Skip to main content

Compliance Checks

Compliance checks are systematic controls and procedures to ensure the bank operates in accordance with applicable laws, regulations, and internal policies. The compliance function protects the bank from legal, regulatory, and reputational risk arising from non-compliance.

๐Ÿ›ก๏ธ Key Characteristicsโ€‹

  • Compliance is a second line of defence function (1LoD: business; 2LoD: compliance/risk; 3LoD: internal audit).
  • Covers AML/CFT, sanctions screening, KYC/CDD, product suitability, data protection, and conduct risk.
  • Regulated by MAS under the Banking Act, MAS Notices, and subsidiary legislation.
  • Breaches must be reported to the Board Risk Committee and MAS (where material).
  • Compliance monitoring is conducted under a risk-based programme approved through the institution's governance process.

๐Ÿงพ Key Compliance Areasโ€‹

AreaRegulatory ReferenceDescription
AML/CFTMAS Notice 626Anti-money laundering and countering financing of terrorism
KYC / CDDMAS Notice 626, FATFKnow Your Customer and Customer Due Diligence
Sanctions ScreeningApplicable Singapore, UN and relevant foreign requirementsScreening clients and transactions against lists applicable to the institution and transaction
Product SuitabilityMAS FAA, SFAEnsuring investment products match client risk profile
Data ProtectionPDPAPersonal data handling, consent, breach notification
Insider TradingSFA Part XIIProhibition on trading on material non-public information
Tax ComplianceCRS, FATCACommon Reporting Standard, US tax reporting

๐Ÿ› ๏ธ Operational Workflowโ€‹

AML Transaction Monitoring:

  1. Core banking system generates alerts on transactions matching typology rules (large cash, structuring, unusual patterns)
  2. Level 1 review by transaction monitoring team within the risk-based service standard
  3. Level 2 review by senior compliance officer for escalated alerts
  4. Suspicious Transaction Report (STR) filed with STRO (Suspicious Transaction Reporting Office) if suspicion confirmed
  5. Account may be placed under enhanced monitoring or relationship exited pending STR outcome
  6. Monthly stats reported to Compliance Committee

KYC Periodic Review:

  1. System triggers an upcoming periodic review according to the customer's risk-based review cycle
  2. RM collects updated documents (business profile, financials, ID documents)
  3. Risk score re-assessed (low/medium/high)
  4. Compliance reviews and approves; account access maintained or restricted pending completion
  5. Overdue reviews escalated under the institution's documented procedure

๐Ÿงฎ Risk Scoring Modelโ€‹

Customer Risk Score โ€” weighted factors:

FactorWeightExample Score
Country risk (domicile)30%Singapore = 1, High-risk = 5
Industry risk25%Low risk = 1, Cash-intensive = 5
Product risk20%CASA = 1, Private banking = 4
Transaction pattern15%Normal = 1, Unusual = 5
PEP status10%Not PEP = 1, PEP = 5

Illustrative thresholds: below 2.0 = low risk; 2.0โ€“3.5 = medium risk; above 3.5 = high risk. Actual factors, weights and thresholds must be calibrated and approved by the institution.

High-risk relationships require enhanced measures, appropriate approval and more frequent review in accordance with applicable AML/CFT requirements and institutional policy.

๐Ÿ“‹ Regulatory Reporting Requirementsโ€‹

  • STR: Filed promptly when the statutory suspicion threshold is met; tipping-off prohibitions must be observed
  • Cash reporting: Applied only where the institution and transaction fall within a statutory cash-transaction reporting regime
  • Technology risk: Incidents and information reported within the scope and timetable of the applicable MAS notice
  • CRS/FATCA: Reportable accounts submitted to the relevant tax authority under the current filing requirements
  • AML/CFT returns: Submitted where required for the institution and at the prescribed frequency
  • Appointments: Notifications or approvals obtained for appointments that fall within the relevant legal and regulatory requirements