MAS Publishes Insights on Enterprise-Wide Assessment of ML/TF Risks
MAS published an information paper that highlights the observations from thematic inspections of enterprise-wide risk assessment (EWRA) in the area of money laundering and terrorism financing (ML/TF). The paper also sets out the supervisory expectations for effective EWRA frameworks and processes that financial institutions should benchmark themselves against. The review analyzed the inherent ML/TF risk profile of selected banks, the effectiveness of the control environment designed to mitigate those risks, and the need to implement additional measures to manage residual risks where necessary. The thematic inspections of MAS show that banks have room to improve the rigor of management oversight of EWRA processes, the robustness of the design of EWRA methodologies, and the effectiveness of EWRA implementation.
The thematic inspections of selected banks were conducted in the first quarter of 2020. The inspected banks generally have established frameworks and processes to conduct the EWRA, in accordance with the requirements set out in MAS Notice 626 and the Guidelines to MAS Notice 626. Robustness of the risk assessment was, however, uneven across the inspected banks. Some banks have established good practices, such as utilizing good quantitative analysis tools to detect ML/TF risks, that the industry can emulate. Others have room to enhance the rigor of management oversight of the risk-assessment processes, the robustness of risk-assessment methodologies, and the effectiveness of risk-assessment implementation. Banks have taken, or are taking, remedial actions to improve their frameworks and processes. MAS will continue to engage financial institutions to promote best practices and maintain high anti-money laundering and countering financing of terrorism (AML/CFT) standards in the industry.
As part of the supervisory expectations, MAS expects the board and senior management of institutions to demonstrate good understanding of the underlying objectives of the EWRA, and set the appropriate tone from the top to instill an appreciation of these objectives among staff. MAS also expects the board and senior management to ensure that the EWRA frameworks and methodologies are sound and implemented effectively to meet the underlying objectives of the EWRA. While the paper is based on MAS’ thematic inspections of banks, the desired outcomes and good practices are relevant and applicable to other types of financial institutions. The paper presents the following desired outcomes based on key observations:
- Banks’ senior management maintain active oversight of EWRA frameworks and processes, including ensuring compliance with the relevant MAS Notices and Guidelines.
- Banks have sound and systematic frameworks and processes to assess inherent risks, control effectiveness, and address residual risks for each business line.
- Banks perform adequate and accurate qualitative and quantitative analyses in assessing risks.
- Banks assess effectiveness of controls, taking into account policies and procedures, control testing results, and insights from the banks’ assessments of their cultures.
- Banks have systematic processes to establish and implement control measures to address areas for improvement identified from the EWRA exercise.
- Banks have structured processes to perform gap analysis against guidance papers and incorporate lessons learned and good industry practices in their own processes.
Keywords: Asia Pacific, Singapore, Banking, ML/TF, AML/CFT, Enterprise Wide Risk Assessment, Operational Risk, Compliance Risk, Governance, Basel, MAS
Featured Experts

María Cañamero
Skilled market researcher; growth strategist; successful go-to-market campaign developer

Pierre-Etienne Chabanel
Brings expertise in technology and software solutions around banking regulation, whether deployed on-premises or in the cloud.

Nicolas Degruson
Works with financial institutions, regulatory experts, business analysts, product managers, and software engineers to drive regulatory solutions across the globe.
Previous Article
MAS Awards SRFB Privileges to Standard Chartered Bank in SingaporeRelated Articles
BIS Examines Use of Big Data and Machine Learning at Central Banks
BIS published a paper that provides an overview on the use of big data and machine learning in the central bank community.
APRA Finalizes Reporting Standard for Operational Risk Requirements
APRA finalized the reporting standard ARS 115.0 on capital adequacy with respect to the standardized measurement approach to operational risk for authorized deposit-taking institutions in Australia.
ECB Publishes Guide for Determining Penalties for Regulatory Breaches
ECB published a guide that outlines the principles and methods for calculating the penalties for regulatory breaches of prudential requirements by banks.
MAS Sets Out Good Practices to Manage Operational Risks Amid COVID
MAS and The Association of Banks in Singapore (ABS) jointly issued a paper that sets out good practices for the management of operational and other risks stemming from new work arrangements adopted by financial institutions amid the COVID-19 pandemic.
ACPR Announces New Data Collection Application for Banks and Insurers
ACPR announced that a new data collection application, called DLPP (Datalake for Prudential), for collecting banking and insurance prudential data will go into production on April 12, 2021.
BCB Maintains CCyB at 0%, Initiates First Cycle of Regulatory Sandbox
BCB announced that the Financial Stability Committee decided to maintain the countercyclical capital buffer (CCyB) for Brazil at 0%, at least until the end of 2021.
EIOPA Launches Study on Non-Life Underwriting Risk in Internal Models
EIOPA has launched a European-wide comparative study on non-life underwriting risk in internal models, also kicking-off of the data collection phase.
SRB Publishes Overview of Resolution Tools Available in Banking Union
SRB published an overview of the resolution tools available in the Banking Union and their impact on a bank’s ability to maintain continuity of access to financial market infrastructure services in resolution.
EBA Consults on Pillar 3 Disclosure Standards for ESG Risks Under CRR
EBA is consulting on the implementing technical standards for Pillar 3 disclosures on environmental, social, and governance (ESG) risks, as set out in requirements under Article 449a of the Capital Requirements Regulation (CRR).
ESAs Issue Advice on KPIs on Sustainability for Nonfinancial Reporting
ESAs Issue Advice on KPIs on Sustainability for Nonfinancial Reporting