NBU Regulation on Financial Monitoring by Institutions

NBU Regulation on Financial Monitoring by Institutions

28.07.2020 · № 107

BOARD OF THE NATIONAL BANK OF UKRAINE

DECREE

07/28/2020 No. 107

On approval of the Regulation on the implementation of financial monitoring by institutions

In accordance with Articles 7 , 15 , 55 , 56 of the Law of Ukraine "On the National Bank of Ukraine", in order to ensure the implementation of the requirements of the Law of Ukraine dated December 6, 2019 No. 361-IX "On Prevention and Counteraction to the Legalization (Laundering) of Proceeds from Crime, Financing of Terrorism and Financing of the Proliferation of Weapons of Mass Destruction", the Board of the National Bank of Ukraine DECIDES:

1. To approve the attached Regulations on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulations).

2. Establish that institutions:

No. 361-IX of December 6, 2019 "On Prevention and Counteraction to the Legalization (Laundering) of Proceeds from Crime, Financing of Terrorism and Financing of the Proliferation of Weapons of Mass Destruction" (hereinafter referred to as the Law), the necessary measures in accordance with the requirements of the Law;

2) apply to clients with whom business relations were established before the Law came into force (hereinafter referred to as existing clients), due diligence measures, identification of facts of clients' (their ultimate beneficial owners) belonging to politically exposed persons, members of their families and/or persons associated with politically exposed persons, reassessment of the risk of business relations with clients in accordance with the requirements of the Regulation during the implementation of procedures for planned updating/clarification by the institution of data on such clients within the terms established by the institution in existing internal documents in accordance with the legislation of Ukraine on financial monitoring, before the Law came into force.

With regard to existing clients who do not maintain business relations with the institution (except for those with high business relations risk), the above measures may be taken beyond the established deadlines when such a client contacts the institution, but before carrying out financial transactions initiated by the client;

3) report to a specially authorized body on threshold financial transactions of politically exposed persons, their family members and/or persons associated with politically exposed persons who did not have such status in accordance with the Law of Ukraine No. 1702-VII of October 14, 2014 "On Prevention and Counteraction to the Legalization (Laundering) of Proceeds from Crime, Financing of Terrorism and Financing of the Proliferation of Weapons of Mass Destruction", starting from the date the institution discovers the fact that the relevant client belongs to a politically exposed person, a member of his family and/or a person associated with a politically exposed person;

4) ensure the setup and automation of the necessary processes of the institution in accordance with the requirements of the Regulation no later than June 30, 2021.

{Subparagraph 4 of paragraph 2 as amended by Resolution of the National Bank No. 2 of 12.01.2021 }

3. To declare as invalid:

1) Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated August 5, 2003 No. 25 "On Approval of the Regulation on Financial Monitoring by Financial Institutions", registered with the Ministry of Justice of Ukraine on August 15, 2003 under No. 715/8036;

2) Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated November 13, 2003 No. 121 "On Amendments to the Regulations on Financial Monitoring by Financial Institutions, approved by Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated August 5, 2003 No. 25", registered with the Ministry of Justice of Ukraine on November 27, 2003 under No. 1088/8409;

3) Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated April 15, 2004 No. 336 "On Approval of Amendments to the Regulations on Financial Monitoring by Financial Institutions", registered with the Ministry of Justice of Ukraine on May 7, 2004 under No. 581/9180;

4) Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated April 28, 2006 No. 5720 "On Approval of Amendments to the Regulation on Financial Monitoring by Financial Institutions", registered with the Ministry of Justice of Ukraine on May 17, 2006 under No. 570/12444;

5) Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated May 10, 2007 No. 7288 "On Approval of Amendments to the Regulation on Financial Monitoring by Financial Institutions", registered with the Ministry of Justice of Ukraine on May 24, 2007 under No. 539/13806;

6) Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated August 7, 2008 No. 951 "On Amendments to the Regulatory Acts of the State Commission for Regulation of Financial Services Markets of Ukraine on the Issues of Training of Employees Responsible for Conducting Internal Financial Monitoring", registered with the Ministry of Justice of Ukraine on October 24, 2008 under No. 1023/15714;

7) Order of the State Commission for Regulation of Financial Services Markets of Ukraine dated February 24, 2011 No. 102 "On Amendments to the Regulations on Financial Monitoring by Financial Institutions", registered with the Ministry of Justice of Ukraine on May 18, 2011 under No. 600/19338;

8) Order of the National Commission for State Regulation of Financial Services Markets of March 5, 2013 No. 712 "On Approval of Amendments to Certain Regulatory Acts of the State Commission for Regulation of Financial Services Markets of Ukraine", registered with the Ministry of Justice of Ukraine on May 18, 2013 under No. 770/23302;

9) Order of the National Commission for State Regulation of Financial Services Markets dated October 13, 2015 No. 2481 "On Approval of the Criteria for Assessing the Risk Level for Primary Financial Monitoring Entities, State Regulation and Supervision of whose Activities is Carried Out by the National Commission for Financial Services", registered with the Ministry of Justice of Ukraine on October 30, 2015 under No. 1335/27780;

10) Resolution of the Board of the National Bank of Ukraine dated September 15, 2016 No. 388 "On Approval of the Regulation on Financial Monitoring by Non-Banking Financial Institutions in the Provision of Financial Services Regarding the Transfer of Funds";

11) Resolution of the Board of the National Bank of Ukraine dated April 17, 2018 No. 43 "On Approval of Amendments to the Regulation on Financial Monitoring by Non-Banking Financial Institutions in the Provision of Financial Services Regarding the Transfer of Funds".

4. The Financial Monitoring Department (Ihor Bereza) shall ensure that this resolution is posted on the page of the official Internet representation of the National Bank of Ukraine.

5. Control over the implementation of this resolution shall be entrusted to the First Deputy Governor of the National Bank of Ukraine, Kateryna Rozhkova.

6. The resolution shall enter into force on the day following the day of its official publication.

Head

K. Shevchenko

AGREE:

Financial Monitoring Service of Ukraine


I. Cherkassky

APPROVED
Board Resolution
National Bank of Ukraine
07/28/2020 No. 107

REGULATIONS
on the implementation of financial monitoring by institutions

I. General provisions↑

1. This Regulation has been developed in accordance with the Laws of Ukraine " On the National Bank of Ukraine " , "On Prevention and Counteraction to the Legalization (Laundering) of Proceeds of Crime, Financing of Terrorism and Financing of the Proliferation of Weapons of Mass Destruction" , in order to prevent the use of institutions for the legalization (laundering) of proceeds of crime, financing of terrorism and financing of the proliferation of weapons of mass destruction.

2. These Regulations establish general requirements of the National Bank of Ukraine (hereinafter referred to as the National Bank) regarding the implementation by institutions of the requirements of the legislation of Ukraine on financial monitoring.

3. The requirements of this Regulation apply to insurers (reinsurers), insurance (reinsurance) brokers, credit unions, pawnshops and other financial institutions (except for financial institutions and other legal entities for which state regulation and supervision in the field of prevention and countermeasures are carried out by other subjects of state financial monitoring); payment organizations, participants or members of payment systems that provide financial services on the basis of relevant licenses or registration documents; postal operators; other institutions that provide services for transferring funds and performing currency transactions; branches or representative offices of foreign business entities that provide financial services on the territory of Ukraine, other legal entities that are not financial institutions by their legal status, but provide certain financial services (hereinafter referred to as institutions).

4. The following abbreviations are used in this Regulation:

1) ML/TF - legalization (laundering) of proceeds of crime, financing of terrorism and/or financing of proliferation of weapons of mass destruction;

2) life insurance contract - a contract (insurance policy, certificate, certificate) of life insurance;

3) DFM - a structural unit of the central office of the National Bank, whose competence includes issues of supervision in the field of preventing and combating ML/TF;

4) EPZ - electronic payment instrument;

5) Unified State Register - Unified State Register of Legal Entities, Individual Entrepreneurs and Public Organizations;

6) Law on AML/CFT - Law of Ukraine "On Prevention and Counteraction to the Legalization (Laundering) of Proceeds of Crime, Financing of Terrorism and Financing of the Proliferation of Weapons of Mass Destruction";

7) ICAO Doc 9303 - recommendations of the International Civil Aviation Organization (ICAO) Doc 9303;

8) KBV - ultimate beneficial owner;

9) QES - qualified electronic signature;

10) code according to the Unified State Register of Enterprises and Organizations of Ukraine - identification code according to the Unified State Register of Enterprises and Organizations of Ukraine;

11) microenterprises - institutions that, according to the criteria set forth in the Law of Ukraine "On Accounting and Financial Reporting in Ukraine", belong to microenterprises;

12) CDD - customer due diligence;

13) AML/CFT - prevention and counteraction to the legalization (laundering) of proceeds from crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction;

14) EAD - enhanced due diligence measures;

15) SEI verification subsystem - a subsystem for verifying information on legal entities and individual entrepreneurs of the integrated electronic identification system;

16) payment institution - an institution that provides funds transfer services;

17) RNOKPP - registration number of the taxpayer's registration card;

18) CA (institutional automation system) - a system for automating financial monitoring processes, which may consist of one or more separate automated software modules that ensure the functioning of an appropriate ML/TF risk management system of the institution;

19) SBU - Security Service of Ukraine;

20) SEI - integrated electronic identification system;

21) SZNP - simplified due diligence measures;

22) BankID NBU system - BankID system of the National Bank of Ukraine;

23) SPFM - subject of primary financial monitoring;

24) LMA - a specially authorized body;

25) FOP - individual entrepreneur;

26) FATF - Financial Action Task Force on Money Laundering;

27) PEP (PEPs in the plural) - a natural person who is a politically exposed person, a member of their family or a person associated with a politically exposed person, or another person whose ultimate beneficial owner is a politically exposed person, a member of their family or a person associated with a politically exposed person;

28) prepaid card - a prepaid card for multi-purpose use.

5. The terms and concepts in this Regulation are used in the following meanings:

1) mass registration address - an address at which more than 50 legal entities, trusts or other legal entities are registered;

2) analysis of financial transactions - a set of risk-oriented measures carried out on an ongoing basis and established by the institution's internal documents on AML/CFT issues, the implementation of which allows the institution to identify financial transactions subject to financial monitoring;

3) high risk of business relations (financial transactions without establishing business relations) with a client - the result of the institution's assessment of the risk of business relations (financial transactions without establishing business relations) with a client, based on the results of the analysis of a set of criteria provided for by the legislation of Ukraine and the institution's internal documents on AML/CFT, and which indicates a high probability of the client using the institution's services for ML/CFT;

4) remote establishment of business relations - establishment of business relations with a client without his physical presence;

5) video verification - a procedure for the institution to verify a person in the video broadcast mode;

6) responsible employee of the institution - an employee of the institution responsible for conducting financial monitoring in the institution;

7) internal documents of the institution on AML/CFT issues - rules, programs, methodologies, other documents developed and approved by the institution for the purpose of properly performing the functions of the SPFM;

7 - 1 ) the holder of the Unified State Register is the Ministry of Justice of Ukraine, which takes organizational measures related to ensuring the functioning of the Unified State Register;

{ Clause 5 of Section I is supplemented with a new subclause 7 - 1 in accordance with Resolution of the National Bank No. 121 of 05.10.2024 }

8) de-risking - a phenomenon in which a financial institution refuses to establish (maintain) business relationships with clients in order to avoid risks, rather than manage them;

9) certificate of assignment of the RNOKPP - a document issued by the relevant regulatory authority, certifying the registration of an individual in the State Register of Individual Taxpayers;

10) SEI access agreement - an agreement between an institution and the Ministry of Digital Transformation of Ukraine on access to the integrated electronic identification system with the ability to receive data from the subsystem for verifying information on legal entities and individual entrepreneurs about the head of the legal entity, other persons who may act on behalf of the legal entity, individual entrepreneur, persons who may act on behalf of the individual entrepreneur, as well as on the presence of restrictions on the representation of the legal entity and individual entrepreneur contained in the Unified State Register;

11) escalation - informing the relevant employee of the institution and/or collegial body about the occurrence of a relevant event;

12) information protection means - software and hardware that ensure the protection of electronic documents from unauthorized actions regarding familiarization with their content, modification or distortion;

13) significant amount - an amount equal to or exceeding the amount specified in part one of Article 20 of the Law on AML/CFT;

14) identification document - a passport of a citizen of Ukraine or another document that certifies an individual and, in accordance with the legislation of Ukraine, can be used on the territory of Ukraine to conclude transactions;

15) shell company - a legal entity, trust or other similar legal entity, regarding which the institution has reasonable suspicions that its (his) activities may be fictitious;

16) counterparty - a person who is the other party to a financial transaction (the counterparty may be an institution) under which assets are transferred between the client and the counterparty;

17) minor - an individual who has not reached the age of fourteen;

18) liveness detection method - a method of photofixing a face in real time using algorithms that make it possible to distinguish a real person from a reproduction in any form of their appearance (for example, digital reproduction, makeup, mask);

19) monitoring of business relationships / monitoring of financial transactions - analysis of the client's financial transactions carried out in the course of business relations with him, regarding the compliance of such financial transactions with the information available in the institution about the client, his activities and risk (including, if necessary, about the source of funds related to financial transactions);

20) reliable sources - sources specified in this Regulation, in addition to official sources and official documents, as possible for use by institutions when fulfilling the requirements of the legislation of Ukraine in the field of AML/CFT;

21) urgently - a period of time determined/established from the moment of occurrence of the grounds for taking relevant actions, which are a priority and are carried out first, but no later than the next business day or the established time of the next business day;

22) immediately - the shortest period during the working day within which the relevant actions must be carried out (take place) from the moment the grounds for their implementation arise;

23) minor - an individual aged fourteen to eighteen years;

24) low risk of business relations (financial transactions without establishing business relations) with a client - the result of the institution's assessment of the risk of business relations (financial transactions without establishing business relations) with a client, which is based on the results of the analysis of a set of criteria provided for by the legislation of Ukraine and the institution's internal documents on AML/CFT, and which indicates a low probability of the client using the institution's services for ML/CFT;

25) online monitoring of funds transfers - a procedure for analyzing funds transfers in real time, carried out until:

crediting funds by the recipient's institution to the recipient's electronic wallet / paying funds to the recipient if he does not have an electronic wallet;

transfer of funds by an intermediary institution to another intermediary SPF or the SPF of the recipient;

26) primary document - a document that contains mandatory details [name of the person (legal entity or individual) who prepared the document, name of the document, date and place of its preparation, content and volume of the transaction, its unit of measurement, signature or other data that allows identifying the person who initiated the transaction; name of the recipient of funds, account number(s)], and is the basis for reflecting the financial transaction in the CA;

27) list of states that do not comply with FATF recommendations - a list of states (jurisdictions) that do not comply or improperly comply with the recommendations of international, intergovernmental organizations involved in the fight against ML/TF, which is formed in accordance with the procedure determined by the Cabinet of Ministers of Ukraine based on the conclusions of international, intergovernmental organizations involved in the fight against ML/TF, and is published on the official website of the OMS;

28) list of terrorists - a list of persons associated with the conduct of terrorist activities or against whom international sanctions have been applied, which is formed in accordance with the procedure determined by the Cabinet of Ministers of Ukraine and published on the official website of the OMS;

29) forgery - the creation (in whole or in part) of a document similar to a genuine/authentic document, with the aim of illegally using it as a genuine/authentic document;

30) subsequent monitoring of funds transfers - a procedure for analyzing funds transfers that is carried out after:

the funds were credited by the recipient's institution to the recipient's electronic wallet / paid to the recipient if he does not have an electronic wallet;

the funds were transferred by the intermediary institution to another intermediary SPF or the SPF of the recipient;

31) referral / referral tool - the use by an institution of information on the identification, verification of clients, establishment of their CDD and taking measures to verify their identity, as well as information on the purpose and nature of future business relationships, received from a third party that is a PFMS in accordance with the requirements of the AML/CFT Law or takes measures similar in content, is subject to appropriate supervision in accordance with the legislation of the country of registration of such an entity and acts on its own behalf;

32) procedure - a clear sequence of actions of a certain process indicating the methods, forms, terms (deadlines) for the institution's employees to take these actions, defined in the institution's internal documents on AML/CFT issues;

33) acceptable level of ML/TF risks - a risk that is manageable, under the control of the institution, cannot cause an increase in legal risk and reputational risk, as well as a deterioration in the financial results of the institution or cause harm to its creditors and clients;

34) suspension of a financial transaction - temporary suspension of the procedure for conducting a financial transaction in the event that the institution discovers information that requires further analysis regarding the need for the institution to take certain actions in order to comply with the requirements of the legislation of Ukraine in the field of AML/CFT and/or the institution's internal documents on AML/CFT issues, in particular, in the event that the data of a participant in a financial transaction matches the data of a person on the list of terrorists;

35) one-time financial transaction for a significant amount - a financial transaction carried out without establishing a business relationship, for an amount equal to or exceeding the amount specified in part one of Article 20 of the Law on AML/CFT (regardless of whether such a financial transaction is carried out once or as several financial transactions that may be interconnected);

36) register of refusals - a register of notifications of the institution about refusals to establish (maintain) business relations with clients;

37) register of freezing/thawing - a register of notifications of the institution on the freezing/thawing of assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing;

38) register of reports on suspicious financial activity - a register of reports of an institution on suspicious financial activity;

39) register of discrepancies on the capital account and ownership structure - a register of notifications from the institution about discrepancies between the information on the capital account and ownership structure contained in the Unified State Register and the information on the capital account and ownership structure obtained by the institution as a result of the implementation of the NPC;

{Subparagraph 39 of paragraph 5 of section I as amended by Resolution of the National Bank No. 121 of 05.10.2024 }

40) register of financial transactions - a register of financial transactions of an institution subject to financial monitoring;

41) risk appetite (risk appetite) of an institution in the field of ML/TF - the amount of ML/TF risk, determined in advance and within the acceptable level of ML/TF risk, regarding which the institution has decided on the expediency/necessity of maintaining it in order to achieve its strategic goals;

42) reputational risk - an existing or potential risk to revenues and capital arising from an unfavorable perception of the institution's image by clients, counterparties, potential investors or supervisory authorities, which affects the institution's ability to establish new relationships with counterparties, provide new services or maintain existing relationships and may lead the institution (or its managers) to financial losses or a reduction in the client base, or to administrative, civil or criminal liability;

43) legal risk - an existing or potential risk to the income or capital of an institution that arises due to the institution's violation or non-compliance with the requirements of the laws of Ukraine, regulatory legal acts and may lead the institution to financial losses, abuse, and the institution and/or its managers to administrative, civil or criminal liability;

44) impostor - a person who impersonates another person, illegally appropriating someone else's identification data;

45) the sanctions list of the National Security and Defense Council - a list of persons against whom special economic and other restrictive measures (sanctions) have been applied in accordance with Article 5 of the Law of Ukraine "On Sanctions";

46) average risk of business relations (financial transactions without establishing business relations) with a client - the result of the institution's assessment of the risk of business relations (financial transactions without establishing business relations) with a client, based on the results of the analysis of a set of criteria provided for by the legislation of Ukraine and the institution's internal documents on AML/CFT issues, and which indicates an increased probability of the client using the institution's services for ML/CFT;

47) scoring risk model - a model for assessing the risk of business relations (financial transactions without establishing business relations) with a client, which calculates a certain integrated indicator (score) based on the specific weight of risk criteria inherent in business relations (financial transactions without establishing business relations) with a client, which is further used to assign the appropriate level of risk to business relations (financial transactions without establishing business relations) with a client;

48) screening procedure - a procedure for conducting data analysis by an institution, including analysis of the institution's databases using automated software modules (if available), in order to identify relevant facts;

49) social engineering - a set of methods for using the psychological characteristics of a person in order to induce him to take certain actions that he would not normally take, misleading a person;

50) client file - all documents/information regarding the client, business relations with him (conducting a one-time financial transaction for a significant amount by him), including the results of due diligence measures, collected and documented by the institution in the course of fulfilling the requirements of the legislation of Ukraine and the institution's internal documents on AML/CFT issues;

51) business entity - a resident legal entity or individual entrepreneur;

52) recipient institution - an institution that provides services for transferring funds to the recipient;

53) payer's institution - an institution that provides funds transfer services to the payer (transfer initiator);

54) intermediary institution - an institution that is an intermediary in the transfer of funds within the meaning of the term defined in paragraph 48 of part one of Article 1 of the Law on AML/CFT;

55) falsification - alteration of a genuine/authentic document (its elements, parts) with the aim of misleading the institution, in particular for the use of an identification document by a person who does not have the right to do so;

56) financial telephone number - the client's contact telephone number used by the institution, in particular for the purpose of its authentication;

57) financial inclusion - the process of implementing open, timely and full access to a wide range of financial products and services, spreading their use in society using existing and innovative approaches;

58) ID card - an identification document in which a contactless electronic medium is implanted;

59) OTP password (one-time password) - a certain sequence of text characters and/or numbers, which is generated by the institution's software centrally and is valid only for this purpose and limited in time, which the institution sends to the person to their financial phone number in the form of a text message.

Other terms and concepts used in this Regulation shall be applied in the meanings defined by the Law on AML/CFT , the Laws of Ukraine "On Financial Services and State Regulation of Financial Services Markets" , "On Payment Systems and Funds Transfer in Ukraine" , regulatory legal acts of the National Bank, the Cabinet of Ministers of Ukraine and the central executive body that ensures the formation and implementation of state policy in the field of AML/CFT (hereinafter referred to as the Ministry of Finance of Ukraine).

II. Proper organization of the institution's internal AML/CFT system↑

6. The institution is obliged to ensure proper organization of the internal AML/CFT system and primary financial monitoring. The purpose of proper organization of the internal AML/CFT system and primary financial monitoring is:

1) compliance with the requirements of Ukrainian legislation in the field of AML/CFT;

2) the ability to properly identify threshold and suspicious financial transactions (activities) and report them to the OMS;

3) preventing the use of the institution's services and products for clients to conduct financial transactions for the purpose of ML/TF.

7. In order to properly organize the internal AML/CFT system and conduct primary financial monitoring, the institution shall take, in particular, the following measures:

1) appoints a responsible employee of the institution in accordance with the requirements of the legislation of Ukraine in the field of AML/CFT at the level of the institution's management;

2) ensures the functioning of the ML/TF risk management system;

3) develops and approves the institution's internal documents on AML/CFT issues to the extent necessary for the effective functioning of the internal AML/CFT system and understanding by the institution's employees of their responsibilities and powers in the field of AML/CFT;

4) ensures on an ongoing basis consideration of problematic and relevant issues related to the functioning of the internal AML/CFT system;

5) provides sufficient resources for the functioning of the internal AML/CFT system;

6) ensures sufficient awareness and knowledge of the institution's management regarding their responsibilities in the field of AML/CFT, as well as regarding the ML/CFT risks inherent in the institution's risk profile;

7) ensures that the institution's management is informed about the importance of complying with the requirements of the legislation of Ukraine on AML/CFT in order to ensure an appropriate risk management system, the need to take effective measures to effectively prevent the use of the institution's services for the purpose of ML/CFT, and understanding the consequences to which the institution is exposed in case of failure to comply with the requirements of the legislation of Ukraine on AML/CFT;

8) ensures that employees of the institution are properly aware of and fulfill their assigned responsibilities in the field of AML/CFT, and that such employees understand their responsibility for failure to fulfill their duties and/or inaction;

9) implements and constantly improves the internal audit (control) system for ML/TF issues and/or involves independent auditors, in particular ensuring timely identification by internal audit (control) and/or independent audit of problematic issues and signs of an inadequate ML/TF risk management system;

10) studies new products/services, including new sales channels, use or development of new technologies for existing or new products in order to properly assess their inherent ML/TF risks and properly control ML/TF risks for existing products/services;

11) ensures on an ongoing basis the conduct of training events for employees of the institution and agents of the institution (their employees) in order for them to understand the duties assigned to them and the procedure for action;

12) ensures verification of the impeccable business reputation of all employees of the institution involved in conducting primary financial monitoring;

13) creates and ensures the functioning of an effective and timely system for escalating suspicions and problematic issues in the field of AML/CFT and the procedure for their consideration, including the reporting of information/facts relating to cases of violation or possible violation of the legislation of Ukraine in the field of AML/CFT, in accordance with the procedure provided for by the institution's internal documents;

14) ensures timely and full fulfillment by the institution of the responsibilities of the SPFM (in particular, identification of financial transactions subject to financial monitoring, freezing of assets related to terrorism and/or its financing / proliferation of weapons of mass destruction and/or its financing, preventing transactions by persons on the terrorist list), including the use of CA (if available);

15) ensures timely detection of financial transactions subject to financial monitoring and proper information exchange with the OMS;

16) develops and implements CDD measures to understand the essence of the client's activities, the purpose and expected nature of the business relationship with him, which allows the institution to be confident that the client's financial transactions correspond to the information available to the institution about him, his business, risk profile, including, if necessary, the source of origin of his funds/assets, establishing CDD for the prompt detection of unusual behavior and suspicious financial transactions (activities);

17) properly documents the actions of the institution's employees and records events related to the institution's performance of its SPFM duties;

18) retains all documents, data, information (including relevant reports, orders, files) related to the institution's performance of its responsibilities as a SPFM, within the time limits specified by the legislation of Ukraine;

19) promptly and fully provides the National Bank with the necessary documents/information/explanations/arguments that duly confirm the institution's compliance with the requirements of Ukrainian legislation on AML/CFT issues;

20) takes measures to continuously improve the internal AML/CFT system.

8. The institution may establish a separate structural unit for AML/CFT, which is headed by a responsible employee of the institution or which is directly subordinate to a responsible employee of the institution, taking into account the specifics of its organizational structure. The specified unit shall operate in accordance with the regulation on this structural unit, which shall be approved in accordance with the requirements of the institution's internal documents.

9. Responsibility for improper organization of the internal AML/CFT system and conduct of primary financial monitoring lies with the head of the institution, as well as the responsible employee of the institution.

10. The responsible employee of the institution shall inform the head of the institution at least once a month in accordance with the requirements of Part Five of Article 9 of the Law on AML/CFT, as well as on the following issues in the field of AML/CFT:

1) the results of monitoring business relationships with clients, which revealed suspicious client activity, and proposals for taking necessary measures in relation to such clients in order to minimize ML/TF risks;

2) issues related to proposals to refuse to continue business relationships with clients (including in the event of establishing an unacceptably high level of risk to the client);

3) problematic issues that arise in institutions during the implementation of NPC activities;

4) changes in the legislation of Ukraine on AML/CFT issues and the institution's taking of necessary measures in connection with such changes (in particular, updating the institution's internal documents on AML/CFT issues) with an indication of the deadlines for taking such measures;

5) the results of the assessment of the institution's new products/services and their inherent ML/TF risks;

6) problematic issues regarding the conduct of training events for employees of the institution, agents of the institution (their employees);

7) problematic issues related to establishing business relationships with PEPs and/or servicing them;

8) other issues regarding the institution's compliance with the requirements of Ukrainian legislation in the field of AML/CFT, which require consideration and response in order for the institution to comply with the requirements of Ukrainian legislation in the field of AML/CFT.

11. The head of the institution has the right to delegate the consideration of the issues specified in paragraph 10 of Section II of these Regulations to a specially created separate committee or a committee already operating in the institution (hereinafter referred to as the Committee).

The powers of the Committee (if established or if it exists), the procedure for its formation and decision-making are determined in the Regulation on the Committee.

The issues specified in paragraph 10 of Section II of these Regulations must be considered at Committee meetings at least once every six months.

The head of the institution or a responsible employee of the institution may be the chairman of a separate committee.

The composition and size of the Committee are formed and approved by an administrative act of the institution.

The Chairman and members of the Committee have the right to invite managers and employees of other departments of the institution to participate in the Committee meeting.

12. The responsible employee of the institution shall report to the executive body (if the executive body is collegial) / head of the institution at least once a year, no later than the first quarter of the year following the reporting year, regarding:

1) the results of the assessment of the institution's risk profile;

2) issues related to the creation of a proper organization of the internal AML/CFT system and the conduct of primary financial monitoring;

3) issues related to ensuring an appropriate ML/TF risk management system.

13. The responsible employee of the institution must constantly maintain his knowledge of AML/CFT issues at the appropriate level, including by undergoing training in the field of AML/CFT, as well as advanced training in the manner and within the time limits established by the Law on AML/CFT .

The institution must help maintain the level of knowledge of the responsible employee and ensure that he or she receives training at appropriate educational institutions.

14. Successor institutions and institutions that have reorganized their separate divisions are obliged to ensure compliance with the requirements of the legislation of Ukraine regarding the storage of information available before the reorganization regarding the institution's compliance with the requirements of the legislation of Ukraine in the field of AML/CFT, including the results of the CDD, information on financial transactions of clients and persons who participated in their conduct, and to provide the OMS with information in a timely manner in cases provided for by the Law on AML/CFT.

15. Based on a risk-based approach, the institution organizes and conducts, in accordance with Article 8 of the Law on AML/CFT, internal inspections or independent audits regarding the institution's compliance with the requirements of the legislation of Ukraine in the field of AML/CFT.

The institution must ensure:

1) inclusion in internal audits or independent audits of issues regarding the adequacy of measures taken by the institution to ensure the functioning of an appropriate ML/TF risk management system, the adequacy and effectiveness of the implemented CA (if any) for the institution to fulfill its PFMS obligations, and the compliance of the institution's responsible employee with the requirements established by the Law on ML/TF and these Regulations;

2) availability of reports based on the results of internal audits or independent audits (if necessary, conclusions and proposals for eliminating shortcomings identified as a result of internal audits or independent audits may be added to the reports);

3) monitoring the elimination of violations identified during internal inspections or independent audits.

The institution is obliged to draw up an action plan to eliminate identified violations of the requirements of the legislation of Ukraine and/or shortcomings in the field of ML/TF in order to minimize ML/TF risks and prevent violations in the future (hereinafter referred to as the risk reduction plan) no later than 15 business days from the date of signing by the person(s) who carried out the internal audit of the report on the results of the internal audit or receipt by the institution of a report on the results of an independent audit.

The institution is obliged to take measures to implement the risk reduction plan within the time limits specified therein.

The institution is obliged to submit in electronic form a report on the results of the internal review or independent audit with a cover letter signed by the CEP of the head of the institution to the DFM no later than the twentieth working day from the date of its signing/reception, ensuring its guaranteed delivery and confidentiality.

The institution is also obliged, at the request of the National Bank, to submit to it in electronic form a risk reduction plan with a cover letter signed by the CEP of the head of the institution.

The National Bank has the right to provide suggestions and comments to the risk reduction plan, which are mandatory for consideration and implementation by the institution.

16. The payment institution is obliged to implement a CA, which must ensure:

1) freezing of assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing;

2) maintaining a protocol of each user's work, protected from modification. The protocol must reflect the start and end of each user's work, indicating the time with an accuracy of up to a second;

3) the presence of an information protection system that meets the requirements of the legislation of Ukraine in the field of information protection;

4) availability of a backup and information storage system;

5) constant monitoring of clients' financial transactions in order to promptly identify indicators of suspicious financial transactions.

17. The implemented CA of a payment institution should contribute to the functioning of an appropriate ML/TF risk management system and be aimed at:

1) ensuring the ability of the institution to promptly process a large amount of data on clients and their financial transactions, using appropriate algorithms, scenarios, etc.;

2) efficient use of the institution's resources to fulfill the tasks and responsibilities of the SPFM.

18. An institution (other than a payment institution) is required to ensure procedures for checking the presence of clients on terrorist lists and freezing assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing, using CA (if available) or using alternative methods, including methods that involve processing information in electronic form.

The institution (other than a payment institution) is required to document a description of the essence of the above measures.

The institution (other than a payment institution) is obliged, upon request of the National Bank, to provide a description and explanation of the essence of such measures (demonstrate their operation if necessary).

19. The institution submits information for registration (deregistration) with the LMA as a financial institution, and also submits to the LMA information on financial transactions subject to financial monitoring, other information that may be related to ML/TF, in accordance with the procedure established by the relevant regulatory legal acts of the Cabinet of Ministers of Ukraine and the Ministry of Finance of Ukraine.

III. Requirements for internal documents of the institution on AML/CFT issues↑

20. The institution develops and approves internal documents to comply with the requirements of Ukrainian legislation in the field of AML/CFT, which must contain effective risk-oriented procedures and orders sufficient for the proper organization and functioning of the internal AML/CFT system and the conduct of primary financial monitoring, and the functioning of an appropriate ML/CFT risk management system.

21. The institution's internal documents on AML/CFT issues are developed by the institution taking into account the requirements of the laws of Ukraine regulating AML/CFT issues, these Regulations, regulatory legal acts of the Cabinet of Ministers of Ukraine, the Ministry of Finance of Ukraine, the National Bank adopted for the implementation of and in accordance with these laws, FATF recommendations, the results of the national risk assessment and the institution's risk profile, the recommendations of the National Bank and typological studies of the OMS.

An institution that is a member of a group has the right to use in its activities procedures/programs/other documents on AML/CFT issues developed and approved by the main (parent) organization of this group (provided that the institution can provide such a document upon request of the National Bank).

22. The main principles for the development and implementation of an institution's internal documents on AML/CFT issues are:

1) proper organization and functioning of the internal AML/CFT system and primary financial monitoring, functioning of an appropriate ML/CFT risk management system, ensuring the functioning of an effective internal AML/CFT system;

2) introduction of a risk-based approach when implementing AML/CFT procedures;

3) the institution's compliance with all requirements specified by the legislation of Ukraine in the field of AML/CFT;

4) taking into account all types and areas of activity of the institution;

5) introducing an AML/CFT culture in the institution and ensuring the direct participation of each employee (within their competence) in the implementation of AML/CFT procedures;

6) a clear division of responsibilities and powers between the head of the institution, the responsible employee of the institution, and other employees of the institution involved in conducting primary financial monitoring, in order to prevent violations of Ukrainian legislation in the field of AML/CFT in the work of the institution;

7) establishing a detailed and as understandable as possible procedure for the institution's employees involved in conducting primary financial monitoring when implementing AML/CFT procedures;

8) ensuring the secrecy of financial monitoring and confidentiality of information on information exchange with the MSA, including the fact of transferring information about the financial transaction of the client to the MSA;

9) ensuring the confidentiality of information about the institution's internal documents on AML/CFT issues;

10) ensuring the confidentiality of information about clients, their financial transactions, as well as other information in accordance with the requirements of the legislation of Ukraine in the field of information protection;

11) preventing the involvement of institution employees in ML/TF.

23. The institution’s internal AML/CFT documents should at least contain:

1) identification of employees and/or departments (if any) of the institution responsible for implementing NCP measures, and distribution of responsibilities between them;

2) a procedure that ensures the implementation of all CDD measures (in particular, identification and verification measures, establishment of CDD, monitoring of business relationships and financial transactions, updating of client data);

3) the procedure for identifying PEPs and the procedure for taking necessary additional measures against them;

4) the procedure for assessing/reassessing the institution's risk profile and the risk profile of customers and taking measures to minimize ML/TF risks;

5) the procedure for identifying ML/TF risk criteria and indicators of suspicious financial transactions;

6) the procedure for maintaining the client questionnaire and client lists specified in clause 61 of section IV of these Regulations, which will ensure the timeliness, completeness and reliability of the information entered into the client questionnaire or the specified client lists;

7) procedure for actions regarding the institution's refusal to establish (maintain) business relations/services, including by terminating business relations, refusal to conduct a financial transaction in cases provided for by the Law on AML/CFT ;

8) the procedure for identifying discrepancies by the institution between information on the CBV and the ownership structure contained in the Unified State Register and information obtained by the institution as a result of conducting the NPC;

{Subparagraph 8 of paragraph 23 of section III as amended by Resolution of the National Bank No. 121 of 05.10.2024 }

9) the procedure for using the placement tool (if the institution decides to use this tool);

10) the procedure for the institution to use agents, conduct training activities for them (their employees) and monitor their activities (if the institution decides to engage agents);

11) the procedure for entering relevant information into the message registers;

12) procedure for using the CA (if available);

13) the procedure for information exchange with the MSA and implementation of relevant decisions/instructions of the MSA;

14) the procedure for freezing assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing;

15) the procedure for the institution to suspend operations in cases specified in the Law on AML/CFT ;

16) the procedure for the institution to accompany transfers of funds with relevant information in accordance with the requirements specified in Article 14 of the Law on AML/CFT (for payment institutions);

17) the procedure for monitoring the relevant limits in the event that the institution uses simplified methods of identification and verification of the client (client representative);

18) procedure for ensuring the secrecy of financial monitoring and confidentiality of other information;

19) the procedure for informing the SBU in cases specified by the legislation of Ukraine in the field of AML/CFT;

20) procedure for conducting training events for employees of the institution;

21) the procedure for familiarizing employees of the institution with the institution's internal documents on AML/CFT issues;

22) the procedure for storing all documents/information regarding the institution's compliance with the requirements of Ukrainian legislation in the field of AML/CFT.

24. The institution's internal documents on AML/CFT issues should take into account the characteristics, areas and specifics of the institution's activities, the characteristics of different types of clients, as well as the institution's implementation of a risk-based approach.

An institution's internal documents on AML/CFT issues may be in the form of one general document or several separate documents.

25. The institution should ensure that the institution's internal documents on AML/CFT issues are up-to-date, taking into account changes to Ukrainian legislation in the field of AML/CFT and events that may affect the institution's ML/CFT risks.

26. The institution shall update the institution's internal documents on AML/CFT issues on an ongoing basis, but no later than three months from the date of entry into force of amendments to the legislation of Ukraine on AML/CFT issues and/or the establishment by the institution of events that may affect ML/CFT risks.

27. The institution independently determines and documents the procedure for classifying the institution's internal documents on AML/CFT issues as documents with restricted access and the procedure for access to them by the institution's employees and third parties.

28. The institution ensures that employees of the institution (depending on their job duties) are familiarized with the institution's internal documents on AML/CFT issues, against signature or using electronic means, in the event of:

1) hiring an employee to work at an institution - before such employee begins performing official duties at the institution;

2) approval, amendments to the institution's internal documents on AML/CFT issues - no later than 20 working days from the date of approval, amendments (except for employees who were on vacation, sick leave, or business trip during this period, who are familiarized with them no later than two working days from the date of starting work).

29. Internal documents of the institution on AML/CFT issues are approved by the executive body (if the executive body is collegial) / the head of the institution in accordance with the procedure specified in the constituent documents of the institution, upon submission by the responsible employee of the institution.

30. The institution is obliged, no later than the third business day from the date of receipt of the National Bank's request for the provision of internal documents, to submit to the DFM in electronic form the institution's internal documents on AML/CFT issues with a cover letter signed by the CEP of the head/responsible employee of the institution.

IV. Proper ML/TF risk management system↑

31. The institution is obliged to apply a risk-based approach in its activities, which must be proportionate to the nature and scale of the institution's activities.

32. A risk-based approach should be applied by the institution on an ongoing basis and ensure the detection, identification, and assessment of all existing and potential ML/TF risks inherent in the institution's activities (the institution's risk profile) and its clients, as well as provide for the timely development of measures to manage ML/TF risks and minimize them.

33. The institution shall document the process of applying the risk-based approach in such a way as to be able to demonstrate its essence (in particular, what the differences in approaches are), the decisions made by the institution in applying it and the justification for such decisions.

34. An institution applying a risk-based approach should refrain from unwarranted use of de-risking. This approach contradicts the risk-based approach and does not promote financial inclusion.

35. The risk-based approach should be based on risk assessment and include:

1) assessment of the institution's risk profile:

identification and assessment of ML/TF risks inherent in the institution's activities;

analysis of existing ML/TF risk management measures to reduce (minimize) them;

determining the institution's risk appetite in the field of ML/TF (the level of ML/TF risk acceptable to the institution);

2) assessment of the client's risk profile:

identification and assessment of the risk of a business relationship (financial transaction without establishing a business relationship) with a client;

analysis of existing ML/TF risk management measures to reduce (minimize) them to an acceptable level of ML/TF risk for the institution (within the institution's AML/TF risk appetite).

36. The institution assesses its own risk profile taking into account the specifics of its activities and the following factors:

1) the nature and scale of the institution's activities;

2) sources of business financing (own or borrowed funds);

3) products and services provided by the institution;

4) types of clients and their risk profile;

5) the geographical location of the institution, the geographical location of the state of registration of clients or institutions through which the institution transfers (receives) assets;

6) channels/methods of providing (receiving) services;

7) counterparties with whose participation the institution carries out actions with assets;

8) other significant factors related to the activities of the institution.

37. When analyzing the ML/TF risks of its products and services, the institution should take into account the specifics and possibilities of their use, in particular:

1) intended use of the product and/or service:

Do the institution's products and/or services allow for the masking of the illegal origin of funds, the transfer of funds for the financing of terrorist activities, the promotion of the anonymity of participants in a financial transaction (the concealment of the real end recipients of certain products and/or services);

whether they can be used by the client on behalf of third parties;

whether they may be interesting for shell companies;

2) special possibilities of using the product and/or service: does the product and/or service allow the institution's client to carry out transactions with counterparties/business segments that are characterized by increased ML/TF risks;

3) target segment for the sale of a product and/or service: types of customers who use a particular product and/or service the most/most often.

38. When analyzing the channels/methods of providing (obtaining) its products and/or services, the institution should pay special attention to the risks inherent in new technologies (in particular, remote establishment of business relations with the client), the presence of agents, and the use of information from other SPFMs.

39. The institution should take into account geographical risk criteria, paying, in particular, special attention to states (territories) that do not comply with FATF recommendations or that have strategic deficiencies in the field of AML/CFT (in accordance with FATF statements), states that carry out armed aggression against Ukraine within the meaning of Article 1 of the Law of Ukraine "On the Defense of Ukraine", the presence/absence of military conflicts, terrorist groups and/or organizations on the territory of the state (territory).

40. The geographical risk criteria of an institution should also take into account the location of the institution itself (its parent institution, branches, representative offices, subsidiaries) and the geography of the provision by the institution of its products and/or services.

41. When determining its risk profile, the institution is also required to take into account the presence and nature of sanctions applied to it.

42. Risk criteria are determined by the institution independently, taking into account the risk criteria established by the National Bank in Appendix 18 to these Regulations, typological studies of the OMS, the results of the national risk assessment, as well as the recommendations of the National Bank.

43. The institution determines the priority/significance of the developed risk criteria, taking into account the possible consequences/impact of such risks, and sets them an appropriate weight for further assessment of the risk level.

44. The institution has the right to assess the risk of business relationships (financial transactions without establishing business relationships) simultaneously for a group of clients (one group risk profile), separating such clients into appropriate categories based on clearly defined and recorded in the institution’s internal documents on AML/CFT parameters (in particular, social status, use of the same types of services, total volume of financial transactions). If the business relationship (financial transaction without establishing business relationships) with the client meets such parameters, the institution assigns to such business relationship (financial transaction without establishing business relationships) with the client the risk level established for such risk profile. The institution shall further ensure on an ongoing basis control over the compliance of business relationships (financial transactions without establishing business relationships) with clients that are separated into a separate risk profile with the appropriate parameters of such risk profile.

45. Based on the assessment of the ML/TF risks inherent in its activities, the institution determines its risk appetite (the level of acceptable risk) in the field of ML/TF, taking into account:

1) the risks that the institution is willing to accept;

2) risks that the institution can accept, but only after taking measures to manage such risks (minimize them);

3) risks that are unacceptable to the institution.

46. Based on the results of the analysis, the institution has the right to determine (if necessary) and prescribe in the institution's internal documents on AML/CFT the established prohibitions/restrictions in its activities (regarding certain types of activities and/or attracting certain types of clients for service).

47. When accepting relevant risks, the institution should take into account the availability of effective measures to manage them, in particular the availability of necessary resources.

48. The executive body (if the executive body is collegial) / head of the institution shall at least once a year review the results of the assessment of the institution's risk profile, approve the appropriate decision based on the results of such review and inform the responsible employee of the institution for its further implementation.

49. The institution shall take into account the results of the assessment of the institution's risk profile when developing risk criteria for assessing the risk of business relationships (financial transactions without establishing a business relationship) with customers and ML/TF risk management measures.

50. The institution shall assess the risk of business relationships (financial transactions without establishing business relationships) with clients before establishing business relationships with the client / conducting financial transactions without establishing business relationships.

51. Based on the results of the assessment of business relations (financial transactions without establishing business relations) with the client, the institution establishes the level of risk using a risk assessment model (if necessary, a scoring risk model) that takes into account the presence of risk criteria inherent in the client and his activities (including those expected at the stage of establishing business relations with the client).

52. The scale for classifying the risk levels of business relationships (financial transactions without establishing a business relationship) must necessarily include high and unacceptably high (a subcategory of high risk, which is the highest risk that cannot be accepted by the institution) risk levels.

53. The institution implements its own risk assessment model (if necessary, a scoring risk model) and independently determines the input data and information sources for conducting risk assessment, the algorithm (model) for conducting risk assessment, and the scale for determining risk levels.

54. When developing risk criteria taking into account its AML/CFT risk appetite, the institution shall determine adequate quantitative limits for those criteria that contain quantitative characteristics (in particular, "significant increase", "large volumes", "regularity").

55. The institution develops algorithms containing quantitative and/or qualitative characteristics that enable it to identify and establish the presence of an appropriate risk criterion inherent in the client and the business relationship with him (financial transaction without establishing a business relationship) [beneficiary (beneficiary) under a life insurance contract].

56. The institution establishes a high risk of business relationships (financial transactions without establishing business relationships) in relation to customers defined in part five of Article 7 of the Law on AML/CFT, in other cases defined by the institution independently in the institution's internal documents on AML/CFT, as well as in relation to:

1) clients (persons) who carry out activities in the field of virtual assets;

2) clients (persons) in respect of whom the institution suspects that they have committed ML/TF transactions or committed other crimes;

3) clients (persons) in respect of whom [beneficiaries (beneficiaries) under life insurance contracts] the institution has suspicions of their belonging to shell companies (their carrying out fictitious activities);

4) clients who carry out financial transactions under foreign economic agreements, the participants of which are persons who are registered, reside or are located in a state (jurisdiction) from the list of states that do not comply with FATF recommendations;

5) clients (individuals) - policyholders, beneficiaries (beneficiaries) under life insurance contracts of which or the beneficiaries (beneficiaries) of the life insurance contracts of which:

are registered, reside or are located in a state (jurisdiction) on the list of states that do not comply with FATF recommendations;

belong to the category of PEPs.

57. The institution establishes an unacceptably high risk of business relationships (financial transactions without establishing business relationships) with respect to customers in cases specified in part six of Article 7 of the Law on AML/CFT, in other cases specified by the institution independently in the institution's internal documents on AML/CFT, as well as in relation to:

1) clients (persons) for whom the institution, based on the results of studying the client's suspicious activity, has reasonable suspicions that they have committed ML/TF transactions or other crimes;

2) clients (persons) for whom the institution has reason to believe that they are shell companies.

58. The institution, in the absence of risk criteria and the absence of suspicions, establishes a low risk in relation to business relationships with clients who use the services of the institution with a low level of ML/TF risk (for example, financial transactions relate mainly to payment of utility services, other ordinary activities of the population).

59. The institution shall continuously take measures to maintain up-to-date (including re-assessing the risk level as necessary):

1) own risk profile - in the event of a change in the business model, introduction of new products or services that are significantly different from existing ones in terms of their inherent ML/TF risks, but at least once a year;

2) client risk profile:

during the implementation of measures to update client data;

in case of identification of new risk criteria inherent in business relations (financial transactions without establishing business relations) with the client - no later than the 15th day of the month following the month in which the new risk criterion was identified.

60. The institution shall on an ongoing basis take measures to identify risk criteria inherent in business relationships (financial transactions without establishing business relationships) with the client, analyzing the information obtained as a result of the implementation of the CDD and the client's financial transactions [using appropriate automated software modules (if available)].

61. The institution is obliged to constantly form and maintain in electronic form lists of clients with established/reassessed by the institution the risk levels of business relationships (financial transactions without establishing business relationships) with such clients, including low, medium, high, unacceptably high risk levels, facts of establishing by the institution that clients belong to the PEP category and facts of identifying discrepancies about the client's creditworthiness and ownership structure (hereinafter referred to as the Client Lists).

{Paragraph one of clause 61 of section IV as amended by Resolution of the National Bank No. 121 of 05.10.2024 }

The institution forms Client Lists indicating the following data:

1) the date of the assessment by the institution;

2) the date of revaluation by the institution (in case of a change in the risk level);

3) the date of discovery of the client's belonging to the PEP category;

3 - 1 ) the date of detection of discrepancies in the information on the CBV placed in the Unified State Register, if there are such discrepancies (in the case of the formation and maintenance of a client questionnaire for such a client, the relevant information is indicated in the questionnaire);

{Clause 61 of Section IV is supplemented with a new subparagraph 3 - 1 in accordance with the Resolution of the National Bank No. 121 of 05.10.2024 }

3 - 2 ) the date of detection of discrepancies regarding information on the ownership structure posted in the Unified State Register, if such discrepancies exist (in the case of the formation and maintenance of a client questionnaire for such a client, the relevant information is indicated in the questionnaire);

{Clause 61 of Section IV is supplemented with a new subparagraph 3 - 2 in accordance with the Resolution of the National Bank No. 121 of 05.10.2024 }

4) for resident individuals: last name, first name, patronymic (if available);

RNOKPP / number (and, if available, series) of the passport of a citizen of Ukraine, in which a note is made about the refusal to accept the RNOKPP / passport number with a record about the refusal to accept the RNOKPP in an electronic contactless medium / unique record number in the Unified State Demographic Register (if available);

5) for non-resident individuals:

last name, first name, patronymic (if available);

number (and, if available, series) of the passport (or other document that certifies the identity and, in accordance with the legislation of Ukraine, can be used on the territory of Ukraine to conclude transactions) / unique entry number in the Unified State Demographic Register (if available);

6) for resident legal entities:

full name;

code according to EDRPOU;

7) for non-resident legal entities (trusts or other similar legal entities) / representative offices of non-resident legal entities:

full name;

country of registration.

The institution is obliged to provide, at the request of the National Bank, in electronic form, certified by the CEP of the head of the institution, Client Lists containing up-to-date information as of the date specified in the request of the National Bank. If it is necessary to form Client Lists on paper, the institution is obliged to ensure that all data identical to those contained in the Client Lists in electronic form and which are provided for in paragraph 61 of Section IV of these Regulations is reflected on paper, with the obligatory indication of the date of printing.

62. The institution is obliged to assess/reassess risks, including those inherent to its activities, document their results, and maintain up-to-date information on the assessment of risks inherent to its activities (the institution's risk profile) and the risk of its clients in such a way as to be able to demonstrate its understanding of the risks posed to it by such clients (the client risk profile).

63. The institution determines the list and scope of measures necessary to be taken to effectively manage ML/TF risks within the institution's pre-determined acceptable level of risks.

64. ML/TF risk management measures include, in particular:

1) clear division of duties and responsibilities between employees of the institution and constant internal control;

2) preliminary analysis of the institution's new products/services to identify their inherent potential ML/TF risks;

3) application of limits, other tools that restrict the use of a particular service/product;

4) implementation of a diversified approach to obtaining permission to establish (continue) business relations (conducting a one-time financial transaction for a significant amount without establishing a business relationship) with a client, applying a risk-oriented approach (according to the principle: higher risk - the highest authorized employee of the institution provides his permission, including the heads of the institution);

5) obtaining additional permission from an authorized employee of the institution / head of the institution to conduct individual financial transactions with a high level of risk within the framework of established business relationships;

6) ensuring monitoring of business relationships with the client, which will enable the prompt identification of relevant inherent risk criteria;

7) implementation of CDD measures (including enhanced ones if necessary) and application of the "know your customer" principle, including obtaining additional necessary information to understand the content of the client's activities and/or the essence of the financial transaction;

8) increasing the degree and nature of monitoring of business relationships with high-risk customers;

9) regular and objective informing of the institution's management about identified ML/TF risks and measures to manage such risks;

10) ensuring that institution employees understand their responsibilities in the field of AML/CFT, including through training activities.

65. The institution shall regularly, but not less than once a year, when updating its risk profile, review the risk management measures available in the institution for their adequacy and effectiveness and develop additional measures if, according to the results of the analysis, the existing measures are insufficient for effective management of ML/TF risks.

66. The institution shall define in the institution's internal AML/CFT documents the essence of all measures to apply a risk-based approach.

67. An institution applying simplified or enhanced CDD measures must be able to justify its approach.

68. The institution is required to document all measures taken to apply its risk-based approach in such a way as to be able to demonstrate compliance of these measures with the requirements of Ukrainian legislation on AML/CFT.

69. Signs of an inadequate risk management system are:

1) improper implementation of a comprehensive assessment/reassessment of the institution's ML/TF risks, including those inherent to its activities (the institution's risk profile), documentation of their results, monitoring measures, risk control and maintaining the institution's risk profile up to date to minimize the use of the institution's services for ML/TF purposes;

2) failure to implement CDD, improper assessment/reassessment of the risk of business relationships (financial transactions without establishing a business relationship) with clients (client risk profiles), documentation of their results, monitoring measures, risk control and keeping the institution's clients' risk profiles up to date to minimize the use of the institution's services for ML/TF purposes;

3) improper application of a risk-based approach, which consists in the institution's improper understanding of ML/TF risks, failure to take effective measures proportionate to the identified risks to minimize them (DRM for low-risk clients and DRM for high-risk clients), lack of a risk-based procedure for approving business relationships with clients;

4) failure to take timely and adequate measures to minimize identified ML/TF risks to an acceptable level of ML/TF risks;

5) lack of effective tools to prevent/impossible multiple, large-scale financial transactions (activities) in relation to which there are suspicions of using the institution for ML/TF or committing another crime, in particular monitoring of business relationships with clients and financial transactions of clients carried out in the course of such business relationships;

6) lack of effective internal control over financial monitoring, untimely identification by internal audit (control) of problems and shortcomings in the internal ML/TF system and signs of an inadequate ML/TF risk management system;

7) the lack of an effective system for escalating suspicions and problematic issues in the field of AML/CFT, which made it impossible to conduct a timely and effective procedure for their consideration, including the reporting of information/facts relating to cases of violation or possible violation of the legislation of Ukraine in the field of AML/CFT;

8) lack of a proper system for identifying PEPs, which led to the institution's failure to properly implement additional measures against them, as defined by Ukrainian legislation in the field of AML/CFT;

9) lack of a proper system for identifying customer fraud;

10) failure by the institution to ensure proper documentation of the actions of the institution's employees and recording of events related to the institution's performance of the SPFM functions.

70. The institution's ML/TF risk management system is considered inadequate if at least one of the signs specified in paragraph 69 of Section IV of these Regulations is established, and facts of multiple, large-scale financial transactions are carried out, in respect of which there are suspicions of the institution being used for ML/TF or committing another crime, which resulted from failure to implement ML/TF measures.

V. Procedure for appointment and dismissal of a responsible employee of an institution↑

71. The responsible employee of the institution is appointed in accordance with the procedure determined by the institution's constituent documents and these Regulations.

The position of responsible employee of the institution has the level of management of the institution.

72. The responsible employee of the institution is directly subordinate to the head of the institution and reports to him.

73. The responsible employee of the institution / the person who will perform the duties of the responsible employee of the institution cannot be the head of the executive body (if the executive body is collegial), the director (president) (if the executive body is single-person) or another official who manages and manages the business entity in accordance with the legislation and constituent documents (the restriction does not apply to micro-enterprises).

74. The responsible employee of the institution must have an impeccable business reputation and meet the qualification requirements established by these Regulations.

The qualification requirements for a responsible employee of an institution are the requirements for the professional suitability of the responsible employee of the institution, as well as for the absence of facts provided for by these Regulations.

75. Signs of a less than impeccable business reputation of a responsible employee of an institution are:

1) the person has a criminal record that has not been cleared and removed in accordance with the procedure established by law;

2) deprivation of a person of the right to hold certain positions or engage in certain activities in accordance with a sentence or other court decision (applicable for the duration of such punishment);

3) the fact that the person was a manager, chief accountant or owner of a significant stake in the institution for at least six months during one year preceding the decision by the relevant state body to apply a measure of influence in the form of:

revocation/cancellation of all licenses to institutions (applies within five years from the date of the decision by the relevant state body to revoke/cancel the license);

removal of management from the management of the institution and appointment of a temporary administration in the institution in the event of violations by the institution of laws and other regulatory legal acts regulating the provision of financial services (applies within five years from the date of the decision by the relevant state body to remove management from the management of the institution and appoint a temporary administration);

4) the fact that the person was a manager, chief accountant or owner of a significant stake in an institution for at least six months, if such institution was declared bankrupt and/or subjected to compulsory liquidation during this period or within one year thereafter (applies within 10 years from the date of declaring the institution bankrupt or commencing compulsory liquidation).

76. The requirements for the professional suitability of a responsible employee of the institution are:

1) having a higher education in economics, law or management (for a responsible employee of a micro-enterprise - higher education);

2) having work experience in an institution whose type of activity is the provision of financial services, in the field of AML/CFT, or work experience in the OMS / Ministry of Finance of Ukraine, related to gaining experience in the field of AML/CFT, - at least one year;

3) knowledge of the legislation of Ukraine in the field of AML/CFT, as well as the skills to apply the requirements of the legislation of Ukraine and the institution's internal documents on AML/CFT in practical activities [must be confirmed by a document on completion of training in the field of AML/CFT at the relevant educational institution, classified under the scope of management of the SMA, or in other educational institutions in agreement with the SMA (hereinafter referred to as AML/CFT training) within the last three years].

A person who is appointed to the position of a responsible employee of an institution for the first time and/or has not undergone training in the field of AML/CFT within the last three years may be appointed to the position of a responsible employee of an institution without having the document specified in subparagraph 3 of paragraph 76 of Section V of these Regulations, provided that he/she undergoes training in the field of AML/CFT within three months from the date of his/her appointment to the position of a responsible employee of an institution and receives a document on the completion of training in the field of AML/CFT.

77. The following facts must be absent regarding the responsible employee of the institution:

1) application by Ukraine, foreign states (except for states carrying out armed aggression against Ukraine), intergovernmental associations or international organizations of sanctions against a person (applied during the term of the sanctions and within three years after their cancellation or the expiration of the term for which they were imposed);

2) inclusion of a person on the list of terrorists (applies during the period of the person's stay on the list and for 10 years after his/her removal from it).

78. The institution verifies the business reputation of a person and his compliance with the qualification requirements established by these Regulations on the basis of the following documents:

1) originals of documents for personal identification that allow establishing the information specified in paragraph 1 of part nine and paragraph 1 of part ten of Article 11 of the Law on AML/CFT;

{Subparagraph 1 of paragraph 78 as amended by Resolution of the National Bank No. 198 of 29.12.2023 }

2) documents for assessing the business reputation of the individual, including a certificate from the competent authority of the country of permanent residence of the individual stating whether or not he or she has a criminal record;

3) documents for assessing the person's compliance with the requirements for professional suitability, including originals of official documents with information about:

higher education of the person;

the person has completed training in the field of AML/CFT (if available);

the person's previous places of employment [for example, employment record (if available)].

79. If it is not possible to establish the conformity of a person's professional qualifications on the basis of a foreign educational document or the authenticity of this document or the status of an educational institution, the institution has the right to request a decision from an authorized state body of Ukraine on the recognition in Ukraine of such a foreign educational document.

80. The institution is obliged to verify the person who is a candidate for the position of a responsible employee of the institution regarding his/her compliance with the requirements of the Law on AML/CFT and these Regulations in accordance with the procedure specified by the internal documents of the institution, prior to his/her appointment.

As a result of such an inspection, the institution must verify the presence/absence of an impeccable business reputation of the person and its compliance/non-compliance with the qualification requirements established by these Regulations, in confirmation of which the institution draws up a written decision (conclusion), which is signed by the head of the executive body (if the executive body is collegial) / the head of the institution [hereinafter referred to as the decision (conclusion)].

81. The institution is prohibited from appointing as a responsible employee of the institution a person who has signs of a less than impeccable business reputation and who does not meet the qualification requirements established by these Regulations.

82. The responsible employee of the institution is obliged, throughout the entire period during which he retains his status, to comply with the requirements established by the Law on AML/CFT and these Regulations.

83. The institution is obliged to constantly monitor the compliance of the responsible employee of the institution with the requirements established by the Law on AML/CFT and these Regulations.

The institution is obliged to check the responsible employee of the institution at least once a year for his compliance with the requirements of the Law on AML/CFT and these Regulations in accordance with the procedure specified by the institution's internal documents, and to draw up a decision (conclusion) based on the results of such a check.

84. The institution shall appoint a person who will temporarily perform the duties of a responsible employee of the institution (due to temporary incapacity for work, vacation, business trip), in accordance with the procedure established by the institution's constituent documents and these Regulations for a period of up to four months.

The institution shall assign the temporary performance of the duties of a responsible employee of the institution to a person who has an impeccable business reputation and meets the qualification requirements established by these Regulations.

The person temporarily performing the duties of a responsible employee of the institution shall be assigned all duties and granted all rights of a responsible employee of the institution, as provided for in the Law on AML/CFT , these Regulations and the institution's internal documents on AML/CFT issues.

85. After the dismissal of a responsible employee of the institution / suspension from work in accordance with the decision of the National Bank / suspension from work in other cases provided for by the legislation of Ukraine, the institution is obliged to appoint another responsible employee of the institution no later than the next working day.

In the event of dismissal/suspension from work of a responsible employee of the institution, the institution may appoint a person who will perform the duties of a responsible employee of the institution for the period of verification by the institution of the business reputation and compliance with the qualification requirements established by these Regulations of a candidate for the position of a responsible employee of the institution, which should not exceed two months.

86. The institution shall retain all documents on the basis of which it verified the business reputation of the responsible employee of the institution and his compliance with the qualification requirements established by these Regulations, as well as the decision (conclusion) within the time limits specified by the legislation of Ukraine.

87. The institution is obliged, at the request of the National Bank, to provide documents on the basis of which it verified the business reputation of the responsible employee of the institution and his compliance with the qualification requirements established by these Regulations, as well as a decision (conclusion) and to provide clarification (if necessary) of the essence of the measures taken by the institution to verify the responsible employee of the institution.

88. The institution is responsible for due diligence of the business reputation of the responsible employee of the institution and his compliance with the qualification requirements established by the Law on AML/CFT and these Regulations, the reliability of the information on the basis of which the decision (conclusion) was made, and which is set out in the decision (conclusion).

VI. Requirements for uniform rules on AML/CFT issues of the group↑

89. The requirements established by Section IV of this Regulation shall apply to a group in which the parent company is a financial institution registered in Ukraine.

90. The Group develops and implements uniform rules on AML/CFT issues, taking into account the requirements of Ukrainian legislation regulating AML/CFT issues.

91. The uniform rules on AML/CFT should contain specifics on the implementation of AML/CFT measures by institutions.

92. The uniform AML/CFT rules of a group apply to all participants included in such a group.

93. The group’s AML/CFT uniform rules should include:

1) description of the organizational structure of the group in terms of ensuring that group members comply with the requirements of Ukrainian legislation on AML/CFT;

2) identification of participants in the AML/CFT group system in accordance with the areas of activity of the group participants;

3) the procedure for circulating and ensuring the confidentiality of information between group members.

94. The main principles for the development and effective implementation of uniform rules on AML/CFT issues for the group are:

1) ensuring the organization and functioning of an effective AML/CFT system by group members;

2) the presence of an appropriate ML/TF risk management system;

3) the presence of an appropriate system for monitoring compliance by group members with international AML/CFT standards, Ukrainian legislation on AML/CFT, and uniform rules on AML/CFT;

4) development of general principles for the application of software for the analysis of financial transactions in order to identify financial transactions subject to financial monitoring, assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing, as well as participants or beneficiaries of which are persons included in the sanctions list of the National Security and Defense Council, other lists determined by the group;

5) introduction of uniform requirements for the procedure for exchanging and using information by group members in cases specified by the Law on AML/CFT , ensuring the confidentiality of the circulation of such information;

6) development of a unified procedure for the transfer and storage of documents and information on AML/CFT issues.

95. The group's unified AML/CFT rules are updated on an ongoing basis, but no later than three months from the date of entry into force of relevant amendments to the legislation of Ukraine on AML/CFT and/or the establishment by the group of events that may affect ML/CFT risks.

96. Institutions that are members of groups, including international groups (whose parent companies are not institutions registered in Ukraine), are allowed to disclose and exchange information that constitutes a financial monitoring secret within such a group (including the parent company and other group members) to ensure the group's compliance with international AML/CFT standards, provided that such group members adhere to uniform AML/CFT rules (including procedures for exchanging information within the group) that ensure the confidentiality of such information.

Appendix 1
to the Regulations on the implementation
of financial monitoring by institutions

CUSTOMER DUE DILIGENCE

1. The institution is obliged to conduct due diligence on new and existing customers in the cases provided for in Article 11 of the AML/CFT Law.

2. Measures to identify and verify a client (client representative) are carried out by the institution in accordance with the procedure specified in Appendix 2 to the Regulations on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulations).

3. The establishment of the CBV and verification of his identity is carried out by the institution in accordance with the procedure specified in Appendix 4 to the Regulations.

4. Assessing the risk of business relationships (conducting a financial transaction without establishing a business relationship) with a client is an integral part of the CDD.

5. Before establishing a business relationship (conducting a financial transaction without establishing a business relationship) with a client, the institution must establish (understand) the purpose and nature of the future business relationship or conducting a financial transaction on the basis of the necessary information received from such a potential client. To this end, the institution, guided by a risk-based approach, in particular ascertains:

1) the nature, scale and type of activity of the client - a legal entity, individual entrepreneur, trust or other similar legal entity;

2) income / social status of the client - an individual;

3) the type of services/products for which the client applies to the institution;

4) the approximate volume of financial transactions that the client plans to conduct at the institution.

6. The institution, using a risk-based approach, when conducting CDD in relation to a legal entity, trust or other similar legal entity, shall conduct a thorough analysis of information about the client in order to identify risk criteria that may indicate that the potential client is a shell company, as defined in Annex 18 to the Regulation.

In the event that the institution identifies relevant risk criteria in order to confirm/disprove that a potential client is a shell company, it is obliged to obtain and analyze additional documents and/or information that may clarify/explain the presence/absence of relevant grounds for the institution's suspicion, for example:

1) financial statements, confirmed by an independent external audit, which disclose the essence and content of financial transactions carried out by the client and allow establishing the correspondence of profit (income) / turnover to its economic activity;

2) confirming the actual movement of goods, provision of services, performance of work during the conduct of economic activities;

3) confirming the conduct of business activities by the potential client's main counterparties;

4) confirming payment of income tax (income);

5) confirming the employment of persons under an employment contract (staffing contract or outsourcing service contract), whose job responsibilities include organizing and ensuring the implementation of economic activities, taking into account the correspondence of such responsibilities to the type of activity of the potential client and the volume of its financial transactions;

6) confirming the availability of production/office premises, other assets sufficient for the potential client to conduct the relevant type of economic activity (title document or lease agreement for premises/equipment);

7) confirming the availability of office space at the potential client's address for mass registration.

The above list of documents/information is not exhaustive. The institution may independently determine other documents/information that, at its discretion, are sufficient to confirm that the potential client is not a shell company, provided that the amount of such information is sufficient to conduct a proper analysis of the information about the client and make an appropriate reasoned decision.

7. The requirements of paragraph 6 of Appendix 1 to the Regulation do not apply to legal entities that are holding companies or their corporate enterprises, provided that the ownership structure of the holding company is transparent, allows for the identification of the CBV (or to ascertain their absence) and the essence of the economic activity of such a legal entity is fully understandable to the institution.

8. If the documents and/or information specified in paragraph 6 of Appendix 1 to the Regulations received by the institution are not sufficient for the institution to refute that the potential client is a shell company (and also if the potential client has refused to provide the institution with the documents/information necessary for the analysis), then the institution shall determine that such potential business relationship with the client is of unacceptably high risk and shall act in accordance with the requirements of Article 15 of the AML/CFT Law.

9. The institution, using a risk-based approach, takes measures to confirm/disprove that a customer is a shell company, also in relation to existing customers, when monitoring business relationships and financial transactions of customers carried out in the course of such relationships.

10. In the event of assigning an unacceptably high level of risk to a client in accordance with the requirements of paragraph 8 of Appendix 1 to the Regulation, the institution shall apply the NDRP to other clients who are related to such client and are also clients of the institution.

11. Taking into account the client's risk profile, the institution shall on an ongoing basis monitor the business relationships and financial transactions of clients carried out in the course of such relationships, with regard to the compliance of such financial transactions with the information available to the institution about the client, his activities and risk (including, if necessary, about the source of funds related to financial transactions) in accordance with the procedure specified in Appendix 1 to the Regulation.

12. If, based on the results of monitoring the client's business relationships, the institution detects suspicious financial transactions (activities), the institution, if necessary, takes measures to reassess the risk level of such business relationships with the client and applies the PDNP in case of assigning a high risk level.

13. The institution is obliged to ensure the updating of data about the client (received and existing documents, data and information about him):

1) at least once a year if the risk of the business relationship with the client is high;

2) at least once every three years if the risk of the business relationship with the client is medium;

3) at least once every five years - in other cases, provided there are no suspicions.

14. The institution is obliged to ensure updating of client data also in the event of:

1) identification of facts of significant changes in the client's activities (in particular, in the event of a change in the name of the client, manager, location of the legal entity, trust, other similar legal entity, individual entrepreneur);

2) expiration (termination), loss of validity or invalidation of submitted documents;

3) loss of validity / exchange of the identification document of the client (client's representative);

4) establishing the fact that the client belongs to a PEP.

15. In the event of loss of validity/exchange of the identification document of the client (client representative), the institution shall take measures to obtain the data of the valid document and update the data about the client no later than six months from the date of the occurrence of the relevant event. In other cases, the institution shall take measures to update the data about the client no later than three months from the date of detection of the relevant fact/occurrence of the event.

16. For clients who do not maintain business relations with the institution or do not carry out further one-time financial transactions for a significant amount (if there is a previous one-time financial transaction for a significant amount), during the last six months before the occurrence of the events specified in paragraphs 14 , 15 of Appendix 1 to the Regulations, the institution updates data about clients on the day of their next contact with the institution and/or until the moment they initiate financial transactions.

17. The institution may provide in its internal documents on AML/CFT issues for other cases of updating customer data.

18. The institution may take measures to update client data by using remote service systems, e-mail with the use of CEP / advanced electronic signature, telephone communication, call center, other remote communication channels within the technical capabilities of the institution. In any case, the institution shall document the implementation of these measures in such a way as to be able to demonstrate their proper implementation (including by saving relevant records and files).

19. The institution determines the need for the client to inform the institution about the occurrence of significant changes in its activities (other information provided by the client to the institution) and establishes the procedure for obtaining the necessary data/information from the client (client representative), in particular by establishing relevant obligations in the contracts for the provision of services by the institution.

20. The institution is obliged to form and maintain customer questionnaires in the event of:

1) if the risk of the business relationship with the client (the risk of a financial transaction without establishing a business relationship with the client) is high;

2) conducting a financial transaction subject to financial monitoring [threshold and/or suspicious financial transaction (activity)];

3) conducting a one-time financial transaction without establishing a business relationship with the client, if the amount of the financial transaction is equal to or exceeds the amount specified in Part One of Article 20 of the AML/CFT Law or the client conducts several financial transactions that may be related to each other for a total amount equal to or exceeds the amount specified in Part One of Article 20 of the AML/CFT Law;

4) identifying the fact that a potential client and a client with whom a business relationship is maintained belong to the PEP category;

5) establishing business relations with the client on the basis of an agreement to accept regular payments in his favor.

The client questionnaire is maintained by the institution in electronic form.

The list of information that must be included in customer questionnaires is provided in Appendices 22-26 to the Regulations.

The institution has the right to supplement the questionnaires with additional data if necessary.

The client questionnaire must contain information obtained by the institution based on the results of the CDD (including the CDD), as well as the institution's conclusions on the risk assessment of the business relationship (financial transaction without establishing a business relationship) with the client, indicating the dates of such assessments and reassessments (in the event of a change in the risk level).

The institution enters information (data) into the questionnaire, the authenticity of which is confirmed by the relevant documents (copies) available to the institution, as well as information received from the client from official, reliable and other sources.

21. The client questionnaire is formed during the establishment of business relations with the client, but before the first financial transaction by the client. The questionnaire is supplemented with new or clarified data within 10 business days based on the results of the measures taken by the institution to update the client data. Information on the assessment/reassessment of the risk level of business relations (financial transactions without establishing business relations) with the client is indicated on the day of such assessment/reassessment (with the indication of the relevant dates of such assessment/reassessment).

22. If it is necessary to create a paper form of the questionnaire, the institution is obliged to ensure that all data from the electronic questionnaire is reflected in it.

23. The institution documents the conduct of DDC and the decisions taken by the institution in a manner that will allow demonstrating their proper implementation and justification, and retains relevant documents and/or information in the client's file for the periods specified in the AML/CFT Law .

24. The client's file may be created and stored electronically.

Appendix 2
to the Regulations on the implementation
of financial monitoring by institutions

PROCEDURE
for identification and verification of the client (client representative)

1. The institution is obliged to carry out identification and verification of the client (client's representative) taking into account the requirements of the Law on AML/CFT and the Regulation on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulation).

2. Identification and verification of the client are carried out before establishing business relations, concluding transactions, or conducting a financial transaction.

In order not to interfere with normal business practices, customer due diligence may be carried out when necessary during the establishment of a business relationship. In such cases, due diligence should be completed as soon as possible after the first contact with the customer, provided that effective ML/TF risk management is in place.

3. During identification, the institution receives the following identification data:

1) for an individual - information specified in clause 1 of part nine and clause 1 of part ten of Article 11 of the Law on AML/CFT;

2) for individual entrepreneurs - information specified in clause 2 of part nine of Article 11 of the Law on AML/CFT;

3) for a legal entity - information specified in clause 3 of part nine and clause 2 of part ten of Article 11 of the Law on AML/CFT;

4) for a trust or other similar legal entity - information specified in clause 3 of part ten of Article 11 of the AML/CFT Law;

5) for a state authority of Ukraine or a social insurance fund:

full name;

location;

details of the administrative act on the basis of which the legal entity was created (name, date of adoption/signing, number of the administrative act), except for those valid on the basis of the legislation of Ukraine;

code according to EDRPOU;

identification data of persons who have the right to dispose of the property;

6) for an international institution or organization (its representative office) in which Ukraine participates in accordance with international treaties of Ukraine, the consent to be bound by which has been granted by the Verkhovna Rada of Ukraine, as well as international treaties of Ukraine that are not subject to ratification:

date of conclusion, number, date of ratification of the agreement by Ukraine (if any);

identification data of persons who have the right to dispose of property on the territory of Ukraine;

7) for representations of institutions, bodies, offices or agencies of the European Union:

full name;

location;

information about the regulatory act and/or agreement on the basis of which such institution, body, office or agency was established;

identification data of persons who have the right to dispose of property on the territory of Ukraine;

8) for diplomatic missions of foreign states accredited in Ukraine in accordance with the established procedure:

full name;

location on the territory of Ukraine;

information about the document confirming accreditation in the territory of Ukraine;

identification data of persons who have the right to dispose of property on the territory of Ukraine;

9) for insurers (reinsurers), insurance (reinsurance) brokers in the event of insurance indemnity or insurance payment under an international compulsory civil liability insurance contract:

regarding a resident legal entity:

full name;

location;

code according to EDRPOU;

regarding a non-resident legal entity:

full name;

location.

4. When developing identification and verification procedures, the institution must be guided by a risk-based approach, adhering to the requirements and restrictions established in the Regulation, and take into account that the result of identification and verification should be:

1) unambiguous identification of the client (client representative);

2) confidence that the obtained identification data belongs to the client (client's representative);

3) belief that the client (client's representative) is not an impostor, but is indeed the person he/she claims to be.

5. The institution may carry out identification on the basis of information received from the client (client's representative), or simultaneously on the basis of documents and/or information received by the institution for the purpose of its verification.

6. The institution is obliged to carry out verification on the basis of official documents or information obtained from official sources or other reliable sources specified in Annex 1 to the Regulations. During verification, the institution must check (confirm) the identity of the relevant person.

7. Official documents must be valid (valid) at the time of submission.

8. The institution ensures verification of compliance of official documents with the requirements of the legislation of Ukraine and their validity (validity), as well as taking other measures to minimize the risk of using forgeries and documents with signs of falsification during identification and verification.

9. The institution verifies the client - an individual (including a minor) / individual entrepreneur or an individual - a representative of the client based on the identification document of its owner (unless otherwise provided for in the Regulations) regarding the following identification data:

1) surname, first name and (if any) patronymic (if, according to the customs of the national minority to which the person belongs, the surname or patronymic are not components of the name, then only the components of the name);

2) date of birth;

3) series (if available) and number of the identification document, date of issue and issuing authority;

4) citizenship (for non-residents);

5) place of residence or place of stay (for residents) / place of residence or place of temporary stay in Ukraine (for non-residents), taking into account paragraph 28 of Appendix 2 to the Regulations;

6) RNOKPP;

7) unique record number in the Unified State Demographic Register (if available).

10. If the identification document of the client (client representative) who is a resident does not contain the RNOKPP and a note or record of refusal to accept the RNOKPP, the institution additionally receives a certificate of assignment of the RNOKPP.

11. If the identification document does not contain a unique record number in the Unified State Demographic Register, the institution may not require additional documents to establish it.

12. The institution receives an identification document during the verification of a client - an individual (including a minor) / individual entrepreneur or an individual - a client representative by:

1) presentation of the original document by the owner in his personal presence (personal presence should be considered the physical presence of the person being verified in the same room with an authorized employee of the institution during the verification of his identity);

2) presentation of the original document by the owner during verification carried out by the institution in video broadcast mode in compliance with the requirements specified in Appendix 3 to the Regulations (hereinafter referred to as video verification).

The institution may also use other methods of identification and verification of representatives of a legal entity who are its signatories (included in the list of persons entitled to sign the client's settlement documents), in particular by obtaining the necessary identification data of the signatories from the client in the form of a letter/questionnaire signed by the CEP of the head of this legal entity.

13. The institution shall document the fact of the physical presence of an individual during the verification by using any of the following methods:

1) production by an authorized employee of the institution of paper copies of the original identification document (page(s) containing identification data), which are certified by the signatures of this authorized employee and the individual - the owner of the document as corresponding to the original (in addition, the date of their production is indicated on the copies);

2) making electronic copies of the original identification document (pages containing identification data), as well as taking a photo of the person with their own identification document, namely the page containing the owner's photo, with subsequent imposition of a CEP by an authorized employee of the institution and a qualified electronic time stamp on the received electronic documents;

3) reading identification data from a contactless electronic carrier implanted in the ID card, saving a protocol of the authentication performed during the reading procedure (at least passive authentication in accordance with paragraph 5.1 of Part Eleven of ICAO Doc 9303) and:

keeping a record of the fact that a person entered the correct personal identification number intended for identification and authorization of access to a contactless electronic medium (PIN1), or

photocopying of a person with their own identification document, namely the page/side containing the owner's photo, with subsequent imposition of a CEP by an authorized employee of the institution and a qualified electronic time stamp on the received electronic document containing the photo.

The institution may document the fact of reading identification data from an ID card in another way, provided that the fact of the personal presence of the owner of the identification document during the reading procedure can be proven by the institution in a manner that does not raise doubts;

4) obtaining an e-passport / e-passport for traveling abroad, certified by a qualified electronic seal of the State Enterprise "DIYA" with a corresponding qualified electronic time stamp, which will correspond to the date of verification of the person by the institution.

14. The institution verifies the minor based on the minor's birth certificate or passport for traveling abroad, or other document certifying the minor as a non-resident, submitted by his/her legal representative (one of the parents, adoptive parent or guardian).

The presence of a minor is not required in this case.

If the minor is a resident of Ukraine, the institution additionally receives a certificate of assignment of the RNOKPP to such a minor.

The institution verifies the legal representative of the minor in the manner prescribed for an individual.

15. The institution carries out verification of a minor in the manner prescribed for an individual.

16. The institution identifies the person on whose behalf or on whose behalf a business relationship is established / a financial transaction is carried out. The institution obtains the necessary identification data from official documents (their copies), in particular a power of attorney, information provided and certified by a legal representative, and from other sources. Verification of this person is carried out during his first application to the institution.

17. When concluding a contract for the provision of services for the benefit of a third party, the institution shall identify and verify the person concluding the contract. The contract shall contain all the identification data of the person for whose benefit it is concluded. The institution shall verify this person when he or she submits the first request to the institution or expresses in another way the intention to receive the relevant services.

The institution identifies and verifies the person in whose favor insurance indemnity or insurance payment is made under third party liability insurance contracts, during the insurance indemnity or insurance payment under such contracts.

18. If a person acts as a representative of another person or on behalf of or in the interests of another person, the institution is also obliged to establish the BIC of the person on behalf of or in the interests of whom the financial transaction is being conducted (if any), or to establish the beneficiary (beneficiary) of the financial transaction.

19. If its client is a nominee holder, in order to minimize ML/TF risks, the institution may decide to identify the person for whose benefit or in whose interests the financial transaction of such nominee holder is being conducted, i.e., to identify the beneficiary (beneficiary).

20. The institution establishes the following data regarding the beneficiary (beneficiary) of a financial transaction:

1) for an individual - surname, first name and (if available) patronymic, date of birth, country of citizenship and permanent place of residence;

2) for a legal entity - full name, location, date and body of registration of the legal entity, data that allows to establish the ultimate beneficial owners.

The institution establishes the beneficiary on the basis of documents and/or information provided by the person acting for the benefit or in the interests of the beneficiary, as well as from other sources if the relevant information is public (open).

21. Insurers (reinsurers), insurance (reinsurance) brokers, in order to identify the beneficiary (beneficiary) under a life insurance contract, in addition to the NPC measures, establish:

1) for beneficiaries (beneficiaries) specifically identified in the life insurance contract - the surname, first name and (if any) patronymic of the individual or the name of the legal entity, trust or other similar legal entity;

2) for beneficiaries (beneficiaries) identified by their characteristics or category (for example, husband, wife or children at the time of the insured event) or in another way (for example, by will), - information sufficient for the insurer (reinsurer), insurance (reinsurance) broker to be confident in the ability to identify the beneficiary (beneficiary) when making an insurance payment.

Insurers (reinsurers), insurance (reinsurance) brokers verify beneficiaries (beneficiaries) under a life insurance contract when making an insurance payment. In the event of the transfer of rights under life insurance contracts to third parties, the identification of new beneficiaries (beneficiaries) is carried out when such rights are transferred.

22. The institution verifies the business entity's identification data related to its state registration, based on the data contained in the Unified State Register, in particular, obtained in the form of free access through the electronic services portal.

The institution obtains the constituent documents of a legal entity by searching for them using the access code provided/entered by the client's representative.

If there are no constituent documents in the Unified State Register, the institution can obtain them in the form of a duly certified copy of the registered constituent document.

23. If a person acts as a representative of a client, the institution must verify on the basis of official documents whether this person has the appropriate powers. Documents issued in a foreign state confirming the powers of a client representative must be legalized in accordance with the established procedure, unless otherwise provided for by the legislation or an international treaty of Ukraine. Copies of these documents must be notarized.

24. If there is an agreement for access to the SEI, the institution may verify the individual entrepreneur or the representative of the client - a business entity and check whether the representative of the business entity has the appropriate powers in the following order:

1) obtaining documents for establishing business relations using information, telecommunications, information and telecommunications systems, which are signed/certified by the CEP of the client, who is an individual entrepreneur, or the CEP of an individual as a representative of the relevant business entity;

2) verification of the presence of the necessary authority of such an individual as a representative of the relevant business entity using the SEI verification subsystem;

3) establishing the fact of correspondence of the identification data contained in the SEI verification subsystem with the identification data contained in the CEP of such a person;

4) properly documenting the facts of carrying out the above-mentioned inspections.

25. When verifying a non-resident client who is a legal entity, the institution also receives a legalized extract from the trade, banking or court register or a notarized registration certificate of an authorized body of a foreign state on the registration of this legal entity.

26. When verifying a non-resident client who is a trust or other legal entity, the institution also receives a notarized copy of the document or its legalized extract on the formation (foundation) of the trust or other similar legal entity.

27. In order to establish information about the executive body (management bodies), the institution receives at least the name of the body and the surname, first name and (if any) patronymic of the persons who are members of such a body.

28. If there are no suspicions regarding the authenticity (validity) of documents and/or information, the institution may not verify the following identification data received from the client and certified by him:

1) place of residence or place of stay of an individual resident of Ukraine (place of residence or place of temporary stay of an individual non-resident in Ukraine);

2) information about the executive body (management bodies).

29. Re-identification and verification of the client (his representative) is not mandatory if this person has previously been identified and verified properly, provided that the institution has no suspicions and/or grounds to believe that the available documents, data and/or information about the client (client's representative) are invalid (invalid) and/or irrelevant.

30. The institution may also verify a client - an individual by using one of the following methods:

1) using the NBU BankID System in the following order:

obtain the identification data of such an individual using the NBU BankID System;

obtain from an individual a copy of the identification document (copies of the pages of the identification document containing identification data) on which the client's CEP is superimposed;

verify the identity data contained in the copy of the identification document, the CEP and the file received using the BankID System of the NBU from the bank that is the subscriber-identifier for their compliance;

2) by obtaining an electronic copy of the identification document, in the following order:

receive an e-passport / e-passport for traveling abroad, certified by a qualified electronic seal of the State Enterprise "DIYA" with a corresponding qualified electronic time stamp corresponding to the date of verification of the person by the institution, and:

to take a photo of a person using the method of face recognition with subsequent imposition of a CEP of an authorized employee of the institution and a qualified electronic time stamp on the received electronic document containing the photo; or

obtain a copy of the identification document or questionnaire on which the client's CEP is superimposed.

The institution may consider the verification of a client - an individual - to be completed only if it successfully checks the correspondence of the received identification data.

31. If the institution simultaneously complies with all the conditions specified in paragraph 32 of Appendix 2 to the Regulation, it may verify a client - an individual by using any of the following methods:

1) obtaining a copy of the identification document and a certificate of assignment of the RNOKPP (if there is no necessary information in the identification document), certified by the CEP of the owner of the identification document;

2) obtaining identification data through the BankID System of the NBU;

3) reading identification data from a contactless electronic carrier implanted in the ID card, saving a protocol of the authentication performed during the reading procedure (at least passive authentication in accordance with paragraph 5.1 of Part Eleven of ICAO Doc 9303) and

keeping a record of the fact that a person entered the correct personal identification number intended for identification and authorization of access to a contactless electronic medium (PIN1), or

performing a photo capture of a person using the method of recognizing the reality of a person and a person with their own identification document, namely the page/side containing the owner's photo, with subsequent imposition of a CEP by an authorized employee of the institution and a qualified electronic time stamp on the received electronic document containing the photo;

4) obtaining identification data and financial phone number from the credit history bureau (provided that the source of such data is a bank) and correct entry by the person being verified of the otp password sent by the institution to such financial phone number, and photographing the person using the method of recognizing the reality of the person and the person with their own identification document, namely the page/side containing the owner's photo, with subsequent imposition of a CEP by an authorized employee of the institution and a qualified electronic time stamp on the received electronic document containing the photo.

32. The institution may exercise the right specified in paragraph 31 of Appendix 2 to the Regulations if all of the following conditions are simultaneously met:

1) the risk of a business relationship with a client (financial transaction without establishing a business relationship) is low;

2) the total amount of all financial transactions that reduce the client's assets does not exceed 40 thousand hryvnias per month (equivalent) and 400 thousand hryvnias per year (equivalent);

3) the total amount of the institution's liabilities to the client / the client's liabilities to the institution does not exceed 40 thousand hryvnias (equivalent) (does not apply to overdue debts).

33. In the event of a transfer within Ukraine for an amount not exceeding 30 thousand hryvnias or an amount equivalent to the specified amount, including in foreign currency, the institution, while carrying out due diligence on the payer/recipient of the transfer in the cases established by the Law on AML/CFT, may, in addition to identification documents, receive other documents issued using the Unified State Demographic Register in accordance with the Law of Ukraine "On the Unified State Demographic Register and Documents Confirming Citizenship of Ukraine, Identifying a Person or Their Special Status", for the purpose of verifying the following data:

1) surname, first name and (if available) patronymic;

2) place of residence (or place of stay of a resident individual or place of temporary stay of a non-resident individual in Ukraine);

3) RNOKPP;

4) date and place of birth.

33 - 1 . In the event of payments of pensions, benefits, subsidies and other payments to the population, determined by the legislation of Ukraine (hereinafter referred to as pensions/social benefits), on the basis of agreements concluded with the bodies of the Pension Fund of Ukraine, bodies of labor and social protection of the population, relevant centers for the accrual and payment of social payments, other authorized bodies for the accrual and payment of social payments (hereinafter referred to as the authorized body), if such payments are made in the amount of from 5 thousand to 30 thousand hryvnias, the postal operator may identify and verify the client - an individual (client's representative) by comparing the data of the passport or other document proving the identity of the client (for the client's representative, also a document confirming his authority), presented by the client (client's representative), with the data specified by the authorized body in the payment documents, the form and content of which are established by the legislation of Ukraine (hereinafter referred to as the payment documents)/data specified by the client (client's representative) in the postal order form.

After the postal operator verifies the data, the client (client's representative) affixes his/her handwritten signature indicating the date of receipt of the pension/social assistance, and the postal operator employee affixes his/her handwritten signature in the relevant columns of the payment documents/postal order form.

The postal operator is obliged to store payment documents/postal transfer forms with the personal signatures of the client (client's representative) and the dates of receipt of pension/social assistance or their copies certified by an authorized employee of the postal operator, within the time limits specified by the Law on AML/CFT .

34. When carrying out customer identification, the institution is obliged to inform the customer of its obligations regarding the processing of personal data for AML/CFT purposes.

{Appendix 2 with amendments made in accordance with the Resolutions of the National Bank No. 145 of 12.11.2020 , No. 198 of 29.12.2023 }

Appendix 3
to the Regulations on the implementation
of financial monitoring by institutions

PROCEDURE
for video verification

1. Verification carried out by an institution in compliance with the requirements specified in Appendix 3 to the Regulations on the Implementation of Financial Monitoring by Institutions (hereinafter referred to as the Regulations) is equivalent to verification carried out in the personal presence of a person.

2. An employee of the institution who ensures the conduct of video verification (hereinafter referred to as the authorized employee) must be in a room during the video verification, in which conditions are provided for obtaining high-quality audiovisual information (in particular, the movement of other persons in the camera's visibility area and extraneous noise are limited).

Video verification must take place in such a way as to make it impossible for other clients of the institution or any third parties to observe this process.

3. During video verification, the exchange of audiovisual information between the authorized employee and the person being verified must take place while ensuring the integrity and confidentiality of the transmitted information.

4. The institution is obliged to obtain the clear and unambiguous consent of the person to conduct video verification before starting such a procedure (including taking a photo of the person and/or the screen with their image, and relevant documents presented by them). The video verification record must also contain the fact of providing such consent.

5. Video verification must be carried out in real time and without interruption. In case of interruption for any reason, video verification must be repeated in full.

6. The quality of audiovisual information (image and sound during video transmission) must be sufficient for unambiguous recognition of the person and the content of communication between the authorized employee and the person, as well as for checks by the authorized employee of the relevant informative and protective elements of the image of documents containing the person's identification data (in particular, a protective grid, microtext).

7. When developing the procedure for conducting video verification, the institution must provide for different communication options between the authorized employee and the person, which must differ at least in the sequence and/or list of questions.

The recording of the video verification process must contain a part where the person being verified voices information about the number and series (if any) of the identification document and the contact phone number for communication with the institution (financial phone number).

8. During video verification, the institution shall take photos of:

1) the person whose verification is being carried out;

2) individuals with their own identification document, namely the page/side containing the owner's photo.

Photographic recording is provided by the institution in such a way that the photographic images allow for the unambiguous recognition of the person and the details of the identification document (in particular, the photo, identification data contained on such a page of the identification document).

9. The institution ensures that at least the following checks of the identification document are carried out during video verification (in particular, through the use of special software modules):

1) for signs of damage, forgery (in particular, that no photo has been pasted into this document, that the relevant elements, text, character size and spacing are properly placed);

2) the belonging of the provided document to the individual whose verification is being carried out (visual verification of the correspondence of the person's face);

3) logical checks of the information contained in a document of this type in order to detect signs of forgery (in particular, the date of issue of the document, the date of its expiration, the authority that issued the document, machine-readable information);

4) make sure that the provided document contains those security features that a document of this type should have and that can be detected during visual inspection in natural light, and then verify these security features.

In order to verify the security elements of the document (including optically variable ink, 3D effect, animation effect, holographic tape), the authorized employee provides appropriate instructions to the person being verified on performing additional actions with the document in front of the camera (including rotating the document at different angles horizontally and vertically).

10. The institution has the right not to check the security features of the identification document during video verification if the institution:

1) a procedure for reading the person's identification data from a contactless electronic medium implanted in this document is provided and at least their passive authentication is carried out in accordance with paragraph 5.1 of Part Eleven of ICAO Doc 9303, with the preservation of the protocol of the passive authentication carried out.

The institution independently determines the software/hardware tools used to remotely read the identity data of a person and perform their passive authentication. The institution is obliged to provide a secure data exchange channel between the specified software/hardware tools and the computer of the authorized employee of the institution during the reading of the identity data; or

2) an e-passport / e-passport for traveling abroad has been received, certified by a qualified electronic seal of the State Enterprise "DIYA" with a corresponding qualified electronic time stamp, which will correspond to the date of verification of the person by the institution.

11. The institution shall independently, in its internal documents on AML/CFT issues, determine the list of identification documents accepted by the institution for verification of a person during video verification. The institution shall determine such a list on the basis of a risk-based approach, taking into account the availability of appropriate own resources and means (including software) for checking the relevant types of documents for signs that may indicate their possible forgery or falsification.

12. If the above-mentioned list of identification documents of the institution includes documents that are made in the form of a booklet and do not contain a contactless electronic medium, then the institution shall additionally ensure the implementation of measures that will minimize the risks of ML/TF, and at least one of the following measures:

1) obtaining information regarding a person's identification data through the BankID System of the NBU and ensuring the comparison (matching) of this data;

2) receiving from the person being verified other document(s) certifying his/her identity, which the institution may check for signs of damage, forgery and to ensure data matching (comparison);

3) obtaining identification data, financial phone number from the credit history bureau (provided that the source of such data is the bank) and correct entry by the person being verified of the otp password sent by the institution to such financial phone number.

The institution may not take the measures specified in paragraph 12 of Appendix 3 to the Regulations if it has ensured successful verification of the identity of the person's identification data using the data contained in the qualified electronic signature with which the client (client's representative) signed the document on establishing business relations with the institution (in particular, the institution's questionnaire, another document submitted by the client or his representative to the institution prior to establishing business relations).

13. When conducting video verification, the authorized employee must ensure that there are no signs of pressure/influence on the person being verified by a third party. If there are signs of such pressure, the authorized employee must question the person in more detail about the purpose of establishing a business relationship in order to reduce the risk of further fraudulent actions using social engineering.

14. If there are signs of suspicious behavior of the person being verified, the authorized employee must ask additional (including indirect) questions to verify his/her own identification data.

15. Other information necessary for the institution to carry out the CDP can be obtained by the institution:

1) from the client's words (obtaining answers to the authorized employee's questions) during video verification;

2) in the form of a completed institution questionnaire signed by the client's CEP (client's representative);

3) from a questionnaire previously filled out by the client on the institution's website or application. In this case, the institution shall properly document the fact that the client has provided the relevant information.

16. When developing the procedure for performing video verification, the institution must provide for the final stage of the correct entry by the person being verified of the OTP password, which the institution sends to this person to the financial phone number announced during video verification.

17. The institution ensures the protection of information received/created by it during video verification of the client (client's representative), in accordance with the requirements of the legislation of Ukraine in the field of information protection.

18. The institution may not use the results of video verification in the following cases:

1) if the video verification process performed does not meet the requirements established in the Regulations;

2) the presence of doubts regarding the validity (validity) of the person's identification document that have not been refuted;

3) there are signs that the client (client's representative) is being influenced by a third party.

19. The institution is obliged to document each stage of video verification and record the results of all checks provided for in the Regulations and internal documents of the institution on AML/CFT issues, carried out by an authorized employee and/or by the institution's software.

The institution is obliged to process, store, and transmit electronic documents in a manner that ensures the impossibility of their modification, as well as ensure their backup storage and protection against loss, destruction, and illegal processing in accordance with the requirements of the regulatory legal acts of the National Bank.

20. An authorized employee of the institution imposes a CEP on the electronic copies of documents received from the client (client's representative), on the basis of which video verification of his identity was carried out.

21. All documents and information regarding the video verification process, in particular files recording the video verification process, electronic documents received by the institution from the client (client representative), other documents recording the facts of conducting relevant inspections provided for in the Regulations and internal documents of the institution on AML/CFT issues, are stored in the client's file for the periods specified by the legislation of Ukraine.

22. The institution ensures that authorized employees, before starting to perform their duties related to ensuring the video verification process, undergo appropriate training and receive appropriate training for conducting video verification.

Appendix 4
to the Regulations on the implementation
of financial monitoring by institutions

ESTABLISHMENT
of ultimate beneficial owners

1. When implementing the NPC, the institution is obliged to:

1) establish the client's CBI or the fact of his/her absence, including obtaining the ownership structure of the legal entity in order to understand it;

2) establish data that allows establishing the KBV [surname, first name and (if available) patronymic, country of citizenship and permanent residence, date of birth, nature and measure (level, degree, share) of beneficial ownership (benefit, interest, influence)];

3) take measures to verify the identity of the CBV (if there is a CBV).

2. For the purpose of establishing a CBV, the institution is obliged to:

1) request and obtain from a client - a legal entity the ownership structure of such client;

2) establish, with respect to a trust or other similar legal entity, information about the founders, trustees, protectors (if any), beneficiaries (beneficiaries) or group of beneficiaries (beneficiaries), as well as about any other natural persons who exercise decisive influence over the activities of the trust or other similar legal entity (including through the chain of control/ownership).

With respect to trusts and other similar legal entities whose beneficiaries (beneficiaries) are characterized by certain characteristics or class, information shall be established about such beneficiaries (beneficiaries) that would allow their identity to be established at the time of payment or exercise of their rights;

3) take appropriate measures to verify the accuracy of information about the CCP and ensure that the institution knows who the CCP is (if any), taking reasonable steps to understand ownership (control) and ownership structure.

2 - 1. The institution, within five business days from the date of receipt of the ownership structure/information on the CBV, the data on which are established based on the results of the NPC, checks the received ownership structure/information on the CBV for the presence/absence of discrepancies with the information on the CBV/ownership structure of such a client, placed in the Unified State Register, and enters the relevant information on the identified discrepancies into the client questionnaire/Lists of clients.

3. To establish and verify the identity of the CBV, the institution has the right to use data contained in official documents, official and/or other open sources, in particular in foreign state registers similar to the Unified State Register. The institution may also use information received from the client, taking the necessary measures to verify the information received using other sources.

4. When establishing a client's creditworthiness, an institution should not rely solely on the Unified State Register of Financial Institutions, except in cases directly specified in the Regulations on the Implementation of Financial Monitoring by Institutions.

5. The institution shall implement the requirements for establishing a CCP using a risk-based approach, taking into account the identified risk criteria. At the same time, the extent of the institution’s activities to collect the necessary information and the depth of the analysis of the information obtained shall be proportionate to the identified risks, in particular the complexity of the ownership structure of the legal entity. In any case, the institution shall take measures sufficient to be confident that it knows who the CCP is (or that there is no CCP) and to obtain an understanding of the ownership (control) and ownership structure.

6. The institution may establish the fact that clients who are issuers that, in accordance with the legislation or the terms of public placement of shares on internationally recognized exchanges, are obliged to publicly disclose information about the CBV, or are subsidiaries or representative offices of such issuers, have no CBV.

7. In the event of establishing a business relationship (conducting a financial transaction without establishing a business relationship) with a client who is an individual or an individual entrepreneur, the institution may consider that such a client does not have a CBV, except in cases where the institution suspects or has sufficient grounds for suspicion (in particular, in the event of identifying relevant risk criteria or indicators of suspicious financial transactions) that such a client is not acting on his own behalf.

{Appendix 4 with amendments made in accordance with the Resolution of the National Bank No. 121 of 05.10.2024 }

Appendix 5
to the Regulations on the implementation
of financial monitoring by institutions

SIMPLIFIED
customer due diligence measures

1. The institution has the right to carry out SZNP in relation to clients with whom the risk of business relationships (the risk of a financial transaction without establishing a business relationship) is low.

2. When making a decision to implement a CSD, the institution must ensure that the risk of the business relationship with the client (the risk of a financial transaction without establishing a business relationship) is low.

3. In the event of the formation of separate group risk profiles of a low risk level in accordance with the procedure specified in Section IV of the Regulations on the Implementation of Financial Monitoring by Institutions (hereinafter referred to as the Regulations), the institution may determine the relevant SZNPs that it will apply to such categories of clients.

4. When determining the categories of clients belonging to low-risk risk profiles, the institution shall take into account the typological studies of the AML/CFT MSA, the results of the national risk assessment, as well as the recommendations of the National Bank. Such categories of clients may include, in particular:

1) individuals who make regular payments for housing and communal services for insignificant amounts;

2) association of co-owners of an apartment building;

3) issuers that, in accordance with the legislation or the terms of public placement of shares on internationally recognized exchanges, are obliged to publicly disclose information about the CBV, or are subsidiaries or representative offices of such issuers;

4) housing and communal services enterprises, providers of Internet access and television services, with which institutions conclude agreements on accepting regular payments from individuals for insignificant amounts, provided that such agreements provide for non-cash transfer of the received funds exclusively to the client's account opened in the bank;

5) state authorities of Ukraine, social insurance funds, local self-government bodies;

6) international institutions or organizations in which Ukraine participates in accordance with international treaties of Ukraine, the binding consent of which has been granted by the Verkhovna Rada of Ukraine;

7) institutions, bodies, offices or agencies of the European Union;

8) diplomatic missions of a foreign member state of the Organization for Economic Cooperation and Development, accredited in Ukraine in accordance with the established procedure.

5. The following measures may be understood as SZNP, in particular:

1) reducing the frequency and scope of activities to monitor business relationships and collect additional information regarding business relationships;

2) use of simplified verification models taking into account the requirements and restrictions specified in Appendix 2 to the Regulations;

3) reducing the amount of additional information required / list of sufficient sources of information, in particular, to establish (understand) the purpose and nature of business relationships / financial transactions, taking into account the specifics of the relevant product/service that limit their use for ML/TF purposes;

4) use of information from the Unified Register of Accounts as a sufficient source for establishing the CDD when implementing CDD measures in relation to the categories of clients defined in subparagraph 4 of paragraph 4 of Appendix 5 to the Regulations.

6. The above list of SNPs is not exhaustive. The institution, taking into account the risk-based approach, independently develops, updates and applies SNPs, adhering to the requirements and restrictions established in the Regulation.

7. The institution shall take the measures provided for in subparagraphs 1-3 of paragraph 5 of Appendix 5 to the Regulations in relation to clients:

1) individuals who carry out ordinary financial transactions for amounts and in volumes that are rationally justified, taking into account the risk profile of such individuals, and whose business relationships are not subject to risk criteria, and whose financial transactions do not contain indicators of suspicious financial transactions identified by the institution;

2) business entities conducting ordinary business activities, paying taxes, in respect of which the institution has no suspicions of ML/TF, business relations with which are not subject to risk criteria, and whose financial transactions do not contain indicators of suspicious financial transactions identified by the institution.

8. In the event of implementing the SZNP and the measures specified in paragraph 7 of Appendix 5 to the Regulation, the institution is obliged to monitor the client's business relationships and financial transactions carried out in the course of such relationships, sufficient to be able to identify risk criteria and/or indicators of suspicious financial transactions inherent in the relevant business relationship (financial transaction without establishing a business relationship) with the client, and, in particular, financial transactions that do not correspond to the financial condition and/or content of the client's activities.

9. The institution shall not have the right to take the SZNP and the measures specified in paragraph 7 of Appendix 5 to the Regulation if there are suspicions, as well as if the business relationship (financial transaction without establishing a business relationship) with the client is characterized by relevant risk criteria and/or indicators of suspicious financial transactions. In such a case, the institution shall be obliged to reassess the risk of the business relationship (financial transaction without establishing a business relationship) with the client and take CDD measures proportionate to such risk.

Appendix 6
to the Regulations on the implementation
of financial monitoring by institutions

ENHANCED
customer due diligence measures

1. The institution is obliged to carry out CDD for customers with whom the risk of business relationships (the risk of a financial transaction without establishing a business relationship) is high.

2. PZNP are carried out by the institution before establishing a business relationship with the client (conducting a financial transaction without establishing a business relationship) during monitoring of the client's business relationship and financial transactions carried out in the course of such relationship, and updating the institution's data on the client.

3. The institution shall carry out the CDD in order to minimize the identified risks inherent in the business relationship (financial transaction without establishing a business relationship) with the client, in particular by:

1) increasing the frequency and scope of actions to monitor business relationships and financial transactions of the client carried out in the course of such relationships;

2) collecting additional information about the client and business relations with him.

4. When implementing the CDD, the institution shall choose the type of measure to be taken depending on the identified risks inherent in the business relationship (financial transaction without establishing a business relationship) with the client and what is proportionate to such risks. Such measures may, in particular, include:

1) identification of persons who exercise direct and/or indirect decisive influence by owning a share of less than 25 percent of the authorized (shared) capital or voting rights of a legal entity;

2) obtaining additional information about the client by searching for information about him in open sources (for example, official sources, public registers, websites of authoritative publications);

3) clarifying the reasons and circumstances of the client's use of a complex ownership structure and/or registration in a certain state (jurisdiction);

4) ascertaining the sources of wealth and/or sources of funds related to financial transactions of the client/client's CBI;

5) increasing the frequency of the institution's actions to update client data;

6) checking the availability/validity of licenses, permits or the availability of information about the client in relevant registers, if this is mandatory in accordance with the requirements of the law for the client to carry out the relevant activity;

7) obtaining more detailed information regarding the purpose and nature of establishing a business relationship, in particular if the client is a non-resident;

8) search for information in open sources regarding the presence of criminal proceedings against the client, his representatives, and the CBV;

9) increasing the number and frequency of appropriate checks regarding the client's financial transactions;

10) ascertaining whether the client has legal and economic ties with other clients of the institution (including clients who share a common CBO/manager/representative with the client) and their nature/role in such a group;

11) a visit by an employee of the institution to the client at his/her location in order to clarify the correspondence of the information provided by the client to the institution regarding the performance of the relevant type of activity by him/her to the real situation;

12) establishing certain restrictions/limits on the client's use of the institution's service/product [in particular, regarding the volume of activities, amounts of financial transactions, countries (jurisdictions), counterparties];

13) establishing a mandatory requirement to obtain supporting documents/information regarding individual financial transactions before the client conducts such financial transactions;

14) obtaining permission from the manager to establish (maintain) business relations (conducting a one-time financial transaction for a significant amount without establishing business relations) with the client;

15) obtaining additional permission from an authorized employee of the institution / head of the institution to conduct individual financial transactions within the framework of established business relationships;

16) implementation of identification and verification of the CBI (if any) of the beneficiary (beneficiary) during insurance payments under a life insurance contract, which fell under the ML/TF risk criteria, as a result of which the institution established a high risk of business relations (financial transaction without establishing a business relationship) with the client.

5. The list specified in paragraph 4 of Appendix 6 to the Regulations is not exhaustive. The institution independently determines the types of measures required to be taken by the institution and the amount of additional information required to implement the PZNP.

6. The institution should increase the degree and nature of monitoring of business relationships with the customer in order to determine whether the customer's financial transactions or actions are suspicious, in case of detection of financial transactions that meet at least one of the following signs:

1) are complex financial transactions;

2) are unusually large financial transactions;

3) conducted in an unusual manner;

4) have no obvious economic or legitimate purpose;

5) do not correspond to the information regarding the client's planned activities using the institution's services, received by the institution from the client when establishing the purpose and nature of the business relationship with him.

7. In the event that an institution identifies financial transactions (their aggregate) that are unusually large financial transactions for a client in accordance with the information available to the institution about his financial condition, the institution, taking into account risk-based approaches, must take measures to clarify the sources of funds related to such financial transactions, sufficient to determine the presence/absence of the client's rationally justified financial capabilities to carry out such financial transactions.

8. The institution shall document the conduct of the DRM and the decisions made in a manner that will enable it to demonstrate their proper implementation and justification, and shall retain relevant documents and/or information in the client's file for the periods specified in the AML/CFT Law .

Appendix 7
to the Regulations on the implementation
of financial monitoring by institutions

MEASURES
regarding non-profit organizations

1. The institution is obliged to take measures regarding non-profit organizations, including charities, to minimize the risk of being used for ML/TF purposes.

2. Risk mitigation measures should be proportionate to the ML/TF risk of a business relationship (financial transaction without establishing a business relationship) with a non-profit organization, taking into account the risk criteria identified by the institution, as well as indicators of suspicious financial transactions.

3. When conducting due diligence on a non-profit organization, the institution must understand the essence of its activities, adjusting the depth of the analysis using a risk-based approach and focusing its attention on the following aspects of the non-profit organization's activities:

1) its main purpose (mission) of creation and activity;

2) the founders of the organization;

3) the organization's assets;

4) the main sources of funds and types of donors/persons transferring funds to its benefit;

5) types of its main expenses and the proportion of items for the maintenance of a non-profit organization in such expenses;

6) types of its beneficiaries - recipients of funds;

7) scale of activity (domestic or international);

8) methods of finding donors;

9) the organization's existing achievements, in particular completed (implemented) projects/programs;

10) transparency of the mechanisms for distributing funds and channels for transferring funds to beneficiaries;

11) targeted use of funds;

12) the share of cash in the organization's revenues/expenditures (its rationality);

13) compliance of the volume of information about the organization's activities in open sources with the volume of activities of such an organization, etc.

Appendix 8
to the Regulations on the implementation
of financial monitoring by institutions

ADDITIONAL MEASURES
regarding clients who (whose CCPs) are politically exposed persons, their family members and persons associated with politically exposed persons

1. During due diligence, the institution must additionally take the measures specified in Part Fourteen of Article 11 of the AML/CFT Law in relation to PEPs.

2. The institution must develop internal procedures to identify whether a potential client and a client with whom a business relationship is maintained belong to the PEP category.

3. The institution, using a risk-based approach, develops internal procedures regarding the specifics of working with PEPs, in particular:

1) regarding the identification of the fact that the client belongs to the PEP category, as well as the beneficiary (beneficiary) under his life insurance contract or the CBP of such beneficiary (beneficiary) to a politically exposed person (an individual who is a national, foreign public figure and a figure who performs public functions in international organizations):

types of information sources used by the institution to establish whether clients are PEPs, as well as the beneficiary (beneficiary) under its life insurance contract or the CBI of such beneficiary (beneficiary) to a politically exposed person;

the number of information sources (their combinations) used by the institution for the relevant categories of clients;

procedure for verification of the information received by the institution;

the procedure for identifying PEPs in the existing client base, including the timing and frequency of screening procedures, including analysis of the institution's databases using automated software modules (if available), and documentation of their results;

2) regarding taking measures against clients who belong to the PEPs category or whose beneficiaries (beneficiaries) under life insurance contracts or the CCPs of the beneficiaries (beneficiaries) under life insurance contracts are politically exposed persons:

the procedure for obtaining permission from the head of the institution for clients belonging to the PEPs category (which heads of the institution have the right to grant such permission and in which cases, the escalation procedure), for establishing (continuing) business relationships, conducting (without establishing business relationships) financial transactions for an amount equal to or exceeding the amount specified in part one of Article 20 of the Law on AML/CFT (regardless of whether such a financial transaction is conducted at once or as several financial transactions that may be interconnected);

the procedure for informing the head of the institution before making an insurance payment under a life insurance contract, if the beneficiary (beneficiary) or his/her CCP is a politically exposed person (which employees of the institution inform and in which cases, the escalation procedure);

the procedure for establishing sources of wealth (wealth) and sources of funds related to financial transactions, and the conditions under which they are sufficient;

the procedure for conducting in-depth monitoring of business relationships with PEPs or with clients whose beneficiaries (beneficiaries) or their CCPs under insurance contracts are politically exposed persons.

4. The institution shall properly document all developed procedures in the institution's internal AML/CFT documents.

5. If a politically exposed person has ceased to perform prominent public functions, the institution shall be obliged to continue to take into account its ongoing risks for at least 12 months and to take measures specified in paragraphs 2-4 of part fourteen of Article 11 of the AML/CFT Law towards persons who (whose PEPs) are politically exposed persons, their family members and persons associated with politically exposed persons, until it is satisfied that such risks no longer exist.

At the same time, the institution must take into account the risks that remain inherent to a politically exposed person, in particular:

1) the level of influence that the person may still have;

2) the scope of the powers with which it was vested;

3) the relationship between past and current powers.

5 - 1. The institution shall not take (cease to take) the measures specified in paragraphs 2-4 of part fourteen of Article 11 of the Law on AML/CFT in relation to a politically exposed person, his/her family members and persons associated with him/her if the conditions specified in paragraphs fifteen and sixteen of part fourteen of Article 11 of the Law on AML/CFT are met.

In order to make a decision on the termination of the measures specified in paragraphs 2-4 of part fourteen of Article 11 of the Law on AML/CFT, in relation to a politically exposed person, his/her family members and persons related to him/her, the institution shall analyze the financial transactions of the politically exposed person, his/her family members and persons related to him/her from the date of termination of the performance of prominent public functions by the politically exposed person in accordance with the procedure specified in the internal documents of the institution on AML/CFT.

The specified procedure must at least include:

1) terms of conducting the analysis of financial transactions;

2) the procedure for assessing the risk of financial transactions carried out by a politically exposed person, members of his family and persons related to him;

3) the procedure for identifying signs that business relations with a politically exposed person contain risks inherent to politically exposed persons;

4) the procedure for identifying signs that business relationships with family members of a politically exposed person and persons associated with them pose risks.

Based on the results of such analysis, the institution documents the decision made and brings it to the attention of the head of the institution or a person authorized by him.

When servicing a politically exposed person, his/her family members and persons related to him/her, in respect of whom the institution has ceased to take measures specified in paragraphs 2-4 of part fourteen of Article 11 of the Law on AML/CFT, the institution shall continue to carry out CDD in accordance with the procedure specified in the Law on AML/CFT, these Regulations and the institution's internal documents on AML/CFT.

6. In order to determine whether a client is a PEP, the institution is required to use not only the information provided by the client, but also other sources of information if the level of risk of the business relationship (one-off financial transaction for a significant amount) with the client is higher than low. Such sources may, for example, be:

1) databases of service providers that provide free or paid information services;

2) public data sources on the Internet, including official Internet representations of state authorities;

3) official online representations of income declaration systems by public figures, including the Unified State Register of Declarations of Persons Authorized to Perform State or Local Government Functions.

However, the institution should take into account that if information about the relevant person is not available in a separate database, this does not constitute confirmation that the person does not belong to the PEP category.

6 - 1. The institution, if necessary, sends a request to a national public figure regarding the performance (cessation of performance) of prominent public functions by the national public figure.

The institution shall submit such a request in the form and manner specified in the institution's internal documents on AML/CFT issues.

The institution ensures verification of information on the performance (cessation of performance) of prominent public functions by a national public figure, received from such a person at the institution's request, in accordance with the procedure specified in the institution's internal documents on AML/CFT issues.

7. When carrying out procedures to update existing client data, the institution shall also update the client's PEP status. In addition, the institution shall periodically, on the basis of a risk-based approach, analyze the existing client base for PEP status, but not less frequently than:

1) once every six months - if the level of risk of business relations (one-time financial transaction for a significant amount) with the client is high;

2) once a year - if the level of risk of business relations (one-time financial transaction for a significant amount) with the client is average;

3) once every three years - for other cases.

8. The procedure for obtaining permission from the head of an institution to establish (continue) business relations / conduct a one-time financial transaction for a significant amount must include:

1) delegating to relevant officials from the list of heads of the institution the right to grant such permission in clearly defined cases depending on the size, structure and specifics of the institution's activities.

When developing this procedure, the institution should take into account that the purpose of such permission is to obtain a considered decision by the manager regarding the ability to manage the risks inherent in the client, who has a comprehensive understanding of the potential and existing ML/TF risks and the risk profile of a specific client, as well as the requirements of the institution's internal documents on ML/TF issues. The delegation system should be built on the principle: the higher the risk of a business relationship / one-time financial transaction for a significant amount, the higher the position of the institution's manager should grant permission;

2) a list of information about the client and the risk of business relations with him/her/a one-time financial transaction for a significant amount, which should contain a document provided to the manager for permission, sufficient for the manager to comprehensively understand the inherent risks and subsequently make a balanced decision;

3) the procedure for preparing such a document (which unit prepares it and which employees of the institution are authorized to approve such a document / provide their alternative point of view, if any);

4) the procedure for documenting this procedure by the institution.

9. When establishing the sources of wealth and the source of funds related to the financial transactions of PEPs, the institution uses a risk-based approach to determine the necessary detail and depth of analysis, the number of sources of information that will be used to obtain and/or verify the information obtained.

10. Institutional staff, when establishing the sources of wealth and sources of funds associated with the financial transactions of PEPs, should focus on the presence/absence of logical explanations for their accumulation from the point of view of legality.

11. The institution should pay significant attention to the training of its staff to prevent cases where employees of the institution mistakenly assume that PEP status in itself is a rational and logical explanation for the presence of significant assets (wealth) in such an individual due to his access to significant funds (assets) in connection with the performance of public functions.

12. The term “size/value of the total assets (wealth) of the person and the history of their accumulation” does not mean that the institution establishes a complete list of them, their exact value and the dates of occurrence of certain events. Thanks to the understanding gained about the size/value of the total assets (wealth) of the person and the history of their accumulation, the institution should properly assess the risk of business relationships / conducting a one-time financial transaction for a significant amount with the PEP, taking into account the risks inherent to such an individual, and form its expectations regarding the potential volume of financial transactions that can be rationally explained and will correspond to the risk profile of the PEP, including the information available to the institution.

13. The institution, analyzing the history of wealth accumulation, should form a general understanding of its origin, for example, through inheritance, hired labor, business, and investment.

14. To establish the sources of wealth and the source of funds related to financial transactions, an institution may use official documents, public information, information received from the client, information available to the institution in connection with servicing its financial transactions in the past, and from other sources.

15. In the event of a high level of risk of business relations with a PEP / one-time financial transaction for a significant amount, the institution must take measures to verify the information received from the client. The institution may verify information only in relation to individual sources of wealth, giving priority to sources of wealth with the highest specific weight.

16. The institution may not take measures to establish the sources of wealth and the source of funds related to the financial transactions of a PEP if the following conditions are simultaneously met:

1) the risk level of business relationships with the client / one-time financial transaction for a significant amount is low;

2) the institution is not suspected of ML/TF;

3) the volume of financial transactions carried out by the PEP through the institution does not exceed 400 thousand hryvnias (equivalent) per month.

16 - 1. The institution must ensure the proper application of a risk-based approach to establishing business relationships/serving clients who are PEPs, in order to assign them a reasonable level of risk, to prevent such clients from being unjustifiably refused to conduct financial transactions and/or establish (continue) business relationships.

The institution is liable for improper application of a risk-based approach to clients who are PEPs, including imposing an unreasonable level of risk on them and/or taking disproportionate measures against them in accordance with the risk category.

17. The institution shall, using a risk-based approach, conduct on an ongoing basis in-depth monitoring of business relationships with PEPs, including financial transactions carried out in the course of such business relationships. When designing its internal procedures, the institution shall take into account that the purpose of such in-depth monitoring is for the institution to promptly identify:

1) financial transactions containing indicators of suspicious financial transactions;

2) financial transactions that do not correspond to the client's risk profile and/or the institution's expectations regarding the volume of financial transactions, which can be rationally explained given the information available to the institution about the client;

3) new material circumstances and events regarding the PEP that may significantly affect the level of risk of business relationships with him.

18. In the event of a refusal to establish (maintain) business relations and/or conduct a financial transaction with a client who is a PEP in cases specified in Article 15 of the AML/CFT Law, the institution is obliged, within five business days from the date of the refusal, to provide such client with an explanation justifying the reason for the refusal in written (electronic) form. Such an explanation is provided to the client with a handwritten signature/with the imposition of a CEP of the head of the institution.

The institution determines the procedure for refusing to establish (maintain) business relations and/or conduct a financial transaction with a client who is a PEP, and providing an explanation in the institution's internal documents on AML/CFT issues.

In cases where a client who is a PEP refuses to establish (maintain) business relations and/or conduct a financial transaction, the institution draws up a conclusion with justification, which is signed by the head of the institution with the mandatory approval of the responsible employee of the institution.

{Appendix 8 with amendments made in accordance with the Resolutions of the National Bank No. 108 of 05.09.2023 , No. 198 of 29.12.2023 }

Appendix 9
to the Regulations on the implementation
of financial monitoring by institutions

USE OF AGENTS

1. The institution has the right to instruct agents, on the basis of a contract, to carry out identification and verification of clients (client representatives).

2. Such agents may be:

1) legal entities (residents and non-residents);

2) individual entrepreneur;

3) resident individuals.

3. Agents identify and verify clients (client representatives) of the institution in accordance with the procedure specified by the institution's internal documents on AML/CFT issues, taking into account the requirements and restrictions established by the Law on AML/CFT and the Regulation on Financial Monitoring by Institutions.

4. The institution is responsible for identifying and verifying its clients (client representatives) in accordance with the requirements of Ukrainian legislation in the field of AML/CFT, regardless of its use/non-use of agents for identification and verification.

5. An institution using an agent is obliged to obtain the necessary information from him before establishing a business relationship (conducting a financial transaction without establishing a business relationship) with the client.

6. The institution makes decisions on establishing business relations (conducting a financial transaction without establishing business relations) with the client, concluding relevant agreements, as well as on refusing to establish business relations / conduct financial transactions.

7. Before making a decision on cooperation with a relevant agent, the institution must conduct a preliminary analysis of its reliability in accordance with the procedure specified in the institution's internal documents on AML/CFT issues. The purpose of such analysis is to identify and assess by the institution the risks associated with future cooperation, namely the institution's ability to comply with the legislation of Ukraine in the field of AML/CFT using such an agent.

8. When conducting an agent reliability analysis, the institution should, in particular, determine the following:

1) presence/absence of an agent or manager of an agent - a legal entity on the list of terrorists, the sanctions list of the National Security and Defense Council;

2) presence/absence of a criminal record of an individual - agent (including an individual entrepreneur) or the manager of an agent - legal entity, which has not been extinguished and has not been removed in accordance with the procedure established by law, for crimes provided for in Sections VI , VII , XVII of the Special Part of the Criminal Code of Ukraine;

3) the presence/absence of restrictions/prohibitions on the agent's right to engage in certain activities pursuant to a pending court sentence, pending the expungement or removal of the criminal record;

4) whether the agent (legal entity or individual entrepreneur) is in the process of liquidation (cessation of activity) and/or whether bankruptcy proceedings have been initiated against it;

5) whether the relevant individual - agent (including an individual entrepreneur) / manager of an agent - legal entity was/is dismissed under Articles 40 ( paragraphs 7 , 8 of part one of this article), 41 (except for paragraphs 4, 5 of part one of this article) of the Labor Code of Ukraine (within the last five years);

6) whether the person has been the subject of measures of influence for violating the requirements of the legislation of Ukraine in the field of AML/CFT by the body supervising its activities in the field of AML/CFT, and/or the subject of an investigation on ML/CFT issues, for at least the last seven years;

7) presence/absence of other negative information in open sources regarding such an agent.

To conduct the analysis, the institution obtains relevant information from official sources, open sources, as well as documents/information provided by the agent.

9. Based on the results of the analysis, the institution draws up a reasoned conclusion on the possibility of cooperation with the relevant agent, taking into account the identified risks and their acceptability/unacceptability for the institution, which is signed by the responsible employee of the institution. Permission to cooperate with the agent is granted by the executive body (if the executive body is collegial) / the head of the institution by imposing a relevant resolution on the conclusion or by a specially created separate committee or a committee already operating in the institution by adopting a relevant decision.

10. In the event of a decision to cooperate with a relevant agent, the institution shall conclude a written agreement with this agent, which shall contain, in particular, the following provisions:

1) the agent's obligation to transfer to the institution all information/documents (including their copies) relating to the identification and verification of clients (client representatives), the identification and verification of which was provided by such agent;

2) the procedure and terms for the agent to provide the institution with relevant information and documents;

3) the agent's obligation to ensure the protection of restricted information, including personal data of clients, and the agent's liability for their disclosure in accordance with the legislation of Ukraine;

4) the agent's obligation to ensure the technical capability to perform identification and verification at the appropriate level (in particular, the availability of computer equipment, appropriate software, communication facilities, and the security of electronic systems);

5) the rights of the parties to refuse cooperation, including cases in which the institution has the right to terminate the contract unilaterally (in particular, if the institution establishes the facts of the agent's submission of inaccurate or incomplete information during its analysis of the agent's reliability).

11. The institution shall constantly ensure that training events are held for agents (their employees) in order to maintain an appropriate level of their knowledge regarding the requirements for the procedure for identifying and verifying clients (client representatives) of the institution in accordance with the institution's internal documents on AML/CFT issues. The institution shall ensure that the fact of holding training events, their content and the list of agents (their employees) who have undergone the relevant training are documented.

12. The institution is obliged to familiarize agents (their employees) with the requirements of the institution's internal documents on AML/CFT issues, relating to the identification and verification of clients (client representatives) of the institution, in the following order:

1) before the agent (its employees) begin to perform their duties;

2) no later than five business days from the date of approval, amendments to the institution's internal documents on AML/CFT issues relating to identification and verification procedures.

13. The institution ensures control over compliance by agents with the requirements of the institution's internal documents on AML/CFT issues regarding identification and verification, in particular by conducting periodic inspections.

14. The institution shall develop a procedure and order for terminating cooperation with agents in the event of the discovery of facts/occurrence of events that increase the institution's risks in the field of AML/CFT, in particular in the event of the institution discovering facts of violations by the agent of the terms of the contract/improper performance by the agent (its employees) of duties related to the identification and verification of clients (client representatives) of the institution.

15. The responsible employee of the institution ensures that an up-to-date list of agents with whom the institution cooperates is maintained.

16. The institution ensures the posting on the official website of the institution of an up-to-date list of agents with whom it cooperates.

Appendix 10
to the Regulations on the implementation
of financial monitoring by institutions

CUSTOMER DUE DILIGENCE INFORMATION OBTAINED FROM A THIRD PARTY

1. The institution has the right to use the laying tool when carrying out the NPC.

2. The institution is always responsible for implementing CDD in accordance with the requirements of Ukrainian legislation in the field of AML/CFT, regardless of its use/non-use of the deposit tool during the implementation of CDD.

3. The institution, using the deposit tool, has the right to receive and use information about:

1) identification and verification of clients;

2) establishing the client's creditworthiness and taking measures to verify their identity;

3) the purpose and nature of the future business relationship with the client.

4. When carrying out the NCP, an institution may use the deposit tool if the following conditions are met:

1) a third party providing relevant information about the NPC to an institution is a person who:

is a PFMS in accordance with the requirements of the AML/CFT Law or an obliged entity in accordance with the legislation of the country of registration and takes similar measures in the field of AML/CFT, with the exception of persons registered and/or licensed in a country that is included in the list of countries that do not comply with the FATF recommendations, or is a shell bank or shell company;

maintains business relations with the client, information about which is provided to the institution, and carries out CDD measures in relation to such client, acting on its own behalf (does not use the entrustment tool itself in such cases);

is designated by the institution as a reliable person for cooperation and use of the deposit instrument;

2) the institution has a contract concluded with a third party, according to which the third party is obliged to:

provide relevant information regarding the NPC within the deadlines set by the institution;

provide relevant information on the PPC to the institution only if the PPC was carried out by a third party without the use of a laying tool (prohibition on the laying chain);

provide, at the request of the institution (if necessary), within the time limits set by the institution, copies of relevant supporting documents regarding the taken CCP measures;

retain information and documents regarding the AML/CFT at least for the period specified in paragraph 18 of part two of Article 8 of the AML/CFT Law.

5. An institution, using a trust instrument, is obliged to obtain the necessary information from a third party before establishing a business relationship (conducting a financial transaction without establishing a business relationship) with the client.

6. In order to establish the fact that a third party is a foreign obliged entity and is taking similar measures in the field of AML/CFT, the institution uses information from open sources, in particular:

1) legislative requirements of the state of registration of such person;

2) results of the assessment of states (jurisdictions) by the FATF or relevant regional organizations of the FATF type;

3) internal documents of such person relating to the procedure for implementing the NCP and storing information.

7. Before making a decision to cooperate with a relevant third party and using the tool of relying on its CDD results, the institution must conduct a preliminary analysis of the reliability of such a person in accordance with the procedure specified in the institution's internal documents on AML/CFT. The purpose of such analysis is to identify and assess by the institution the risks associated with future cooperation, namely the institution's ability to comply with Ukrainian legislation in the field of AML/CFT, using the CDD results of a third party.

When conducting the analysis, the institution must determine whether the person was subject to enforcement measures for violating the requirements of the Code of Conduct and/or the procedure for storing information by the body supervising its activities in the field of ML/TF, and whether the institution was the subject of an ML/TF investigation.

Based on the results of the analysis, the institution draws up a reasoned conclusion on the possibility of cooperation with the relevant third party, taking into account the identified risks and their acceptability/unacceptability for the institution, which is signed by the responsible employee of the institution. Permission to cooperate with a third party is granted by the executive body (if the executive body is collegial) / the head of the institution by imposing a relevant resolution on the conclusion or by a specially created separate committee or a committee already operating in the institution by adopting a relevant decision.

8. The institution documents the fact of receiving relevant information from a third party and stores the data received, as well as supporting documents/files in which the information was received, within the time limits specified in the AML/CFT Law .

9. The client questionnaire must indicate the fact of reliance on the results of the third-party NPC, indicating the date of receipt of the relevant information and the name of the third party that provided the relevant information.

10. If, at the request of the institution, a third party has not provided copies of relevant supporting documents regarding the taken CDD measures or has repeatedly violated the deadlines for providing such information without good reason, the institution must terminate cooperation with this person and not use the information received from such person in the future when carrying out CDD.

11. The responsible employee of the institution ensures that an up-to-date list of third parties with whom the institution cooperates regarding the use of the deposit instrument is maintained.

12. If a third party and an institution belong to the same group, the conditions specified in subparagraph 1 of paragraph 4 of Appendix 10 to the Regulations on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulations) shall be deemed to be met ( subparagraph 2 of paragraph 4, as well as paragraphs 6 and 7 of Appendix 10 to the Regulations - optional), if:

1) group members adhere to uniform group rules on AML/CFT issues, including requirements for CDD implementation and retention of information and documents, and such rules are consistent with FATF recommendations;

2) compliance by group members with the single group rules on AML/CFT issues is subject to consolidated supervision by the relevant AML/CFT supervisory/enforcement authority.

13. The institution may use the submission tool to obtain information through the NBU BankID System. In such a case, the institution may not comply with the requirements specified in paragraphs 4 , 6 and 7 of Appendix 10 to the Regulations, and in the client questionnaire the institution may indicate the name "NBU BankID System" instead of the name of the identifier bank.

Appendix 11
to the Regulations on the implementation
of financial monitoring by institutions

PROCEDURE for
the institution's refusal to establish (maintain) business relations / conduct a financial transaction

1. The institution is obliged to refuse to establish (maintain) business relations / refuse to provide services to the client, including by terminating business relations, and to refuse to conduct a financial transaction in cases provided for in Part One of Article 15 of the AML/CFT Law.

2. The institution has the right to refuse to carry out a suspicious financial transaction.

3. In cases provided for in part one of Article 15 of the Law on AML/CFT, the institution is obliged, within one business day, but no later than the next business day from the date of refusal, to notify the LMA of attempts to conduct financial transactions and of persons who have or intended to establish business relations and/or conduct financial transactions, or with whom business relations have been terminated on the basis of Article 15 of the Law on AML/CFT, as well as of financial transactions, the conduct of which was refused.

4. The institution is prohibited (except for cases provided for by UN Security Council resolutions) from establishing business relations and conducting financial transactions, providing financial and other related services in cases provided for in Part Four of Article 15 of the AML/CFT Law.

5. In cases provided for in Part Four of Article 15 of the AML/CFT Law, the institution shall immediately notify the LMA of attempts to establish business relations and conduct financial transactions, receive financial and other related services directly or indirectly by persons specified in Part Four of Article 15 of the AML/CFT Law.

6. The institution must determine in the institution's internal documents on AML/CFT issues the procedure for refusing, in cases provided for by the AML/CFT Law, to establish (maintain) business relations (including by terminating contractual relations) or conduct a financial transaction, which must also include:

1) a list of authorized employees of the institution / collegial bodies of the institution who have the right to make decisions on refusal in cases established by the Law on AML/CFT ;

2) the procedure for considering and adopting relevant decisions by authorized employees of the institution, as well as their documentation;

3) drawing up an opinion clearly indicating the reasons for refusing to maintain business relations with the client (with reference to specific paragraphs, clauses and parts of Article 15 of the AML/CFT Law) in each case;

4) the procedure for informing the responsible employee of the institution or an employee authorized by the responsible employee of the institution about the decision to refuse;

5) the procedure for informing the client about the refusal to establish (maintain) business relations with him, with the mandatory indication of the date of refusal and the relevant grounds for refusal, specified in Article 15 of the AML/CFT Law (with reference to specific paragraphs, items and parts of this article);

6) the procedure for informing the client about the refusal to carry out a financial transaction with the mandatory indication of the date of refusal and the relevant grounds for refusal, specified in Article 15 of the Law on AML/CFT (with reference to specific paragraphs, items and parts of this article), and certification by signature of an authorized employee of the institution who made the decision to refuse to carry out the relevant financial transaction, of the document for the transfer of funds submitted to the institution in paper form.

Annex 12
to the Regulation on the implementation
of financial monitoring by institutions

PROCEDURE
for suspension, resumption of financial transactions and execution of decisions (instructions) of the Management Board

1. The institution, in accordance with Part One of Article 23 of the Law on AML/CFT:

1) has the right to stop a financial transaction if it is suspicious;

2) is obliged to stop financial transactions in case of suspicion that they contain signs of committing a criminal offense defined by the Criminal Code of Ukraine .

Such financial transactions are suspended without prior notice to the client for two business days from the date of suspension inclusive.

2. The responsible employee of the institution issues an internal order in the event of a decision to:

1) suspension of a financial transaction in cases provided for in Part One of Article 23 of the Law on AML/CFT - on the day of suspension of the financial transaction;

2) resumption of a financial transaction in the case established by paragraph two of part ten of Article 23 of the Law on AML/CFT - on the day the institution resumes conducting the relevant financial transaction.

3. On the day of issuing the relevant order, the responsible employee of the institution must notify the head of the executive body (if the executive body is collegial) / head of the institution of this fact. If the decision/instruction of the LMA is received by the institution after the end of the working day, then the day of receipt of the relevant decision/instruction of the LMA to the institution is the next working day of the institution.

4. Internal orders of the responsible employee of the institution must contain:

1) client name;

2) name, number and date of the primary document;

3) the amount of the financial transaction;

4) the grounds for suspending a financial transaction as defined by the Law on AML/CFT ;

5) the period of suspension of the financial transaction;

6) date and time of issuance of the order;

7) signature of the responsible employee of the institution.

Such internal orders may be issued on paper or in electronic form.

In the case of issuing orders in electronic form, the signature of the responsible employee of the institution is not required, and the date and time of issuing the order is the date and time of its creation in the relevant automated software module or the date and time of sending such an order using the institution's information systems.

5. Internal orders of the responsible employee of the institution must be stored in a separate file for at least five years in the manner prescribed for the storage of documents with restricted access.

6. The institution is obliged to notify the LMA of the suspension of a financial transaction in the cases provided for in Part One of Article 23 of the AML/CFT Law by immediately informing on the same business day when the financial transaction was suspended.

7. The institution is obliged to ensure that the responsible employee of the institution is immediately informed of the fact that the institution has received decisions and/or instructions from the OSA.

8. The institution is obliged to execute the decisions and/or instructions of the LMA in accordance with the procedure established by the relevant regulatory legal act of the Ministry of Finance of Ukraine, agreed with the National Bank.

9. Upon the written request of the client, the institution shall notify him in writing of the number and date of the decision of the SMA on the extension of the suspension of the relevant financial transactions.

Appendix 13
to the Regulations on the implementation
of financial monitoring by institutions

PROCEDURE
for freezing/thawing assets

1. In accordance with Part One of Article 22 of the Law on AML/CFT, the institution is obliged to immediately, without prior notice to the client (person), freeze assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing (hereinafter referred to as terrorist assets).

2. The payment institution is obliged to use the CA to ensure the freezing of terrorist assets.

3. An institution (other than a payment institution) is required to ensure procedures for checking the presence of clients on terrorist lists and freezing terrorist assets using CA (if available) or using alternative methods, including methods that involve processing information electronically.

The institution (other than a payment institution) is required to document a description of the essence of the above measures.

The institution (except for a payment institution) is obliged, at the request of the National Bank, to provide an explanation of the essence of such measures (demonstrate their operation if necessary).

4. The institution shall develop and document in the institution's internal documents on AML/CFT issues the procedure for implementing measures that ensure the institution's ability to freeze terrorist assets, in particular:

1) the procedure for downloading the list of terrorists and making changes to it;

2) the procedure for implementing screening procedures that allow the institution to identify in its client base and financial transactions carried out through the institution indicators of connections with persons on the terrorist list;

3) the procedure for considering and escalating cases of identifying indicators of connection with persons on the terrorist list, in particular the coincidence of individual data (combinations of data) from the client base and financial transactions carried out through the institution with data of persons on the terrorist list;

4) measures to suspend financial transactions and/or freeze/unfreeze relevant assets.

5. The institution must ensure that no person can dispose of/use terrorist assets, except in cases expressly provided for by law.

6. When developing screening procedures that enable the institution to identify indicators of connection with persons on the terrorist list, the institution should be guided by the principle of the maximum possible analysis of data of persons at the disposal of the institution, including those obtained as a result of the implementation of the NPC, ensuring at least the analysis of data of the following persons:

1) participants in financial transactions carried out through the institution (including details of all fields of primary documents that may contain personal data) and beneficiaries of financial transactions;

2) clients of the institution;

3) representatives of the institution's clients; persons acting on behalf of, on behalf of or for the benefit of clients;

4) Clients' key personnel; persons who exercise direct or indirect decisive influence on the client;

5) officials of the clients' management bodies.

7. The "presence of an indicator of connection with persons on the terrorist list" should be understood as the institution's discovery of the fact that a person (including an organization) is included in the terrorist list.

8. The institution is obliged to implement an appropriate monitoring system that will enable the institution, regardless of the institution's risk profile and the risk profiles of its clients, to detect all indicators of connection with persons on the terrorist list (hereinafter referred to as the TF monitoring system).

9. The TF monitoring system should ensure:

1) identification of indicators of connection with individuals on the terrorist list;

2) real-time detection of indicators of connection with individuals on the terrorist list before establishing business relations with the client or conducting a financial transaction;

3) reviewing existing data in the client database on a periodic basis;

4) ensure the suspension of a financial transaction before its implementation and the suspension of the procedure for establishing business relations in the event of the detection of an indicator of connection with persons on the terrorist list or a match of data that has not been refuted;

5) informing the authorized employee of the institution about the detection of an indicator of connection with persons on the terrorist list, including using built-in rules for escalating this issue;

6) informing an authorized employee of the institution about an attempt to conduct a financial transaction in favor of a person or the initiation of a financial transaction by a person (representative of a person) whose assets are frozen.

10. The institution should regularly ensure an analysis of the effectiveness of the TF monitoring system, in particular by analyzing the history of incidents for individual dates/periods, reviewing the existing system settings in order to identify possible shortcomings in it, and taking operational measures to eliminate the identified shortcomings.

11. The institution ensures the allocation of resources sufficient to perform its duties to freeze the assets of terrorists for the analysis of identified indicators of connection with persons on the terrorist list.

12. The institution shall update its list of terrorists immediately, but no later than the next business day from the date of posting of changes to the list of terrorists on the official website of the OMS.

13. If the TF monitoring system detects a match between certain data and the data of a person on the terrorist list, the institution ensures that measures are taken to confirm/rebut the detected match before establishing business relations with the client or conducting a financial transaction.

14. If the results of the analysis of the detected match confirm the presence of an indicator of connection with persons on the terrorist list (the person is included in the terrorist list), then the institution:

1) is obliged to refuse to establish business relations (within the framework of the provision of financial and other services), conduct financial transactions with persons (including organizations) defined by Part Four of Article 15 of the Law on AML/CFT;

2) has the right to refuse to establish business relations and/or conduct financial transactions in other cases. When deciding whether or not to apply the right of refusal, the institution must carefully analyze the existing ML/TF risks.

15. The institution also ensures that the screening procedure processes data in the existing client base each time:

1) amendments to the list of terrorists;

2) updating data on clients and persons who have connections with the client (in particular, client representatives, CBV).

If the FT monitoring system detects a data match in connection with the updating of client data, the institution shall, no later than the next business day from the date of updating client data, ensure the analysis of the detected match and temporarily suspend the execution of financial transactions of such client until the analysis is completed.

If the TF monitoring system detects a data match due to changes to the list of terrorists, the institution is obliged to analyze the detected matches as soon as possible (taking into account the size of the client base and the number of data matches detected by the TF monitoring system), but no later than two weeks from the date the institution uploads the updated list of terrorists (changes to it).

If the institution does not have information (or it is insufficient) to confirm/disprove that a person is included in the terrorist list, the institution may request additional information from the client or obtain it from other reliable sources. In such a case, the institution shall suspend the financial transactions of such client until the fact that the person is included in the terrorist list is disproved/confirmed.

16. If the FT monitoring system detects a match of the data of a participant in a financial transaction for whom the institution does not have identification data sufficient to refute/confirm the fact that the participant in the financial transaction is a person included in the list of terrorists, the institution is obliged to suspend the implementation of such a financial transaction until the analysis of the match is completed and take the necessary measures, in particular, request additional information to complete the analysis:

1) within a period not exceeding three business days from the moment of detection of a match - for financial transactions within Ukraine;

2) within a period not exceeding five business days from the moment of detection of a match - for cross-border financial transactions.

17. If, within the time limits specified in paragraph 16 of Appendix 13 to the Regulations on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulations), the institution has not received information sufficient to refute the fact that a person is included in the list of terrorists, the institution shall take measures to freeze assets that are the subject of such financial transaction.

18. The institution is obliged to ensure accounting of frozen assets that are the subject of a financial transaction in such a way as to be able, upon request of the National Bank, to demonstrate the measures taken by the institution to freeze assets and the presence of frozen assets in full (if necessary).

19. The institution shall unfreeze assets within the time limits and only in the cases specified in Part Four of Article 22 of the AML/CFT Law.

20. The responsible employee of the institution issues an internal order on the freezing/unfreezing of terrorist assets, which must contain:

1) date and time of decision and its essence (unfreezing or freezing);

2) available identification data of the person whose assets are being frozen/unfrozen;

3) details of the entry in the list of terrorists: number (C1), date of entry (C2), source of entry (C5);

4) information regarding business relations with the client (if available):

amounts/values of frozen/thawed assets;

numbers and dates of conclusion of contracts for the provision of services by the institution, types of assets that are the subject of such contracts, and amounts/values for which they are concluded (if any);

5) information on financial transactions with terrorist assets without establishing business relationships (if available):

name, number and date of the primary document;

date of initiation of the financial transaction;

date of asset freezing;

6) grounds for unfreezing assets (for unfreezing cases);

7) the connection of the person whose assets are frozen (were frozen) with a person on the terrorist list (if the person whose assets are frozen is not a person on the terrorist list);

8) signature of the responsible employee of the institution.

The institution ensures the storage of orders of the responsible employee of the institution regarding the freezing/thawing of assets in a separate case for at least five years, ensuring the protection of information with limited access.

21. In the event of the freezing of terrorist assets, the institution is obliged to immediately inform:

1) LMO - by sending a notification in accordance with the procedure provided for in paragraph 19 of Section II of these Regulations;

2) SBU - by sending a notification letter.

22. The institution shall inform the relevant territorial unit of the SBU at its location about the freezing of terrorist assets by sending a notification letter in the form provided in Appendix 20 to the Regulations. The procedure for providing such information shall ensure its guaranteed delivery and confidentiality.

23. In the event of freezing of client assets, the institution shall conduct financial transactions that increase the assets of such client and shall immediately freeze the assets obtained as a result of such financial transactions.

24. The institution shall inform the SMU and the SBU about financial transactions that increase the client's assets and/or attempts to carry out financial transactions that decrease the client's assets on the day of the financial transaction (attempt to carry it out), but no later than 11 a.m. on the next business day from the day of the financial transaction that increases the client's assets and/or attempts to carry out a financial transaction that decreases the client's assets, in accordance with the procedure specified in paragraph 20 of Appendix 13 to the Regulations. The institution shall notify the client (person) in writing about the freezing of his (her) assets and assets under a blocked financial transaction (of which such person is a participant) in response to a written request received from him (her).

25. The institution is obliged to immediately unfreeze the assets:

1) no later than the next business day from the date of removal of a person or organization from the terrorist list;

2) no later than the next business day from the date of receipt of information from the SBU that a person or organization that has the same or similar name (designation) as a person or organization included in the list of terrorists and whose assets have become the object of freezing, according to the results of the verification, is not included in the specified list.

In the event of unfreezing of assets, the institution shall inform the SMU and the SBU no later than the next business day from the date of unfreezing of assets in accordance with the procedure specified in paragraph 20 of Appendix 13 to the Regulations.

26. The institution, its head and employees are prohibited from disclosing information regarding the facts of informing the SMU and the SBU about the freezing/unfreezing of assets.

27. Access to assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing shall be carried out in accordance with the procedure established by Article 11 - 2 of Section III of the Law of Ukraine "On Combating Terrorism".

Appendix 14
to the Regulations on the implementation
of financial monitoring by institutions

PROCEDURE
for monitoring financial transactions, their registration and information exchange with the OMS

1. The institution must provide in its internal documents on AML/CFT issues a procedure for monitoring financial transactions of clients in order to identify those subject to financial monitoring.

2. The payment institution is obliged to use CA to detect:

1) financial transactions with assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing (hereinafter referred to as terrorist assets);

2) threshold financial transactions;

3) indicators of suspicious financial transactions.

3. An institution (other than a payment institution) may use CA to detect financial transactions specified in paragraph 2 of Appendix 14 to the Regulation, taking into account the specifics of its activities (in particular, the nature and volume of activities, types of services provided, types of clients served, use of the latest technologies) and the ML/TF risks inherent in its activities.

4. The institution must ensure timely detection of financial transactions with terrorist assets, threshold financial transactions and indicators of suspicious financial transactions in order to promptly identify suspicious financial transactions (activities).

5. Institution for detecting suspicious financial transactions (activities):

1) conducts on an ongoing basis monitoring of business relationships with clients and financial transactions carried out in the course of such relationships, regarding the compliance of such financial transactions with the information available to the institution about the client, his activities and risk profile (including the compliance of the client's financial transactions with his expected/planned activities at the stage of establishing business relationships with the institution);

2) ensures the selection [including through automated software modules (if available)] of unusual financial transactions (which, in particular, are complex financial transactions, unusually large, conducted in an unusual manner, have no obvious economic or legal purpose, do not correspond to the financial situation of the client), introducing periodic analysis of all client financial transactions using appropriate rules/scenarios (in particular, daily, weekly, monthly, quarterly);

3) involves the necessary employees of the institution in analyzing financial transactions [including those detected using automated software modules (if available)], delegating to them the relevant functional responsibilities and rights, and conducting training activities for them in such a way that such employees are able to detect unusual and suspicious customer activity;

4) ensures the functioning of a proper procedure for escalating suspicions by employees of the institution, the procedure for their prompt consideration by authorized employees of the institution, and making decisions on the presence/absence of suspicions based on the results of the analysis.

6. In order to identify suspicious financial transactions (activities), the institution provides analysis of financial transactions of clients (their aggregate) for the presence/absence of indicators of suspicious financial transactions, including the use of automated software modules (if available) that implement the selection of financial transactions using appropriate rules/scenarios.

7. The institution independently develops a list of indicators of suspicious financial transactions, taking into account the indicators specified in Appendix 19 to the Regulation on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulation), typological studies of the SMA and recommendations of the National Bank in the field of ML/TF.

When developing indicators of suspicious financial transactions, the institution determines quantitative limits for those indicators that contain quantitative characteristics (in particular, "significant increase", "large volumes", "regularly").

8. When developing rules/scenarios for selecting financial transactions, the institution must take into account the client's risk profile, information obtained as a result of conducting due diligence and other information available to it (in particular, information obtained from law enforcement agencies).

The institution also ensures the detection of financial transactions that do not meet its expectations in view of:

1) the future activities planned by the client when establishing business relations with him (taking into account the announced volume of financial transactions, types of services to be used);

2) the client's risk profile (in particular, the financial transactions carried out by the client do not have a rational basis, taking into account the information obtained as a result of the due diligence measures, and/or are not typical for clients similar in size / type of activity / income / social status).

9. The developed rules/scenarios for the selection of financial transactions of the institution should ensure the detection of:

1) a financial transaction with cash that contains indicators of suspicious financial transactions - no later than 20 business days after the completion of such a financial transaction;

2) other financial transactions (a set of related financial transactions) containing indicators of suspicious financial transactions - no later than the last business day of the month following the month in which such financial transactions were carried out.

10. If the documents and/or information available to the institution are insufficient to conduct an analysis, refute/confirm suspicions and/or make an appropriate decision regarding individual financial transactions (their aggregate), the institution shall ensure the prompt taking of additional measures (in particular, requesting additional documents and/or information relating to the financial transaction or the client's activities), but no later than two months from the date of selection/detection of indicators of suspicious financial transactions, and shall necessarily record the dates of receipt of the relevant documents and/or information.

11. The institution is obliged to document all measures taken by it to refute/confirm its suspicions during the analysis of clients' financial transactions (in particular, to establish the purpose and essence of financial transactions, their compliance with the client's financial condition and/or activities, and to establish, if necessary, the source of funds related to financial transactions).

12. In the event of facts indicating (may indicate) that the client has carried out suspicious financial transactions (activities) or is unable to refute its suspicions based on the results of the measures taken, the institution, depending on the volume of such financial transactions, decides to send a report on suspicious financial transaction(s) or suspicious activity, and draws up a reasoned conclusion on the suspicious financial transaction(s) (activity), which is submitted to the SMA together with the specified report, copies of documents and other information on the basis of which the suspicion was formed.

13. When drawing up a reasoned opinion on suspicious financial transaction(s) (activity), the institution shall ensure the clearest and most comprehensive statement of its suspicion and other circumstances, facts, and events that led to the emergence of such suspicion. A reasoned opinion shall be considered to have been drawn up properly if, after reviewing such opinion, the content of the expressed suspicion is clear to a third party with experience in the field of AML/CFT (a person other than the one who worked on its preparation).

14. The institution ensures the recording (date, time and content of relevant events):

1) actions of the institution's employees regarding sending and receiving [including using automated software modules (if available)] by the institution's employees information about financial transactions that may be subject to financial monitoring, identified indicators of suspicious financial transactions, as well as decisions made by them regarding further escalation of suspicion;

2) receipt/reception by the responsible employee of the institution or an employee authorized by the responsible employee of the institution of relevant information from the institution's employees and/or automated software modules (if available), making a final decision on the presence/absence of suspicions and classifying the financial transaction as one subject to financial monitoring.

15. For the purpose of internal control, the institution periodically conducts further monitoring of financial transactions in accordance with the procedure established in the institution's internal documents on AML/CFT issues, in order to identify financial transactions that are subject to financial monitoring, but for certain reasons were not detected by it in a timely manner.

In the event that further monitoring reveals financial transactions subject to financial monitoring that the institution has not informed the LMA about, the institution shall immediately ensure that the LMA is informed about such financial transactions. The institution shall also analyze the reasons for the failure to detect such financial transactions and take prompt measures to eliminate the identified deficiencies/problems and prevent the occurrence of similar deficiencies/problems in the future.

The institution does not conduct further monitoring of financial transactions throughout the entire period of the National Bank's inspection of the institution for compliance with the requirements of Ukrainian legislation in the field of AML/CFT, including the day of the start of such inspection (does not apply to financial transactions carried out during the specified inspection).

16. The institution, upon request of the National Bank, must be able to demonstrate the adequacy of the measures taken to comply with the requirements of the AML/CFT legislation, in particular in terms of identifying financial transactions subject to financial monitoring, and prove that the relevant decisions taken for this purpose are based on substantive facts and the results of a comprehensive and proper analysis.

17. The institution shall maintain a register of financial transactions, a register of reports of suspicious financial activity, a register of discrepancies regarding the CBA and ownership structure, a register of refusals and a register of freezing/unfreezing (hereinafter referred to as the registers of reports) taking into account financial transactions and relevant facts that took place in separate divisions of the institution, with separate numbering in such registers, the countdown of which shall begin from the beginning of the calendar year.

18. The institution maintains message registers in electronic form (including the possibility of using Word, Excel programs). Message registers are documents with limited access.

19. Access to the message registers is granted to the responsible employee of the institution, as well as to employees of the institution authorized by the responsible employee of the institution.

The responsible employee of the institution establishes, if necessary, access of the employees of the institution designated by him to the relevant message registers by issuing a corresponding order.

20. The responsible employee of the institution is responsible for protecting the message registers from destruction, unauthorized access, modification or distortion of data.

21. The responsible employee of the institution or an employee of the institution authorized by the responsible employee of the institution makes a decision on:

1) that the client's financial transaction(s) is/are suspicious by entering information about it(them) into the financial transactions register on the day sufficient grounds for suspicion arise;

2) that the activity of the client(s) is suspicious, by entering information about such activity in the register of suspicious financial activity reports on the day of signing the reasoned conclusion on suspicious financial activity;

3) entering information on the presence of discrepancies between the information on the KBV, the ownership structure contained in the Unified State Register and the information on the KBV, the ownership structure obtained by the institution as a result of the implementation of the NPC, into the register of discrepancies on the KBV and the ownership structure;

4) entering information about the refusal to establish (maintain) business relations with a client (person) into the register of refusals;

5) entering information on the freezing/thawing of terrorist assets into the freeze/thawing register;

6) entering information about other financial transactions subject to financial monitoring into the register of financial transactions.

The powers of an employee authorized by a responsible employee of the institution to make such a decision must be provided for in the employment contract (job description) of such employee.

22. The institution ensures the entry of information into the register of financial transactions about:

1) threshold financial transactions;

2) suspicious financial transactions;

3) financial transactions suspended by the institution, including for the purpose of implementing the relevant decision or instruction of the SMA;

4) financial transactions for which the institution has refused to perform them to the client (person);

5) attempts to conduct financial transactions by clients and financial transactions for the benefit of clients whose assets have been frozen by the institution;

6) financial transactions for which the institution provides tracking (monitoring) measures upon the relevant request/decision/instruction of the OMS.

23. The institution provides information to the OMS in cases and within the time limits specified by the Law on AML/CFT .

24. The following data shall be entered into the register of financial transactions:

1) serial number of registration in the register from the beginning of the calendar year and date of registration;

2) unique financial transaction number in the institution's CA (if available);

3) date of execution / attempted execution / refusal to execute / suspension of a financial transaction / freezing of assets of a financial transaction;

4) the code of the sign of the financial transaction in accordance with the directory of codes of signs of the financial transactions, determined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

5) the amount of the financial transaction in the currency of its execution and its equivalent in the national currency at the official exchange rate of the hryvnia to the foreign currency established by the National Bank on the day of the financial transaction (for currency exchange transactions, the amount is indicated at the institution's foreign currency purchase/sale/exchange rate);

6) surname, first name and (if available) patronymic or name of the client and RNOKPP / code according to the Unified State Register of Legal Entities of this person (if RNOKPP / code according to the Unified State Register of Legal Entities of this person is not assigned, then nine zeros are indicated);

7) surname, first name and (if available) patronymic or name of the counterparty and RNOKPP / code according to the Unified State Register of Legal Entities of this person (if RNOKPP / code according to the Unified State Register of Legal Entities

8) the code (codes) of the characteristic of threshold financial transactions / types of suspicions and signs of suspicion in accordance with the directories of codes of characteristics of threshold financial transactions / types of suspicions, signs of suspicions, defined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

9) comments (if any). A brief comment from the reasoned conclusion is indicated for a suspicious financial transaction.

Other information provided for by these Regulations shall also be entered into the register of financial transactions.

25. The institution shall enter the following data into the register of suspicious financial activity reports:

1) serial number of registration in the register from the beginning of the calendar year and date of registration;

2) the code of the type of suspicion in accordance with the directory of codes of the type of suspicion defined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

3) the suspicious sign code in accordance with the directory of suspicious sign codes defined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

4) surname, first name and (if available) patronymic / name of the client(s) - participant(s) of suspicious financial activity and his/her RNOKPP / code according to the Unified State Register of Legal Entities (if the RNOKPP / code according to the Unified State Register of Legal Entities is not assigned, then nine zeros are indicated);

5) the approximate amount of suspicious financial transactions in hryvnia equivalent;

6) the start and end dates of the suspicious activity;

7) comments (a brief comment on the reasoned conclusion).

26. The institution shall enter the following data into the register of disagreements on the CBV and ownership structure:

1) serial number of registration in the register from the beginning of the calendar year and date of registration;

2) the date of detection of discrepancies between information on the CBV and/or ownership structure;

3) name and code according to the Unified State Register of Legal Entities of the legal entity for which discrepancies were found between the information on the capital and/or ownership structure contained in the Unified State Register and the information on the capital and/or ownership structure obtained by the institution as a result of the implementation of the NPC;

4) comments (if any).

27. The institution determines the presence of discrepancies between the information on the beneficial owner and/or the ownership structure of a legal entity obtained as a result of the implementation of the NPC and the relevant information posted in the Unified State Register (hereinafter referred to as discrepancies), taking into account the types of discrepancies specified in the Procedure for notifying the holder of the Unified State Register of Legal Entities, Individual Entrepreneurs and Public Organizations about the detection of discrepancies between the information obtained by the subject of primary financial monitoring as a result of due diligence and posted in the Unified State Register of Legal Entities, Individual Entrepreneurs and Public Organizations about the ultimate beneficial owners and/or the ownership structure of a legal entity , approved by the Order of the Ministry of Justice of Ukraine dated July 12, 2023 No. 2542/5, registered with the Ministry of Justice of Ukraine on July 12, 2023 under No. 1185/40241 (as amended) (hereinafter referred to as the Procedure notification of the USR holder).

The date of detection of discrepancies is the date of entry into the client's questionnaire of information about the relevant CBV/ownership structure, regarding the information about which there are discrepancies. For clients for whom, in accordance with the requirements of the Regulation, the institution is not obliged to form and maintain client questionnaires, the institution enters the relevant information into the Client Lists.

The institution provides the USR holder with information on the detection of discrepancies in accordance with the procedure specified in the USR Holder Notification Procedure , within the time limits established by the AML/CFT Law .

28. The institution shall enter the following data into the register of refusals:

1) serial number of registration in the register from the beginning of the calendar year and date of registration;

2) the date of the institution's decision to refuse to establish (maintain business relations);

3) the code of the type of refusal notification in accordance with the directory of codes of the type of refusal notification, determined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

4) code of the reason for refusal in accordance with the directory of codes of reasons for refusal, determined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

5) surname, first name and (if available) patronymic / name of the person who was refused, and his/her RNOKPP / code according to the Unified State Register of Legal Entities [if the RNOKPP / code according to the Unified State Register of Legal Entities is not assigned, then nine zeros are indicated];

6) comments (including reasons for rejection).

29. The institution enters the following data into the freeze/thaw register:

1) serial number of registration in the register from the beginning of the calendar year and date of registration;

2) the code of the type of notification on the freezing/thawing of assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing, in accordance with the directory of codes of the type of notification on the freezing/thawing of assets related to terrorism and its financing, proliferation of weapons of mass destruction and its financing, determined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

3) surname, first name and (if available) patronymic / name of the client, and his RNOKPP / code according to the Unified State Register of Economic Activities [if the RNOKPP / code according to the Unified State Register of Economic Activities is not assigned, then nine zeros are indicated];

4) code of the type of frozen/thawed asset in accordance with the directory of codes of the type of frozen/thawed assets, determined by the relevant regulatory legal act of the Ministry of Finance of Ukraine;

5) the amount of frozen/thawed assets in hryvnia equivalent;

6) comments (if any).

30. Deletion of data entered into message registers is not permitted.

31. If it is necessary to correct erroneously entered data in the registers of notifications, the institution shall note in the information line of the register with such erroneous data the fact of cancellation of the relevant entry and indicate the grounds for cancellation in the "Comments" field, and shall also supplement the register with a new entry if the relevant information is subject to provision to the MSA/USR holder.

32. The decision to cancel an entry in the relevant register of messages is made by the responsible employee of the institution or an employee authorized by the responsible employee of the institution.

33. If, based on the results of the internal audit (control) / independent audit or the National Bank (including during on-site supervision), facts of failure by the institution to provide relevant information to the LMS / USR holder, which should have been provided by the institution in accordance with the requirements of the legislation of Ukraine in the field of AML / FT, are revealed, the institution shall enter such information into the relevant notification registers no later than 30 business days from the date of receipt by the responsible employee of the report on the results of the internal audit signed by the responsible employee or the date of receipt by the institution of the independent audit report / certificate of inspection by the National Bank / act on the results of on-site supervision on financial monitoring issues (except for cases when, at the time of receipt of the report on the results of the internal audit / report on the results of the independent audit / certificate of inspection by the National Bank / act on the results of on-site supervision on financial monitoring issues, the relevant information will not be subject to provision to the LMS / USR holder in accordance with the requirements of the legislation of Ukraine).

34. In the event of an institution's refusal to conduct a financial transaction/establish a business relationship with a client, the data available at the time of making the relevant decision related to such financial transaction/business relationship shall be entered into the relevant notification registers, with a mandatory indication of the reasons for the refusal in the "Comments" field.

35. If it is necessary to create an extract from the register of messages on paper, the institution is obliged to ensure that all data identical to those contained in the register of messages in electronic form and provided for by the Regulations are displayed on paper, with the mandatory indication of the date of printing.

36. The procedure for transmitting information to the OMS should ensure its guaranteed delivery and confidentiality.

37. The institution is obliged to ensure the timeliness, completeness and reliability of the provision of relevant information to the MSA/USR holder.

38. The request of the LSA to provide information necessary to fulfill the request of the relevant authority of a foreign state must contain a reference to the number and date of registration of this request in the LSA.

39. The institution is obliged to fulfill the request of the OMS to provide information on tracking (monitoring) of the client's financial transactions in accordance with the procedure established by the relevant regulatory legal act of the Ministry of Finance of Ukraine, agreed with the National Bank.

{Annex 14 as amended by Resolution of the National Bank No. 121 of 05.10.2024 }

Appendix 15
to the Regulations on the implementation
of financial monitoring by institutions

MEASURES
regarding funds transfers

1. In order to comply with the requirements set out in Article 14 of the AML/CFT Law, the institution must ensure:

1) the transfer documents contain all necessary fields for entering information about the payer and/or recipient of the transfer;

2) accompanying transfers of funds with mandatory information about the payer and recipient of funds;

3) introduction of appropriate measures to monitor the presence of mandatory information in the transfer and identify details filled in using characters that are not allowed by the payment system;

4) development and application of effective risk-based procedures for the purpose of making decisions on the execution, suspension, rejection of transfers of funds that lack information about the payer and/or recipient or that are filled in using symbols that are not allowed by the rules of the relevant payment system;

5) informing the National Bank about SPFMs that repeatedly fail to provide information upon request about the payer and/or recipient of a money transfer.

2. Lack of information about the payer and/or recipient of the transfer (hereinafter referred to as lack of information) - lack of necessary information about the payer and/or recipient of the transfer, which is required in cases specified in Article 14 of the AML/CFT Law.

3. Incomplete information about the payer and/or beneficiary (hereinafter referred to as incomplete information) - partial absence of the necessary information about the payer and/or beneficiary of the transfer, which is required in the cases specified in Article 14 of the AML/CFT Law.

4. Meaningless information about the payer and/or recipient (hereinafter referred to as meaningless information) - if the relevant fields, which should contain the necessary information about the payer and/or recipient of the transfer, contain information that does not make sense and/or is filled in as a set of random characters (for example, "xxxxx" or "ABCDEFGHIJKLMNOPQRSTUVWXYZ"), or as a word (word combination) that cannot be considered data about the payer and/or recipient of the transfer (for example, "others", "my client"), even if such information is filled in using characters allowed by the rules of the relevant payment system.

5. An institution's procedures for monitoring transfers of funds are considered adequate if they:

1) ensure the identification of cases of missing information, incomplete information and meaningless information;

2) allow the institution to combine online monitoring and subsequent monitoring of funds transfers;

3) ensure immediate notification to the authorized employee of the institution of any coincidence with the indicators of online monitoring of information about the payer/recipient of the transfer of funds.

6. The institution should periodically review the settings of automated software modules that monitor fund transfers regarding the relevance of the list of words (word combinations) that are detected as cases of meaningless information, and ensure its relevance.

7. The institution should treat cases of meaningless information as a lack of information about the payer and/or recipient.

8. If a transfer of funds using EPZ or prepaid cards can be made both for payment for goods or services and for transfer of funds for another purpose (in particular, transfers between individuals), then the institution may apply the exception provided for in paragraph 4 of part eighteen of Article 14 of the AML/CFT Law if it is able to clearly determine that the transfer of funds is made for payment for goods or services.

9. The institution, using a risk-based approach, develops procedures for monitoring transfers of funds, taking into account:

1) features of the client base;

2) the specifics of the activity (the nature of the products and services provided);

3) geography of service provision [states (jurisdictions) of transfer participants];

4) channels (methods) of service provision;

5) the number of SPFMs that repeatedly fail to provide information about the payer and/or recipient of the transfer;

6) complexity of the payment route;

7) volumes and amounts of transfers made.

SPFMs that repeatedly fail to provide information upon request about the payer and/or recipient of the transfer - SPFMs of the payer or SPFM-intermediary that repeatedly fail to provide information about the payer/recipient upon request of the institution without proper justification.

10. The institution's internal documents on AML/CFT issues should contain:

1) a list of payment services (products) of the institution provided by the institution, which are subject to the requirements of Article 14 of the AML/CFT Law;

2) the distribution of responsibilities and the procedure for authorized employees of the institution in the event of detection of cases of lack of information, incomplete information and/or meaningless information in transfers;

3) methods for filling in the necessary information about the payer and/or recipient in funds transfer documents;

4) signs of connection between transfers of funds;

5) means that make it possible to determine the country of registration of the payer's SPFM and the recipient's SPFM;

6) indicators for monitoring information about the payer and/or recipient of the transfer of funds;

7) the procedure for identifying and cases in which a payer/recipient who regularly initiates/receives transfers of funds will be considered by the institution as one that maintains business relations with it and in respect of which due diligence measures must be carried out in accordance with the procedure provided for in Appendix 1 to the Regulation on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulation).

11. The intermediary institution must implement control systems to store and accompany the transfer of funds with the necessary information about the payer and the recipient (including by ensuring the ability to convert information to another format without errors and omissions).

12. The intermediary institution and the recipient institution must ensure online monitoring and further monitoring of information about the payer and/or recipient of money transfers in order to identify cases of missing information, incomplete information, meaningless information or filling in data using symbols that are not allowed by the rules of the relevant payment system. The depth and frequency of monitoring of money transfers are determined taking into account the results of the assessment of the level of its ML/TF risks (the institution's risk profile), taking into account the factors listed in paragraph 9 of Appendix 15 to the Regulation.

13. The intermediary institution and the recipient institution shall determine procedures for identifying indicators, the presence of which shall trigger online monitoring of information about the payer and/or recipient.

14. Indicators of online monitoring of information about the payer and/or recipient of a money transfer should include, in particular, the following:

1) making a transfer of funds for an unusually large amount (an amount exceeding a certain threshold level). When determining the threshold level of a transfer of funds, the intermediary institution / recipient institution should be based on the average amount of regular transfers of funds carried out during the day, taking into account the specifics of its activities;

2) the state (jurisdiction) of the payer's or the payee's PFMS is a state that is on the list of states that do not comply with the FATF recommendations and/or a state that has strategic deficiencies in the field of AML/CFT in accordance with FATF statements;

3) the presence of negative information about the SPFM from which the transfer of funds was received;

4) receiving a transfer of funds from a SPFM that repeatedly fails to provide information upon request about the payer and/or recipient;

5) a transfer of funds in which the name of the payer and/or recipient is missing.

15. The settings of automated software modules that ensure monitoring of money transfers by the intermediary institution/recipient institution should ensure immediate notification of authorized employees of the institution in the event of detection of indicators of online monitoring of information about the payer and/or recipient of the money transfer.

16. The institution, in addition to monitoring information about the payer and/or recipient, carries out, including using automated software modules, monitoring of transfers of funds in order to identify suspicious financial transactions using indicators of suspicious financial transactions developed by the institution independently, taking into account the indicators listed in Appendix 19 to the Regulations.

17. The intermediary institution and the recipient institution must implement risk-based procedures for making a decision to execute, reject or stop a transfer of funds in the event that the results of online monitoring of transfers reveal cases of missing information, incomplete information, meaningless information or filling in data using symbols that are not allowed by the rules of the relevant payment system.

18. If the payer's institution, during the analysis of financial transactions carried out by the institution within the payment system without establishing a business relationship with the recipient, identifies ML/TF risk criteria and/or indicators of suspiciousness of financial transactions (their aggregate) and/or financial transactions (their aggregate) in respect of which there are suspicions of the institution being used for ML/TF or committing another crime, and the documents and/or information available to the institution are insufficient to conduct the analysis, refute/confirm suspicions and/or make an appropriate decision regarding individual financial transactions (their aggregate), the payer's institution must contact the recipient's institution to obtain the necessary documents and/or information.

19. The intermediary institution/recipient institution, when making a decision to execute, reject or suspend a transfer, must take into account the ML/TF risks associated with such a transfer, in particular:

1) whether the lack of information about the payer and/or recipient leads to increased ML/TF risks;

2) whether the presence of one or more indicators of monitoring information about the payer and/or recipient of the transfer of funds leads to suspicion in the institution.

20. If the intermediary institution/recipient institution has decided to reject the transfer of funds, it shall notify the intermediary SPFM/payer SPFM of the reasons for such rejection. In this case, a request to clarify information about the payer and/or beneficiary is not required.

21. If the intermediary institution / recipient institution has decided to stop the transfer of funds, it must send a request to the SPFM from which the transfer was received to provide the missing information regarding the payer and/or recipient or to provide information using symbols permitted by the rules of the relevant payment system.

22. In the event of a decision to make a transfer based on the results of online monitoring or detection of a completed transfer based on the results of further monitoring, in which there is no information / incomplete information / meaningless information / filled with data using symbols not allowed by the rules of the relevant payment system, the intermediary institution / recipient institution must, after making such a transfer, send a request to the intermediary SPFM / SPFM of the payer to provide the missing information or provide information using symbols allowed by the rules of the relevant payment system.

23. In the event of a decision based on the results of online monitoring to carry out a transfer in which there is no information / incomplete information / meaningless information / filled with data using symbols that are not allowed by the rules of the relevant payment system, the institution is obliged to take into account the existing ML/TF risks and identified indicators of suspicious financial transactions and document the grounds for making such a decision with its proper justification.

24. A request for the provision of missing information or the provision of information using symbols permitted by the rules of the relevant payment system must set a deadline for the provision of information:

1) for payments within Ukraine - up to three business days;

2) for cross-border payments - up to five business days.

At the same time, if the payment has a complex payment route, the institution may set longer terms.

25. In the event of failure to receive the requested information, the intermediary institution/recipient institution may decide to send a repeated request, in particular with a warning that if the requested information is not provided within the time limits specified in the request, such a PFMS may be subject to in-depth monitoring of business relationships, as well as its qualification as a PFMS that repeatedly fails to provide information upon request about the payer and/or recipient of the transfer.

26. If the requested information has not been provided by the intermediary SPFM / SPFM of the payer within the time limits specified in the request, the intermediary institution / recipient institution, taking into account internal procedures and based on a risk-based approach, makes a decision on:

1) conducting or rejecting a transfer of funds;

2) presence/absence of suspicion regarding the transfer of funds and informing the LMA about the transfer of funds regarding which suspicion has arisen;

3) the feasibility of further cooperation with the SPFM, from which a response to the request has not been received, taking into account the presence/absence of suspicion;

4) qualification of such a PFMS as a PFMS that repeatedly fails to provide information upon request about the payer and/or recipient of the transfer.

27. Identifying only cases of missing information, incomplete information, meaningless information or filling in data using symbols that are not allowed by the rules of the relevant payment system may not indicate the presence of suspicion. The institution makes a decision on the presence/absence of suspicion of ML/TF in relation to a transfer of funds based on a comprehensive review of all indicators of suspicious financial transactions inherent in this transfer.

28. The institution qualifies an intermediary SPFM/SPFM of the payer as an SPFM that repeatedly fails to provide information upon request about the payer and/or the recipient of the transfer, taking into account, in particular, the following factors:

1) the share of transfers of funds that did not contain or contained incorrect or incomplete information about the payer and/or recipient over a certain period of time;

2) the proportion of requests for clarification of information that were not answered or received unsatisfactory answers;

3) experience of interaction with the SPFM, taking into account the quality of its processing of requests sent by the institution;

4) type of information missing from the funds transfer.

29. For this purpose, the institution shall document all identified cases of missing information, incomplete information, meaningless information or filling in data using characters not permitted by the rules of the relevant payment system.

30. In the event of a decision to qualify an intermediary SPFM/SPFM of a payer as an SPFM that repeatedly fails to provide information upon request about the payer and/or recipient of the transfer, the institution shall, within 15 business days from the date of such decision, send an electronic message to the address of the Financial Monitoring Department of the National Bank, which must contain the following details:

1) the name of the SPFM, which repeatedly fails to provide information upon request about the payer and/or recipient of the transfer;

2) the name of the state (jurisdiction) of registration of the SPFM, which repeatedly fails to provide information upon request about the payer and/or recipient of the transfer;

3) information on cases of failure to provide information:

number of cases of failure to provide information;

the type of information on the transfer of funds for which a request was made but no response was received (for example, last name, first name and (if available) patronymic, RNOKPP);

the period of time given by the institution to respond;

reasons for failure to provide information to the payer's SPFM/SPM intermediary (if any);

a list of measures taken by the institution regarding such SPFM.

31. In order to manage the risks associated with a PSP that repeatedly fails to provide information upon request about the payer and/or recipient of the transfer, the institution may take, in particular, the following measures:

1) send a warning letter to such PFMS about taking further measures in case of failure to provide the requested information, in particular, refusal to make any payments in the future;

2) introduce online monitoring of all transfers of funds received from such a PFMS;

3) making a decision to restrict or refuse to maintain (terminate) business relations.

32. The institution ensures documentation of the developed procedures for transfers of funds and the performance by the institution's employees of the duties delegated to them, the taking of actions by them, and the adoption of relevant decisions related to the implementation of the institution's procedures, in such a way as to be able to demonstrate their reasonable implementation and promptly provide relevant information upon request of the National Bank, the OMS or law enforcement agencies.

Annex 16
to the Regulation on the implementation
of financial monitoring by institutions

PROCEDURE
for individuals to report violations in the field of AML/CFT, and the procedure for their consideration

1. The institution must develop and implement separate communication channels for the purpose of informing the employees of the executive body (if the executive body is collegial) / the head of the institution and/or the responsible employee of the institution about possible violations of the requirements of the law or the institution's internal procedures in the field of AML/CFT (hereinafter referred to as the violation report).

2. The institution's procedures should include:

1) the procedure for employees to report violations [including using automation tools (if available)];

2) measures to ensure the confidentiality of the fact that a person has sent a report of a violation and its protection;

3) the procedure for receiving and considering reports of violations by the executive body (if the executive body is collegial) / the head of the institution and/or the responsible employee of the institution.

3. The reporting procedure should provide for the possibility of reporting violations both anonymously and with indication of authorship.

4. The institution may provide for various channels for receiving reports of violations, provided that confidentiality conditions are observed, in particular by means of e-mail correspondence, sending a fax, a letter by mail to the institution's address, a telephone "hotline", a request for a personal meeting with the head of the executive body (if the executive body is collegial) / the head of the institution and/or a responsible employee of the institution, filling out a form on the official and/or internal website of the institution, and other means.

5. In the event of receiving an anonymous report of a violation, the institution must provide, in particular, the following in the form of providing such information:

1) date/period of financial transactions;

2) the currency and amount of each financial transaction;

3) participants in financial transactions and their role;

4) actual beneficiaries (if information is available);

5) content of financial transactions;

6) there are signs of ML/TF;

7) under what circumstances (means) were financial transactions detected;

8) third parties, including those outside the institution, who may have been involved in carrying out the specified operations.

6. The institution must ensure that during recruitment, as well as during scheduled AML/CFT training, employees are familiarized with the available communication channels in the institution for reporting violations.

7. The training activities specified in paragraph 6 of Appendix 16 to the Regulations on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulations) must contain a part explaining what exactly an employee of the institution is recommended to indicate in the notification of a violation in the event of anonymous reporting.

8. The recommended minimum list of details of a violation notification may contain the data specified in paragraph 5 of Appendix 16 to the Regulations.

9. The institution ensures protection of employees who have filed a report of a violation. The institution is prohibited from taking any discriminatory measures against employees [dismissal or forced dismissal, disciplinary action or other negative measures of influence (transfer, certification (re-certification), change of working conditions, refusal to appoint to a higher position, salary reduction, etc.), or threat of such measures of influence] in connection with their filing a report of a violation.

10. The institution may establish in its internal procedures the procedure for submitting reports of violations by third parties.

11. The institution is obliged to take measures to protect the personal data of all persons concerned by the violation report.

12. Employees of the institution, as well as third parties, may send reports of violations to the National Bank using the telephone hotline, the official Internet representative office of the National Bank, or e-mail.

Annex 17
to the Regulation on the implementation
of financial monitoring by institutions

CONDUCTING TRAINING EVENTS

1. The institution must determine in its internal documents on AML/CFT the categories of employees (relevant positions, structural units of the institution) who must undergo AML/CFT training.

Such categories of employees should include employees who participate in the implementation of measures aimed at the institution's compliance with AML/CFT legislation and to whom the relevant rights and responsibilities are delegated.

2. When developing the content of training activities, the institution should take into account the specifics of the employees' job responsibilities, their powers and responsibilities, as well as the level of knowledge and qualifications required for such employees to properly perform their AML/CFT responsibilities. The result of the training should be an understanding by employees of the institution's expectations and their responsibilities/roles in AML/CFT.

3. The institution annually develops a plan for conducting training activities on AML/CFT issues, which should include:

1) planned training activities (developed and conducted at the expense of the institution's internal human resources and/or with the involvement of external lecturers/teachers);

2) planned external training events (attendance by employees of the institution at external training events / completion of relevant certifications in the field of AML/CFT);

3) familiarizing employees of the institution with the requirements of the institution's internal documents on AML/CFT issues before they start performing their official duties (including in the event of a significant change in them) and in the event of amendments to the institution's internal documents on AML/CFT issues.

The plan for conducting training activities on AML/CFT issues is approved by the executive body (if the executive body is collegial) / the head of the institution.

4. Training activities should include, in particular, the following:

1) requirements of legislation and internal documents of the institution on AML/CFT issues;

2) liability provided for by law for violation of the requirements of the legislation on AML/CFT;

3) the highest risk areas of the institution based on the results of the institution's risk profile assessment;

4) examples of violations of relevant sanctions by institutions and other persons;

5) the institution's escalation/reporting procedures (in particular regarding its suspicions, possible violations, identified indicators of suspicious financial transactions, risk criteria, and other problematic issues in the field of AML/CFT);

6) practical aspects of working with automated software modules available in the institution in order to comply with the requirements of the legislation and internal documents of the institution on AML/CFT issues.

5. After the institution's employees have completed the relevant training, the institution shall ensure testing of the level of knowledge obtained by the employees, and shall ensure retraining for those employees who, according to the results of the testing, received unsatisfactory results.

6. The institution documents the fact of conducting relevant training activities, recording, in particular, the following information:

1) type of training event and name of the training course;

2) surname, first name and (if available) patronymic, position of the person who completed the training;

3) surname, first name and (if available) patronymic, position of the person who conducted the training (in the case of conducting a training event, except for electronic courses);

4) place of training (in case of attending an external training event);

5) details of the person who conducted the external training;

6) date of training;

7) test results and/or copy of certificate (if available).

7. The plan for conducting training events on AML/CFT issues, as well as the information specified in paragraph 6 of Appendix 17 to the Regulations on the implementation of financial monitoring by institutions, shall be stored by the institution for at least five years from the time of the relevant training event.

8. The institution periodically ensures that the content of training events is updated, taking into account changes in the institution's internal documents on AML/CFT issues, internal processes and procedures, and the results of the institution's risk profile assessment.

9. The institution ensures that its employees have the opportunity to receive relevant explanations and answers to questions related to the performance of their duties in the field of AML/CFT.

10. The institution should pay significant attention to the training of the responsible employee of the institution and other employees of the institution in order to maintain their appropriate level of knowledge and qualifications in the field of AML/CFT.

Annex 18
to the Regulation on the implementation
of financial monitoring by institutions

ML/TF RISK CRITERIA

I. Risk criteria by client type↑

1. Risk criteria by type of client are ML/TF risk criteria inherent in the client's legal form, ownership structure, business, professional or personal activities and their CBC.

2. When developing its own risk criteria by type of client, the institution must take into account the risk criteria specified in paragraphs 3 - 6 of Section I of Appendix 18 to the Regulation on the implementation of financial monitoring by institutions (hereinafter referred to as the Regulation).

3. The risk criteria that are determined by the commercial or personal activities of the client or his CBV, in particular, are the following:

1) the client provides legal, consulting, accounting services or services for the establishment of business entities and their further operation, opening a bank account in his own name to carry out financial transactions on behalf of the client;

2) the period of activity of the legal entity from the date of state registration is less than six months;

3) the client's previous activities and professional experience are significantly different from what the client plans to do using the institution's services;

4) the client carries out any of the following activities:

gambling, lotteries;

collection services;

activities that are characterized by a high level of cash turnover;

trade in real estate, luxury goods, antiques, works of art;

trade in precious metals and stones;

production and/or trade in weapons, ammunition, military equipment and military vehicles (their parts);

activities related to the production and/or trade of nuclear reactor materials;

activities of professional sports clubs (including international sports organizations);

reinsurance services;

foreign exchange trading intermediary services (e.g. Forex dealers);

provision of services that are difficult to document as having actually been provided (e.g. advertising, marketing, consulting services, market research services, development and maintenance of IT solutions);

investment services and ancillary investment services [except for cases where the service provider is licensed and subject to AML/CFT supervision by the relevant supervisory authority of the state (except for states included in the list of states that do not comply with FATF recommendations (black list) and that have strategic AML/CFT deficiencies according to FATF statements (grey list)];

binary options trading;

activities related to virtual assets (is a provider of services related to the circulation of virtual assets);

activities of non-profit organizations, including charitable activities, activities of religious organizations, political parties (except for condominiums);

5) the client or its CBO carries out activities characterized by a high risk of corruption, in particular:

production and/or trade in pharmaceutical products or narcotic substances (precursors);

production and/or trade in weapons, ammunition, military equipment and military vehicles (their parts);

mining of ores and/or precious stones;

extraction of crude oil, natural gas and/or production of petroleum products;

types of activities that require obtaining special permits for the use of subsoil within the territory of Ukraine, its continental shelf and exclusive (maritime) economic zone;

public procurement.

4. Risk criteria that are determined by the specifics related to the legal form of establishment, ownership structure and customer behavior, in particular, are as follows:

1) the business entity is a new client of the institution, with whom less than three months have passed since the date of establishment of business relations;

2) the client issues or has the right to issue bearer shares (equity securities);

3) a legal entity whose ownership or control structure or membership is unusually complex;

4) there is an element of nominal management/ownership in the client's management or ownership structure;

5) there are trust relationships in the client's ownership structure;

6) the client's financial transactions are complex, unusually large for his activities or do not correspond to his financial condition;

7) there are grounds to believe that the client is using financial transaction fragmentation - artificial structuring (dividing) the amount of a financial transaction, the maximum size of which is determined by the relevant requirements and restrictions provided for by the AML/CFT legislation, into several interconnected financial transactions carried out for smaller amounts, in order to avoid certain thresholds/requirements specified by the AML/CFT legislation;

8) there are grounds to believe that there is a regular implementation by the client of financial transactions regarding the initiation/reception of transfers of funds - the implementation (conducting) of a transfer of funds by one initiator (payer)/recipient five or more times a day (except for transfers defined by part eighteen of Article 14 of the Law on AML/CFT) in order to avoid certain thresholds/requirements defined by the legislation on AML/CFT;

9) the client unreasonably delays the deadlines for providing information for the institution to carry out due diligence, tries to hide as much as possible from the institution details of its business activities;

10) available information about the client gives reason to suspect that the client may be a shell company.

To refute/confirm that a client is a shell company, the institution shall take into account at least the criteria specified in paragraph 5 of Section I of Annex 18 to the Regulation.

5. Risk criteria that may indicate that a client [beneficiary (beneficiary) under his life insurance contract] is a shell company include, in particular:

1) reputation criteria:

The CBO of a legal entity is a manager, accountant or signatory;

The CEO of a legal entity is a participant in many other legal entities, in some of which he is the manager and/or accountant/signatory (authorized based on the act of the legal entity, agreement and power of attorney);

the charter of the legal entity contains restrictions on the powers of the manager who is a KBV (provided that the KBV owns a share of more than 50 percent of the authorized capital of this legal entity);

the conclusion of transactions or the application of a third party for a power of attorney in connection with the limited legal capacity of the individual, imprisonment or military service;

availability of information about open criminal proceedings investigating crimes in the field of economic activity against the owner of a significant stake/controller or legal entity, its managers and/or representatives;

availability of information about the influence and coordination of actions by third parties on the decision-making of the Board of Directors regarding the economic activities of the legal entity;

uncertainty, lack of awareness of the Board of Directors in matters of planning the further business activities of the legal entity, its strategic goals, distribution and use of dividends;

there is information about repeated restrictions on the rights of the owner of a significant stake / controller of a legal entity and/or the legal entity itself regarding the disposal of funds placed on his/her account(s), the bank's seizure of funds stored on the account of the client - legal entity, suspension (further suspension, continued suspension) of the implementation of a financial transaction (s) of the client - legal entity at the initiative of the banks / specially authorized body;

inconsistency of the circle of communication or communicative level of communication (including the predominant use of template language structures with references to legislative acts to avoid providing clear answers) of the owner of a significant stake / KBV with the content and type of activity of the legal entity;

2) registration criteria:

the address of the legal entity coincides with the address of mass registration of taxpayers (except for the addresses of business centers);

the place of registration of the owners of a significant stake / CCP is a state (jurisdiction) included by the Cabinet of Ministers of Ukraine in the list of offshore zones or whose legislation provides for a mechanism of nominal/trust ownership;

there are facts of repeated changes in the Board of Directors and/or the head of the legal entity, and/or changes in the name of the legal entity in the absence of signs of economic feasibility of such changes;

availability of information on the registration of a legal entity based on stolen, lost documents or documents of persons who have died or who do not exist;

The head of a legal entity is the person:

who belong to socially vulnerable groups of the population (students, pensioners, those on leave to care for a child until he or she reaches the age of three);

with a specific social status (poor, beggars);

young (under 20 years old) or elderly (after 75 years old);

which is registered in the territory not controlled by Ukraine (temporarily occupied territory in Donetsk and Luhansk regions, the Autonomous Republic of Crimea and the city of Sevastopol);

the location of the legal entity is an apartment at an address that is the location of another legal entity, the participant(s) of which are not owners or associates of the owner of such apartment;

there is information that the owner of a significant stake/controller of the legal entity did not take any action to register the legal entity and the registration of the legal entity took place without his knowledge;

the location of the legal entity is a fictitious address;

there are facts of a change in the Board of Directors or the head of a legal entity that belonged/belongs to public figures;

3) operational criteria:

the legal entity does not have (in its ownership or use) production facilities / commercial and warehouse premises, other assets necessary for conducting the declared economic activity, or the volumes of economic activity are not comparable with the volumes of available assets;

there is information that the legal entity does not comply with the legislative requirements for submitting reports to fiscal authorities / statistical authorities;

the number of employees (including those working under civil law agreements, in particular contract agreements) of a legal entity does not correspond to the type and scope of its activities;

a legal entity mainly uses the following means of payment: bill of exchange, barter, assignment of claims, etc. (provided that such transactions are not present in the types of activity);

there is no income or it is generated mainly from non-core (non-core) activities;

operating cash flows have been negative for the past few years and/or the business is financed primarily through financial assistance;

the presence of significant external and/or internal long-term borrowings from individuals and/or legal entities (except banks) that are not part of the ownership structure, including its unspecified CBV (except for bonds).

6. The risk criteria determined by the reputation of the client, his/her CBV or the beneficiary (beneficiary) under his/her life insurance contract, in particular, are as follows:

1) there is negative information about him in official and/or public sources, indicating a possible connection with terrorism or other criminal/illegal activities;

2) his funds are frozen or seized in connection with criminal proceedings related to ML/TF;

3) the institution has repeatedly informed the OMS about the client's financial transactions in connection with its suspicions.

When analyzing information from public sources, the institution must take into account the authority of such a source in terms of its reliability and independence, as well as the quality of the materials presented.

II. Geographic risk criteria↑

7. Geographic risk criteria are ML/TF risk criteria inherent in the cooperation between an institution and a client who [whose CBO or beneficiary (beneficiary) under a life insurance contract] is associated with a country (territory) in which economic, social, legal or political conditions may give rise to a high level of ML/TF risk.

8. When developing its own geographical risk criteria, the institution should, in particular, take into account:

1) the state (territory) of residency, citizenship, registration, location of the client, his/her CBI, key counterparties of the client, beneficiary (beneficiary) under his/her life insurance contract;

2) the state (territory) in which the client's main economic activity is carried out;

3) the country (territory) of origin of the client, their CCP and the country (territory) in which they have significant personal or business connections;

4) states (territories):

that are included by the Cabinet of Ministers of Ukraine in the list of offshore zones;

that are included in the list of states that do not comply with FATF recommendations (blacklist);

that have strategic AML/CFT deficiencies in accordance with FATF statements (grey list);

that are identified by the European Commission as countries with weak AML/CFT regimes;

which are characterized by an increased risk of corruption;

which are characterized by an increased risk of terrorist financing.

To create a list of countries with an increased risk of corruption, an institution may use, for example, the national corruption risk assessment provided by Transparency International, and to list countries with an increased risk of terrorist financing, the Institute for Economics and Peace's Global Terrorism Index Report.

III. Risk criteria by type of service (product)↑

9. Risk criteria by type of service (product) are ML/TF risk criteria inherent in the relevant service (product) of the institution.

10. When developing its own risk criteria by type of service (product), the institution must take into account:

1) the level of transparency of the service (product);

2) the level of complexity of the service (product);

3) the potential amount (turnover) of funds that can be used by the client using the service (product).

11. The risk criteria inherent in the relevant service (product) of the institution, in particular, are as follows:

1) the client wishes to use the services of the institution on the terms of individual service for wealthy clients - individuals, who are characterized by the following elements:

the planned or actual annual turnover of financial transactions exceeds 10 million hryvnias;

services include comprehensive asset management, including advice on financial planning, investment, tax issues and succession;

special lending conditions are provided and special terms and conditions for servicing such clients and their financial transactions are developed, and there is also a strengthened confidentiality policy for information about such clients and their financial transactions;

2) the client receives loans secured by financial instruments or other guarantees of the institution, except in cases of repo transactions;

3) the client uses asset management services (fiduciary services);

4) the client uses products (services) that have at least one of the following characteristics:

the product (service) promotes customer anonymity (e.g., electronic money, prepaid cards);

the product (service) is complex in terms of the possibility of tracking the transaction [in particular, transfers carried out with the involvement of a large number of intermediaries, "fast" electronic services (international transactions carried out with electronic money)];

conducting financial transactions for unusually large amounts (or total turnover), which is unusual for the client's known activity;

instructions for conducting a financial transaction are provided by a third party who is not a party to the business relationship;

a large proportion of cash transactions, which is unusual for the client's type of activity;

the ability to carry out complex large-scale operations with a large number of participants involved.

IV. Risk criteria by service (product) delivery channel↑

12. Risk criteria by service (product) delivery channel are ML/TF risk criteria inherent in the service (product) delivery channel, i.e. the way in which the client receives and uses the service (product).

13. When developing its own risk criteria for the service (product) supply channel, the institution must take into account, in particular, the following risk criteria:

1) agents who are not SPFMs are involved in the client identification and verification process;

2) the institution used the submission tool to identify and verify the client (client representative);

3) the provision of financial services is based on technological solutions that in some way limit the institution's capabilities in terms of process management and decision-making efficiency.

Annex 19
to the Regulation on the implementation
of financial monitoring by institutions

INDICATORS
of suspicious financial transactions

I. Indicators related to client activity or behavior↑

1. The client (client's representative) cannot clearly explain what his business activity (nature of the activity) consists of.

2. The client (client's representative) is unwilling or refuses to provide the information required to take due diligence measures, provides it insufficiently, or provides questionable information that is difficult to verify.

3. There are grounds to suspect that the information/documents provided for the NPC contain false or falsified information (in particular, significant inconsistencies are obvious, significant errors have been made).

4. It is impossible to contact the client (client representative) using the data provided by him, in particular at the address of location, residence or at the specified telephone number and e-mail (especially in a short time after providing such contact information).

5. The client (client representative) is nervous for no apparent reason or exhibits atypical behavior.

6. The client demonstrates unusual interest in the requirements of the AML/CFT legislation and the institution's internal AML/CFT system (in particular, the institution's internal documents on AML/CFT issues).

7. The client (client's representative) cancels the planned financial transaction after the institution has requested relevant supporting documents and/or clarifications from him.

8. The client (client's representative) insists on the urgency of carrying out a financial transaction, demonstrating nervous behavior, without any obvious reasons (grounds) for this.

9. A client (client representative) offers money, gifts, or other form of gratitude to an employee of an institution for conducting a financial transaction in an unusual or suspicious manner.

10. The information provided by the client (client's representative) contradicts that contained in public sources.

11. The financial transactions of an individual do not correspond to the client's risk profile (in particular, age, profession, income).

12. The client demonstrates ignorance of information related to his financial transactions and/or cannot explain their content.

13. The client unusually and excessively justifies or explains the financial transaction, emphasizing the absence of any connection with illegal activity.

14. The nature of the financial transaction and/or the circumstances under which it is initiated give reason to believe that it is being carried out on behalf of and/or for the benefit of another party whose identity is not disclosed to the institution.

15. The same representative acts on behalf of several clients, between whom there are no logically explained relationships.

16. The representative of the client - an individual - does not have a clear and understandable relationship with the client (for example, the person is not a relative, family member, lawyer).

17. Representatives of the client - a business entity, as much as possible, avoid contact with employees of the institution [visiting the institution (a separate unit of the institution)], even when under normal conditions of conducting a financial transaction(s) this would be much more convenient for them.

18. There are obvious signs that other persons are controlling the financial transaction [the client reads everything from notes or the phone or other persons are watching the client inside the institution's premises (a separate unit of the institution) or from outside].

19. The purpose or motivation for receiving services in Ukraine by non-residents is unconvincing or unclear.

20. The client constantly insists on being served by one employee of the institution (separate unit of the institution), even if these are routine transactions, and/or stops carrying out financial transactions through the institution (separate unit of the institution) for the period of absence of a specific employee.

II. Indicators related to the client's financial transactions↑

21. For a long time, a similar trend has been observed regarding the volume of a client's financial transactions within one day (unusually rapid execution of financial transactions for large amounts).

22. Conducting several financial transactions by a client within one day in an institution (one separate unit of the institution), but with an obvious attempt to be served by different employees of the institution (client manager or cashier).

23. The financial transaction/set of related financial transactions is/are not typical of the client's usual activities (e.g., the objectives, type and volume of the transaction), and the explanations provided are not substantiated.

24. The client's counterparties are persons about whom the institution has negative information [in particular, persons with whom the institution has refused to establish (maintain) business relations due to the assignment of an unacceptably high ML/TF risk].

25. There have been significant changes in the volume of financial transactions carried out by the client/for the benefit of the client.

26. The client regularly makes or receives a significant number of transfers.

27. Regular receipt of funds from abroad and/or transfer of funds abroad, if the purpose of such transfers is not obvious or the set of such financial transactions is of an unusual nature.

28. Transfers outside Ukraine made by several different clients on the same day or within three days have signs of connection [in particular, similar in amount, sender/recipient names, test questions, free message texts, and recipient countries (territories)].

29. The sender of the transfer does not have sufficient information about the recipient to whom the transfer is being sent, or the recipient does not have sufficient information about the sender of the transfer.

30. A significant number of transfers from individuals / business entities / non-profit (including charitable) organizations are used to collect and further transfer funds to a small number of non-resident recipients.

31. The intermediary institution or the institution of the recipient of the payment refused to execute the client's payment and returned the funds to the client who initiated the payment.

32. The transfer comes from a PFMS that is known to not provide information about the payer and/or beneficiary without proper justification.

33. A client receives many cash or non-cash payments for small amounts through an institution, which are subsequently aggregated and transferred to another client in a large amount.

34. The client (legal entity) mainly receives non-cash payments in its own favor through the institution and the institution becomes aware that it is paying cash to other persons.

35. Conducting large-scale financial transactions with cash by the client that are not related to the client's main activity, and/or conducting a significant number of transactions using electronic payment instruments.

36. Conducting so-called return transfers, i.e. when funds received from a person from a foreign state (territory) are immediately transferred to another person from the same state (territory), or to the sender's account in another state (territory).

37. Transfers are routed for payment to separate branches of the institution located very close to the borders of countries with an increased risk of terrorism.

38. Repeated financial transactions under agreements of assignment of claims (debt transfer) in favor of the client.

39. Payments made on the initiative/in favor of a client - a business entity - usually do not contain a clear and unambiguous purpose in their designations (in particular, they usually contain only references to contract or invoice numbers, without specifying the type of goods or services).

40. A client (business entity) that has entered into an agreement with an institution to accept regular payments from individuals receives payments whose content clearly does not correspond to the content and type of its activity.

41. Regular payments are received in favor of a client (business entity) who has concluded an agreement with an institution to accept regular payments from individuals, the reason and purpose of which are unclear.

42. The retailer's declared and/or actual transaction volumes, individual transaction amounts, customer refunds/reimbursements (in the event of a product return) do not correspond to the usual practice of retailers in the same industry (competitors).

43. A client purchases a large number of prepaid cards for a significant amount.

44. Concluding an agreement for accepting online payments with a client who does not have any activities related to online trading or online auctions, or other similar activities.

45. Conducting financial transactions for significant amounts, on the initiative of/for the benefit of an individual, the nature of which is inherent in commercial activities.

46. Significant discrepancy between payment/receipt details and the data specified in the relevant supporting documents (e.g. contract number, type and name of the product or service).

III. Indicators for different types of products (services)↑

47. Cash transactions:

1) the volume of cash transactions does not correspond to the volume inherent in the type and scale of the client's activities;

2) the client carries out regular financial transactions in cash for large rounded amounts;

3) the client regularly exchanges a large number of low-denomination banknotes for high-denomination banknotes;

4) the client deposits significant amounts of cash, the source of which is indicated as proceeds from the sale of assets, but cannot confirm this with documentation;

5) regular cash financial transactions for the purchase, sale or conversion of foreign currency for large amounts;

6) conducting a significant number of financial transactions involving the deposit of cash in small amounts in favor of one recipient through various separate divisions of the institution or by a group of persons who simultaneously apply to one separate division of the institution;

7) conducting a large number of financial transactions involving the deposit of cash by one client within a short period of time using self-service bank machines for a total significant amount;

8) the cash financial transaction is conducted (structured) in such a way as to circumvent the requirements required when conducting the relevant threshold financial transactions.

48. Credits / financial credits / loans:

1) the client is not interested in the material terms of the loan (in particular, interest rate, penalties) or the costs associated with repaying the loan / financial credit / loan;

2) the client is reluctant to provide information about the purpose of the credit / financial loan / loan or the stated purpose is questionable;

3) the client indicates that the source of funds related to the fulfillment of obligations under the loan / financial credit / loan is a foreign source and is reluctant to provide an explanation;

4) the client intends to obtain a credit / financial credit / loan, while providing financial statements containing information on investments or income from companies registered in states (territories) included by the Cabinet of Ministers of Ukraine in the list of offshore zones, or whose legislation provides for a mechanism of nominal / trust ownership;

5) the economic feasibility of obtaining a credit / financial loan / loan is not clear;

6) the collateral for the client's credit / financial loan / loan is assets belonging to third parties who are not related to the client;

7) the collateral for the credit / financial loan / loan of the client is his own assets / property, the source of origin of which is unknown;

8) the credit / financial credit / loan is repaid with funds belonging to a third party, in the absence of a rational justification for its connection with the client;

9) the client uses the issued credit / financial credit / loan not in accordance with the approved purposes, carrying out operations that are atypical for the client's activities;

10) the client repays a long-overdue credit/financial loan/loan with funds whose sources of origin are unclear;

11) the client repays a long-term loan / financial credit / loan in an unusually short period of time after receiving it;

12) an increase in the number of cases of the client obtaining large amounts of credits / financial credits / loans, unless it is established that such behavior is justified / typical for the client;

13) the client receives several credits / financial credits / loans for a small amount each within a short period of time, but the total amount of which exceeds the threshold amount of financial transactions subject to financial monitoring, and the obligations under such credits / financial credits / loans are fulfilled in full before the payment deadline in accordance with the concluded agreement;

14) the client repeatedly receives credits / financial credits / loans for amounts below the threshold established for financial transactions subject to financial monitoring, in order to avoid reporting on such financial transactions, as well as in order to evade the application of CDD requirements to him;

15) the client applies to the institution for a loan / financial credit / loan for a significant amount (approximately several million hryvnias) and/or for a short period of use, the information available to the institution about the client's financial condition indicates that such person does not have sufficient financial capabilities to fulfill obligations under the loan / financial credit / loan;

16) the client returns funds in a significantly larger amount than is necessary to fulfill the obligation under the credit / financial loan / loan, without trying to count them;

17) the client applies for a credit / financial loan / loan for an amount that is significantly different from the amounts of credits / financial loans / loans received by him previously;

18) early fulfillment of an obligation under a credit / financial loan / loan by making a lump sum payment in an amount that does not correspond to the client's financial situation;

19) in order to pay off the debt on a credit / financial loan / loan, the client provides funds in high-denomination banknotes in a large amount;

20) in order to pay off a debt on a credit / financial loan / loan, the client provides banknotes in unusual packaging;

21) the collateral for a credit / financial loan / loan in a significant amount provided to the client is the funds placed on deposit by him.

49. Insurance/reinsurance services:

1) a client's request to conclude insurance/reinsurance contracts on obviously unfavorable terms for the parties to such contracts, as well as making significant changes to the main terms of the insurance/reinsurance contract, in particular within a short period of time;

2) a client's request for an increase, without obvious necessity, of the insured amount established when concluding the insurance contract;

3) a client's request for concluding insurance/reinsurance contracts with insurance amounts that do not correspond to the potential risk;

4) payment of insurance premiums in amounts significantly exceeding the amounts of insurance premiums specified in the insurance contract;

5) a client's request for property insurance, the total cost of which does not correspond to the client's financial situation;

6) occurrence of an insured event within a short period of time after the conclusion of the insurance contract;

7) using significant amounts of cash when paying insurance premiums;

8) provision by the client of documents that are the basis for payment of insurance benefits that have signs of forgery;

9) payment of insurance premiums through third parties and/or by third parties;

10) conclusion of insurance contracts for risks that are unusual or impossible for the object of insurance;

11) the client frequently and/or unexpectedly initiates early termination of the life insurance contract and transfers the redemption amount to his own accounts in various banks or in favor of a third party;

12) insurance payments are made in favor of persons who are not insured persons or beneficiaries (beneficiaries) under the relevant insurance contract;

13) the client pays insurance premiums for amounts below the threshold established for financial transactions subject to financial monitoring, in order to avoid reporting on such financial transactions, as well as in order to evade the application of the requirements for the implementation of the CDD to him;

14) the age of the client is unusual for the type of insurance product in question (for example, the client is too young or elderly);

15) the client often changes insurers;

16) the client frequently changes accounts used to pay insurance premiums or insurance benefits.

50. Financial leasing services:

1) the purpose of concluding a financial leasing agreement is not justified from the point of view of the intended use of the leasing object (for example, it does not correspond to the essence of the client's activities);

2) the client fulfills obligations under the financial leasing agreement using funds received from states (territories) included by the Cabinet of Ministers of Ukraine in the list of offshore zones or whose legislation provides for a mechanism of nominal/trust ownership;

3) providing the lessee client with a guarantee under the terms of which payment is made through a financial institution registered in a state (territory) included by the Cabinet of Ministers of Ukraine in the list of offshore zones or included in the list of states that do not comply with FATF recommendations (black list);

4) the lessee client offers to conclude a financial leasing agreement at a price significantly exceeding the normal market price of such a leasing object;

5) a third party pays leasing payments on behalf of the client without reasonable grounds.

51. Factoring services:

1) the client who assigns the right of monetary claim against the buyer (debtor) to the factor is known to frequently change counterparties, while the usual business activities of such buyer (debtor) do not correspond to the type of goods/services that were purchased from the client;

2) the client additionally and/or unexpectedly offers to cede to the factor the right to a monetary claim against the buyer (debtor) also for another transaction/type of goods (services) that does not correspond to the type of usual economic activity of such buyer (debtor);

3) the factor has reason to believe that the client proposes to conclude an agreement on the assignment of the right of claim to the buyer (debtor), which is a newly established company that will cease operations shortly after the conclusion of the agreement;

4) the factor became aware that the client was offering to assign the right of claim against the buyer (debtor) also to other factoring companies, while at the same time providing various information that contradicts the available information about the buyer (debtor), guarantors, primary documentation, customs documentation and other aspects of the economic activities of the participants in financial transactions;

5) the client offers unusually favorable rules for calculating fees under the factoring agreement (interest and fees) for the factor and, in turn, wants to receive more flexible financing terms;

6) the client proposes to involve a third party with a dubious reputation as a guarantor/surety;

7) the client often makes proposals for amendments to the factoring agreement regarding the procedure for the factor to fulfill its obligations under the agreement;

8) the client with whom the factoring agreement is concluded is a foreign company operating in the markets of states (territories) included by the Cabinet of Ministers of Ukraine in the list of offshore zones, or states included in the list of states that do not comply with FATF recommendations (black list);

9) the buyer (debtor) fulfills obligations under the relevant agreement to the factor using a bank account in a jurisdiction that differs from the jurisdiction of registration of such debtor, for example, in states (territories) included by the Cabinet of Ministers of Ukraine in the list of offshore zones or whose legislation provides for a mechanism of nominal/trust ownership, or in states included in the list of states that do not comply with FATF recommendations (black list);

10) the client proposes to conclude an agreement on the assignment of the right of claim against the buyer (debtor), regarding which the factor immediately has doubts about the debtor's fulfillment of the obligation / the possibility of collecting the relevant debt from the debtor;

11) the price of the contract in respect of which the right to a monetary claim is assigned does not correspond to the market price;

12) the contract between the client and the buyer (debtor) provides for the inclusion in the supply chain of goods of an intermediary doing business in a country other than the country of the buyer and the seller, in the absence of obvious reasons for using such an intermediary (there are no obvious obstacles to the direct supply of goods between the seller and the buyer);

13) the assignment of the right to a monetary claim under a contract is provided for, where the seller, buyer and intermediary for the supply of goods are related parties, or all participants in the supply chain of goods belong to the same group of companies.

52. Online services:

1) the client contacts the same agent to open electronic wallets / purchase prepaid cards from different issuers, often replenishes the corresponding wallet/prepaid card or withdraws cash several times in a short period of time and in the absence of a rational explanation for this;

2) different representatives of several unrelated customers use the same IP (Internet Protocol) addresses to access the online service;

3) there are reasons to believe that a third party is using the client's online service (for example, access to the online service is initiated from outside Ukraine, while the institution has information about the client's presence in Ukraine).

Annex 20
to the Regulation on the implementation
of financial monitoring by institutions

LETTER-MESSAGE
on freezing/thawing assets

(choose)

from "___" ____________ No.

Table

No. of the company

Attribute

Information

1

2

3

I. Information about the institution providing the information

1

Name of the institution

2

Code according to EDRPOU

3

Contact number of the responsible employee of the institution

4

Email for feedback

II. Information about the person whose assets are frozen/thawed

5

Terrorist List Entry Number (C1)

6

Full name [(last name, first name, patronymic (if available)]

7

Available personal identification data

8

Additional information (if available), in particular regarding the connection of the person whose assets are frozen (were frozen) with a person on the terrorist list (if the person whose assets are being frozen is not a person included in the terrorist list)

III. Information on frozen/thawed assets

9

Date and time of freezing/unfreezing of assets

10

Grounds for freezing/thawing assets

11

Asset type

12

Amounts of frozen/thawed assets

13

Numbers and dates of conclusion of contracts for the provision of services by the institution, types of assets that are the subject of such contracts, and the amounts for which they are concluded (if any)

14

Information on financial transactions with terrorist assets without establishing a business relationship (if available): name, number and date of the primary document; date of initiation of the financial transaction; date of freezing of assets

15

Additional information (if available)

16

Attachments (if available)

Responsible employee of the institution

____________
(signature)

Full name

Annex 21
to the Regulation on the implementation
of financial monitoring by institutions

EXAMPLE of
a schematic representation of the ownership structure of a client - a legal entity

Annex 22
to the Regulation on the implementation
of financial monitoring by institutions

QUESTIONNAIRE
for a client - legal entity - resident

The questionnaire for a client - a legal entity - a resident must contain the following information:

1. Full and abbreviated (if available) name.

2. Organizational and legal form.

3. Form of ownership.

4. Location.

5. Number of employees.

6. Code according to the Unified State Register of Educational Institutions.

7. Date of state registration.

8. Date and number of entry in the Unified State Register.

9. Contact telephone and fax numbers.

10. Information about separate units (branches, representative offices, offices or other separate units).

11. Email address (if available).

12. Date of establishment of business relations / execution of a financial transaction for a significant amount without establishment of business relations.

13. Risk level of business relationships (conducting financial transactions without establishing a business relationship). Information is provided separately for each established risk level, indicating the date of establishment/change.

14. Date of initial completion of the questionnaire.

15. Date/method of verification of the client (client representative).

16. Information on the institution's adoption of other CDD measures (in particular, updating client data, PZNP, results of monitoring financial transactions).

17. Date of last changes to the questionnaire.

18. Identification data of persons who have the right to dispose of the client's property; identification data of the client's representative (except for other persons who are in an employment relationship with the client).

19. Data on the executive body.

20. Surname, first name, patronymic (if any) of the manager or person entrusted with the functions of management and control of economic activities.

21. Data that allows establishing the KBV (or an indication of the fact of their absence), and the date of detection of discrepancies in the information on KBV placed in the Unified State Register (if there are such discrepancies).

22. Data on the ownership structure (direct ownership) indicating the ownership share and the date of detection of discrepancies with the information on the ownership structure posted in the Unified State Register (if there are such discrepancies).

23. Information on the client's PEP status:

1) the date of discovery of the relevant fact;

2) date of receipt of permission from the head of the institution to establish/continue business (contractual) relations;

3) indication of belonging to a PEP (the PEP is a politically exposed person, a member of their family, or a person associated with a politically exposed person) and the position of the relevant politically exposed person;

4) the date from which the institution ceased to take the measures specified in part fourteen of Article 11 of the AML/CFT Law.

24. Information about the parent company, corporation, holding group, industrial and financial group or other association of which the client is a member, subsidiaries.

25. Amount of authorized capital.

26. Type(s) of business (economic) activity.

27. Content/essence of the activity.

28. Institution services (products) used by the client.

29. Accounts opened in banks, including in other countries (bank name, its code, account number).

30. Date of refusal to establish/maintain (terminate) business (contractual) relations.

31. Date of asset freeze.

32. Date of unfreezing of assets.

{Appendix 22 with amendments made in accordance with the Resolutions of the National Bank No. 198 of 12/29/2023 , No. 121 of 10/05/2024 }

Annex 23
to the Regulation on the implementation
of financial monitoring by institutions

QUESTIONNAIRE
for a client - a legal entity - a non-resident (trust or other similar legal entity)

The questionnaire for a client - a legal entity - a non-resident (trust or other similar legal entity) must contain the following information:

1. Full and abbreviated (if available) name.

2. Form of ownership.

3. Country of registration.

4. Registration date.

5. Registration authority.

6. Details of the registration certificate or extract from the bank, trade or court register.

7. Location.

8. Information about separate units (branches, representative offices, offices or other separate units).

9. Number of employees.

10. Contact phone numbers.

11. Email address (if available).

12. Date of establishment of business relations.

13. Risk level of business relationships (conducting financial transactions without establishing a business relationship). Information is provided separately for each established risk level, indicating the date of establishment/change.

14. Date of initial completion of the questionnaire.

15. Date/method of verification of the client (client representative).

16. Information on the institution's adoption of other CDD measures (in particular, updating client data, PZNP, results of monitoring financial transactions).

17. Date of last changes to the questionnaire.

18. Identification data of persons who have the right to dispose of the client's property; identification data of the client's representative (except for other persons who are in an employment relationship with the client).

19. Information about the executive body.

20. Surname, first name, patronymic (if any) of the manager or person entrusted with the functions of management and control of economic activities.

21. Data that allows establishing the CBV (or indicating the fact of their absence).

22. Data on the ownership structure (direct ownership) with an indication of the ownership share.

23. Information on the client's PEP status:

1) the date of discovery of the relevant fact;

2) date of receipt of permission from the head of the institution to establish/continue business (contractual) relations;

3) indication of belonging to a PEP (the PEP is a politically exposed person, a member of their family, or a person associated with a politically exposed person) and the position of the relevant politically exposed person;

4) the date from which the institution ceased to take the measures specified in part fourteen of Article 11 of the AML/CFT Law.

24. Information about the parent company, corporation, holding group, industrial and financial group or other association of which the client is a member.

25. Amount of authorized capital.

26. Type(s) of business (economic) activity.

27. Content/essence of the activity.

28. Institutional services (products) used by the client.

29. Accounts opened in banks, including in other countries (bank name, code, account number). To be filled in if such information is available.

30. Date of refusal to establish/maintain (terminate) business (contractual) relations.

31. Date of asset freeze.

32. Date of unfreezing of assets.

{Appendix 23 with amendments made in accordance with the Resolution of the National Bank No. 198 of 29.12.2023 }

Annex 24
to the Regulation on the implementation
of financial monitoring by institutions

QUESTIONNAIRE
for a client - representative office of a legal entity - non-resident

The client's questionnaire - a representative office of a non-resident legal entity - must contain the following information:

1. Full and abbreviated (if available) name.

2. Location.

3. Data on registration as a payer of income tax [registration (accounting) number, date of registration, registration authority] - if available.

4. Type(s) of business (economic) activity.

5. Content/essence of the activity.

6. Licenses (permits) for the right to carry out certain operations (activities) (name, series, numbers, by whom issued, validity period).

7. Institution services (products) used by the client.

8. Identification data of persons who have the right to dispose of the client's property, identification data of the client's representative.

9. Contact phone numbers.

10. Email address (if available).

11. Date of establishment of business relations.

12. Accounts opened in banks (bank name, code, account number).

13. Risk level of business relationships (conducting financial transactions without establishing a business relationship). Information is provided separately for each established risk level, indicating the date of establishment/change.

14. Date of initial completion of the questionnaire.

15. Date/method of verification of the client (client representative).

16. Data on the institution's adoption of other CDD measures (in particular, updating client data, PZNP of the results of monitoring financial transactions).

17. Date of last changes to the questionnaire.

18. Full and abbreviated (if available) name of the non-resident legal entity.

19. Organizational and legal form of a non-resident legal entity.

20. Form of ownership of a non-resident legal entity.

21. Country of registration of the non-resident legal entity.

22. Date of registration of a non-resident legal entity.

23. Registration authority of a non-resident legal entity.

24. Details of the registration certificate or extract from the bank, trade or court register.

25. Location of a non-resident legal entity.

26. Information on separate divisions (branches, representative offices, departments or other separate divisions) of a non-resident legal entity.

27. Identification data of persons who have the right to dispose of the property of a non-resident legal entity.

28. Contact phone numbers of a non-resident legal entity.

29. Email address of the non-resident legal entity (if available).

30. Data on the executive body of a non-resident legal entity.

31. Surname, first name, patronymic (if any) of the manager or person entrusted with the functions of management and control of the economic activities of the non-resident legal entity.

32. Data that allows establishing the CBI of a non-resident legal entity (or an indication of the fact of their absence).

33. Data on the ownership structure (direct ownership) indicating the share of ownership of the non-resident legal entity.

34. Information on the client's PEP status:

1) the date of discovery of the relevant fact;

2) date of receipt of permission from the head of the institution to establish/continue business (contractual) relations;

3) indication of belonging to a PEP (the PEP is a politically exposed person, a member of their family, or a person associated with a politically exposed person) and the position of the relevant politically exposed person;

4) the date from which the institution ceased to take the measures specified in part fourteen of Article 11 of the AML/CFT Law.

35. Information about the parent company, corporation, holding group, industrial and financial group or other association of which the client is a member.

36. The amount of the authorized capital of a non-resident legal entity.

37. Type(s) of business (economic) activity of a non-resident legal entity.

38. Content of activities of a non-resident legal entity.

39. Date of refusal to establish/maintain (terminate) business (contractual) relations.

40. Date of freezing of assets.

41. Date of unfreezing of assets.

{Appendix 24 with amendments made in accordance with the Resolution of the National Bank No. 198 of 29.12.2023 }

Annex 25
to the Regulation on the implementation
of financial monitoring by institutions

QUESTIONNAIRE
for a client - an individual

The questionnaire for a client - an individual must contain the following information:

1. Last name, first name, patronymic (if available).

2. Date of birth.

3. Place of birth (if available).

4. Citizenship (for non-residents).

5. Place of residence or stay.

6. Information about the identification document.

7. Place of temporary stay in Ukraine (for non-residents).

8. RNOKPP or the number (and, if available, the series) of the passport of a citizen of Ukraine, in which a note is made about the refusal to accept the RNOKPP, or the number of the passport with a note about the refusal to accept the RNOKPP in an electronic contactless medium.

9. Unique record number in the Unified State Demographic Register (if available).

10. Place of work, position.

11. Contact phone numbers.

12. Email address (if available).

13. Date of establishment of business relations / first one-time financial transaction for a significant amount.

14. Business relationship risk level (conducting financial transactions without establishing a business relationship). Information is provided separately for each established risk level, indicating the date of establishment/change.

15. Date of initial completion of the questionnaire.

16. Date/method of verification of the client (client representative).

17. Information on the institution's adoption of other CDD measures (in particular, updating client data, PZNP of the results of monitoring financial transactions).

18. Date of last changes to the questionnaire.

19. Identification data of the client's representative(s).

20. Data on the registration of an individual as an entrepreneur (for clients - individuals engaged in entrepreneurial activities) - if available.

21. Type of business activity (for clients - individuals engaged in business activities) - if available.

22. Types of independent professional activity (for clients - individuals who conduct independent professional activity) - if available.

23. Types of services used by the client.

24. Information on the client's PEP status:

1) connection with politically exposed persons (a politically exposed person, a family member of a politically exposed person, or a person associated with a politically exposed person);

2) category of positions of politically exposed persons;

3) surname, first name, patronymic (if any) of the politically exposed person (to be indicated if the client himself is not a politically exposed person), other identification data (if any) and residency status of such politically exposed person;

4) the date of discovery of the relevant fact;

5) date of receipt of permission from the head of the institution to establish/continue business (contractual) relations;

6) the date from which the institution ceased to take the measures specified in part fourteen of Article 11 of the AML/CFT Law.

25. Data on the institution's adoption of other CDD measures (in particular, updating client data, PZNP, results of monitoring financial transactions).

26. Date of refusal to establish/maintain (terminate) business (contractual) relations.

27. Date of freezing of assets.

28. Date of unfreezing of assets.

{Appendix 25 with amendments made in accordance with the Resolution of the National Bank No. 198 of 29.12.2023 }

Annex 26
to the Regulation on the implementation
of financial monitoring by institutions

QUESTIONNAIRE
for a client - individual - entrepreneur

The questionnaire for a client - an individual - an entrepreneur must contain the following information:

1. Last name, first name, patronymic (if available).

2. Date of birth.

3. Place of birth (if available).

4. Citizenship.

5. Place of residence or place of stay.

6. Information about the identification document.

7. Place of temporary stay in Ukraine (for non-residents).

8. RNOKPP or the number (and, if available, the series) of the passport of a citizen of Ukraine, in which a note is made about the refusal to accept the RNOKPP, or the number of the passport with a note about the refusal to accept the RNOKPP in an electronic contactless medium.

9. Unique record number in the Unified State Demographic Register (if available).

10. Date and number of entry in the Unified State Register.

11. Contact phone numbers.

12. Email address (if available).

13. Date of establishment of business relations / implementation of a one-time financial transaction for a significant amount.

14. Business relationship risk level (conducting financial transactions without establishing a business relationship). Information is provided separately for each established risk level, indicating the date of establishment/change.

15. Date of initial completion of the questionnaire.

16. Date/method of verification of the client (client representative).

17. Data on the institution's adoption of other CDD measures (in particular, updating client data, PZNP, results of monitoring financial transactions).

18. Date of last changes to the questionnaire.

19. Type(s) of business activity.

20. Content/essence of the activity.

21. Licenses (permits) for the right to carry out certain operations (activities) (name, series, numbers, by whom issued, validity period).

22. Identification data of the client representative.

23. Types of services used by the client.

24. Client accounts opened in banks (bank name, bank code, account number). To be filled in if such information is available.

25. Information on the client's PEP status:

1) connection with politically exposed persons (a politically exposed person, a family member of a politically exposed person, or a person associated with a politically exposed person);

2) category of positions of politically exposed persons;

3) surname, first name, patronymic (if any) of the politically exposed person (to be indicated if the client himself is not a politically exposed person), other identification data (if any) and residency status of such politically exposed person;

4) the date of discovery of the relevant fact;

5) date of receipt of permission from the head of the institution to establish/continue business (contractual) relations;

6) the date from which the institution ceased to take the measures specified in part fourteen of Article 11 of the AML/CFT Law.

26. Date of refusal to establish/maintain (terminate) business (contractual) relations.

27. Date of freezing of assets.

28. Date of unfreezing of assets.

{Appendix 26 with amendments made in accordance with the Resolution of the National Bank No. 198 of 29.12.2023 }

On approval of the Regulation on the implementation of financial monitoring by institutions
Resolution of the National Bank of Ukraine; Regulation, Procedure, Measures, Criteria, Letter, Notification, Form of a standard document dated 07/28/2020 No. 107
Revision dated 10/08/2024 , basis — v0121500-24
Permanent address:
https://zakon.rada.gov.ua/go/v0107500-20

The legislation of Ukraine
as of 09/25/2026
is in force

Document publications

Official online representation of the National Bank of Ukraine from 07/29/2020

Official Gazette of Ukraine dated 01.09.2020 — 2020, No. 68, p. 45, article 2203, act code 100507/2020

2026 Edition

Choose a business task

Since 2003, UBC has created thousands of successful companies in Ukraine - we can help you too. We will be pleased to answer any further questions you may have. We wish you every success in business!