FICA answer

What must a risk management and compliance programme contain?

An RMCP should explain the institution's own money laundering, terrorist financing and proliferation financing risks, then show how governance, people, processes, systems and evidence manage those risks in practice.

Start with the institution—not a template

A template can help with structure, but the finished RMCP must reflect the institution's nature, size, products, services, clients, geography, delivery channels, systems and exposure to new or changing risks. The business-level risk assessment should drive the control design.

The FIC also distinguishes product or service risk and client-level risk. Client risk determines whether due diligence should be simplified, normal or enhanced. A generic risk rating that is not connected to actual onboarding and monitoring decisions is not enough.

Nine practical RMCP sections

  1. Governance. Approval authority, accountable owners, oversight, escalation, independent testing and the process for keeping the RMCP current.
  2. Institutional risk assessment. Method, risk factors, inherent risk, controls, residual risk, risk appetite and review triggers.
  3. Customer due diligence. Identification, verification, beneficial ownership, purpose and intended nature, ongoing due diligence and exit controls.
  4. Targeted financial sanctions. Screening at take-on, rescreening when lists change, match handling, freezing or reporting steps and evidence.
  5. Prominent and influential persons. Identification, approval, source-of-wealth or source-of-funds measures and enhanced monitoring where required.
  6. Account and transaction monitoring. Scenarios, thresholds, manual or automated review, alert handling, escalation and closure quality.
  7. Regulatory reporting. How staff identify, escalate, decide, submit and retain evidence for applicable reports without tipping off.
  8. Record keeping. What is retained, format, access, integrity, retrieval, security, supplier arrangements and disposal.
  9. Training and implementation. Role-based training, competence checks, attestations, change communication and monitoring that proves controls operate.

The evidence pack behind the document

Risk evidenceRisk assessment, methodology, approval and change record.
Control evidenceProcedures, system settings, samples, exceptions and remediation.
People evidenceRoles, training, knowledge checks and escalation records.
Reporting evidenceDecision trail, submissions, receipts and management information.

When should the RMCP be updated?

Update it on an ongoing basis. Useful triggers include a new product, service, client segment, country, delivery channel, technology, ownership structure, supplier, sanctions exposure, regulatory publication, monitoring finding or material incident. A periodic review should still take place even if no trigger was recorded.

Record the version, the change, the reason, approval, effective date, affected procedures, training or system changes, and testing. That turns “we updated the policy” into evidence of implementation.

Official source shelf

Need an implementable RMCP?

Connect the risk assessment to operating evidence.

Request an RMCP review