Financial institutions are ultimately responsible for outsourced anti-money laundering (AML) and countering the financing of terrorism (CFT) control functions. 

Such outsourcing of AML/CFT control functions should be considered a material outsourcing, given the criticality of these controls and the access that AML/CFT service providers (ASPs) may have to sensitive customer information. Material outsourcing arrangements are particularly important as they have significant impact on the FIs’ operations, reputation and/or ability to comply with MAS’ laws and regulations.

In 2020, MAS published a guidance paper on “Strengthening Capital Markets Intermediaries’ (“CMIs”) Oversight over AML/CFT Outsourcing Arrangements” after a series of thematic inspections to understand the extent of the CMIs’ oversight of their ASPs. The guidance paper sets out MAS’ key observations and expectations of sound practices where AML/CFT control functions are outsourced, which may also be relevant to other types of FIs.
MAS noted that several FIs failed to detect major lapses by their ASPs, which resulted in FIs breaching MAS’ AML/CFT requirements. Overall, the root causes of the more serious breaches were due to FIs’:
  • inadequate understanding of their ASPs’ practices; and
  • lack of oversight and timely ongoing monitoring of ASPs post-appointment.
This content leverages on the key observations from this guidance paper issued in 2020, and is useful in understanding the best practices expected of FIs.

 
Stages of the Outsourcing Process

In general, the outsourcing process has three stages:

Stage 1: Due diligence of shortlisted ASPs

The FI performs a thorough due diligence of the potential ASPs. This is crucial in understanding and ensuring that the ASP is suitably competent to support the needs of the FI.

Stage 2: Review contract terms and engagement of ASP

Scope and terms of the engagement are finalised in an outsourcing contract after the FI has decided on a suitable ASP.

Stage 3: Post-engagement monitoring of ASP

The FI monitors and reviews the performance of the ASP in relation to the outsourced control functions, on a periodic basis.


An outsourcing arrangement does not equate to “Reliance on Third Parties” as defined in the AML/CFT MAS Notices.

Based on MAS’ Guidelines on Outsourcing (Oct 2018), an outsourcing arrangement refers to an arrangement where the ASP provides the FI with a service that may currently or potentially be performed by the FI itself. Under an outsourcing arrangement, the ASP will perform the required AML/CFT control function(s) on behalf of the FI, and in accordance with the FI’s AML/CFT policies, procedures and standards, and is subjected to the FI’s control measures.

Whereas, reliance on third parties under paragraph 9 of MAS Notice SFA04-N02 (or the relevant MAS Notices, depending on the type of FIs) is different from an outsourcing arrangement. The third party will perform the control function(s) according to its own AML/CFT policies, procedures and controls. Taking the example of performing CDD measures on a customer, the third party will typically have an existing relationship with the customer that is independent of the relationship to be formed by the customer with the relying FI.

FIs may refer to paragraph 9 of the relevant MAS Guidelines to AML/CFT Notices for more details.

Robust Assessment of ASPs During Stages 1 and 2 is a Crucial First Step

FIs can strengthen their due diligence frameworks by establishing:

  • Right tone set by the Board and Senior Management – It is crucial to set a formalised outsourcing policy, and for experienced AML/CFT compliance officer(s) to support the assessment of ASPs.

  • Structured assessment process with defined criteria – The suitability and ability of ASPs must be evaluated. FIs should perform gap analyses to assess if the ASPs’ AML/CFT policies and procedures adhere to MAS’ requirements.

  • A well-defined outsourcing agreement with clear scope and responsibilities of the ASP – FIs must scrutinise contractual terms to avoid expectations gaps, i.e. significant differences between the scope of outsourced AML/CFT control functions and the FIs’ intended scope of the arrangement. This ensures that key AML/CFT controls are implemented consistently.

  • Proper documentation of assessments and approvals – FIs should maintain clear basis for the appointment of ASPs. Documentation of due diligence undertaken by FIs will ensure that subsequent periodic reviews can be conducted consistently.

Some Observations from MAS’ Inspections:
  1. The FI engaged an ASP to perform several AML/CFT control functions. However, the ASP did not perform certain key AML/CFT controls for an extended period of time, as the actual scope of the outsourcing agreement was narrower than intended by the FI.
     
  2. Another FI selected an ASP due to favourable commercial terms offered without a thorough review of the ASP’s AML/CFT practices. As the customer risk assessment framework used by the ASP differed from the FI’s framework, lower ML/TF risk ratings were assigned to some customers; enhanced CDD measures were thus not performed.

Regular Oversight over ASPs is a Necessary Control

FIs can strengthen its oversight over ASPs by having:
  • Board and Senior Management’s involvement – There should be effective oversight over outsourcing arrangements at all times. AML/CFT compliance officers’ role is to ensure outsourced control functions are performed as intended.
  • Regular monitoring and defined escalation mechanisms – FIs should require ASPs to provide regular management reports on their execution of key AML/CFT control functions and ML/TF risk issues, such as status reports on CDD checks and periodic reviews. Escalation procedures for ASPs to surface pertinent ML/TF issues, such as potential sanction hits and material changes to the ASPs’ processes, should also be established.
  • Regular quality assurance reviews – A formalised approach to conduct regular post-appointment reviews of ASPs is essential. This can be conducted through (i) regular sample reviews of ASPs’ work to ensure effective implementation; and/or (ii) regular discussions with ASPs to monitor that performance and control standards are met.
Some Observations from MAS’ Inspections:
  1. The FI did not have defined metrics to assess the ASP’s performance of AML/CFT control functions, nor did it require the ASP to regularly provide status reports. As such, the FI was unaware that its ASP missed conducting periodic reviews on some high-risk customers for extended periods.
  2. Another FI relied on its ASP to escalate pertinent AML/CFT issues of its own accord, without clearly-defined circumstances. As a result, the ASP had dismissed potential positive screening matches, without first escalating to the FI for its consideration.


Final Words

FIs remain responsible for complying with AML/CFT requirements under their respective MAS Notices, even when they outsource AML/CFT control functions. The Board and Senior Management play a pivotal role to set a strong tone from the top and to ensure that the FI’s AML/CFT controls are adequate and effective.

FIs should conduct a gap analysis against the best practices outlined in MAS’ 2020 guidance paper on outsourcing as well as MAS’ Guidelines on Outsourcing (Oct 2018), and take appropriate measures to enhance their practices.