NISM Professor

Risk Based Approach

Also written RBA · Risk Based Approach (RBA)

Applying each due diligence measure in proportion to the money-laundering risk a client poses — enhanced diligence for higher-risk clients, simplified for lower-risk, never simplified where suspicion exists.

In plain language

An intermediary cannot examine every client with the same intensity, and should not try. A retired teacher with a Rs 2 lakh portfolio and an offshore trust routing Rs 40 crore a year do not warrant the same effort, and treating them alike wastes the effort on the wrong one.

The risk based approach is the instruction to spend diligence where the risk is. SEBI requires registered intermediaries to apply each of the client due diligence measures on a risk sensitive basis, under policies approved by their senior management, and to monitor the implementation of those controls and enhance them where necessary.

The approach has one hard limit, and it is the most examined sentence in the section: low risk provisions shall not apply when there are suspicions of money laundering or terrorist financing, or when other factors give rise to a belief that the customer does not in fact pose a low risk.

How it works

Classification. Risk factors for assessing and monitoring must be clearly defined, considering the client's location — registered office, correspondence address and any other relevant address — nature of business, trading turnover, and mode of payment. These parameters classify clients as low, medium or high risk. Clients of special category may be placed higher still.

Consequence of classification. The basic principle is that an enhanced client due diligence process applies to higher risk categories and a simplified process may be adopted for lower risk categories. The type and amount of identification information and documents obtained therefore depends on the client's risk category — as does the extent of transaction monitoring, which must be aligned with the risk category of the client.

Risk assessment underneath it. Rule 9(13) and the SEBI guidelines require the intermediary to carry out a risk assessment covering clients, countries or geographical areas, nature and volume of transactions, payment methods and delivery channels, consistent with any national risk assessment. That assessment must be documented, consider all relevant risk factors before determining overall risk, be kept up to date, and be available to competent authorities and self-regulating bodies. It must also take account of country-specific information circulated by the Government of India and SEBI, and the updated list of individuals and entities subject to sanction measures under United Nations Security Council Resolutions.

New products. The exchanges and intermediaries must identify and assess the ML and TF risks arising from new products, new business practices, new delivery mechanisms and new or developing technologies, and must undertake that assessment before launch or use.

A worked example

Girnar Stock Broking Ltd rebuilds its client risk model and documents the parameters.

ClientLocationBusinessTurnoverPayment modeCategory
Salaried investor, PuneDomesticSalariedRs 6 lakh a yearOwn bank accountLow
Jewellery trader, RajkotDomesticCash-intensiveRs 9 crore a yearOwn account, frequent large creditsHigh
NRI, non-face-to-faceOverseasConsultancyRs 3 crore a yearOverseas remittanceHigh (also CSC)
SME manufacturerDomesticManufacturingRs 80 lakh a yearOwn accountMedium

What differs. The low-risk client gets the standard document set and periodic monitoring. The jewellery trader gets enhanced due diligence, documented source of funds, an internal alert threshold set at Rs 25 lakh a month, and a KYC refresh every year. Monitoring intensity is set by category, exactly as the guidelines require.

The limit in action. Six months later the low-risk salaried investor starts receiving inward transfers of Rs 40 lakh from three unrelated parties. The relationship manager argues the client is categorised low risk and the simplified documentation stands. That is wrong: low risk provisions shall not apply where there are suspicions of ML or TF, or where other factors suggest the client is not in fact low risk. The category has to be revisited and, if suspicion crystallises, an STR filed.

What a missing model costs. In the SKSE Securities matter SEBI found the broker had not categorised clients into high, medium and low at all, and so was exercising no additional due diligence on higher-risk clients; the AML policy required within one month of the January 2006 circular was still not implemented in 2010. Penalty: Rs 2,00,000 under section 15HB. In the Raima Equities matter, the categorisation existed but had no documented basis, which the Adjudicating Officer held to be arbitrary — again Rs 2,00,000.

Why NISM asks about it

Chapter 6 (SEBI Guidelines for AML, CFT and PF), sections 6.2.4 (Risk Management — Risk Based Approach) and 6.2.5 (Risk Assessment), with the statutory hook in Rule 9(13) from Chapter 3. Expect a question on when simplified measures may not be used, one on the four attributes of a documented risk assessment, and case questions from Chapter 8 where the absence or arbitrariness of risk categorisation was the violation.

Common exam traps

  • Simplified due diligence is never available where there is suspicion, where a higher-risk scenario applies, or where the identified risk is inconsistent with the national risk assessment. This is the trap the paper sets most often.
  • A risk category is a live judgement, not a permanent label. Behaviour that contradicts the category overrides it.
  • Risk assessment must be documented and available to competent authorities. An assessment that exists only in the compliance officer's head fails on the face of Rule 9(13).
  • Categorisation needs a written basis. Raima Equities had categories but no documented rationale, and that was held arbitrary — the penalty was the same as for having no system at all.
  • New products must be risk-assessed before launch, not after the first complaint.
  • RBA never reduces the reporting obligation. STR reporting has no threshold and no exempt risk category; a low-risk client's attempted transaction of any size is still reportable.

Check yourself

  1. 1.Under the risk based approach, when may simplified client due diligence NOT be applied?

    1. a)When there are suspicions of ML or TF, or when other factors give rise to a belief that the customer does not in fact pose a low risk
    2. b)Only for corporate clients
    3. c)Only where the client invests above Rs. 10 lakh
    4. d)Simplified CDD is never permitted
    Show the answer

    Answer: (a) When there are suspicions of ML or TF, or when other factors give rise to a belief that the customer does not in fact pose a low risk

    It may be noted that low risk provisions shall not apply when there are suspicions of ML/FT or when other factors give rise to a belief that the customer does not in fact pose a low risk.

    Two triggers — actual suspicion, or a belief that the low-risk classification was wrong.

    Option D overstates the position. The basic principle enshrined in this approach is that the registered intermediaries shall adopt an enhanced client due diligence process for higher risk categories of clients. Conversely, a simplified client due diligence process may be adopted for lower risk categories of clients.

    Simplified CDD is permitted — it is simply unavailable once suspicion arises.

    Options B and C invent classifications the guidelines do not use. Risk classification rests on the client's location (registered office, correspondence address, and any other relevant addresses), nature of business, trading turnover, and mode of payment for transactions, producing low, medium, or high-risk categories.

    And no client escapes CDD altogether: there shall be no minimum investment threshold/ category-wise exemption available for carrying out CDD measures by registered intermediaries.

    What the RBA requires structurally. Intermediaries shall apply a Risk Based Approach (RBA) for mitigation and management of the identified risk and should have policies approved by their senior management, controls and procedures in this regard. Further, the registered intermediaries shall monitor the implementation of the controls and enhance them if necessary.

    The documentation demanded also varies: the type and amount of identification information and documents that registered intermediaries shall obtain necessarily depend on the risk category of a particular client.

    And so does monitoring: the extent of monitoring shall be aligned with the risk category of the client.

    The underlying risk assessment covers clients, countries or geographical areas, nature and volume of transactions, payment methods used by clients, etc., and must be documented, updated regularly and made available to competent authorities and self-regulating bodies, as and when required.

  2. 2.As a regulatory requirement, all intermediaries should:

    1. a)All of the above
    2. b)Have an anti-money laundering policy
    3. c)Apply customer due diligence on a risk sensitive basis
    4. d)Appoint a Principal Officer
    Show the answer

    Answer: (a) All of the above

    All three appear as findings in the SKSE Securities case, each a separate violation.

    On the policy: SEBI vide its Circular No. ISD/CIR/RR/AML/1/06 dated January 18, 2006 issued guidelines on AML standards and advised all intermediaries to ensure that a proper policy framework as per the guidelines on anti-money laundering measure is put into place within one month from the date of the circular. In the instant case, the Noticee has failed to implement the said policy in time.

    On risk-sensitive due diligence: the circular required intermediaries to develop customer acceptance policies and procedures aimed at identifying the types of customers that are likely to pose a higher than the average risk of money laundering or terrorist financing, enabling them to apply customer due diligence on a risk sensitive basis depending upon the type customer business relationship — with classification into low, medium and high risk.

    SKSE had done none of it until 2010.

    On the Principal Officer: the circular mandates that the intermediaries designate an officer as 'Principal Officer' who would be responsible for ensuring the compliance of the provisions of the Prevention of Money Laundering Act, 2002 (PMLA). The name, designation and addresses (including e-mail address) of the 'Principal Officer' had to be intimated to the Office of the Director, FIU on an urgent basis.

    SKSE appointed one on December 14, 2007, i.e., with a delay of almost two years from the date of the SEBI Circular, and intimated FIU only on January 10, 2008.

    The result was a penalty of Rs. 2,00,000/- (Rupees Two Lakhs only)... in terms of section 15HB of the SEBI Act.

    These three requirements run right through the syllabus — the AML policy from Chapter 6's four specific parameters, risk-sensitive CDD from the Risk Based Approach, and the Principal Officer from Rule 7 of the PML Rules.

Where this is taught

Free preparation for NISM Series XXIV

Related terms

← All terms
Something look wrong? Report it