11 July 2022
EBA ¦ Final Report on Joint EBA and ESMA Guidelines on the Assessment of Suitability
Fit and proper governance becomes an anti-money laundering control
The suitability of a financial institution’s management is not merely a governance or prudential concern. It is also a central component of the framework for preventing money laundering, terrorist financing and the predicate offences that generate criminal proceeds.
European supervisory expectations require institutions to assess whether members of their management bodies and relevant key function holders have the reputation, knowledge, skills, experience, integrity and independence needed to perform their roles. Those criteria directly affect an institution’s ability to identify criminal proceeds, understand exposure to predicate offences and prevent its products and services from being misused.
The underlying principle is straightforward. A weak, conflicted or poorly informed management body may fail to recognise serious financial crime risks even where formal policies and controls exist. Conversely, a suitably qualified and independent management body should be capable of challenging business decisions, demanding effective controls and taking corrective action when risks emerge.
The responsibility applies across different governance structures, including unitary and dual-board models. It also extends across prudentially consolidated groups, including relevant subsidiaries established outside the European Union.
Money laundering risk is linked to management suitability
The supervisory framework treats money laundering and terrorist financing risk as matters capable of affecting an institution’s safety and soundness. This is significant because it links anti-money laundering weaknesses to the assessment of whether individuals remain fit to hold senior positions.
A reassessment should be considered where there are reasonable grounds to suspect that money laundering or terrorist financing has been committed, attempted or presents an increased risk in connection with the institution. This does not require a criminal conviction. The suitability assessment is preventive and prudential, not a substitute for criminal or administrative proceedings, and must respect the presumption of innocence and other fundamental rights.
Triggers may include weaknesses in internal controls or oversight mechanisms, breaches of anti-money laundering obligations in the home or host state or in a third country, and material changes to the institution’s business model that significantly increase its exposure to financial crime risk.
The same logic applies where adverse findings are made by internal or external auditors, competent authorities or other reliable sources. The absence of a conviction does not, by itself, resolve concerns about possible misconduct or inadequate oversight. Institutions must assess the credibility, reliability and seriousness of the available information and determine its relevance to the individual’s role.
The predicate offence cannot be overlooked
An effective suitability assessment must look beyond laundering activity itself and consider the criminal conduct that may generate the proceeds. Relevant offences include corruption, fraud, dishonesty, tax offences, market manipulation, insider dealing, offences involving banking or securities activities, and other financial crimes.
The assessment should also consider offences connected with companies, bankruptcy, insolvency and consumer protection. This broader approach reflects the fact that laundering is often the final stage of a wider criminal process. An individual may be exposed to serious financial crime risk not only because of suspected handling of illicit funds, but also because of involvement in the conduct that produced those funds.
For example, a history of fraud, corruption, tax evasion or market abuse may raise questions about a person’s honesty, integrity and ability to manage a regulated institution. The relevance of the conduct depends on the circumstances, including the individual’s role, the seriousness of the offence, the penalty, the time elapsed, rehabilitation measures and subsequent behaviour.
Business failure and financial distress may also be relevant. Defaulted debts, personal bankruptcy, insolvency proceedings involving entities managed or controlled by the individual, and significant financial exposures can affect an assessment where they raise concerns about integrity, financial soundness or vulnerability to improper influence.
A designated board member must understand AML risk
The management body retains overall responsibility for the institution’s activities and for its compliance framework. At the same time, institutions should identify a member of the management body as responsible for implementing the laws and administrative requirements applicable to anti-money laundering and counter-terrorist financing.
That allocation of responsibility does not transfer the ultimate accountability of the management body to one individual. It does, however, require the designated member to possess deeper knowledge, skills and experience in identifying, assessing, managing and mitigating money laundering and terrorist financing risk.
The designated member should understand how the institution’s business model, customer base, products, delivery channels, geographical exposure and group structure affect its financial crime risk. A nominal appointment without the necessary competence is unlikely to satisfy the purpose of the requirement.
Other management body members also need sufficient understanding of these risks. The board’s collective suitability assessment should establish whether it can understand the institution’s activities and main risks, including the way money laundering and terrorist financing risks affect strategic decisions and day-to-day operations.
Key function holders are part of the control framework
Financial crime risk does not sit only with the board or the formally designated AML responsible person. Heads of compliance, risk management and internal audit, together with the chief financial officer where the role is separate from the management body, may have significant influence over the institution’s direction.
These individuals must be suitable for their functions on an ongoing basis. Relevant institutions should assess their good repute, honesty, integrity, knowledge, skills and experience before appointment and during their tenure. Other senior individuals may also fall within scope where they have significant influence over the institution, such as heads of major business lines, significant branches or third-country subsidiaries.
A reassessment may be necessary where a key function holder is connected with suspected or attempted money laundering or terrorist financing, where the institution has breached AML/CFT obligations, or where a change in its activities materially increases exposure to financial crime risk.
This is particularly important where compliance or risk functions are structurally weak, lack access to the management body or are unable to challenge revenue-generating divisions. A formally independent control function that cannot influence decisions is not an effective safeguard.
Independence of mind is essential to effective challenge
Suitability includes independence of mind for every member of the management body. This is distinct from the separate concept of being an independent director.
Independence of mind concerns behaviour. Board members should be able to ask difficult questions, challenge proposed decisions, resist groupthink and reach objective conclusions. They must also be able to identify and manage conflicts of interest that could impair their judgement.
Relevant conflicts may arise from financial interests, loans, ownership interests, close personal relationships, previous employment, relationships with major customers or suppliers, external professional activities and political connections. Conflicts must be disclosed, discussed, documented and managed. A member should abstain from voting on matters where a conflict exists.
This principle has direct AML significance. Senior managers who are unwilling to challenge profitable but high-risk relationships may allow suspicious customers, opaque ownership structures or risky products to remain within the institution. Independence of mind helps ensure that commercial pressure does not override financial crime controls.
Reputation assessments must be evidence-based but broad
The assessment of reputation, honesty and integrity should be based on objective and demonstrable information. Institutions and supervisors should consider criminal and administrative records, regulatory findings, disciplinary action, ongoing investigations and reliable adverse information.
Whistleblowing reports may be relevant where the information is credible and reliable. They do not automatically establish unsuitability, but they should not be ignored simply because they have not resulted in a conviction or formal sanction.
The assessment should also consider whether the individual has been transparent, open and cooperative with supervisors; whether a licence or authorisation has been refused, withdrawn or revoked; whether the person has been dismissed from a position of trust; and whether a regulator has prohibited the individual from acting as a director or from effectively directing a business.
The cumulative effect of less serious incidents may matter. A series of omissions, failures to disclose information or repeated control weaknesses may reveal a pattern that is more significant than any single event.
Ongoing monitoring is more important than a one-time check
Suitability must be monitored throughout a person’s tenure. Significant institutions should conduct periodic reassessments at least annually, while non-significant institutions should do so at least every two years. Event-driven reassessments may be required sooner.
Changes in business model, risk appetite, ownership, group structure or geographical footprint can alter the knowledge and experience required from the management body. New information about an individual’s conduct, conflicts, financial position or external activities may also affect suitability.
A material AML/CFT weakness should prompt an assessment of how responsibilities were allocated and whether the relevant management body members took reasonable steps to prevent, remedy or stop the problem. The review should consider board minutes, governance documents, reporting lines, internal policies, job descriptions and communications with control functions.
This approach helps distinguish a control failure from a governance failure. Not every AML breach proves that a director is unsuitable. However, a failure to respond to known deficiencies, a refusal to act on compliance advice or inadequate oversight of repeated breaches may support such a conclusion.
Institutions must be able to prove their assessment
A suitability framework should be documented, transparent and integrated into the institution’s wider governance arrangements. It should cover recruitment, appointment, reappointment, succession planning, monitoring, reassessment and communication with supervisors.
For individual assessments, institutions should gather and verify information through multiple sources, including curricula vitae, qualifications, references, interviews, questionnaires, official records and reliable external information. Candidates should disclose actual and potential conflicts of interest and confirm the accuracy of the information supplied.
The assessment file should explain the individual’s role, expected time commitment, knowledge and experience, reputation, integrity and independence of mind. It should also explain how the individual contributes to the collective competence of the management body.
For AML purposes, records should show how the board understands the institution’s financial crime exposure, how relevant risks are reported, which corrective measures were considered and why particular decisions were taken. A matrix that merely records titles and years of experience is not enough. The assessment should demonstrate real competence and effective challenge.
Corrective action must be timely
Where shortcomings are identified, institutions should take appropriate corrective measures. Depending on the circumstances, these may include targeted training, changes to the division of responsibilities, conflict mitigation, additional appointments, replacement of a member or changes to the composition of the management body.
Knowledge and skills gaps may be remediable. Deficiencies involving reputation, honesty and integrity are less likely to be resolved through training alone. If an individual is not suitable, the institution should not appoint that person or should replace the individual if already appointed.
The same principle applies to collective suitability. A board may contain individually competent members but still lack the combined expertise needed to understand the institution’s activities and risks. In that case, the institution may need to recruit additional expertise, redistribute responsibilities or strengthen training.
Material shortcomings must be reported to the competent authority without delay, together with the measures taken or proposed and the timetable for implementation.
Supervisory cooperation can expose hidden risk
Competent authorities should exchange relevant information about management body members and key function holders, subject to data protection requirements. This may include previous suitability decisions, regulatory findings, refused registrations, criminal records, administrative penalties and information held by AML/CFT supervisors, Financial Intelligence Units or law enforcement agencies.
Where financial crime risk is elevated, prudential supervisors should seek relevant information from AML/CFT authorities and other bodies. A decision that an individual is unsuitable because of facts connected with money laundering or terrorist financing should, subject to applicable law, be shared with the competent AML/CFT supervisor.
This cooperation is particularly important for individuals who have moved between institutions or jurisdictions. A history of regulatory action, control failure or unexplained involvement in a predicate offence may not be visible from the information held by a single supervisor.
What institutions should take from the framework
The central message is that anti-money laundering governance begins with the people who direct and oversee the institution. A policy framework cannot compensate for a management body that lacks the knowledge to understand criminal proceeds, the independence to challenge commercial decisions or the integrity to act on warning signs.
Institutions should therefore treat suitability assessments as active financial crime controls rather than administrative appointment exercises. They should assess the relevance of predicate offences, examine the quality of AML/CFT oversight, test the board’s ability to challenge management and reassess suitability when risk events occur.
The strongest governance model is one in which responsibility is clearly allocated, collective accountability is preserved, control functions have genuine influence and the management body can demonstrate how it understands and manages financial crime risk. That is the point at which fit and proper governance becomes a practical defence against money laundering.
Dive deeper
- Europena Banking Authority (EBA) ¦ EBA and ESMA publish final guidance on fit and proper requirements ¦ Link