Client due diligence and supplier screening that continue
A client relationship and a supplier relationship have this in common: they continue, while the investigation usually happens at the start. A party that appears on a sanctions list today is one you may no longer serve tomorrow.
Wwft due diligence
Sanctiewet ongoing
Re-verification during the relationship
Client due diligence under the Wwft
The Wwft (in full, the Wet ter voorkoming van witwassen en financieren van terrorisme, the Dutch anti-money-laundering and anti-terrorist-financing act) designates accountants, tax advisers and administration offices as gatekeepers. As gatekeepers, they must carry out client due diligence, known internationally as know your customer (KYC) and customer due diligence (CDD).
The act recognises three forms of it: standard client due diligence (article 3), simplified client due diligence (article 6) and enhanced client due diligence (article 8), also known as enhanced due diligence or EDD. You must be able to substantiate which form you applied.
That choice is not fixed at the outset. The monitoring obligation can mean that a change in the risk profile during the client relationship still makes enhanced due diligence necessary. The same applies when it turns out that the client or the ultimate beneficial owner is a politically exposed person: article 8 Wwft then requires enhanced due diligence, and that extends to family members and close associates.
Identifying the ultimate beneficial owner is part of that investigation, and the UBO register alone is not enough for it. The Bureau Financieel Toezicht treats the register extract as an aid and states that you must consult other sources as well. What you consulted alongside it, and when, is therefore itself part of your case file.
What must be recorded
Article 33 Wwft requires you to record the documents and data you used in the client due diligence and to keep them accessible. Which those are depends on the form of due diligence, and that follows from the risk profile. So that profile and the risks you established with it belong there as well.
The retention period runs until five years after the end of the relationship. After that you must destroy the data, and that is not a choice you can postpone on the basis of some other interest.
In Noctua every item of data gets a source, a moment and a user, with the query that preceded it. Documents are filed by investigation and by entity, so that the accessibility article 33 demands follows from the ordering itself. Per case file you record a risk classification, and your organisation sets the retention period itself.
What the regulator looks at
For accountants, tax advisers and administration offices, the Bureau Financieel Toezicht supervises compliance. The BFT assesses from the content of the client case files whether the investigation was carried out properly. In a case litigated all the way to the College van Beroep voor het bedrijfsleven, the BFT requested the file of one client covering three years and asked for additional information several times. What had been recorded in that file at the time determined the outcome.
If you work with an external service provider, the BFT advises you to be alert to the limitations of the system and to check which search terms and databases are used and which criteria the search function applies. The purpose is to be able to assess whether all the necessary elements of client due diligence are covered. The BFT itself gives the example of UBOs and PEPs in foreign structures.
In Noctua, every flag states what is checked and against what. Each item of data is linked to the source it came from and to the query that preceded it, so that for every finding you can show what was searched. Which lists and registers are available to you, and which countries they cover, is fixed in what was recorded during the setup.
This question carries weight. Failing to carry out client due diligence, or not carrying it out properly, is a criminal offence under the Wet op de economische delicten, the Dutch act on economic offences. In the case mentioned, the tribunal held that the firm should have recognised that a client presented a higher risk of money laundering, and that the investigation carried out fell short as enhanced client due diligence. For the most serious category of breaches, publication by name can follow before the fine becomes final.
Bring your own client case file
We take a case file from your practice and go through what is recorded for each finding and what was searched.
Supplier screening and re-verification
In a public tender it does not end at award. The exclusion grounds and suitability requirements are tested at the front, but the relationship then runs on for years. What you want to keep checking during that period, and how often, you set down in the contract and in your own procurement policy.
Some municipalities set this down as a term: self-declarations from existing suppliers are updated and verified periodically, and where there is reason to doubt an earlier screening, a re-verification follows.
One thing is not a policy choice. Sanctions rules apply to everyone, not only to financial institutions, and they apply at every moment. You may not make funds available to a party on a sanctions list, whatever you established when entering into the relationship. Whoever is free of sanctions today may be on a list tomorrow.
At the outset, and after
The screening at the outset shows who is behind the party, how control runs, and what has changed in recent years. A financial company report adds creditworthiness and payment behaviour to that.
Every entity you add is checked against sanctions lists, PEP lists, enforcement measures by regulators and adverse media. That applies to legal persons and to natural persons, and whoever is attached through control or a shared company appears in the same network.
Checking against lists is done broadly. Names appear there in varying spelling and transliteration, and Noctua reports a possible match with the entries it found. You assess each report yourself as relevant or not relevant, and that assessment stays in the case file.
Article 3(11) Wwft requires the data from the client due diligence to stay current, matched to the risk profile. That calls for two things you set yourself: how often a case file goes past the lists again, and what you want to be alerted to in between. A change of management, an insolvency, a new entry on a list. That alert lands in the case file that holds the original screening.
Thresholds from your own risk assessment
Which thresholds and risk factors lead to a flag follows from your organisation's risk policy and from your own risk assessment. We set those up together with you.
Bring a client or supplier case you got stuck on
A client under the Wwft, a supplier under exclusion grounds, a relationship under the Sanctiewet: the investigation is the same. In Noctua, client due diligence, supplier screening and sanctions screening are the same relationship screening. What differs are the sources you may query and the thresholds you want to be alerted to.
We set this up based on what applies to your organisation. Which sources you can use depends on your authority to consult them and the agreements behind that authority, and we work that out together with you.