On Approval of Requirements to the Rules of internal control in order to counteract the legalization (laundering) of proceeds from crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction for mail operators providing money transfer services
Order of the Deputy Prime Minister - Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan dated April 8, 2026 No. 192/NK. Registered with the Ministry of Justice of the Republic of Kazakhstan on April 9, 2026 No. 38377
In accordance with paragraph 3-2 of Article 11 of the Law of the Republic of Kazakhstan "On Countering the Legalization (Laundering) of Proceeds from Crime, the financing of terrorism and the financing of the proliferation of weapons of mass Destruction," I ORDER:
1. To approve the attached Requirements to the rules of internal control in order to counteract the legalization (laundering) of proceeds from crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction for mail operators providing money transfer services.
2. The Telecommunications Committee of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan, in accordance with the procedure established by the legislation of the Republic of Kazakhstan, shall ensure:
1) the state registration of this order in the Ministry of Justice of the Republic of Kazakhstan;
2) posting of this order on the Internet resource of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan after its official publication.
3) within ten working days after the state registration of this order with the Ministry of Justice of the Republic of Kazakhstan, submit to the Legal Department of the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan information on the implementation of measures provided for in subparagraphs 1) and 2) of this paragraph.
3. Control over the execution of this order is entrusted to the supervising Vice Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan.
4. This order shall enter into force upon the expiration of ten calendar days after the date of its first official publication.
Deputy Prime Minister – Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan
J. Madiev
"APPROVED"Agency of the Republic of Kazakhstan for Financial Monitoring
Approved by the Order of the Deputy Prime Minister - Minister of Artificial Intelligence and Digital Development of the Republic of Kazakhstan on April 8, 2026 No. 192/NK
Requirements to the rules of internal control in order to counteract the legalization (laundering) of proceeds from crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction for mail operators providing money transfer services
Chapter 1. General provisions
1. These Requirements to the rules of internal control for countering the legalization (laundering) of proceeds from crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction for mail operators providing money transfer services (hereinafter referred to as the Requirements) have been developed in accordance with paragraph 3-2 of Article 11 of the Law of the Republic of Kazakhstan "On Countering the Legalization (Laundering) of proceeds from crime, financing of terrorism and financing the proliferation of weapons of mass destruction" (hereinafter – The Law), as well as taking into account the international standards of the Financial Action Task Force on Money Laundering (FATF).
2. The following concepts are used in these Requirements:
1) money transfer services – financial services that provide for the acceptance of cash, checks, other monetary instruments or other means of saving, as well as the payment of the corresponding amount in cash or in another form to the recipient through communication, message, transfer or through a clearing network;
2) personal account - the profile of the user (subject of financial monitoring) on the dedicated communication channels of the authorized body in the information and telecommunication network of the Internet, providing electronic interaction of its users (subjects of financial monitoring) with the authorized body;
3) AML, CFT, and FMT risk management – a set of measures aimed at identifying and reducing risks associated with the activities of clients and the use of the Entity's services;
4) risks of legalization (laundering) of income and financing of terrorism – causing damage to the financial system and economy of a country by performing financial transactions (transactions) for the purpose of legalization (laundering) of income and financing of terrorism, in connection with the implementation of threats and (or) the presence of vulnerabilities;
5) financial monitoring entities – mail operators providing money transfer services (hereinafter referred to as Entities);
6) form FM-1 is a form of information and information about an operation subject to financial monitoring, provided for by the Rules for the provision by financial monitoring entities of information and information about transactions, suspicious activities of the client subject to financial monitoring, and signs of identification of suspicious transactions, activities of the client, approved by the order of the Chairman of the Agency of the Republic of Kazakhstan for Financial Monitoring dated February 22 2022 No. 13 (registered in the Register of State Registration of Regulatory Legal Acts under No. 26924);
7) Impeccable business reputation – the presence of facts confirming professionalism and good faith, including the absence of facts of a person committing illegal actions (inaction) that led to insolvency, which led to the forced liquidation of a financial institution, or to classifying the bank as an insolvent bank, the absence of an outstanding or outstanding criminal record, including the absence of an effective judicial act on the application of criminal penalties in in the form of deprivation of the right to hold the position of a senior employee of a financial institution, a banking and (or) insurance holding company and be a major participant (major shareholder) of a financial organization for life, as well as the absence of relations with third parties (control and influence of third parties), whose actions contributed to the legalization (laundering) of proceeds from crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction, based on information from the authorized body the authority;
8) authorized body – a state body that carries out financial monitoring and takes other measures to counteract the legalization (laundering) of proceeds from crime, the financing of terrorism, and the financing of the proliferation of weapons of mass destruction.
3. Internal control is carried out in order to:
1) ensuring that Subjects comply with the requirements of the Law;
2) maintaining the effectiveness of the internal control system at a level sufficient to manage the risks of AML, CFT, and FML legalization;
3) minimizing the risks of AML, CFT, and CFMEU legalization.
4. As part of the organization of internal control in order to counteract the legalization (laundering) of proceeds from crime, the financing of terrorism and the financing of the proliferation of weapons of mass destruction (hereinafter referred to as AML, CFT, FMT), Entities ensure:
1) development and approval of internal control rules (hereinafter referred to as the Rules), including the procedure for evaluating the effectiveness of internal control;
2) using your personal account on the Internet portal www.websfm .kz for interaction with the authorized body.
5. The Rules are a document that regulates the organizational basis of work aimed at AML, CFT, and FMT and establishes the procedure for the actions of Subjects for the purposes of AML, CFT, and FMT. They are approved and fixed by the Subject in the personal account on the Internet portal www.websfm.kz .
6. In case of amendments and (or) additions to the Law, the Subjects shall make appropriate amendments to the Rules within 30 (thirty) calendar days from the date of entry into force of the amendments and (or) additions.
Chapter 2. The program of the organization of internal control for the purposes of AML, CFT, FMT
7. The Program for the Organization of internal Control for AML, CFT, and FMT purposes (hereinafter referred to as the Program) establishes the procedure for applying procedures aimed at preventing the use of the Entity's services for purposes regulated by Law.
The program includes:
1) the use of information systems used to implement internal control and transfer information to the authorized body;
2) the procedure for refusal to establish or terminate a business relationship, as well as refusal to conduct transactions in cases provided for by law;
3) recognizing the Subject of the transaction and the activities of the client and (or) his representative as suspicious in accordance with paragraphs 3, 4, 5 of Article 4 of the Law;
4) the procedure for providing information on transactions subject to financial monitoring through the information systems of the authorized body;
5) the procedure for informing the head of the Entity about the revealed violations of the Rules;
6) the procedure for interaction between the responsible employee and structural divisions in the implementation of internal control measures;
7) fulfillment of the requirements of the legal entity exercising control over the organization (if any);
8) the procedure for preparing reports based on the results of evaluating the effectiveness of internal control;
9) the procedure for identifying the client and (or) his representative, as well as the beneficial owner, including the application of simplified and enhanced verification measures;
10) the procedure for identifying operations and activities that correspond to established typologies and methods of performing actions subject to the regulation of the Law;
11) the procedure for assessing and documenting AML, CFT, and FMT risks;
12) the procedure for applying risk mitigation measures;
13) the procedure for classifying clients by risk levels;
14) the procedure for storing documents and information necessary to comply with legal requirements for at least five years.
8. The subjects appoint a person responsible for the implementation and observance of the Rules (hereinafter referred to as the responsible employee) from among the managers at least at the level of the head of the structural unit. The following requirements apply to the responsible employee:
1) Higher education;
2) work experience of at least two years in the field of AML, CFT, FMT, or in the relevant fields of activity of the Subjects;
3) impeccable business reputation;
9. The functions of a responsible official or structural subdivision in accordance with the program for the organization of internal control for AML, CFT, and FMT purposes include:
1) development and coordination of Rules, amendments and (or) additions to them with the head of the Entity, as well as monitoring the implementation and compliance with the Rules;
2) organization and control of the submission of information and information on transactions and activities subject to financial monitoring to the authorized body in accordance with the Law;
3) making decisions on the recognition of transactions and activities of clients as suspicious;
4) making decisions on classifying operations and activities of clients as complex, unusually large, operations and activities with characteristics corresponding to typologies, schemes and methods of legalization of AML, CFT, FRM;
5) making decisions on suspending or refusing to conduct customer transactions and the need to send information about transactions and activities to the authorized body;
6) making decisions on establishing, continuing or terminating business relationships with clients;
7) sending requests to the head of the Entity for making decisions on establishing, continuing or terminating business relationships with clients;
8) documenting decisions taken regarding the operation and activities of the client and (or) his representative and beneficial owner;
9) the formation of the client's dossier based on the data obtained as a result of the implementation of the Rules;
10) informing the head of the Entity about the revealed violations of the Rules;
11) taking measures to improve the risk management and internal control system;
12) ensuring the confidentiality of information obtained in the exercise of their functions;
13) providing information to the authorized body for monitoring the implementation of legislation on AML, CFT, and CFMEU;
14) provision of information, information and documents to the authorized body upon its request;
15) preparation of information on the results of the implementation of the Rules and recommended measures to improve the risk management system of AML, CFT, FMT and internal control of AML, CFT, FMT for the preparation of reports to the head of the Entity;
16) provision of measures for the storage of all documents and information.
10. Subjects in accordance with their assigned functions:
1) ensure the confidentiality of information obtained during the exercise of authority;
2) provides information to the relevant state bodies for monitoring the implementation of the legislation of the Republic of Kazakhstan on AML, CFT, and CFMEU;
3) provide the authorized body, upon its request, with the necessary information, information and documents in accordance with paragraph 3-1 of Article 10 of the Law.
It is allowed for Subjects to include additional functions and powers of a responsible employee or an AML, CFT, or FRM unit.
11. In accordance with paragraph 5 of Article 11 of the Law, it is prohibited to inform clients and other persons about AML, CFT, and FRM measures taken against such clients and other persons, except for informing clients about measures taken to freeze transactions with money and (or) property, refusal to establish business relationships, and refusal to conduct transactions with money and (or) property.
12. If there are postal operators in branches, representative offices and other separate structural divisions, employees who are fully or partially entrusted with the functions and powers provided for in paragraphs 10 and 11 of these Requirements, the coordination of activities on AML, CFT, and FRM issues of such employees is carried out by a responsible employee.
Chapter 3. AML, CFT, and FMT Risk Management Program
13. In order to manage the risks of AML, CFT, and FRMU legalization, Entities develop a risk management program for AML, CFT, and FRMU legalization that takes into account the risks of customers and the risks of using services for criminal purposes, including the risk of using technological advances.
The AML, CFT, and FMF Risk management Program includes, but is not limited to:
1) the procedure for the organization of risk management for the legalization of AML, CFT, FRMU of the Subject, including in the context of its structural units (if any);
2) a methodology for assessing the risks of AML, CFT, and FMT legalization, taking into account the main risk categories (by type of client, country risk, and risk of services/products, and/or the method of its provision) in relation to the client's risk level, as well as the degree of exposure of the Subject's services (products) to the risks of AML, CFT legalization, FROME;
3) the procedure for regular monitoring, analysis and control of customer risks and the degree of exposure of the Entity's products (services) to the risks of AML, CFT, and CFMEU legalization, providing for a list of preventive measures, the procedure and timing of their implementation, and monitoring the results in accordance with the measures taken;
4) the order of assignment, deadlines and grounds for reviewing the risk levels of clients.
Subjects annually assesses the degree of exposure of the services of Subjects to the risks of AML, CFT, and FRM risks, taking into account information from the AML, CFT, and FRM risks report and the following specific risk categories: risk by type of customer, country (geographical) risk, service risk and (or) the method of its provision.
The assessment of the degree of exposure of the services (products) of Subjects to the risks of AML, CFT, and FMT legalization is accompanied by a description of possible measures aimed at minimizing the identified risks, including changing procedures for identifying and monitoring customer transactions and activities, changing the terms of service (products), and refusing to provide services (products).
The results of the risk assessment are provided at the request of the relevant government agencies and non-profit organizations of which the Subjects are members.
14. The types of clients whose status and/or activities increase the risk of AML, CFT, and CFMEU legalization include, but are not limited to:
1) public officials, their spouse and close relatives, as well as legal entities whose beneficial owners are these persons;
2) stateless persons;
3) citizens of the Republic of Kazakhstan who do not have a registration or residence address in the Republic of Kazakhstan;
4) organizations and persons included in the list of persons involved in terrorist activities (hereinafter referred to as the List) and (or) in the list of organizations and persons associated with the financing of terrorism and extremism, as well as in the list of organizations and persons associated with the financing of proliferation of weapons of mass destruction (hereinafter referred to as the List) provided for in articles 12 and 12-1 of the Law, as well as organizations and persons whose beneficial owners are the specified persons or who are under the control and acting in the interests of the specified persons;
The List and the List are posted on the official Internet resource of the authorized body.
5) non-profit organizations in the organizational and legal form of foundations, religious associations;
6) persons located (registered) in the foreign countries specified in paragraph 19 of these Requirements, as well as branches and representative offices of such persons located in the Republic of Kazakhstan;
7) the client, in respect of whom there are grounds for doubt about the accuracy of the data received;
8) the client insists on the haste of the operation or on non-standard or unusually complex payment schemes, the use of which differs from the usual practice of the Subjects;
9) a client against whom the Subject has previously expressed suspicions;
10) the client and (or) his representative, as well as the beneficial owner, commit acts aimed at evading due diligence procedures for the client and (or) his representative, as well as the beneficial owner, provided for by Law;
11) with an increased level of corruption or other criminal activity.
15. The types of clients whose status and/or whose activities reduce the risk of AML, CFT, and CFMEU legalization include, but are not limited to::
1) state bodies of the Republic of Kazakhstan, as well as legal entities controlled by state bodies;
2) organizations whose shares are included in the official list of the stock exchange of the Republic of Kazakhstan and (or) the stock exchange of a foreign state;
3) international organizations located on the territory of the Republic of Kazakhstan or to which the Republic of Kazakhstan is a party;
4) persons located (registered) in foreign countries and in the Republic of Kazakhstan, branches and representative offices of such persons.
16. Entities shall assess the country (geographical) risk associated with conducting business in the foreign Countries specified in this paragraph, providing services (products) to clients from such foreign countries, and conducting transactions with money and (or) other property involving such foreign States.
Foreign countries whose transactions and activities increase the risk of AML, CFT, and CFMEU legalization include, but are not limited to::
foreign States (territories) included in the list of States (territories) that do not comply with or insufficiently comply with the recommendations of the Financial Action Task Force on Money Laundering (FATF), compiled by the authorized financial monitoring body;
foreign States (territories) subject to international sanctions (embargoes) adopted by UN Security Council resolutions;
foreign states (territories) included in the list of offshore zones, in accordance with Resolution No. 8 of the Board of the Agency of the Republic of Kazakhstan for Regulation and Development of the Financial Market dated February 24, 2020 "On Establishing a List of Offshore Zones for the purposes of Banking and Insurance Activities, activities of Professional Participants in the Securities Market and other Licensed Types of Activities in the Securities Market securities, activities of joint-stock investment funds and activities of organizations, engaged in microfinance activities" (registered in the Register of State Registration of Regulatory Legal Acts No. 20095);
foreign states (territories) identified by Entities as posing a high risk of AML, CFT, and CFMEU legalization based on other factors (information on the level of corruption, illicit production, trafficking, and/or transit of drugs, information on support for international terrorism, and others).
Links to the lists of such states (territories) according to the UN and international organizations are posted on the official Internet resource of the authorized body.
17. Foreign countries whose transactions reduce the risk of AML, CFT, and CFMEU legalization include, but are not limited to::
foreign States (territories) that comply with international standards and have an effective AML/CFT system in accordance with the information provided by the Financial Action Task Force on Money Laundering (FATF).
18. The services (products) of Entities that increase the risk of AML, CFT, and CFMEU legalization include, but are not limited to::
transactions with money and (or) other assets exceeding the threshold value;
business relations with the client are conducted under unusual circumstances (for example, an unexplained geographical distance between the Subject and the client is too large);
performing an operation on behalf of or for the benefit of unknown or unrelated third parties;
making transactions involving anonymous bank accounts or using anonymous, fictitious names, including cash payments;
performing operations that have no economic sense or legal purpose;
making transactions by the client with an unusual frequency or for an unusually large amount for this client.
19. Methods of providing a product (service) that increase the risk of AML, CFT, and CFMEU legalization include, but are not limited to::
performing an operation without the physical presence of the client and/or his representative;
the use of third-party services to apply customer due diligence measures against the customer and/or his representative, as well as the beneficial owner.
20. Methods of providing a product (service) that reduce the risk of AML, CFT, and CFMEU legalization include, but are not limited to::
execution of the transaction in the personal presence of the client and (or) his representative.
It is allowed for Subjects to include additional risk factors in agreement with the authorized body.
21. As part of the implementation of the risk management program for the legalization of AML, CFT, and FRM by the Subjects, measures are being taken to classify clients taking into account the categories and risk factors specified in paragraph 17 of these Requirements, as well as other risk categories established by the Subjects.
The risk level of the client (group of clients) is determined by the Subjects based on the results of an analysis of the information available to the Subjects about the client (clients) and is assessed on a risk level scale, which consists of at least two levels: low and high.
Risk assessment using the risk categories and factors specified in paragraphs 17-22 of these Requirements is carried out in relation to clients (groups of clients) based on the results of monitoring operations (business relationships).
The review of the risk level of the client (group of clients) is carried out by the Subjects as the information about the client (group of clients) and the results of monitoring operations (business relations) are updated.
22. Subjects identify and assess the risks of AML, CFT, and CFMEU legalization that arise when:
1) development of new products and new business practices, including new transfer mechanisms;
2) the use of new or developing technologies for both new and existing products.
The assessment of the risks of AML, CFT, and CFMEU legalization is carried out before the launch of new products, business practices, or the use of new or developing technologies.
Chapter 4. Customer Identification Program
23. The program of identification of the client and (or) his representative, as well as the beneficial owner, consists in carrying out measures by Subjects to record and verify the accuracy of information about the client and (or) his representative, as well as to identify the beneficial owner and record information about him, update previously received information about the client and (or) his representative, establish and recording the intended purpose of a business relationship, as well as obtaining and recording other legally required information about the client and their representatives, includes, but is not limited to:
1) the procedure for accepting clients, including the procedure and grounds for refusing to establish a business relationship and/or conduct an operation, as well as termination of a business relationship;
2) the procedure for identifying the client and (or) his representative, as well as the beneficial owner, including the specifics of the procedures for applying simplified and enhanced due diligence measures for the client and (or) his representative, as well as the beneficial owner, and the procedure for making a decision by the Entity to recognize an individual as the beneficial owner of the client;
3) a description of measures aimed at identifying public officials, their spouses and close relatives, as well as among legal entities whose beneficial owners are these persons, and accepting such clients for service (with the written permission of the organization's senior employee).;
4) the procedure for checking the client and (or) his representative, as well as the beneficial owner for presence in the List and Lists;
5) identification features during remote establishment of business relations (without the personal presence of the client and (or) his representative);
6) specifics of the exchange of information obtained during the identification of the client and (or) his representative, as well as the beneficial owner, in the framework of meeting the Requirements;
7) the specifics of customer identification by obtaining information from other organizations, including the identification of individuals and legal entities for or on behalf of which (his representative) and the beneficial owner transactions are performed;
8) a description of additional sources of information, including those provided by government agencies, in order to identify the client and (or) his representative, as well as the beneficial owner;
9) the procedure for verifying the accuracy of information about the client and (or) his representative, as well as the beneficial owner;
10) requirements for the form, content and procedure for maintaining the client's dossier, updating information (at least once a year) contained in the dossier, indicating the frequency of updating information;
11) the procedure for ensuring access of the subject's employees to the information obtained during identification;
12) the procedure for assessing the client's risk level and the grounds for assessing such risk.
If, in accordance with the Law, the Entity has, on the basis of a contract, instructed another person or a foreign financial institution to apply the measures provided for in paragraphs 1), 2), 2-1), 2-2) and 4) paragraph 3 of Article 5 of the Law, the Entity develops rules for interaction with such persons, which include:
the procedure for concluding contracts by Entities with persons charged with identification, as well as the list of officials of the organization authorized to conclude such contracts;
the procedure for identifying the client and (or) his representative, as well as the beneficial owner in accordance with the agreements between the organization and the persons entrusted with the identification;
the procedure and timing of the transfer to the organization of information obtained during identification by persons charged with identification;
the procedure for the Subject to monitor compliance by persons charged with identification with identification requirements, including the procedure, timing and completeness of the transfer of information received to the organization, as well as measures taken by the Subject to eliminate identified violations;
the grounds, procedure and deadlines for the Subject's decision to unilaterally refuse to perform the contract with the persons charged with identification in case of non-compliance with identification requirements, including procedures, deadlines and completeness of the transfer of the information received to the organization.;
the list of officials of the organization authorized to make a decision on unilateral refusal to perform the contract with the persons who are entrusted with the identification;
provisions on the responsibility of persons to whom the Entity has entrusted the identification for non-compliance with identification requirements, including the procedure, timing and completeness of the transfer of the information received to the organization;
the procedure for the organization's interaction with persons charged with conducting identification on issues of providing them with methodological assistance in order to meet identification requirements;
the procedure for identifying possible risks of AML, CFT, and FMT legalization.
In accordance with paragraph 10 of Article 5 of the Law, Entities are not entitled to perform the actions provided for in paragraphs 6, 6-1 and 8 of Article 5 of the Law in the case of registration, residence or location of another Entity or a foreign financial institution in a state (territory) that does not comply and (or) insufficiently implements the recommendations of the Financial Action Task Force Anti-Money Laundering (FATF).
24. When conducting proper verification of the client and (or) his representative, as well as the beneficial owner, the entities identify them according to the following obligations::
1) identification of the client and (or) his representative, as well as the beneficial owner and confirmation of the client's identity using reliable, independent primary documents, data or information;
2) determining the beneficial owner and taking reasonable measures to verify the identity of the beneficial owner, which allows the Entity to believe that it knows who the beneficial owner is. For legal entities and foreign entities without forming a legal entity, this should include obtaining information from the Entity about the management structure and ownership of the client.;
3) understanding and, where necessary, obtaining information about the purpose and intended nature of the business relationship;
4) conducting, on an ongoing basis, a proper review of business relationships and a full analysis of transactions made within the framework of such relationships in order to ensure that the transactions conducted correspond to the information of the Entities about the client and (or) his representative, as well as the beneficial owner, his business activities and the nature of risks, including, where necessary, about the source of funds;
5) in relation to foreign entities without forming a legal entity, legal entities, personal data holding equivalent or similar positions.
25. A list of documents required for proper verification of the client and/or his representative, as well as the beneficial owner.:
a document(s) certifying the identity of an official(s) authorized to sign documents of a legal entity, as well as to perform actions on behalf of a client without a power of attorney to perform transactions with money and (or) other property;
documents confirming the authority of the client's representative to perform transactions with money and (or) other property on behalf of the client, including signing the client's documents;
a document certifying registration with the authorized bodies of the Republic of Kazakhstan for the right of entry, exit and stay of a non-resident individual in the territory of the Republic of Kazakhstan, unless otherwise provided by international treaties ratified by the Republic of Kazakhstan.
When conducting a proper audit of the client and (or) his representative, as well as the beneficial owner, the subjects document information about the client and (or) his representative, as well as the beneficial owner on the basis of originals or notarized copies of documents submitted at the choice of the client and (or) his representative, or copies of documents with an apostille or in accordance with the legalized procedure established by international treaties ratified by the Republic of Kazakhstan.
26. Subject to the requirements of Article 6 of the Law on Subjects, they identify the client and (or) his representative, as well as the beneficial owner, before establishing a business relationship.
27. Subject to the requirements of paragraph 1 of Article 7 of the Law, Entities identify the client and (or) his representative, as well as the beneficial owner, verify business relationships and examine transactions, including, if necessary, obtaining and recording information about the source of financing for transactions, taking into account the client's risk level, and verify the accuracy of the information received about the client in cases:
1) making a threshold transaction by the client;
2) commission (attempt to commit) by the client of a suspicious transaction (transaction);
3) commission of an unusual transaction by the client;
4) the client performs an operation (transaction) having characteristics corresponding to typologies, schemes and methods of money laundering and terrorist financing.
If the person with the controlling interest is not identified as the beneficial owner, or if there are no individuals exercising control through a share in ownership rights, the Entities verify the identity of the beneficial owners using the personal data of the individual exercising control over the legal entity or a foreign entity without forming a legal entity.
The beneficial owner, in accordance with the procedure established by law, is a person who directly or indirectly owns more than twenty–five percent of the shares in the authorized capital or outstanding (minus preferred and repurchased by the company) shares of a client - a legal entity, a foreign structure without forming a legal entity.
If it is impossible to establish the beneficial owner on the basis of participation in the authorized capital, the beneficial owner is the person exercising control over the client in another way or in whose interests the client performs transactions with money and (or) other property.
Documents and information about transactions with money and (or) other property, including those subject to financial monitoring, and suspicious transactions and activities, as well as the results of studying all complex, unusually large and other unusual transactions and activities, are subject to storage by the Subject throughout the entire period of business relations with the client and for at least 5 years (five) years from the date of termination of business relations with the client.
Subjects form a client's dossier by recording information about him, depending on the level of his risk assigned by them in accordance with their Rules. If a low level is assigned to a client, simplified due diligence measures are carried out against him and the list of information provided for in the sub-paragraphs is recorded. 1), 2), 2-1), 2-2) and 4) paragraph 3 of Article 5 of the Law.
In the case of assigning a high level of risk to the client, additional information includes information provided for in paragraph 5 of Article 5 of the Law (information on tax residence, type of activity and source of financing of transactions).
Enhanced due diligence measures for the client and/or his representative, as well as the beneficial owner, are applied when there is a high risk of AML, CFT, and CFMEU legalization.
Simplified due diligence measures for clients and/or their representatives, as well as beneficial owners, are applied when the risk of money laundering and terrorist financing is low.
28. In the process of identifying the client and (or) his representative, as well as the beneficial owner, Subjects check for the presence of such a client in the List and Lists.
Information about the client and (or) his representative, as well as the beneficial owner with a high risk of AML, CFT, and CFMEU legalization, is updated at least once every six months.
The frequency of updates and (or) the need to obtain additional information about the client and (or) his representative, as well as the beneficial owner, are established taking into account the level of risk of the client (group of clients) and (or) the degree of exposure of the services (products) of the Entity used by the client to the risks of AML, CFT, FRMU legalization.
If the client is refused to establish business relations and conduct transactions with money and (or) other property, if it is impossible to take the measures provided for in the sub-paragraphs 1), 2), 2-2), 4) and 6) paragraph 3 of Article 5 of the Law, as well as taking measures to freeze transactions with money and (or) with other property, the Subjects send to the authorized body a notification of such a fact in the Form of FM-1.
If it is impossible to take the measures provided for in subparagraph 6) of paragraph 3 of Article 5 of the Law, as well as if, during the study of transactions and activities carried out by the client, suspicions arise that the business relationship is being used by the client for AML, CFT, FMT purposes, the Entities terminate the business relationship with the client. If the business relationship is terminated for the above-mentioned reasons, the Entities send a message to the authorized body in the FM-1 Form.
Chapter 5. A program for monitoring and studying customer transactions, including the study of complex, unusually large and other unusual customer transactions
29. In order to implement the requirements of the Law for proper verification of the client and (or) his representative, as well as the beneficial owner, as well as to identify and send to the authorized body reports on transactions and activities subject to financial monitoring, Entities develop a program for monitoring and studying customer transactions.
30. The program for monitoring and studying customer operations includes:
1) a list of signs of unusual and suspicious transactions and activities, compiled on the basis of signs of the definition of suspicious transactions and activities, approved by the authorized body in accordance with paragraph 2 of Article 10 of the Law, as well as independently developed by the Subjects;
2) the procedure for identifying a client's transaction that has characteristics consistent with the typologies, schemes and methods of AML, CFT, and FRM legalization approved by the authorized body in accordance with paragraph 5 of Article 4 of the Law;
3) the procedure for taking and describing the measures taken by the Entities in relation to the client and its operations in the event that the client systematically and (or) carries out significant amounts of unusual and (or) suspicious transactions and activities.;
4) the procedure for conducting continuous enhanced monitoring of financial transactions accepted for servicing clients who are public officials, their spouse and close relatives, as well as whose beneficial owners these persons are, regardless of the form of their implementation and the amount for which they were or may have been committed, including the identification of the source of origin funds and or other property of such clients.
31. If the Subject appoints a responsible employee or employees of the AML, CFT, and FRMU divisions, the program for monitoring and studying customer operations additionally includes, but is not limited to:
1) the distribution of responsibilities between the divisions (employees) of the Entity for updating previously received and (or) obtaining additional information about the client and (or) his representative, as well as the beneficial owner in the cases provided for by these Requirements;
2) the distribution of responsibilities between the divisions (employees) of the Entity for the identification and transfer between divisions (employees) of information on threshold, unusual and suspicious transactions and activities;
3) a description of the mechanism of interaction of the Entity's divisions in identifying threshold, unusual and suspicious transactions and activities;
4) the procedure, grounds and deadline for the responsible employee to make a decision on the qualification of the client's operation;
5) the procedure for interaction of departments (employees) to make a decision on refusal to conduct a client's operation (with the exception of refusal due to the presence of the client, the beneficial owner in the List), as well as on termination of business relations with the client;
6) the procedure for interaction of departments (employees) of the Entity to identify clients and beneficial owners who are on the List and Lists, as well as to refuse to conduct transactions with money and (or) other property of such clients, service such clients, or terminate business relations with them;
7) the procedure for informing (if necessary) officials of the Entity about the identification of threshold and suspicious transactions and activities, clients from the List and Lists.
32. The frequency of studying the client's operations is determined by the Subjects, taking into account the level of risk of the client and (or) the degree of exposure of the services of the Subjects used by the client to the risks of AML, CFT, FRM, commission (attempt to commit) transactions (operations) with money by the client, as well as taking into account typologies, schemes and methods of AML, CFT, FRM legalization approved by the authorized body in accordance with paragraph 5 of Article 4 of the Law.
In the case of assigning a high level of risk to the client, as well as in the case of a suspicious transaction and activity by the Client, the transactions that the client conducts (conducted) during the period before the transaction, determined by the Subject, but usually not more than one month, are studied.
33. The client's transactions and activities are considered suspicious if, based on the results of the study of the transactions and activities specified in paragraph 21 of these Requirements, the Subjects have reason to believe that the client's transactions and activities are related to the legalization of AML, CFT, FRMU.
The decision to recognize (not recognize) the client's operation and activity as suspicious is made by the Subjects independently on the basis of information and documents available to them describing the status and activities of the client and (or) his representative, as well as the beneficial owner carrying out the operation, as well as information on financial and economic activities, financial position and business the client's reputation.
At the same time, the difference between the time of the transaction and the activity, as well as the time of recognition of such a transaction and activity as suspicious, may not exceed the time interval that determines the frequency of studying the transaction and the client's activities in accordance with the rules of internal control of the financial monitoring entity.
Subjects submit to the authorized body reports on the commission of suspicious transactions and activities involving money and (or) other property, no later than the business day following the day when the Subjects make the appropriate decision (action) electronically through dedicated communication channels.
Reports on transactions involving money and (or) other property that were not recognized as suspicious before they were conducted are submitted by Subjects to the authorized body no later than twenty-four hours after the operation and activity are recognized as suspicious.
Chapter 6. The program of training and education of Subjects in the field of AML, CFT, FMT
34. The program of training and education of Subjects in the field of AML, CFT, FMT (hereinafter referred to as the Training Program) is being developed taking into account the requirements of the legislation of the Republic of Kazakhstan in the field of AML, CFT, FMT.
The training program includes:
1) the procedure for the initial training of employees when they are appointed or hired;
2) a list of topics and issues required for study by employees of the Entity, including:
AML, CFT, and FMT legislation requirements;
customer identification and verification procedures;
procedure for monitoring and examining operations;
the procedure for classifying clients by risk levels;
employee responsibilities in identifying operations that require investigation;
3) the procedure for conducting regular training, including the frequency of;
4) the procedure for verifying the knowledge of employees, including documenting the results;
5) the procedure for professional development of employees responsible for the implementation of the Rules;
6) the procedure for documenting learning processes and storing materials;
7) the procedure for informing employees of the Subject about changes in legislation in the field of AML, CFT, and CFMEU.
35. Employees involved in the implementation of the Rules are trained within the time limits and in accordance with the procedure established by the internal documents of the Entity.
36. The training, recording of its results and reporting are carried out by a responsible employee or authorized units of the Entity.
37. The subjects ensure that the training content meets the requirements of current legislation, as well as employees' access to up-to-date information on AML, CFT, and FMT issues.
Constitution Law Code Standard Decree Order Decision Resolution Lawyer Almaty Lawyer Legal service Legal advice Civil Criminal Administrative cases Disputes Defense Arbitration Law Company Kazakhstan Law Firm Court Cases Declaration Decree Order Resolution Decision Report Conclusion Statement Conclusion Convention Contract Memorandum Methodology Norms Note Rules Program Charter Charter Article Commentary Resolution Regulations Protocol Draft Program Rules Messages