
As we noted in part one of this series, risk assessments will soon become a regulatory requirement. In part one, we detailed the critical components of the risk assessment. Once the information has been gathered, the analysis is the next step.
Once you have gathered all of the information necessary for completing the analysis, we suggest using analyses that doesn’t necessary assign numbers to risk, but prioritizes the potential for findings. Remember the effectiveness of your compliance program is ultimately judged by the level and frequency of findings. The effective risk assessment reviews those areas that are most likely to result and findings and develops a plan for reduction.
Inherent Risk
For each regulation that applies to your institution, you must first determine the level of inherent risk. According to the Federal Reserve Bank, inherent risk can be defined this way:
inherent risk is the baseline level of exposure to money laundering or terrorist financing that a business activity, client, or sector naturally carries. This structural vulnerability exists before any internal controls (like KYC or transaction monitoring) are applied to mitigate or manage the risk.
Your risk assessment should consider the inherent risk associated with each product that is offered. For each regulation, consideration should be given to the penalties associated with a violation. As a best practice, the likelihood of review of the area by regulators should also be factored into the overall level of inherent risk.
Effectiveness of Controls
Once the inherent risk has been established, the next step is to assess the overall effectiveness of internal controls. Your internal controls are the policies, procedures, training and monitoring that are performed on a regular basis. This includes audits and internal reviews that are performed by the compliance department.
To complete the analysis, it is necessary to be self-reflective honest and brutal! If staff is weak in its understanding of the requirements of anti-money laundering regulations, it is necessary to make a plan to address the weakness. If more training is necessary, it really is appropriate as part of the assessment to say so and attempt to make the case to management. The cost of compliance goes up geometrically when a bank is faced with enforcement action. It is much more efficient to seek the assistance when there are only potential problems as opposed to when actual problems have been found.
Residual Risk
Residual risk is defined as the possibility that compliance findings will occur after consideration of the effectiveness of controls. The less effective the controls, the higher the residual risk. Again, it is critical that the assessment in this area is one that has to be brutally honest. If overall controls are not what they should be, the weaknesses that exist should be reflected in the risk assessment. The goal of the assessment is to determine the areas that have the highest levels of risk and to allocate resources accordingly.
Using the Document
The compliance risk assessment is like a Swiss army knife- it has several uses. First, the compliance risk assessment should be used to help with the planning and scoping of audits for the year. The highest areas of risk should receive the greatest scrutiny by the auditors. Mover, the highest risk areas should be scheduled for review as early in the year as possible so that remediation efforts can be commenced and tested.
Rather than setting a basic training schedule, use the assessment to make sure that classes are focused on areas where the risk assessment has shown the potential for problems. The risk assessment can also be used to set the priorities for which policies and procedures need to be updated and in what order. The compliance risk assessment is a good tool for measuring the level and quality of compliance resources. As part of the risk assessment process, the level and quality of resources must be considered. As the process is concluded, it is natural to use the results to develop specific requests for additional staff, software, training or other resources that are necessary to maintain a strong compliance program.
Resource Allocation
Ultimately, resource allocation is one of the areas that examiners will consider when evaluating the effectiveness of the AML program. For example, if the company has identified a list of high risk customers and written a procedure for monitoring these clients, there must be sufficient people, software, training and other resources to complete the required monitoring.
Creating the Compliance Environment
Probably the greatest untapped asset for any compliance officer is staff. Without the support and input of the people who are actually contacting customers and performing day to day operations, the effectiveness of your compliance program will be greatly limited. Taking the time to discuss the purpose and goal of the regulations can go a long way toward getting staff involvement.
Making sure that senior management accepts the importance of compliance and the costs of non- compliance can help increase support.
***For More Information, please visit www.VCM4you.com ***