1. Purpose
The purpose of this circular is to provide minimum AML/CFT programme expectations for entities seeking or holding an NLA-issued license. The programme should be proportionate to the nature, scale, and risk profile of the business.
2. Programme components (minimum)
- Risk assessment: documented assessment of customer, product, geography, delivery channel, and transaction risks.
- Customer due diligence (CDD): onboarding checks, identity verification, and beneficial ownership identification where applicable.
- Ongoing monitoring: transaction monitoring calibrated to risk and service model.
- Sanctions screening: screening at onboarding and at appropriate intervals thereafter.
- Recordkeeping: retrievable records and audit trails, including decision rationale for risk ratings and exceptions.
- Escalation & reporting: internal escalation triggers and documentation of decisions and actions taken.
- Training: role-based AML training for staff and relevant outsourced functions.
- Independent review: periodic independent testing proportionate to risk and complexity.
3. Customer onboarding expectations
- Define customer types and onboarding routes (retail, professional, institutional, intermediated).
- Apply enhanced due diligence for higher-risk customers and contexts (high-risk jurisdictions, complex ownership, high-volume activity).
- Maintain clear rules for acceptance, rejection, and exception approvals.
Minimum onboarding evidence (examples)
Identity document verification (where relevant), proof of address (where relevant), source of funds/source of wealth rationale for higher-risk profiles, beneficial ownership mapping for corporate structures, screening logs, and onboarding approval records.
4. Ongoing monitoring & triggers
- Define monitoring rules suitable for the product model (brokerage flows, payments, wallets, custody, exchange activity, etc.).
- Document triggers for review (rapid in/out flows, unusual volumes, repeated failed deposits, anomalous geographies, pattern breaks).
- Keep investigation notes and decision outcomes, including rationale for “no action” decisions.
5. Outsourcing & reliance
Where a licensee relies on third parties (e.g., onboarding vendors, screening tools, payment processors, KYC providers), the licensee remains responsible for ensuring controls are effective and auditable.
- Maintain contracts, SLAs, and evidence of vendor due diligence.
- Ensure access to logs, screening results, alerts, and case history.
- Define how data is retained and produced during reviews.