Copyright © 2007 Deloitte Development LLC. All rights reserved. BSA/AML Update Peter Fitzgerald Principal Deloitte & Touche LLP.

Slides:



Advertisements
Similar presentations
1 K P M G L L P A D V I S O R Y Changes in the IT Audit Profession Stephen G. Hasty, Jr. National Partner in Charge IT Advisory Savannah, GA January 4,
Advertisements

Organizational Governance
General tax landscape.
Internal Control–Integrated Framework
Seven sound practices Understand the quantity of money laundering risk at your organization Confirm that policies, procedures, and controls address all.
The Corporate Laws Amendment Bill, B6/2006. © 2006 Deloitte Touche Tohmatsu Corporate Laws Amendment Bill, B6/2006 – 29 May 2006 Introduction Presenting.
©2010 Prentice Hall Business Publishing, Auditing 13/e, Arens/Elder/Beasley The CPA Profession Chapter 2.
COMPLIANCE AND INTEGRITY IN GOVERNMENT AND NON-PROFIT ORGANIZATIONS Michael E. Nawrocki, CPA Managing Partner Nawrocki Smith LLP, CPA’s Historical Perspective.
© 2010 Deloitte Touche Tohmatsu Sustainable Business Australia Counting the beans - retro-fitted commercial buildings Chris Leach Partner, National Leader.
Introduction to Enterprise Risk Management (ERM)
Mind the Gap: Evaluating Internal Controls in Pharmaceutical Supply Chains across Sub-Saharan Africa AIDS 2012: July Julianna Kohler, Revathi Avasarala,
Tax Risk Management Keeping Up with the Ever-Changing World of Corporate Tax March 27, 2007 Tax Services Bryan Slone March 27, 2007.
University of Connecticut April 17, Copyright © 2006 Deloitte Development LLC. All rights reserved. Items to discuss… Introduction Deloitte Overview.
Charles E. Constantin Director, Senior Bank Regulatory Compliance Officer Royal Bank of Canada, RBC Capital Markets Institute of International Bankers.
Pricing for value Tom Friedman, Principal Deloitte Consulting LLP Global Consulting Leaders Symposium December 5–7, 2007.
Deloitte in India APLG Annual Meeting Savannah, Georgia February 14, 2011.
Caribbean Indigenous Banks Anti-Money Laundering Survey
© 2013 Cengage Learning. All Rights Reserved. 1 Part Four: Implementing Business Ethics in a Global Economy Chapter 8: Developing an Effective Ethics Program.
Risk Intelligence Map – Board level output
The CPA Profession Chapter 2.
1 Copyright © 2006 Deloitte Development LLC. All rights reserved. The Case ABC Molecular Imaging is seeking an Investment Bank to advise them on the sale.
Financial structure, management, and IFRS Reporting Creating value for growth Presenter: John Robinson Partner.
TELLEFSEN AND COMPANY, L.L.C. SEC Regulation SCI and Automation Review Policy Compliance March 2013 Proprietary and Confidential.
“The Impact of Sarbanes Oxley, An Evolving Best Practice” Ellen C. Wolf Senior Vice President & Chief Financial Officer American Water National Association.
V. Conferencia Internacional Antilavado de dinero y Contra el Financiamiento al Terrorismo Anti-Money Laundering Compliance for Broker/Dealers Current.
Trade Across the Americas: Bolstering Security and Efficiency Supply Chain Risk Analytics May 2015.
Internal Auditing and Outsourcing
Agenda Overview Current Environment
CLICK TO ADD TITLE The 5th Global Health Supply Chain Summit
Tax Transformation: What does it mean to you?
The Institutionalization of Business Ethics
The CPA Profession Chapter 2 By Arens et. al. Learning Objective 1 Describe the nature of CPA firms, what they do, and their structure.
Global Risk Management Survey: Fifth Edition Key Findings
Audit objectives, Planning The Audit
Fiduciary & Investment Risk Management Association
Do it pro bono. Strategic Scorecard Service Grant The Strategy Management Practice is presented by Wells Fargo. The design of the Strategic Scorecard Service.
Developing an Effective Ethics Program
Chapter 5 Internal Control over Financial Reporting
Internal Control in a Financial Statement Audit
A high-level and hands-on approach for organizations to deal with counterfeiting and piracy. Jan Corstens WIPO Moscow
© 2011 Deloitte Global Services Limited United Nations Global Compact Management Model Signatory Training.
Domestic Production Activities Deduction – Section 199 March 26, 2007 Pamela C. Beckey.
DoC NTIA Digital-to-Analog Converter Box Coupon Program NPRM Nicholas Van Dongen, Senior Manager Allen Hockenbury, Senior Manager November 14, 2006.
Mike Wyatt, Director State Public Sector Cyber Risk Services
Corporate Governance Yoshi Kawai Secretary General, IAIS IAIS-ASSAL Regional Seminar Buenos Aires, Argentina, November 2011 PUBLIC.
KNR- Studiedag 25 september 2013 Btw-checklist. © 2013 Deloitte The Netherlands KNR Studiedag Btw-checklist 1.
October 10-13, 2006 San Diego Convention Center, San Diego California Regulation for VoIP Providers What’s the impact on your business.
+ Regulation and Compliance Summary “ Making Great Ideas Become Reality”
Copyright © 2007 Pearson Education Canada 1 Chapter 1: The Demand for Auditing and Assurance Services.
BSA PROGRAM REQUIREMENTS.  Written, approved by the board of directors, and noted in the board minutes.  Based on the risk assessment  Fully implemented.
Deloitte Forensic Forensic Technology Conference of Regulatory Officers - CORO November 2012.
ANTI-MONEY LAUNDERING COMPLIANCE PROGRAM FCM TRAINING
Enterprise Risk Management for US Operations of International Banks Communication and Education.
1 Copyright © 2006 Deloitte Development LLC. All rights reserved. The Case ABC Automotive Products has selected you to advise them on the sale of their.
AML Compliance Findings & Observations Wyn Clark U.S. Treasury.
Internal/External Audit and Internal Controls February 23, 2000 David Dudley Federal Reserve Bank of NY.
Company: Cincinnati Insurance Company Position: IT Governance Risk & Compliance Service Manager Location: Fairfield, OH About the Company : The Cincinnati.
Copyright © 2007 Pearson Education Canada 9-1 Chapter 9: Internal Controls and Control Risk.
Risks and Controls A day in the life of our Advisory Practice November 2015.
MIS 374 Christine Lyman, Sr. Manager Jan 2015 Root Cause Analysis.
ICAJ/PAB - Improving Compliance with International Standards on Auditing Planning an audit of financial statements 19 July 2014.
1 Vereniging van Compliance Officers The Compliance Function in Banks Amsterdam, 10 June 2004 Marc Pickeur CBFA CBFA.
1Third Party Assurance Optimization and Control RationalizationCopyright © 2016 Deloitte Development LLC. All rights reserved. Third-Party Assurance (TPA)
Chapter 6 Internal Control in a Financial Statement Audit McGraw-Hill/IrwinCopyright © 2012 by The McGraw-Hill Companies, Inc. All rights reserved.
The CPA Profession Chapter 2.
The Importance of an AML Programme
Modernizing compliance: Moving from value protection to value creation
Chapter 8 Developing an Effective Ethics Program
Onboarding: Update Your Approach with Human-Centered Design
MAZARS’ CONSULTING PRACTICE Helping your Business Venture Further
Presentation transcript:

Copyright © 2007 Deloitte Development LLC. All rights reserved. BSA/AML Update Peter Fitzgerald Principal Deloitte & Touche LLP

Copyright © 2007 Deloitte Development LLC. All rights reserved. Evolving Regulatory Approach Risk-based supervisory approach Establish a “culture of compliance” –Set tone at the top Top management is ultimately responsible for compliance –Business is responsible for day-to-day compliance –Compliance management plays a key role in corporate governance, monitoring and advisory functions

Copyright © 2007 Deloitte Development LLC. All rights reserved. Evolving Regulatory Approach (cont.) Greater reliance on institution’s own monitoring Focus on systems, procedures and controls Compliance with “letter and spirit” of the law Enforcement actions are mainly being driven by failure of institutions to adequately design and/or implement their BSA/AML programs, e.g., –Failure to effectively file SARs –Insufficient resources/oversight –Inadequate testing –Missing the risks

Copyright © 2007 Deloitte Development LLC. All rights reserved. Evolving Regulatory Approach (cont.) “Examiners expect to find certain core principles of risk management including, top level involvement, clear responsibilities at each level of management, independence of risk controls, strong well- developed systems and effective monitoring and reporting.” Mary Ann Gadziala, Associate Director, OCIE, Securities and Exchange Commission “A culture of compliance should establish – from the top of the organization – the proper ethical tone that will govern the conduct of business. In many instances, senior management must move from thinking about compliance as a cost center to considering the benefits of compliance in protecting against legal and reputational risks that can have an impact on the bottom line.” Former Governor Susan Schmidt Bies, Board of Governors of the Federal Reserve System

Copyright © 2007 Deloitte Development LLC. All rights reserved. BSA/AML Program Should Be Based A Risk-Based One Process People Technology Threads Policy & Procedures Account / Transaction Monitoring Record Keeping / Retention AML Regulatory Requirements Risk Profile Testing Governance Risk Assessment P&P / Structure CIP/CDD/EDD Reporting Organization & Controls Maintenance Training / Testing

Copyright © 2007 Deloitte Development LLC. All rights reserved. Characteristics of a BSA/AML Program Provide adequate human and financial resources Provide compliance staff with appropriate authority and independence Link compliance objectives to Senior Management’s goals (and compensation) Identify and assess compliance risk across the entire organization Maintain understanding of applicable laws and regulations Establish policies, procedures and internal controls

Copyright © 2007 Deloitte Development LLC. All rights reserved. Characteristics of a BSA/AML Program (cont.) Develop risk measurement, monitoring and MIS to provide timely reports Establish internal controls for analyzing new business activities and products Establish an escalation process for reporting identified risks or breaches Take corrective actions/interim controls to address breaches and track exceptions until resolved Ensure compliance staff objectivity and independence from business lines

Copyright © 2007 Deloitte Development LLC. All rights reserved. Readiness Level Risk AssessmentCompliance Organization MonitoringReportingIndependent Testing 1 No Risk AssessmentA Written Program Board Approval Manual Efforts, No Standards Set Manual Efforts, Inconsistent Standards across business units No Independent Testing or testing is not effective 2 Risk Assessment Completed at the BU Level for High Risk Businesses based on products and services but not quantity of risk assessment Policies and Procedures are defined but not adequate to address the risks defined to the BU Level Standards Set at the BU level. Technology is in place but not effectively implemented Some Automation, Inconsistent Standards across Business Units results in incomplete or inconsistent reporting Testing takes place but is not risk based, does not cover assessment of the business compliance unit and is not effective 3 Risk Assessment Completed at the BU level for all LOBS Policies and Procedures are defined and are adequate to address the risks defined to the BU Level Standards Set at the BU Level. Technology is in place at BU and effectively implemented Automation and Consistent BU standards are in place however inability to aggregate at the enterprise level results in unclear reporting Testing takes place, is somewhat effective and is aligned with Enterprise Risk Assessment 4 High Level Risk Assessment completed for the enterprise Policies and Procedures are defined and are adequate to address the risks defined to the enterprise Standards are set at the Enterprise Level. Supporting Technology is in place at the enterprise level but not effectively implemented Automated Reporting and enterprise standards are in place Testing is effective and aligned with the enterprise 5 Detailed Enterprise Risk Assessment for all lines of business and is communicated to the Board as well as key business owners Culture of Compliance is imbedded into the corporate DNA and is embedded into operational process of all of the business units Ongoing refinement of policies and procedures is way of life Technology is in place at the enterprise level and the organization has the ability to monitor accounts for suspicious activity based on the total relationship and transaction life cycle SAR Reporting threshold is consistently applied across business units Sr Management and Board Level reporting is consistent and effective in a culture of compliance Attests to overall integrity/effectivenes s of management and controls Where is Your Organization? A method to project, manage and monitor progress

Copyright © 2007 Deloitte Development LLC. All rights reserved. 9 Motivation for Compliance Privileged and Confidential Fulfilling a social responsibility for the companies and a moral imperative for the individuals. Guarding your employment, good name, professional integrity, and the good name of your company. Avoiding criminal and civil liability under the BSA as well as money laundering laws, regulatory enforcement actions, and related shareholder suits. Avoiding aggressive scrutiny by regulators and a loss of confidence in your company by the regulators. Trust and good will lost are hard to regain.

Copyright © 2007 Deloitte Development LLC. All rights reserved. Contact Information Peter Fitzgerald Principal Deloitte & Touche LLP

Copyright © 2007 Deloitte Development LLC. All rights reserved. About Deloitte Deloitte refers to one or more of Deloitte Touche Tohmatsu, a Swiss Verein, its member firms and their respective subsidiaries and affiliates. Deloitte Touche Tohmatsu is an organization of member firms around the world devoted to excellence in providing professional services and advice, focused on client service through a global strategy executed locally in nearly 150 countries. With access to the deep intellectual capital of 120,000 people worldwide, Deloitte delivers services in four professional areas, audit, tax, consulting and financial advisory services, and serves more than one-half of the world’s largest companies, as well as large national enterprises, public institutions, locally important clients, and successful, fast-growing global growth companies. Services are not provided by the Deloitte Touche Tohmatsu Verein and, for regulatory and other reasons, certain member firms do not provide services in all four professional areas. As a Swiss Verein (association), neither Deloitte Touche Tohmatsu nor any of its member firms has any liability for each other’s acts or omissions. Each of the member firms is a separate and independent legal entity operating under the names “Deloitte”, “Deloitte & Touche”, “Deloitte Touche Tohmatsu” or other related names. In the US, Deloitte & Touche USA LLP is the US member firm of Deloitte Touche Tohmatsu and services are provided by the subsidiaries of Deloitte & Touche USA LLP (Deloitte & Touche LLP, Deloitte Consulting LLP, Deloitte Financial Advisory Services LLP, Deloitte Tax LLP and their subsidiaries), and not by Deloitte & Touche USA LLP. The subsidiaries of the US member firm are among the nation's leading professional services firms, providing audit, tax, consulting and financial advisory services through nearly 30,000 people in more than 80 cities. Known as employers of choice for innovative human resources programs, they are dedicated to helping their clients and their people excel. For more information, please visit the US member firm’s web site at This presentation contains general information only, including the results of an informal survey conducted by Deloitte & Touche LLP. Deloitte & Touche LLP is not, by means of this presentation, rendering accounting, business, financial, investment, legal, tax, or other professional advice or services. This presentation is not a substitute for such professional advice or services, nor should it be used as a basis for any decision or action that may affect your business. Before making any decision or taking any action that may affect your business, you should consult a qualified professional advisor. Deloitte & Touche LLP, its affiliates and related entities shall not be responsible for any loss sustained by any person who relies on this publication.