[eu]cite

Home› Anti-Money Laundering› GwG-EN

Section 6

Internal Safeguards

(1) Obliged entities shall establish appropriate business- and customer-related internal safeguards, in the form of policies, procedures and controls, to manage and mitigate the risks of money laundering and terrorist financing. Measures are appropriate where they correspond to, and adequately cover, the particular risk situation of the individual obliged entity. Obliged entities shall monitor the effectiveness of the internal safeguards and update them where necessary.
(2) Internal safeguards include in particular: 1. the development of internal policies, procedures and controls relating to a) the management of risks under subsection (1), b) the customer due diligence obligations under sections 10 to 17, c) compliance with the reporting obligation under section 43(1), d) the recording of information and the retention of documents under section 8, and e) compliance with other money-laundering-law provisions; 2. the appointment of an anti-money laundering officer and of that officer's deputy under section 7; 3. for obliged entities that are the parent undertaking of a group, the establishment of group-wide procedures under section 9; 4. the development and ongoing enhancement of appropriate measures to prevent the misuse of new products and technologies for the commission of money laundering and terrorist financing, or for purposes conducive to the anonymity of business relationships or transactions; 5. checking the reliability of employees by appropriate means, in particular through personnel vetting and assessment systems maintained by the obliged entity; 6. the initial and ongoing instruction of employees regarding typologies and current methods of money laundering and terrorist financing, and the relevant provisions and obligations, including data protection provisions; and 7. the review of the foregoing policies and procedures by way of an independent audit, insofar as such a review is appropriate in view of the nature and scale of the business.
(3) Insofar as an obliged entity under section 2(1), nos. 10 to 14 and 16 carries on its professional activity as an employee of an undertaking, the obligations under subsections (1) and (2) fall upon that undertaking.
(4) Obliged entities under section 2(1), no. 15 must, in addition to the measures referred to in subsection (2), operate data-processing systems by means of which they are able to detect business relationships as well as individual transactions in game operations and via a player account under section 16 that are to be regarded as doubtful or unusual, based on the publicly available knowledge, or the knowledge available within the undertaking, of the methods of money laundering and terrorist financing. They shall update these data-processing systems. The supervisory authority may determine criteria on the fulfilment of which obliged entities under section 2(1), no. 15 may dispense with the use of data-processing systems under the first sentence.
(4a) Crypto-asset service providers shall take appropriate measures to ensure compliance with the requirements of Regulation (EU) 2023/1113.
(5) Obliged entities shall, having regard to their nature and size, take appropriate arrangements to enable their employees and persons in a comparable position, while maintaining the confidentiality of their identity, to report breaches of money-laundering-law provisions to appropriate bodies.
(6) Obliged entities shall take arrangements to enable them, on request by the Financial Intelligence Unit or by another competent authority, to provide information as to whether, during a period of five years prior to the request, they maintained a business relationship with particular persons and as to the nature of that business relationship. They shall ensure that the information is transmitted to the requesting body securely and confidentially. Obliged entities under section 2(1), nos. 10 and 12 may refuse to provide the information where the request relates to information they received in the course of providing legal advice or representation in legal proceedings. The obligation to provide the information nonetheless remains where the obliged entity knows that the legal advice or representation in legal proceedings is or was used for the purpose of money laundering or terrorist financing.
(7) Obliged entities may have the internal safeguards carried out by a third party under contractual arrangements, provided they have given prior notice to the supervisory authority. The supervisory authority may prohibit the transfer where 1. the third party does not provide the assurance that the safeguards will be properly carried out, 2. the ability of the obliged entity to manage the matter is impaired, or 3. supervision by the supervisory authority is impaired. Obliged entities shall demonstrate in their notification that the grounds for a prohibition of the transfer under the second sentence do not apply. Responsibility for the fulfilment of the safeguards remains with the obliged entities.
(8) The supervisory authority may, in an individual case, issue orders that are suitable and necessary to ensure that the obliged entity establishes the necessary internal safeguards.
(9) The supervisory authority may order that, in respect of individual obliged entities or groups of obliged entities, having regard to the nature of the business they conduct and the size of their business operations and taking account of the money laundering or terrorist financing risks involved, the provisions of subsections (1) to (6) are to be applied in a manner proportionate to risk.

←→ also move between sections