• Skip to main content
  • Skip to footer

SILO Compliance

  • Why SILO?
  • Demo
  • FAQ
  • AML Grey Matters
  • Contact Us
You are here: Home / Blog / What is the Risk Based Approach and How Does It Affect Businesses and Compliance?

What is the Risk Based Approach and How Does It Affect Businesses and Compliance?

Applying a risk based approach to anti-money laundering, counter-terrorism financing and anti-proliferation programmes has been a difficult switch for many. For the past decade, most regulated businesses appointed a compliance officer and left him or her with the task of incorporating checklists, ticking boxes and maintaining records to show compliance.

However, adopting a risk based approach requires the participation of everyone in the organisation to be truly effective. But what is it exactly? Because no two businesses are the same, finding practical guidance can be frustrating.

We asked Kendra Foster, Founding Principal of U Law in the Cayman Islands, for some guidance on effectively switching to a risk based approach. Kendra noted that the four basic stages of a risk based approach are: (1) identifying risk; (2) assessing risk; (3) understanding risk; and (4) mitigating risk. She suggests the following approach to get started:

  1. Use common risk criteria – For identifying, assessing, understanding and mitigating your business risks as well as your customer risks, use common risk criteria as follows
    • Country or geographical risk (e.g. countries which do not have equivalent regulation);
    • Customer risk (e.g. costumers which present higher risks such as PEPs);
    • Product/service risk (e.g. how your products/services may be misused); and
    • Delivery channel risk (e.g. how your customers find you).
  2. Assign a risk level to your business and each customer – Risk levels to be assigned should represent a range such as low, medium or high. To assign a risk level, you could use a numerical system based on the common risk criteria above. When all relevant risk factors are considered together an appropriate risk level can be documented.
  3. Use appropriate tools – Business and customer risk assessment could be conducted using a paper based checklist with manual sign-off, using an automated spreadsheet with set formulas or using a customisable technology solution with electronic sign-off. Implementing a technology solution to automate the risk assessment, track assigned risk levels, implement workflows for internal controls and monitor requirements is highly recommended.
  4. Ensure the risk level assigned permeates the programme – Policies and procedures in relation to client acceptance, due diligence measures, ongoing monitoring, and termination of the relationship or conclusion of the transaction should be risk-based. For example, simplified or standard due diligence measures should not be applied for customers that have been assessed as high-risk.

You will need to write new procedures for your staff to document each aspect of the risk based programme including mitigation procedures. There are numerous ways to mitigate risk in your business. An example of mitigation procedures could be to require compliance and senior management sign-off on all higher risk customers while lower risk customers can be signed off by the account manager alone.

Remember, the reason for applying a risk based approach is to efficiently allocate your resources. A well designed risk based compliance programme will actually reduce your compliance costs in the long-run.

*Kendra is a founder of U Law in the Cayman Islands.  Formerly a Senior Associate at Maples and Calder and the Deputy Compliance Director at Intertrust, Kendra has over 14 years experience in the financial services industry and specialises in regulatory and risk management.  Kendra can be reached at kendra@ulaw.ky.

August 7, 2018 · m@kangabloo · Filed Under: Blog

Sign Up for AML Grey Matters

Subscribe Now

Footer

What Is SILO?

SILO is an easy-to-use application that enables you to archive and retrieve your client due diligence materials; to risk-rate and monitor your clients; to run the necessary reports on them; and to train your staff. It is, therefore, the ideal application to meet all your AML obligations.

Navigation

  • Why SILO?
  • Demo
  • FAQ
  • AML Grey Matters
  • Contact Us
  • Privacy Policy
  • Cookie Policy & Consent

Contact Us

+1 501-422-8030
info@silocompliance.com

Follow Us

SILO Compliance on LinkedIn

Copyright © 2022 SILO Compliance Ltd. All Rights Reserved. Powered by Kanga Studio.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of all the cookies. Read More
.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
_GRECAPTCHA5 months 27 daysThis cookie is set by the Google recaptcha service to identify bots to protect the website against malicious spam attacks.
cookielawinfo-checkbox-advertisement1 yearSet by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category .
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
CookieLawInfoConsent1 yearRecords the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie.
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
CookieDurationDescription
__cf_bm30 minutesThis cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
na_id1 year 24 daysThe na_id is set by AddThis to enable sharing of links on social media platforms like Facebook and Twitter.
ouid1 year 24 daysAssociated with the AddThis widget, this cookie helps users to share content across various networking and sharing forums.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
CookieDurationDescription
_ga2 yearsThe _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
_gat_gtag_UA_117971909_11 minuteSet by Google to distinguish users.
_gcl_au3 monthsProvided by Google Tag Manager to experiment advertisement efficiency of websites using their services.
_gid1 dayInstalled by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously.
uid1 year 24 daysThis is a Google UserID cookie that tracks users across various website segments.
vuid2 yearsVimeo installs this cookie to collect tracking information by setting a unique ID to embed videos to the website.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
CookieDurationDescription
__ss1 dayThis cookie is set by SharpSpring, a marketing automation platform. This is used for tracking visitors and form submissions.
__ss_referrer1 hourThis cookie is set by SharpSpring, a marketing automation platform. This is used for tracking visitors and form submissions.
__ss_tk25 yearsThis cookie is set by SharpSpring, a marketing automation platform. This is used for tracking visitors and form submissions.
_fbp3 monthsThis cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website.
fr3 monthsFacebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin.
IDE1 year 24 daysGoogle DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile.
IDSYNC1 yearThis cookie is set by Yahoo to store information on how users behave on multiple websites so that relevant ads can be displayed to them.
koitk10 yearsThis cookie is set by SharpSpring, a marketing automation platform. This is used for tracking visitors and form submissions.
pa_crosswise_ts2 yearsThe pa_crosswise_ts cookie is set by Perfect Audience for advertising purposes based on user behavioural data.
pa_google_ts2 yearsThe pa_google_ts cookie is set by Perfect Audience for advertising purposes based on user behavioural data.
pa_openx_ts2 yearsThe pa_openx_ts cookie is set by Perfect Audience for advertising purposes based on user behavioural data.
pa_rubicon_ts2 yearsThe pa_rubicon_ts cookie is set by Perfect Audience for advertising purposes based on user behavioural data.
pa_twitter_ts2 yearsThe pa_twitter_ts cookie is set by Perfect Audience for advertising purposes based on user behavioural data.
pa_uid2 yearsThis cookie is set by prfct.co. This cookie is used across the websites that use same ad network to display ads to the other advertisers in the network.
pa_yahoo_ts2 yearsThe pa_yahoo_ts cookie is set by Perfect Audience for advertising purposes based on user behavioural data.
personalization_id2 yearsTwitter sets this cookie to integrate and share features for social media and also store information about how the user uses the website, for tracking and targeting.
test_cookie15 minutesThe test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies.
uuid23 monthsThe uuid2 cookie is set by AppNexus and records information that helps in differentiating between devices and browsers. This information is used to pick out ads delivered by the platform and assess the ad performance and its attribute payment.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
CookieDurationDescription
A31 yearNo description
SAVE & ACCEPT
Powered by CookieYes Logo