All DPMS are required by the AMLA and the AML Regulations to fulfill certain obligations. These obligations include: (1) Registration with the FIA (2) Reporting suspicious transactions and certain cash transactions (3) Undertake customer due diligence (CDD) measures (4) Ascertain whether the customer is acting for a Third Party (5) Record keeping (6) Develop and implement internal control measures, policies and procedures to mitigate ML/TF risks (7) Appoint a Money Laundering Control Officer (8) No Tipping Off
5.1 Registration with FIA In accordance with regulation 4 of the AML Regulations 2015, DPMS are required to register with the FIA for the purpose of identifying them as entities which are supervised by the FIA. They must also notify the FIA of a change of address of their registered office or principal place of business.
a) How to Register The registration process is simple and free of charge. Registration forms are available on the FIA's website; www.fia.go.ug which, you may download, complete and have it delivered to FIA office, on Plot 6 Nakasero Road, 4th Floor Rwenzori Towers (Wing B).
5.2 Reporting suspicious transactions and certain cash transactions By virtue of section
9
of the AMLA as amended, DPMS are required to report to the FIA if they suspect or have reasonable grounds to suspect that;
• A transaction or attempted transaction involves proceeds of crime or, • A transaction or attempted transaction involves funds related or linked to or to be used for money laundering or • A transaction or attempted transaction involves funds related or linked to or to be used for terrorism financing, regardless of the value of the transaction.
According to section
9(2)
of the AMLA, the STR must be submitted within two (2) working days of the date the transaction was deemed to be suspicious.
According to Regulation 12(7) and (8) of the Anti-Terrorism Regulations 2016, you must submit an STR to the FIA immediately if a designated entity* attempts to enter into a transaction or continue a business relationship. You must not enter into or continue a business transaction or business relationship with a designated entity.
* A designated entity means any individual or entity and their associates designated as terrorist entities by the United Nations Security Council (UNSC). You can access the Security Council of the United Nations List ("the UN list") on the UN website.
a) Defining Knowledge and Suspicion The first criterion provides that, before you become obliged to report, you must know or have reasonable grounds for suspecting, that some other person is engaged in money laundering or terrorism financing. If you actually 'know' that your Customer is engaged in money laundering, then your situation is quite straightforward - the first
criterion is met. However, knowledge can be inferred from the surrounding circumstances, so, e.g., a failure to ask obvious questions may be relied upon to imply knowledge.
You are also required to report if you have 'reasonable grounds' to suspect that the Customer or some other related person is engaged in money laundering or financing of terrorism. By virtue of this second, 'objective' test, the requirement to report will apply to you if based on the facts of the particular case, a person of your qualifications and experience would be expected to draw the conclusion that those facts should have led to a suspicion of money laundering. The main purpose of the objective test is to ensure that Jewellers (and other regulated persons) are not able to argue that they failed to report because they had no conscious awareness of the money laundering activity, for example by having turned a blind eye to incriminating information which was available to them, or by claiming that they simply did not realize that the activity concerned amounted to money laundering.
b) Attempted Transactions You also have to pay attention to suspicious attempted transactions. If a customer attempts to conduct a transaction, but for whatever reason that transaction is not completed, and you think that the attempted transaction is suspicious, you must report it to the FIA.
Example of suspicious attempted transaction: a customer wants to purchase a $10,000 necklace, and to pay in cash, and you, as a Jeweler, ask for some identification from the customer who refuses to provide it. If you think that this cash is related to drug money or some other crime, you have to report that attempted transaction to the FIA. On the other hand, a customer simply asking how much the necklace costs would not be sufficient for it being an attempted transaction.
Therefore, an attempt is only when concrete action has been taken to proceed with the transaction.
NOTE: It is only when you know or reasonably suspect that the funds are criminal proceeds or related to money laundering or financing of terrorism that you have to report: you do not have to know what the underlying criminal activity is or whether illegal activities occurred.
C) How to Identify a Suspicious Transaction/Activity You are the one to determine whether a transaction or activity is suspicious based on your knowledge of the customer and of the industry. You are better positioned to have a sense of particular transactions which appear to lack justification or cannot be rationalized as falling within the usual parameters of legitimate business. You will need to consider factors such as; is the transaction normal for that particular customer or is it a transaction which is a typical i.e. unusual; and the payment methods. Industry-specific indicators would also help you and your employees to better identify suspicious transactions whether completed or attempted.
NOTE: A list of red flags has been provided under clause 6 to guide you on identifying suspicious transactions.
5.3. Reporting Terrorist Funds
In accordance with regulation 12(7) and (8) of the Anti-Terrorism Regulations 2016, DPMS must report immediately to the FIA the existence of funds within your business where you know or have reasonable grounds to suspect that the funds belong to an individual or legal entity who:
• commits terrorist acts or participates in or facilitates the commission of terrorist acts or the financing of terrorism; or • is a designated entity.
You must report immediately to the FIA where you know or have reasonable grounds to believe that a person or entity named on the UNSC sanctions' list or the list circulated by the FIA, has funds in Uganda.
You can access the UNSC Sanctions' list ("the UN list") by visiting the United Nations website.
5.4. Reporting Cash Transactions By virtue of section
8
of the AMLA, DPMS are required to report all cash and monetary transactions equivalent to or exceeding one thousand currency points.
5.5. Undertake Customer Due Diligence (CDD) Measures
In accordance with section
6
of the AMLA, DPMS are required to conduct CDD when the dealer engages in any cash transaction with a customer of high risk or in any foreign currency equivalent to or above United States Dollars 10,000. These cash transactions include domestic gemstone/jewellery sale or purchase, gemstones/jewellery imports or exports and, gemstone/jewellery sale or purchase using auctions and exhibitions. CDD in general will be conducted as a minimum requirement. However, when it comes to situations where a customer is identified as of high risk with respect to ML and TF, the reporting entity should apply enhanced due diligence measures.
DPMS should ensure that they have in place a process for screening existing and prospective business relationships and customers against Sanctions Lists (see clause 5.2 and 5.3 above), and for performing background checks on them to identify any potentially adverse information (including associations with Politically Exposed Persons - PEPs, or financial or other crimes) about them. In
this regard, DPMS should become familiar with the various tools available for these purposes, including but not limited to: publicly accessible government and intergovernmental Sanctions Lists; commercially available or subscriptionbased customer intelligence databases and due-diligence investigation services; and the use of internet search techniques.
DPMS should be particularly attentive to establishing and verifying the identity of the true beneficial owner and, considering the risk involved, corroborating the legitimacy of their source of funds through reliable independent sources, wherever ongoing business relationships are concerned, or when high risk situations are identified involving occasional or one-off customer transactions.
DPMS should be alert to situations in which existing or prospective business partners or customers appear unable or unwilling to divulge relevant ownership information or to grant any required permissions to third parties to divulge such information about them for corroboration or verification purposes.
DPMS should be alert to customer due-diligence factors such as: • Compatibility of the customer's profile (including their economic or financial resources, and their personal or professional circumstances) with the specifics (including nature, size, frequency) of the transaction or activities involved; • Utilisation of complex or opaque legal structures or arrangements (such as trusts, foundations, personal investment companies, investment funds, or offshore companies), which may tend to conceal the identity of the true beneficial owner or source of funds; • Possible association with PEPs, especially in regard to foreign customers.
Customer due diligence (CDD) measures as defined in section 6(3) of the Anti- Money Laundering Act as amended include but are not limited to:
• verify the identity of the client using reliable, independent source documents, data or information; • identify and take reasonable measures to verify the identity of a beneficial owner; • understand and, as appropriate, obtain information on the purpose and intended nature of the business relationship to permit the accountable person to fulfil its obligations under the Act; • if another person is acting on behalf of the customer, identify and verify the identity of that other person, and verify that person's authority to act on behalf of the customer; • verify the identity of a customer using reliable, independent source documents, data or information, such as passports, birth certificates, driver's licences, identity cards, national identification card, utility bills, bank statements, partnership contracts and incorporation papers or other identification documents; • verify the identity of the beneficial owner of the account, in the case of legal persons and other arrangements; • conduct ongoing due diligence on all business relationships and scrutinise transactions undertaken throughout the course of the business relationship to ensure that the transactions are consistent with the accountable person's knowledge of the customer and the risk and business profile of the customer, and where necessary, the source of funds.
High Risk Customers/ Transactions
There are customers and types of transactions, services and products which may pose higher risk to your business and you are required to apply additional measures in those cases. The AML/CFT laws have identified certain high risk customers and require you to conduct enhanced due diligence ("EDD") on these
customers. You may also determine that certain customers', transactions and products pose a higher risk to your business and apply EDD.
You must apply EDD measures to high risk customers, which include, but are not limited to: • obtaining further information that may assist in establishing the identity of the person or entity; • applying extra measures to verify any documents supplied; • obtaining senior management approval for the new business relationship or transaction sought by the person or customer; • establishing the source of funds of the person or entity; • carrying out on-going monitoring of the business relationship.
The enhanced due diligence measures shall be applied at each stage of the customer due diligence process and shall continue to be applied on an on-going basis.
As per section
7
of the AMLA, DPMS are required to keep a record of each and every transaction for a specified period. Record keeping is important to antimoney laundering investigation which allows for swift reconstruction of individual transactions and provides evidence for prosecution of money laundering and other criminal activities.
DPMS must keep records in electronic or written form for a period of ten (10) years or such longer period as the FIA may direct. The records must also be kept for ten (10) years after the end of the business relationship or completion of a one-off transaction. The records to be kept are;
a) All domestic and international transaction records; b) Source of funds declarations; c) Customer's identification records; d) Customer's information records; e) Copies of official corporate records; f) Copies of Suspicious Transaction Reports submitted by your staff to your anti-money laundering control officer; g) A register of copies of suspicious transaction reports submitted to the FIA; h) A register of all enquiries made by LEAs (date, nature of enquiry, name of officer, agency and powers being exercised) or other competent authority; i) The names, addresses, position titles and other official information pertaining to your staff; j) All wire transfer records; (originator and recipient identification data); and k) Other relevant records.
5.7. Ascertain whether the customer is acting for a Third Party In accordance with section
6(20)
of the AMLA and regulation 16 of the AML Regulations, DPMS must take reasonable measures to determine whether the customer is acting on behalf of a third party especially where you have to conduct enhanced due diligence. Such cases will include where the customer is an agent of the third party who is the beneficiary and who is providing the funds for the transaction. In cases where a third party is involved, you must obtain information on the identity of the third party and their relationship with the customer.
In deciding who the beneficial owner is in relation to a customer who is not a private individual (e.g., a company), you should identify those who have ultimate control over the business and the company's assets such as the
shareholders. Particular care should be taken to ensure that any person purporting to act on behalf of the company is fully authorized to do so.
5.8. Internal Control Measures
In accordance with regulation 11 of the AML Regulations, DPMS should develop, adopt and implement internal control measures, policies and procedures for the prevention of money laundering and financing of terrorism.
DPMS must take appropriate measures to ensure that all officers, employees, and agents engaged in dealing with clients or processing business transactions understand and comply with all applicable AML/CFT procedures.
DPMS must appoint a money laundering control officer (MLCO) with overall responsibility for AML/CFT compliance.
The MLCO must be in a senior managerial position and possesses sufficient professional experience and competence in the legal profession. The MLCO acts as the liaison point with the FIA and relevant supervisory authorities in Uganda, and commands the necessary independence and authority to train and supervise all other officers, employees, and agents within the firm.
The MLCO should at all times be resident in Uganda. In addition, it is highly recommended that an alternate to the MLCO is appointed to assume the prescribed responsibilities and duties in the MLCO's absence.
The MLCO's specific responsibilities include: • establishing and maintaining a manual of compliance procedures; • establishing an audit function to test AML/CFT procedures and systems; • taking overall responsibility for all STRs; and
• ensuring that all officers, employees, and agents: ➢ are screened by the MLCO and other appropriate officers before recruitment; ➢ are trained to recognize suspicious transactions and trends and particular risks associated with money laundering and financing of terrorism; and ➢ comply with all relevant obligations under AML/CFT laws and with the internal compliance manual.
MLCOs and reporting entities should review their arrangements on a regular basis, both to verify compliance with internal procedures and to ensure that those procedures are updated in light of any amendments to the AML/CFT legislation.
These guidelines do not specify the nature, timing, or content of the training that must be provided. This is a matter that must be addressed by the MLCO.
5.9. No Tipping Off When you have made a suspicious transaction report to the FIA, you or your agent, employee must not disclose that you have made such a report or the content of such report to any person including the customer. According to section
117
of the AMLA, it is an offence to deliberately tell any person, including the customer, that you have or your business has filed a suspicious transaction report about the customer's activities/transactions. You must also not disclose to anyone any matter which may prejudice money laundering or financing of terrorism investigation or proposed investigation.
The prohibition applies to any person acting, or purporting to act, on behalf of a DPMS, including any agent, employee, partner, director or other officer, or any person engaged under a contract for services.