Four query types.
Real questions, real outputs.
BASILISK answers in four shapes. Below are actual outputs from the BASILISK API, run against the Isle of Man corpus. Click any example to expand the full answer and citations.
The AML/CFT Code 2019 does not specify a fixed review frequency for the business risk assessment. The statutory text, at paragraph 5, states that the business risk assessment must be "regularly reviewed (details of any review must be recorded) and, if appropriate, amended so as to keep the assessment up-to-date." That is the full extent of what the Code prescribes on timing — the word "regularly" is used without further definition of interval.
The Code also requires, at paragraph 5, that the business risk assessment be "undertaken as soon as reasonably practicable after the relevant person commences business" and "recorded in order to demonstrate its basis." These are the three limbs of the obligation: initial completion, recording, and regular review with recorded details of each review.
Any more specific guidance on what "regularly" means in practice — for example, annual review cycles or event-triggered reviews — would come from the Authority's AML/CFT Handbook (https://www.iomfsa.im/amlcft/amlcft-requirements-and-guidance/) rather than from the Code itself. The Handbook is not a legal document and should not be relied upon as statute; it represents supervisory expectation rather than a binding statutory requirement. For the precise supervisory framing, consult the Handbook directly.
Citations
- 1ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 20195IoM
(1) A relevant person must carry out an assessment that estimates the risk of ML/FT posed by the relevant person’s business and customers.
Under the AML/CFT Code 2019, paragraph 15(3) sets out three circumstances in which enhanced customer due diligence is mandatory. First, where a customer poses a higher risk of ML/FT as assessed by the customer risk assessment. Second, without limiting the ongoing monitoring obligation in paragraph 13, in the event of any unusual activity. Third, without limiting the suspicious activity reporting obligation in paragraph 26, in the event of any suspicious activity — unless the relevant person reasonably believes that conducting EDD would tip off the customer.
Paragraph 15(5) identifies two matters that automatically constitute a higher risk of ML/FT for these purposes: a business relationship or occasional transaction with a customer resident or located in a jurisdiction in List A, and a customer that is the subject of a warning in relation to AML/CFT matters issued by a competent authority or equivalent authority in another jurisdiction. Where either of those conditions applies, paragraph 15(6) requires that the relevant person's senior management must approve the establishment or continuation of the business relationship or occasional transaction. Paragraph 15(7) also identifies a broader range of matters that may pose a higher risk, including activity in a List B jurisdiction, business with a PEP, companies with nominee shareholders or shares in bearer form, high-net-worth individuals, legal arrangements, and high-risk products, among others.
The consequences of failing to complete EDD within a reasonable timeframe are set out in paragraph 15(8): the business relationship or occasional transaction must proceed no further, the relevant person must consider terminating the relationship, and the relevant person must consider making an internal disclosure. It is also important to note that where a higher risk of ML/FT is assessed under paragraph 15(3)(a), the simplified or reduced CDD provisions in paragraphs 16 to 19 and certain other provisions cease to apply, as confirmed by paragraph 15(4). Contravention of the Code's requirements, including paragraph 15, constitutes an offence under AML/CFT Code 2019, paragraph 42.
Citations
- 1Anti-Money Laundering and Countering the Financing of Terrorism Code 201915(3)IoM
A relevant person must conduct enhanced customer due diligence — (a) where a customer poses a higher risk of ML/FT as assessed by the customer risk assessment; (b) without limiting paragraph 13, in th
- 2ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201942IoM
A person who contravenes the requirements of this Code is guilty of an offence and liable —
- 3ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201913IoM
A relevant person must perform ongoing and effective monitoring of any business relationship or occasional transaction, including — (a) a review of information and documents held for the purpose of cu
- 4Anti-Money Laundering and Countering the Financing of Terrorism Code 201915(5)IoM
Matters that pose a higher risk of ML/FT include — (a) a business relationship or occasional transaction with a customer that is resident or located in a jurisdiction in List A; and (b) a customer tha
- 5Anti-Money Laundering and Countering the Financing of Terrorism Code 201915(6)IoM
If sub-paragraph (5)(a) or (b) applies, the relevant person’s senior management must approve the establishment, or continuation, of the business relationship or the occasional transaction.
- 6Anti-Money Laundering and Countering the Financing of Terrorism Code 201915(7)IoM
Matters that may pose a higher risk of ML/FT include — (a) activity in a jurisdiction the relevant person deems to be higher risk of ML/FT; (b) a business relationship or occasional transaction with a
- 7Anti-Money Laundering and Countering the Financing of Terrorism Code 201915(8)IoM
Except as provided in Part 6, where the requirements of this paragraph are not met within a reasonable timeframe, the procedures and controls must provide that — (a) the business relationship or occas
- 8Anti-Money Laundering and Countering the Financing of Terrorism Code 201915IoM
(1) A relevant person must establish, record, maintain and operate appropriate procedures and controls in relation to undertaking enhanced customer due diligence.
- 9Anti-Money Laundering and Countering the Financing of Terrorism Code 201915(4)IoM
For the avoidance of doubt, if higher risk of ML/FT within the meaning of sub-paragraph (3)(a) is assessed, then paragraphs 8(4), 11(4), 11(5), 16 to 19, 20(2), (3), (5) and 21 do not apply.
The AML/CFT Code 2019, paragraph 13, sets out the ongoing monitoring obligation. A relevant person must perform ongoing and effective monitoring of any business relationship or occasional transaction. This has two principal limbs: first, a review of information and documents held for CDD and enhanced CDD purposes to ensure they remain up-to-date, accurate and appropriate — with particular attention where the transaction or relationship poses a higher risk of ML/FT; and second, appropriate scrutiny of transactions and other activities to ensure they are consistent with the relevant person's knowledge of the customer, the customer's business and risk profile, and the source of funds of the transaction, and with the business risk assessment carried out under paragraph 5.
Paragraph 12 of the Code is also engaged: it applies whenever a relevant person is operating any of the procedures and controls required by Parts 3, 4, 5 and 6, which encompass the ongoing monitoring regime. The practical effect is that ongoing monitoring is not a standalone exercise but sits within the broader framework of CDD procedures that must be established, recorded, maintained and operated throughout the life of the relationship.
The full text of paragraph 13 beyond the elements reproduced here — including any further sub-paragraphs — is not fully set out in the provisions considered for this brief. Firms should verify the complete wording of paragraph 13 against the AML/CFT Code 2019 directly. The IOMFSA's AML/CFT Handbook (https://www.iomfsa.im/amlcft/amlcft-requirements-and-guidance/) provides additional interpretive guidance on how the Authority expects these obligations to be discharged in practice, though the Handbook is not a legal document and does not substitute for the statutory provisions of the Code.
Citations
- 1ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201913IoM
A relevant person must perform ongoing and effective monitoring of any business relationship or occasional transaction, including — (a) a review of information and documents held for the purpose of cu
- 2ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 20195IoM
(1) A relevant person must carry out an assessment that estimates the risk of ML/FT posed by the relevant person’s business and customers.
- 3ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201912IoM
This paragraph applies when a relevant person is operating any of the procedures and controls required by Parts 3, 4, 5 and 6.
Beneficial Ownership Act 2017: Definition and Threshold
Statutory Framework
The Beneficial Ownership Act 2017 establishes two distinct but related concepts: the general definition of "beneficial owner" and the narrower category of "registrable beneficial owner". Each carries different obligations and thresholds. The Act applies to all Isle of Man legal entities listed in Beneficial Ownership Act 2017, s.5(1), including companies under both the Companies Act 1931 and the Companies Act 2006.
1. General Definition: "Beneficial Owner"
Under Beneficial Ownership Act 2017, s.4(1):
"beneficial owner" means a natural person who ultimately owns or controls a legal entity to which this Act applies, in whole or in part, through direct or indirect ownership or control of shares or voting rights or other ownership interest in that entity, or who exercises control via other means
Key elements of this definition:
- The beneficial owner must be a natural person (not a company or other legal arrangement)
- Ownership or control may be direct or indirect
- The routes to beneficial ownership are: ownership of shares, ownership of voting rights, any other ownership interest, or control via other means
- There is no percentage threshold in the general definition — a natural person who ultimately owns or controls any part of a legal entity may qualify
2. Registrable Beneficial Owner: The Threshold
The narrower category of "registrable beneficial owner" — which triggers the obligation to submit information to the Isle of Man Database of Beneficial Ownership — carries a specific threshold. This definition was substituted by the Beneficial Ownership Act 2017 (Amendment) Order 2026, s.4, in operation 25 May 2026.
Under the amended definition (Beneficial Ownership Act 2017, s.3(1), as substituted by the 2026 Amendment Order):
"registrable beneficial owner" means a natural person who — (a) ultimately owns or controls 25% or more of a legal entity to which this Act applies, including through direct or indirect ownership of — (i) shares; or (ii) voting rights; or (b) exercises, or is entitled to exercise, control over the legal entity via other means, whether directly or indirectly
The threshold is therefore "25% or more" of shares or voting rights for registration purposes.
Meaning of "Control via Other Means"
Beneficial Ownership Act 2017, s.3(1A) (inserted by the 2026 Amendment Order, s.4) provides that:
"control via other means" includes any ability (whether formal or informal, legally enforceable or not) to direct, determine, influence or veto a decision relating to the management, activities, assets, governance, beneficiaries, distributions, or other affairs of the legal entity, including where such control is exercised through a legal arrangement (such as a trust, or any equivalent structure)
The same provision clarifies that where ownership or control is exercised through a legal arrangement:
the registrable beneficial owner — (i) is the natural person who ultimately exercises such ownership or control; and (ii) is not the legal arrangement or any legal person acting in a nominee, representative or fiduciary capacity
3. Required Details for Registrable Beneficial Owners
Under Beneficial Ownership Act 2017, s.11(1)(a), the required details for a beneficial owner include, among other items, the nature and extent of the interest in the legal entity, expressed as a percentage unless the control is via other means (this qualification was inserted by the 2026 Amendment Order, s.6).
4. Summary: Two Thresholds, Two Obligations
| Concept | Threshold | Source |
|---|---|---|
| Beneficial owner (general) | No percentage threshold — any ultimate ownership or control | Beneficial Ownership Act 2017, s.4(1) |
| Registrable beneficial owner (Database registration) | "25% or more" of shares or voting rights, or control via other means | Beneficial Ownership Act 2017, s.3(1), as substituted by the 2026 Amendment Order |
5. Transitional Provisions (2026 Amendment)
The 2026 Amendment Order, s.5, sets out transitional provisions for entities incorporated before 25 May 2026. Nominated officers of such entities are required to submit a statement of compliance by dates that vary depending on when the entity's annual return falls due, with a longstop date of 15 September 2026 in most cases. Entities incorporated on or after 25 May 2026 must submit registrable beneficial ownership information in accordance with the amended definitions from the outset (2026 Amendment Order, s.5(6)).
Citations
- 1BENEFICIAL OWNERSHIP ACT 20175(1)IoM
This Act applies to the following legal entities — (a) a company to which the Companies Acts 1931 to 2004 apply, including — (i) a company within the meaning of the Companies Act 1931; (ii) a protecte
- 2BENEFICIAL OWNERSHIP ACT 20174(1)IoM
In this Act “beneficial owner” means a natural person who ultimately owns or controls a legal entity to which this Act applies, in whole or in part, through direct or indirect ownership or control of
- 3BENEFICIAL OWNERSHIP ACT 20173(1)IoM
In this Act — “annual return” means — (a) in relation to a company to which the Companies Acts 1931 to 2004 apply, the annual return required by sections 107 to 110 of the Companies Act 1931; (b) in r
- 4BENEFICIAL OWNERSHIP ACT 20173(1A)IoM
For the purposes of the definition of “registrable beneficial owner” in subsection (1) — (a) “control via other means” includes any ability (whether formal or informal, legally enforceable or not) to
- 5BENEFICIAL OWNERSHIP ACT 2017 (AMENDMENT) ORDER 20264IoM
In section 3 (interpretation) — (a) in subsection (1), for the definition of “registrable beneficial owner” substitute — «“registrable beneficial owner” means a natural person who — (a) ultimately own
- 6BENEFICIAL OWNERSHIP ACT 201711IoM
(1) The “required details” are — (a) in respect of a beneficial owner — (i) his or her name; (ii) his or her usual r
- 7BENEFICIAL OWNERSHIP ACT 2017 (AMENDMENT) ORDER 20266IoM
In section 11(1)(a)(vii), after “expressed as a percentage” insert «, unless the control is via other means».
- 8BENEFICIAL OWNERSHIP ACT 2017 (AMENDMENT) ORDER 20265IoM
For the purposes of this article — “statement of compliance” means the annual statement to be submitted to the Department for Enterprise by the nominated officer under section 42(1)(b) of the Act whic
- 9BENEFICIAL OWNERSHIP ACT 2017 (AMENDMENT) ORDER 20265(6)IoM
To avoid doubt, the nominated officer of a legal entity incorporated on or after 25 May 2026, must submit registrable beneficial ownership information in accordance with the Act, taking account of the
MLRO Independence and Reporting Line to Senior Management — AML/CFT Code 2019
Statutory Framework
The AML/CFT Code 2019 (the "Code") addresses the appointment, qualifications, and functions of the Money Laundering Reporting Officer ("MLRO") principally in paragraphs 23, 24, and 25. The provisions reproduced here do not contain a freestanding "independence" clause using that term, but they establish structural requirements that bear directly on the MLRO's position and reporting obligations.
1. Appointment Obligation
Under the AML/CFT Code 2019, paragraph 23(1), a relevant person must appoint a Money Laundering Reporting Officer ("MLRO") to exercise the functions required under paragraphs 25 and 27.
The Code does not, in the provisions considered here, set out the full eligibility criteria for who may be appointed as MLRO (e.g., seniority requirements, fit-and-proper requirements) within paragraph 23 itself — the text of paragraph 23(1) as reproduced here is limited to the appointment obligation and the functional remit. Verify the complete wording of paragraph 23 against the Code directly for any additional sub-paragraphs.
2. Insurance Sector: Specific MLRO Requirements
For insurers, insurance intermediaries, and insurance managers, AML/CFT Code 2019, paragraph 24(1) imposes additional requirements without limiting paragraph 23. Specifically:
- (a) In the case of an insurer authorised under section 8 of the Insurance Act 2008, an insurance intermediary or an insurance manager registered under section 25 of the Insurance Act 2008, the MLRO must be resident in the Island;
- (b) The MLRO must be treated as a principal control officer for the purposes of the notice required under section 29(1) of the Insurance Act 2008; and
- (c) The MLRO must be sufficiently senior in the organisation or have sufficient experience and authority, including where the MLRO is not an employee of the insurer.
Paragraph 24(1)(c) is the closest the reproduced statutory text comes to an express seniority/authority requirement. It applies specifically to the insurance sector. Whether an equivalent provision applies to all relevant persons under paragraph 23 cannot be confirmed from the text of paragraph 23(1) as reproduced here; verify the full text of paragraph 23 against the Code directly.
3. Reporting Procedures and the MLRO's Role in the Reporting Chain
Under AML/CFT Code 2019, paragraph 25, a relevant person must establish, record, maintain and operate reporting procedures and controls that:
- (a) enable its officers and all other persons involved in its management, and all appropriate employees and workers to know to whom any suspicious activity is to be disclosed;
- (b) ensure that there is a clear reporting chain to the MLRO;
- (c) require an internal disclosure to be made to the MLRO if any information, or other matters that come to the attention of the person handling that business, are in that person's opinion suspicious activity;
- (d) ensure that the MLRO has full access to any other information that may be of assistance and that is available to the relevant person;
- (e) require the MLRO to consider internal disclosures in light of all other relevant information available to the MLRO for the purpose of determining whether the activity is, in the MLRO's opinion, suspicious activity;
- (f) enable the information to be provided as soon as is practicable to the Financial Intelligence Unit as an external disclosure if the MLRO knows or suspects, or has reasonable grounds for knowing or suspecting, the activity is ML/FT; and
- (g) ensure the registers required by paragraphs 28 and 29 are maintained and completed in accordance with those paragraphs.
Paragraph 25(b) expressly requires a clear reporting chain to the MLRO — this is the Code's structural mechanism for ensuring the MLRO sits at the apex of internal suspicious-activity reporting. Paragraph 25(d) reinforces this by requiring that the MLRO have full access to all relevant information available to the relevant person.
4. MLRO Functions: External Disclosure
Under AML/CFT Code 2019, paragraph 27(1), where an internal disclosure has been made, the MLRO must assess the information contained within the disclosure to determine whether there are reasonable grounds for knowing or suspecting that the activity is ML/FT.
This provision confirms that the MLRO exercises an independent assessment function — the MLRO, not senior management, makes the determination on whether to escalate to the Financial Intelligence Unit.
5. Internal Disclosure Trigger
Under AML/CFT Code 2019, paragraph 26, where a relevant person identifies any suspicious activity in the course of a business relationship or occasional transaction, the relevant person must:
- (a) conduct enhanced customer due diligence in accordance with paragraph 15, unless the relevant person reasonably believes conducting enhanced customer due diligence will tip off the customer; and
- (b) make an internal disclosure.
6. Registers
Under AML/CFT Code 2019, paragraph 28(1), a relevant person must establish and maintain separate registers of:
- (a) all internal disclosures;
- (b) all external disclosures; and
- (c) any other disclosures to the Financial Intelligence Unit.
Under paragraph 29, a relevant person must establish and maintain a register of all ML/FT enquiries received by it from competent authorities.
Summary Table
| Requirement | Code Paragraph |
|---|---|
| Obligation to appoint an MLRO | Paragraph 23(1) |
| Insurance MLRO: IoM residency, seniority/authority | Paragraph 24(1)(a), (c) |
| Insurance MLRO: principal control officer status | Paragraph 24(1)(b) |
| Clear reporting chain to the MLRO | Paragraph 25(b) |
| Full information access for the MLRO | Paragraph 25(d) |
| MLRO's independent assessment of disclosures | Paragraph 27(1) |
| Internal disclosure obligation on identification of suspicious activity | Paragraph 26(b) |
| Registers of disclosures | Paragraph 28(1) |
| Register of ML/FT enquiries | Paragraph 29(1) |
Gap Notice
The full text of paragraph 23 (including any sub-paragraphs addressing seniority, fit-and-proper status, authority, location, and reporting to senior management) is not fully reproduced here. The obligation in paragraph 23(1) as reproduced extends only to the appointment obligation and the functional remit (paragraphs 25 and 27). Consult the AML/CFT Code 2019, paragraph 23, directly for the complete eligibility and structural requirements applicable to all relevant persons.
The AML/CFT Handbook (https://www.iomfsa.im/amlcft/amlcft-requirements-and-guidance/) provides supervisory guidance on the MLRO role, including on seniority and reporting to senior management, but that guidance is not statutory authority and must not be read as if it were the Code.
Citations
- 1ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201923(1)IoM
A relevant person must appoint a Money Laundering Reporting Officer (“MLRO”) to exercise the functions required under paragraphs 25 and 27.
- 2ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201924(1)IoM
Without limiting paragraph 23, the MLRO of an insurer, an insurance intermediary or an insurance manager must — (a) in the case of an insurer authorised under section 8 of the Insurance Act 2008, an i
- 3ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201925IoM
A relevant person must establish, record, maintain and operate reporting procedures and controls that — (a) enable its officers and all other persons involved in its management, and all appropriate em
- 4ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201927(1)IoM
Where an internal disclosure has been made, the MLRO must assess the information contained within the disclosure to determine whether there are reasonable grounds for knowing or suspecting that the ac
- 5ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201926IoM
Where a relevant person identifies any suspicious activity in the course of a business relationship or occasional transaction the relevant person must — (a) conduct enhanced customer due diligence in
- 6ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201928(1)IoM
A relevant person must establish and maintain separate registers of — (a) all internal disclosures; (b) all external disclosures; and (c) any other disclosures to the Financial Intelligence Unit.
- 7ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201923IoM
A relevant person must appoint a Money Laundering Reporting Officer (“MLRO”) to exercise the functions required under paragraphs 25 and 27.
- 8ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201924IoM
Without limiting paragraph 23, the MLRO of an insurer, an insurance intermediary or an insurance manager must — (a) in the case of an insurer authorised under section 8 of the Insurance Act 2008, an i
- 9Anti-Money Laundering and Countering the Financing of Terrorism Code 201915IoM
(1) A relevant person must establish, record, maintain and operate appropriate procedures and controls in relation to undertaking enhanced customer due diligence.
- 10ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201929IoM
(1) A relevant person must establish and maintain a register of all ML/FT enquiries received by it from competent authorities.
PRIVATE AND CONFIDENTIAL ADVISORY MEMORANDUM
TO: Money Laundering Reporting Officer FROM: Senior Compliance Officer DATE: [Current Date] RE: Obligations Arising on Re-Rating of Long-Standing Client to High Risk CLASSIFICATION: Restricted — MLRO / Senior Management Only
SUMMARY
A long-standing client whose risk rating has been elevated to high triggers an immediate and concurrent set of statutory obligations under the Anti-Money Laundering and Countering the Financing of Terrorism Code 2019 (the "Code"). These obligations are not discretionary and do not benefit from any transitional grace period by reason of the client's tenure. This memorandum sets out the firm's immediate obligations, the applicable timelines, and the documentation that must be produced.
1. The Trigger: What the Re-Rating Means in Law
The Code imposes a risk-based framework. A customer risk assessment is required under AML/CFT Code 2019, paragraph 6(1), which requires the firm to carry out an assessment estimating the risk of ML/FT posed by each customer. Where that assessment now produces a higher risk finding, a distinct and mandatory set of obligations is activated across multiple Code provisions simultaneously.
Critically, paragraph 15(4) of the Code provides that where higher risk of ML/FT is assessed within the meaning of paragraph 15(3)(a), certain simplified or standard-track provisions (paragraphs 8(4), 11(4), 11(5), 16 to 19, 20(2), (3), (5) and 21) cease to apply. Any prior reliance on those provisions for this client must be reviewed and, where applicable, discontinued immediately.
2. Immediate Obligation: Enhanced Customer Due Diligence (ECDD)
AML/CFT Code 2019, paragraph 15(3)(a) provides that a relevant person must conduct enhanced customer due diligence where a customer poses a higher risk of ML/FT as assessed by the customer risk assessment. This obligation is mandatory and arises at the point of re-rating.
Paragraph 15(2) specifies what ECDD includes:
(a) considering whether additional identification information needs to be obtained and, if so, obtaining such additional information; (b) considering whether additional aspects of the identity of the customer need to be verified by reliable independent source documents, data or information and, if so, taking reasonable measures to obtain such additional verification; (c) taking reasonable measures to establish the source of the wealth of a customer; (d) undertaking further research, where considered necessary, in order to understand the background of a customer and the customer's business; and (e) considering what additional ongoing monitoring should be carried out in accordance with paragraph 13 and carrying it out.
Each of these five limbs must be considered and, where applicable, actioned. The MLRO should note that source of wealth is a mandatory element of ECDD — it is not optional even for a long-standing client whose identity was verified at onboarding.
Senior Management Approval Requirement
Where the higher risk arises because the customer is resident or located in a List A jurisdiction, or is the subject of an AML/CFT warning issued by a competent authority (paragraph 15(5)(a) and (b)), paragraph 15(6) requires that senior management must approve the continuation of the business relationship. The MLRO must determine whether either of these specific triggers applies and, if so, escalate to senior management for a documented approval decision before the relationship continues.
Even where paragraph 15(5) does not apply, the re-rating to high risk may engage one or more of the factors listed in paragraph 15(7) (e.g., a legal arrangement, high-net-worth individual, PEP status, non-face-to-face relationship). The MLRO should review each sub-paragraph of 15(7) against the client's profile.
3. Immediate Obligation: Enhanced Ongoing Monitoring
AML/CFT Code 2019, paragraph 13(1) requires the firm to perform ongoing and effective monitoring of any business relationship, including:
(a) a review of information and documents held for the purpose of customer due diligence and enhanced customer due diligence to ensure they are up-to-date, accurate and appropriate, in particular where the transaction or relationship poses a higher risk of ML/FT; (b) appropriate scrutiny of transactions and other activities to ensure that they are consistent with the relevant person's knowledge of the customer, the customer's business and risk profile and source of funds of the transaction...
Paragraph 13(4) requires that the extent and frequency of monitoring be determined:
(a) on the basis of materiality and risk of ML/FT; (b) in accordance with the risk assessments carried out under Part 3; and (c) having particular regard to whether a customer poses a higher risk of ML/FT.
The re-rating to high risk therefore requires an immediate recalibration of the monitoring frequency and intensity for this client. The firm's existing monitoring parameters — calibrated to a lower risk rating — are no longer compliant. The MLRO must ensure that enhanced monitoring is implemented without delay and that the new parameters are documented.
Paragraph 13(5) further requires that the firm record the date when each review of the business relationship takes place and details of any examination, steps, measures or determination made or taken. This recording obligation is ongoing from the point of re-rating.
4. Obligation to Review Existing CDD Records
Paragraph 13(1)(a) specifically requires a review of CDD and ECDD information to ensure it is up-to-date, accurate and appropriate, with particular emphasis where the relationship poses a higher risk. For a long-standing client, this means the firm cannot rely on documentation gathered at onboarding without actively confirming its currency and adequacy against the higher-risk standard.
The MLRO should commission a gap analysis of the existing CDD file against the ECDD requirements in paragraph 15(2), identifying any elements — particularly source of wealth — that were not previously required or obtained.
5. Beneficial Ownership Obligations
AML/CFT Code 2019, paragraph 12(1) provides that the beneficial ownership and control paragraph applies when the firm is operating any of the procedures and controls required by Parts 3, 4, 5 and 6. The re-rating to high risk engages ECDD (Part 4), which in turn re-engages the beneficial ownership identification requirements.
The MLRO must confirm that the firm holds current and verified beneficial ownership information for this client. Where the client is a legal entity, the firm must verify whether any changes to beneficial ownership have occurred since onboarding that have not been captured. Under Beneficial Ownership Act 2017, section 12(2), legal owners are required to give notice of relevant changes to the nominated officer as soon as reasonably practicable but in any event within 21 days of learning of the change — though this is an obligation on the legal owner, not the firm. The firm's own obligation is to hold accurate and current BO information as part of its CDD/ECDD file.
6. Reporting Obligations: Internal Disclosure Consideration
AML/CFT Code 2019, paragraph 26 requires that where a relevant person identifies suspicious activity in the course of a business relationship, it must conduct ECDD (unless tipping-off risk applies) and make an internal disclosure.
Paragraph 13(3) separately requires that where suspicious activity is identified in the course of ongoing monitoring, the firm must conduct ECDD and make an internal disclosure.
The re-rating to high risk does not, of itself, constitute suspicious activity. However, the MLRO must consider whether the reason for the re-rating — or any activity identified during the ECDD review — gives rise to a suspicion. If so, the internal disclosure and MLRO assessment obligations under paragraphs 25, 26, and 27 are engaged.
Paragraph 27(1) requires the MLRO to assess information contained in any internal disclosure to determine whether there are reasonable grounds for knowing or suspecting that the activity is ML/FT, and to make an external disclosure to the Financial Intelligence Unit where those grounds exist.
7. The "Appropriate Period" / Failure to Complete ECDD
AML/CFT Code 2019, paragraph 15(8) provides that where the requirements of paragraph 15 are not met within a reasonable timeframe, the firm's procedures must provide that:
(a) the business relationship or occasional transaction must proceed no further; (b) the relevant person must consider terminating that relationship; and (c) the relevant person must consider making an internal disclosure.
The Code does not define "reasonable timeframe" for ECDD in paragraph 15. The MLRO must therefore document the firm's assessment of what constitutes a reasonable timeframe in the specific circumstances of this client, having regard to the nature of the information required and the complexity of the client's structure. The Authority has penalised firms that allowed relationships to continue without completing ECDD — the MLRO should treat this as a live enforcement risk and set an internal deadline.
RISK ASSESSMENT
| Risk Area | Assessment | Basis |
|---|---|---|
| Failure to conduct ECDD promptly | High | Paragraph 15(3)(a) — mandatory obligation activated at point of re-rating |
| Failure to recalibrate monitoring | High | Paragraph 13(4)(c) — monitoring must reflect higher risk rating |
| Failure to obtain source of wealth | High | Paragraph 15(2)(c) — mandatory ECDD element |
| Senior management approval (if List A / AML warning applies) | Critical | Paragraph 15(6) — relationship cannot continue without approval |
| Failure to record monitoring reviews | Medium-High | Paragraph 13(5) — recording obligation is ongoing and inspected |
| Suspicious activity not escalated | High | Paragraphs 26 and 27 — if re-rating reason discloses suspicion |
RECOMMENDATIONS (PRIORITISED)
Priority 1 — Immediate (Day 0–5):
- Suspend any new transactions or material activity for this client pending completion of the ECDD review, unless and until the firm can confirm that proceeding is consistent with its obligations under paragraph 15(8).
- Determine whether paragraph 15(5) applies (List A jurisdiction or AML/CFT warning). If so, obtain senior management approval for continuation of the relationship before any further activity — paragraph 15(6) requires this.
- Commission a CDD gap analysis against the ECDD standard in paragraph 15(2), with particular focus on source of wealth documentation.
- Recalibrate the monitoring programme for this client to reflect the higher risk rating — paragraph 13(4)(c). Document the new monitoring parameters and their rationale.
Priority 2 — Short Term (Day 5–20):
- Obtain all outstanding ECDD information identified in the gap analysis. Set an internal deadline and document it. If information is not obtained within the firm's assessed reasonable timeframe, apply paragraph 15(8): halt the relationship, consider termination, and consider internal disclosure.
- Review transaction history under the enhanced monitoring obligation in paragraph 13(1)(b) to confirm all past activity is consistent with the client's known profile and risk. Document the review and its findings — paragraph 13(5).
- Verify beneficial ownership information is current and accurate — paragraph 12(1). Obtain updated verification where records are stale.
- Assess whether the reason for re-rating constitutes suspicious activity — paragraphs 26 and 27. If so, make an internal disclosure and the MLRO must assess whether an external disclosure to the FIU is required.
Priority 3 — Ongoing:
- Update the customer risk assessment — paragraph 6(1) — to formally record the re-rating and its basis, and ensure it is linked to the ECDD file.
- Update the business risk assessment — paragraph 5(1) — if this client's re-rating has implications for the firm's overall risk profile.
- Maintain the registers required by paragraphs 28 and 29 — registers of disclosures and ML/FT enquiries — ensuring any internal disclosures arising from this review are recorded.
- Document all steps taken, with dates, in a consolidated ECDD file for this client. The Authority's inspection focus on ongoing monitoring means this file must be capable of demonstrating, on its face, that the firm acted promptly and thoroughly upon re-rating.
DOCUMENTATION THAT MUST BE PRODUCED
The following documents must be created or updated as a direct result of the re-rating:
| Document | Statutory Basis | Owner |
|---|---|---|
| Updated Customer Risk Assessment | AML/CFT Code, paragraph 6(1) | Compliance / MLRO |
| ECDD file (gap analysis + new information obtained) | AML/CFT Code, paragraph 15(2) | Compliance / Relationship Manager |
| Source of wealth documentation | AML/CFT Code, paragraph 15(2)(c) | Compliance |
| Senior management approval (if paragraph 15(5) applies) | AML/CFT Code, paragraph 15(6) | Senior Management / MLRO |
| Revised monitoring plan with documented parameters | AML/CFT Code, paragraph 13(4) | MLRO / Compliance |
| Record of monitoring review date and findings | AML/CFT Code, paragraph 13(5) | Compliance |
| Internal disclosure (if suspicious activity identified) | AML/CFT Code, paragraph 26 | MLRO |
| MLRO assessment of internal disclosure | AML/CFT Code, paragraph 27(1) | MLRO |
| Register of internal/external disclosures (updated) | AML/CFT Code, paragraphs 28 and 29 | MLRO |
| Updated BRA (if client re-rating affects firm-level risk) | AML/CFT Code, paragraph 5(1) | MLRO / Senior Management |
*This memorandum is prepared for the MLRO's internal use. It does not constitute legal advice. Statutory provisions should be verified against the AML/CFT Code 2019 and the Beneficial Ownership Act 2017 directly.
Citations
- 1BENEFICIAL OWNERSHIP ACT 201712IoM
(1) Where a legal owner of a legal entity to which this Act applies is required to give notice to the nominated officer under section 9(3) (duty of legal owners), the
- 2ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 20196(1)IoM
A relevant person must carry out an assessment that estimates the risk of ML/FT posed by the relevant person’s customer.
- 3Anti-Money Laundering and Countering the Financing of Terrorism Code 201915IoM
(1) A relevant person must establish, record, maintain and operate appropriate procedures and controls in relation to undertaking enhanced customer due diligence.
- 4ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201913(1)IoM
A relevant person must perform ongoing and effective monitoring of any business relationship or occasional transaction, including — (a) a review of information and documents held for the purpose of cu
- 5ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201912(1)IoM
This paragraph applies when a relevant person is operating any of the procedures and controls required by Parts 3, 4, 5 and 6.
- 6ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201926IoM
Where a relevant person identifies any suspicious activity in the course of a business relationship or occasional transaction the relevant person must — (a) conduct enhanced customer due diligence in
- 7ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201913IoM
A relevant person must perform ongoing and effective monitoring of any business relationship or occasional transaction, including — (a) a review of information and documents held for the purpose of cu
- 8ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 201927(1)IoM
Where an internal disclosure has been made, the MLRO must assess the information contained within the disclosure to determine whether there are reasonable grounds for knowing or suspecting that the ac
- 9ANTI-MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM CODE 20195IoM
(1) A relevant person must carry out an assessment that estimates the risk of ML/FT posed by the relevant person’s business and customers.