MAS Publishes Insights on Enterprise-Wide Assessment of ML/TF Risks
MAS published an information paper that highlights the observations from thematic inspections of enterprise-wide risk assessment (EWRA) in the area of money laundering and terrorism financing (ML/TF). The paper also sets out the supervisory expectations for effective EWRA frameworks and processes that financial institutions should benchmark themselves against. The review analyzed the inherent ML/TF risk profile of selected banks, the effectiveness of the control environment designed to mitigate those risks, and the need to implement additional measures to manage residual risks where necessary. The thematic inspections of MAS show that banks have room to improve the rigor of management oversight of EWRA processes, the robustness of the design of EWRA methodologies, and the effectiveness of EWRA implementation.
The thematic inspections of selected banks were conducted in the first quarter of 2020. The inspected banks generally have established frameworks and processes to conduct the EWRA, in accordance with the requirements set out in MAS Notice 626 and the Guidelines to MAS Notice 626. Robustness of the risk assessment was, however, uneven across the inspected banks. Some banks have established good practices, such as utilizing good quantitative analysis tools to detect ML/TF risks, that the industry can emulate. Others have room to enhance the rigor of management oversight of the risk-assessment processes, the robustness of risk-assessment methodologies, and the effectiveness of risk-assessment implementation. Banks have taken, or are taking, remedial actions to improve their frameworks and processes. MAS will continue to engage financial institutions to promote best practices and maintain high anti-money laundering and countering financing of terrorism (AML/CFT) standards in the industry.
As part of the supervisory expectations, MAS expects the board and senior management of institutions to demonstrate good understanding of the underlying objectives of the EWRA, and set the appropriate tone from the top to instill an appreciation of these objectives among staff. MAS also expects the board and senior management to ensure that the EWRA frameworks and methodologies are sound and implemented effectively to meet the underlying objectives of the EWRA. While the paper is based on MAS’ thematic inspections of banks, the desired outcomes and good practices are relevant and applicable to other types of financial institutions. The paper presents the following desired outcomes based on key observations:
- Banks’ senior management maintain active oversight of EWRA frameworks and processes, including ensuring compliance with the relevant MAS Notices and Guidelines.
- Banks have sound and systematic frameworks and processes to assess inherent risks, control effectiveness, and address residual risks for each business line.
- Banks perform adequate and accurate qualitative and quantitative analyses in assessing risks.
- Banks assess effectiveness of controls, taking into account policies and procedures, control testing results, and insights from the banks’ assessments of their cultures.
- Banks have systematic processes to establish and implement control measures to address areas for improvement identified from the EWRA exercise.
- Banks have structured processes to perform gap analysis against guidance papers and incorporate lessons learned and good industry practices in their own processes.
Keywords: Asia Pacific, Singapore, Banking, ML/TF, AML/CFT, Enterprise Wide Risk Assessment, Operational Risk, Compliance Risk, Governance, Basel, MAS
Featured Experts

María Cañamero
Skilled market researcher; growth strategist; successful go-to-market campaign developer

Nicolas Degruson
Works with financial institutions, regulatory experts, business analysts, product managers, and software engineers to drive regulatory solutions across the globe.

Patrycja Oleksza
Applies proficiency and knowledge to regulatory capital and reporting analysis and coordinates business and product strategies in the banking technology area
Previous Article
SRB Chair Discusses Path to Harmonized Liquidation Regime for BanksRelated Articles
FINMA Approves Merger of Credit Suisse and UBS
The Swiss Financial Market Supervisory Authority (FINMA) has approved the takeover of Credit Suisse by UBS.
BOE Sets Out Its Thinking on Regulatory Capital and Climate Risks
The Bank of England (BOE) published a working paper that aims to understand the climate-related disclosures of UK financial institutions.
OSFI Finalizes on Climate Risk Guideline, Issues Other Updates
The Office of the Superintendent of Financial Institutions (OSFI) is seeking comments, until May 31, 2023, on the draft guideline on culture and behavior risk, with final guideline expected by the end of 2023.
APRA Assesses Macro-Prudential Policy Settings, Issues Other Updates
The Australian Prudential Regulation Authority (APRA) published an information paper that assesses its macro-prudential policy settings aimed at promoting stability at a systemic level.
BIS Paper Examines Impact of Greenhouse Gas Emissions on Lending
BIS issued a paper that investigates the effect of the greenhouse gas, or GHG, emissions of firms on bank loans using bank–firm matched data of Japanese listed firms from 2006 to 2018.
HMT Mulls Alignment of Ring-Fencing and Resolution Regimes for Banks
The HM Treasury (HMT) is seeking evidence, until May 07, 2023, on practicalities of aligning the ring-fencing and the banking resolution regimes for banks.
MFSA Sets Out Supervisory Priorities, Issues Reporting Updates
The Malta Financial Services Authority (MFSA) outlined its supervisory priorities for 2023
German Regulators Issue Multiple Reporting Updates for Banks
Deutsche Bundesbank published the nationally deactivated validation rules for the German Commercial Code (HGB) users on the taxonomy 3.2, which became valid from December 31, 2022
BCBS Report Examines Impact of Basel III Framework for Banks
The Basel Committee on Banking Supervision (BCBS) published results of the Basel III monitoring exercise based on the June 30, 2022 data.
PRA Consults on Prudential Rules for "Simpler-Regime" Firms
Among the recent regulatory updates from UK authorities, a key development is the first-phase consultation, from the Prudential Regulation Authority (PRA), on simplifications to the prudential framework that would apply to the simpler-regime firms.