The full package of internal AML/CFT instructions and policies (Internal Framework) includes a comprehensive set of documents necessary to meet regulatory standards (National Bank of Georgia, Financial Monitoring Service) and to mitigate the company's operational risks.
The complete package is divided into 4 main blocks:
I. Core Policies
AML/CFT Policy: Framework document defining the company's general principles, risk appetite, and governance structure.
Enterprise-Wide Risk Assessment Methodology and Report (EWRA): Identification and analysis of risks related to the company's products, customers, geographic presence, and delivery channels, tailored to its business specifics.
Sanctions Compliance Policy: Standards for ensuring compliance with international (OFAC, EU, UN, UK) and national sanctions regimes.
II. Standard Operating Procedures (SOPs)
Customer Due Diligence (CDD/EDD) Instruction:
Identification/Verification of individuals and legal entities (KYC);
Ultimate Beneficial Owner (UBO) identification procedure;
Politically Exposed Persons (PEP) identification;
Enhanced Due Diligence (EDD) for high-risk customers.
Customer Risk Rating Methodology (CRR): Matrix and algorithm for categorizing customers into risk levels (low, medium, high).
Transaction Monitoring Instruction: Rules, limits, scenarios, and red flag indicators for detecting suspicious and unusual transactions.
Suspicious Transaction/Activity Reporting Procedure (STR/SAR Procedure): Rules and timelines for internal escalation and submission of reports to the Financial Monitoring Service (FMS).
III. Governance & Control
AML Compliance Officer Charter: Functions, authorities, and lines of defense for the responsible person.
Employee Screening Policy (Fit & Proper / Employee Screening): Procedure for verifying the reputation and reliability of personnel during hiring.
Employee Training and Awareness Program: Plan, frequency, and knowledge assessment system for AML training.
Record Keeping and Confidentiality Policy: Rules for retaining data and transaction history, alongside non-disclosure requirements (prevention of tipping-off).
IV. Templates & Registers
KYC forms/questionnaires (for individuals and legal entities);
UBO declaration form;
Internal suspicious activity report form (Internal SAR Form);
Register of suspicious/declined transactions and rejected customers (Declined/Rejected Register);
AML training log register.
