Skip to main content

Chapter VIII: General Framework

No: 18318/486 Date(g): 17/11/2019 | Date(h): 20/3/1441 Status: In-Force
The principles in this Guide have been developed in accordance with the regulatory requirements provided for in the Anti-Money Laundering Law, the Law on Combating Terrorism Crimes and Financing, and their Implementing Regulations, which aim to establish effective requirements, guidelines, and procedures to prevent the use of Saudi Arabia’s financial system for purposes of ML/TF. These principles fall under the following headings: 
 
 ML/TF Risk Assessment.
 
 Internal Policies, Procedures and Controls to Mitigate Risks.
 
 Due Diligence Measures.
 
 Enhanced Due Diligence Measures.
 
 Simplified Due Diligence Measures.
 
 Record Keeping.
 
 Monitoring of Transactions and Activities.
 
 Reporting of Suspicious Transactions.
 
 Arrangements of AML/CTF Compliance Function.
 
 Independent Audit Function.
 
 AML/CTF Training.
 
 Recruitment and Follow-up Criteria.
 
 Correspondent Relationship.
 
 Wire Transfer.
 
Based on the above requirements, a financial institution shall prepare and adopt a risk-based approach commensurate with the nature and size of its business. Such approach shall be prepared according to the following steps: 
 
 First Step: Identifying the inherent risks of business and business relationships as well as any other risks.
 
 Second Step: Determining the financial institution’s risk appetite.
 
 Third Step: Developing preventive measures to mitigate risks based on the results of risk assessment.
 
 Fourth Step: Reviewing residual risks after developing the preventive measures.
 
 Fifth Step: Implementing the preventive measures to mitigate risks.
 
 Sixth Step: Reviewing and updating the risk-based approach.
 
Risks to which a financial institution is exposed are variable and changing over time as new products, business practices, or means of providing services, products, or transactions are developed. Therefore, the risk-based approach shall be regularly reassessed and updated when the risk factors associated with the financial institution change. The financial institution shall ensure that the risk-based approach is updated once every two years at a minimum or when risk factors change.