New guidelines and standards for designing and implementing a self-controlled and self-managed system to address the risk of ML/FT
The Superintendence of Companies (SC) issued External Letter No. 100-000005, stating guidelines and standards for designing and implementing a self-controlled and self-managed system to address the risk of ML/FT.
Last February 19th, the SC issued External Letter No. 100-000005 (hereinafter “External Letter 100”), which provides guidelines and standards to the entities under the surveillance of the mentioned Superintendence, to design and implement a self-controlled and self-managed system to address the risk of money laundering and financing terrorism (hereinafter “ML/FT”).
External Letter 100 states that every entity under the surveillance of the Superintendence of Companies that by December 31st. 2013 reported income over 160,000 minimum monthly legal wages (hereinafter “SMLMV”, for its acronym in Spanish), equivalent to $98.560.000.000 pesos and approximately 53 Million Dollars, are obliged to adopt and implement a self-controlled and self-managed system to address the risk ML/FT. The term entity comprises commercial corporations, branches of foreign corporations, one-person entrepreneurships, and Simplified Stock Corporations.
According to External Letter 100, the entities mentioned above, must adopt and implement the afore-mentioned system before December 31st, 2014. Those entities that by December 31st, 2013 did not report income over 160,000 SMLMV are not obliged to adopt and implement the system to address the risk of ML/FT. However, if any of those entities at any time reports total income over 160,000 SMLMV, such entity will be obliged to adopt and implement the self-controlled and self-managed system to address the risk ML/FT, contained within External Letter 100.
The above-mentioned entities currently under a situation of entrepreneurial group shall adopt the necessary actions for each of the entities belonging to the entrepreneurial group to adopt the system to address the risk ML/FT.
The self-controlled and self-managed system to address the risk of ML/FT implies to adopt a plan that must:
- Identify every situation that may cause the risk of ML/FT within the entity in the operations, businesses, or contracts performed.
- Establish due diligence proceedings over clients, publically exposed people, providers, associates, workers or employees, and every person with whom a transaction is carried out.
- Regulate the management of cash within the entity.
- Create controls to reduce all the risk of ML/FT situations in the operations, businesses, or contracts performed by the entity.
- Establish tools to identify unusual or suspicious operations.
- Keep the records of all the operations, businesses, or contracts performed.
- Report to the UIAF suspicious operations, fulfilling the requirements set forth in the regulations issued for the matter.
When designing the self-controlled and self-managed system to address the risk of ML/FT, it is advisable to use as framework the ML/FT Risk Managing Model in the Real Sector, issued by the program Responsible and Safe Businesses, of the United Nations Office against Drugs and Crime, Bogotá’s Chamber of Commerce, and the British Embassy in Colombia.
Taking into account the above, please find below a brief outline of the proceedings that must be followed to adopt and implement the self-controlled and self-managed system to address the risk of ML/FT:
- The Plan must be designed by the legal representative of the entity that will adopt it, verifying that it is designed for the entity’s needs.
- The Plan must be approved by the entity’s board of directors, so it may be able to approve it. If the entity does not have a board of directors, then the Plan must be informed in the management report brought before the entity’s maximum corporate body, for its approval.
- Those entities that already have implemented policies or systems to prevent and control the risk of ML/FT, must verify that these comply with the dispositions contained within External Letter 100.
- Once the system is adopted, the legal representative must give publicity to the Plan, verify its performance, and report periodically of the performance to the Board of Directors, or the maximum corporate body if there is no Board of Directors.
- Entities must appoint a system compliance officer, who will render periodic reports to the legal representative of the system’s compliance. If the legal representative does not inform the Board of Directors, or the entity’s maximum corporate body, if applicable, the compliance officer may report directly of his or her findings to the Board of Directors, or the maximum corporate body, if it is the case.
- Entities must instruct on the system those employees that according to their functions are deemed to necessarily be trained on addressing the risk of ML/FT. The characteristics and management of the training plan on addressing the risk of ML/FT, are defined by each entity as per their convenience.
In case any further information is required, please do not hesitate in contacting us.