Singapore legislation
Regulation 17
Regulation 17
Internal policies, procedures and controls
Subregulation 1
An accounting entity must establish and maintain appropriate and risk‑sensitive internal policies, procedures and controls relating to all of the following matters in order to prevent activities related to money laundering, the financing of terrorism and proliferation financing:
CDD measures (including simplified CDD measures and enhanced CDD measures) and ongoing monitoring (including enhanced ongoing monitoring);
reporting;
record keeping;
risk assessment and management;
audit of the internal policies, procedures and controls;
the monitoring and management of compliance with, and the internal communication of, such internal policies, procedures and controls;
hiring and training of employees;
group policy, if the accounting entity has one or more subsidiaries or branches.
Subregulation 2
The internal policies, procedures and controls mentioned in paragraph (1) must include —
internal policies, procedures and controls which provide for the identification and scrutiny of —
complex or unusually large transactions;
unusual patterns of transactions which have no apparent economic or visible lawful purpose; and
any other activity which the accounting entity or an individual practitioner of the accounting entity regards as particularly likely by its nature to be related to money laundering, the financing of terrorism or proliferation financing;
internal policies, procedures and controls which specify the taking of additional measures, where appropriate, to prevent —
the development of new services and new business practices, including new delivery mechanisms, for money laundering, the financing of terrorism and proliferation financing; and
the use of new or developing technologies, for both new and pre‑existing services, for money laundering, the financing of terrorism and proliferation financing; and
internal policies, procedures and controls to determine whether any client, beneficial owner in relation to a client, or an agent of a client is a politically‑exposed person.
Subregulation 3
An accounting entity or individual practitioner —
must —
assess the risks of money laundering, the financing of terrorism or proliferation financing that may arise in relation to —
the development of new services and new business practices, including new delivery mechanisms; and
the use of new or developing technologies for both new and pre‑existing services,before the launch or use of the services, business practices and technologies; and
must take appropriate measures to manage and mitigate the risks.
Subregulation 4
An accounting entity and its individual practitioners must comply with the internal policies, procedures and controls established and maintained by the accounting entity.
Subregulation 5
An accounting entity or individual practitioner must, in complying with the requirements of paragraphs (2) and (3), pay special attention to any —
new services and new business practices, including new delivery mechanisms; and
new or developing technologies for both new and pre‑existing services,that favour anonymity.