Compliance Checks
Compliance checks are systematic controls and procedures to ensure the bank operates in accordance with applicable laws, regulations, and internal policies. The compliance function protects the bank from legal, regulatory, and reputational risk arising from non-compliance.
๐ก๏ธ Key Characteristicsโ
- Compliance is a second line of defence function (1LoD: business; 2LoD: compliance/risk; 3LoD: internal audit).
- Covers AML/CFT, sanctions screening, KYC/CDD, product suitability, data protection, and conduct risk.
- Regulated by MAS under the Banking Act, MAS Notices, and subsidiary legislation.
- Breaches must be reported to the Board Risk Committee and MAS (where material).
- Compliance monitoring is conducted under a risk-based programme approved through the institution's governance process.
๐งพ Key Compliance Areasโ
| Area | Regulatory Reference | Description |
|---|---|---|
| AML/CFT | MAS Notice 626 | Anti-money laundering and countering financing of terrorism |
| KYC / CDD | MAS Notice 626, FATF | Know Your Customer and Customer Due Diligence |
| Sanctions Screening | Applicable Singapore, UN and relevant foreign requirements | Screening clients and transactions against lists applicable to the institution and transaction |
| Product Suitability | MAS FAA, SFA | Ensuring investment products match client risk profile |
| Data Protection | PDPA | Personal data handling, consent, breach notification |
| Insider Trading | SFA Part XII | Prohibition on trading on material non-public information |
| Tax Compliance | CRS, FATCA | Common Reporting Standard, US tax reporting |
๐ ๏ธ Operational Workflowโ
AML Transaction Monitoring:
- Core banking system generates alerts on transactions matching typology rules (large cash, structuring, unusual patterns)
- Level 1 review by transaction monitoring team within the risk-based service standard
- Level 2 review by senior compliance officer for escalated alerts
- Suspicious Transaction Report (STR) filed with STRO (Suspicious Transaction Reporting Office) if suspicion confirmed
- Account may be placed under enhanced monitoring or relationship exited pending STR outcome
- Monthly stats reported to Compliance Committee
KYC Periodic Review:
- System triggers an upcoming periodic review according to the customer's risk-based review cycle
- RM collects updated documents (business profile, financials, ID documents)
- Risk score re-assessed (low/medium/high)
- Compliance reviews and approves; account access maintained or restricted pending completion
- Overdue reviews escalated under the institution's documented procedure
๐งฎ Risk Scoring Modelโ
Customer Risk Score โ weighted factors:
| Factor | Weight | Example Score |
|---|---|---|
| Country risk (domicile) | 30% | Singapore = 1, High-risk = 5 |
| Industry risk | 25% | Low risk = 1, Cash-intensive = 5 |
| Product risk | 20% | CASA = 1, Private banking = 4 |
| Transaction pattern | 15% | Normal = 1, Unusual = 5 |
| PEP status | 10% | Not PEP = 1, PEP = 5 |
Illustrative thresholds: below 2.0 = low risk; 2.0โ3.5 = medium risk; above 3.5 = high risk. Actual factors, weights and thresholds must be calibrated and approved by the institution.
High-risk relationships require enhanced measures, appropriate approval and more frequent review in accordance with applicable AML/CFT requirements and institutional policy.
๐ Regulatory Reporting Requirementsโ
- STR: Filed promptly when the statutory suspicion threshold is met; tipping-off prohibitions must be observed
- Cash reporting: Applied only where the institution and transaction fall within a statutory cash-transaction reporting regime
- Technology risk: Incidents and information reported within the scope and timetable of the applicable MAS notice
- CRS/FATCA: Reportable accounts submitted to the relevant tax authority under the current filing requirements
- AML/CFT returns: Submitted where required for the institution and at the prescribed frequency
- Appointments: Notifications or approvals obtained for appointments that fall within the relevant legal and regulatory requirements