus ongoing monitoring throughout the relationship (see §4.6).
CDD timing — the trigger events syllabus 2.2
CDD must be applied when:
- Establishing a new business relationship
- Occasional transaction ≥ €15,000 (or equivalent — the FATF baseline)
- Wire transfer ≥ €1,000 (with Travel Rule info)
- Suspicion of ML/TF
- Doubt about previously obtained identification data
Verification must generally be complete BEFORE establishing the relationship (some limited exceptions for continuity of business where interrupted verification wouldn't work, subject to controls).
"Reliable, independent source" — what qualifies syllabus 2.3
Identity data must be verified from a source that is:
- Reliable — trustworthy, low risk of manipulation
- Independent — not created or controlled by the customer
Common qualifying sources:
- Government-issued passport / national ID
- Driving licence
- Certified extract from a credit bureau
- Utility bill (last 3 months) for address
- Companies House / equivalent for corporate customers
- Trusted digital identity schemes (UK GOV.UK Verify, EU eIDAS)
Non-face-to-face verification syllabus 2.4
Historically flagged as higher-risk (impersonation risk). Modern position:
- Still a risk factor to consider in overall customer rating
- Mitigation: video ID verification, biometric matching, liveness checks, government digital ID
- Regulators (FCA, EU) now recognise robust remote verification as equivalent to in-person
Firms rely heavily on RegTech providers (Onfido, Jumio, iProov, Yoti) for automated remote verification at scale.
4.3 Beneficial ownership
▼Beneficial owner — the definition syllabus 3.1
The beneficial owner is the natural person who ultimately owns or controls the customer, or on whose behalf a transaction is conducted.
Two limbs:
- Ownership — direct or indirect shareholding above threshold
- Control — even without ownership, controlling directors, veto rights, dominant influence
Always a natural person — never a company or trust structure.
BO threshold — the 25% benchmark syllabus 3.2
FATF baseline: identify natural persons owning or controlling 25% or more of the customer entity (directly or indirectly).
Key caveats:
- 25% is a default — firms should apply a LOWER threshold for higher-risk cases (per their RBA)
- Some jurisdictions set lower defaults (e.g. certain sensitive sectors)
- UK PSC register uses 25% for the notification threshold
When no natural person can be identified syllabus 3.3
Where no natural person meets the ownership threshold AND no controlling individual can be identified, firms should:
- Consider whether the ownership structure has been deliberately obscured (red flag)
- As a fallback, treat senior managing official(s) as beneficial owners
- Document the analysis + rationale
Never leave a corporate customer without an identified beneficial owner — the file must show either the BO or a documented reason why the senior managing official is being used instead.
BO in trusts syllabus 3.4
Trusts have multiple parties, ALL of whom are beneficial owners for AML purposes:
- Settlor — the person who created the trust
- Trustee(s) — the person(s) holding legal title
- Protector — where one exists
- Beneficiaries — named beneficiaries or class
- Any other individual exercising ultimate effective control
UK: Trust Registration Service (TRS) — HMRC register requiring most trusts (including many non-taxable) to register + disclose these parties. In force since 2017, extended by 5MLD from 2020.
Complex ownership structures syllabus 3.5
Multi-layered ownership (parent → sub → sub → …) requires calculating indirect BO across the chain. Techniques:
- Multiply through the chain (50% × 50% = 25%)
- Consider control separately from ownership (voting rights, board appointments)
- Watch for nominee arrangements — the nominee is legal owner, not BO
- Watch for bearer shares — historically anonymous (banned in many jurisdictions post-2015)
4.4 Enhanced Due Diligence (EDD) + PEPs
▼EDD — the mandatory trigger categories syllabus 4.1
EDD is mandatory for:
- PEPs (foreign + domestic + international organisation)
- Customers established in high-risk third countries (FATF grey/black list; EU Commission list)
- Correspondent banking relationships (see [[Ch 3]])
- Complex or unusually large transactions
- Transactions with no apparent economic or lawful purpose
- Higher risk identified by firm's RBA
Plus discretionary EDD for any relationship the firm rates high-risk on its own metrics.
EDD measures — what "enhanced" means syllabus 4.2
EDD typically includes:
- Additional identity information beyond standard CDD (source of funds, source of wealth)
- Enhanced adverse-media + sanctions screening
- Senior management approval to establish or continue the relationship
- More frequent CDD refresh (annually or more)
- Enhanced ongoing monitoring — lower alert thresholds, more manual review
- On-site verification for corporate customers where appropriate
Source of wealth vs source of funds: SoW = how the customer accumulated total assets (career, inheritance); SoF = where a specific transaction's money came from. Both required for EDD.
PEP — the definition syllabus 4.3
A politically exposed person is a natural person who is or has been entrusted with a prominent public function. Categories:
- Foreign PEP — non-domestic prominent public function
- Domestic PEP — in your own jurisdiction (broadened by 4MLD)
- International organisation PEP — UN, IMF, WTO senior officials
Prominent functions include: heads of state, senior ministers, senior judiciary, senior military, senior state-enterprise executives, ambassadors, senior political-party officials.
Family members + close associates of a PEP are also subject to EDD.
Domestic vs foreign PEPs syllabus 4.3
Historically only foreign PEPs required EDD (assumption: domestic corruption easier to detect). 4MLD (2015) extended EDD to domestic PEPs too.
Modern practice: both categories screened; risk-rating may still differ based on jurisdiction, role, adverse media.
PEP status duration syllabus 4.4
PEP status persists for at least 12 months after the person leaves office. Beyond 12 months, firms may de-classify but only after a risk assessment — some individuals remain higher-risk indefinitely (former heads of state, individuals still influential in politics).
UK FCA guidance (FG17/6): apply a proportionate approach — most former PEPs need not be treated the same as active PEPs after de-classification.
4.5 Simplified Due Diligence (SDD)
▼SDD — when it applies syllabus 5.1
Simplified Due Diligence is permitted where the firm has determined the relationship or transaction presents lower risk. Examples of lower-risk factors:
- Listed companies subject to disclosure requirements
- Domestic public authorities
- Regulated firms in equivalent jurisdictions
- Products with low ML risk (e.g. certain life insurance, low-value e-money)
- Customers resident in low-risk jurisdictions
SDD is not a CDD exemption — the four CDD components still apply, but the depth and frequency of verification can be lower.
SDD requires ongoing risk validation syllabus 5.2
SDD is not "set and forget." If risk indicators change (customer moves to a higher-risk jurisdiction, adverse media surfaces, unusual transaction pattern), the firm must upgrade to standard or enhanced CDD.
4.6 Ongoing monitoring + refresh
▼Ongoing monitoring — two arms syllabus 6.1
Ongoing monitoring has two arms:
- Transaction scrutiny — analysing transactions to ensure consistency with what the firm knows about the customer + business/risk profile
- CDD refresh — periodic review + update of customer information + risk rating
Typical refresh cadence: low-risk every 3-5 years, standard 2-3 years, high-risk annually or more.
Transaction monitoring systems syllabus 6.2
Firms deploy transaction monitoring systems (TMS) that:
- Score transactions against typology scenarios (structuring, wire circulation, TBML patterns)
- Generate alerts for human review
- Feed disposition data back to tune scenarios
Modern hybrid: rules + ML models (see [[Ch 7]]). Alert false-positive rates are historically 90%+ — a major cost driver.
4.7 SARs + the MLRO role
▼SARs — the reporting mechanism syllabus 7.1
Suspicious Activity Report (SAR) — a report filed by a regulated firm to the national FIU when the firm knows / suspects / has reasonable grounds to suspect ML or TF.
Naming conventions vary:
- UK / Australia: SAR
- US: SAR (via FinCEN) + CTR (Currency Transaction Report — mandatory for cash transactions ≥$10,000)
- Continental Europe: STR (Suspicious Transaction Report)
- UAE: STR (to FIU-UAE)
Filed to the national FIU: UK NCA, US FinCEN, France TRACFIN, UAE FIU, etc.
DAML — Defence Against ML request syllabus 7.2
A specific type of SAR that also seeks consent to proceed with a transaction that would otherwise be a POCA principal offence. See [[Ch 2 §2.6]] for the timing rules.
Practical: consent regime lets firms comply with POCA while continuing business — but NCA's consent notice does not immunise the firm from other regulatory issues.
MLRO — the operational role in Ch 4 syllabus 7.3
MLRO's operational duties:
- Receive internal disclosures from staff
- Assess whether external report warranted
- Submit SARs / DAMLs to national FIU
- Maintain records of internal + external reports
- Annual MLRO report to senior management + board
- Liaise with regulators + law enforcement
- Ensure staff training + awareness
Sole authority to file SARs — staff report internally to the MLRO, who alone decides whether an external SAR is filed. Sits under SMCR as SMF17 (MLRO) in UK.
4.8 Training, record-keeping, governance
▼Training — the "reasonable steps" requirement syllabus 8.1
Regulated firms must ensure staff:
- Are aware of the ML/TF laws + firm policies
- Understand red flags for their role
- Know how to make an internal disclosure
- Are trained at induction + refreshed periodically (annually is typical)
Failure to provide adequate training is itself a regulatory breach + a potential aggravating factor in enforcement.
Record-keeping — 5-year rule syllabus 8.2
Records to retain:
- CDD documentation (identity data, verification evidence, BO analysis)
- Transaction records
- Correspondence with customer
- Internal disclosures + MLRO decisions
- SARs + related documents
- Training records
- Risk assessments
Retention period: minimum 5 years from end of the business relationship or one-off transaction (FATF Rec 11 / UK MLR 2017). Some records (SARs) may be required longer.
AML governance — the three lines syllabus 8.3
Modern AML governance uses the three lines of defence:
- First line — business + customer-facing staff (do CDD, spot red flags, make internal disclosures)
- Second line — Compliance + Financial Crime (policy, oversight, MLRO, monitoring)
- Third line — Internal Audit (independent assurance on effectiveness)
Board + senior management ultimately accountable — SMCR imposes personal duty of responsibility on Senior Managers.
4.9 Ch 4 cheat sheet
▼All the numbers + names
| Item | Answer |
|---|---|
| Standard CDD components (4) | Identify · verify · BO · purpose & nature |
| Ongoing monitoring | Transaction scrutiny + CDD refresh |
| CDD triggers | New relationship · occasional ≥€15k · wire ≥€1k · suspicion · doubt |
| BO threshold | 25% ownership OR control (default — lower for higher-risk) |
| BO always | A natural person |
| Trust BO parties | Settlor · trustee · protector · beneficiaries · controllers |
| UK Trust Registration Service | HMRC · in force since 2017 · extended 2020 (5MLD) |
| EDD triggers | PEPs · high-risk 3rd countries · correspondent · complex/unusual |
| EDD SoW vs SoF | SoW = total wealth origin · SoF = specific txn origin |
| PEP scope (4MLD+) | Foreign + domestic + int'l org |
| PEP status duration | Min 12 months after leaving office (risk-based thereafter) |
| PEP family + close associates | Also EDD |
| PEP onboarding | Senior management approval REQUIRED |
| SDD | Lower risk · CDD components still apply · not "set and forget" |
| SAR (UK) | Filed to NCA |
| STR (elsewhere) | Filed to national FIU |
| US CTR threshold | Cash ≥$10,000 · mandatory report |
| DAML deemed consent | 7 working days |
| DAML moratorium (refused) | 31 days (extendable) |
| MLRO UK SMF | SMF17 |
| MLRO SAR authority | Sole — staff report internally |
| Records retention | Minimum 5 years (FATF Rec 11 / UK MLR 2017) |
| 3 lines of defence | Business · Compliance/FC · Internal Audit |
| FATF Rec 10 | Standard CDD |
| FATF Rec 12 | PEPs |
| FATF Rec 13 | Correspondent banking (see [[Ch 3]]) |