## IMF/MONEYVAL Detailed Assessment — Liechtenstein (cr18257)

## Source details

**Canonical URL:** [IMF/MONEYVAL Detailed Assessment — Liechtenstein (cr18257)](https://www.imf.org/-/media/files/publications/cr/2018/cr18257.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2018/cr18257.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2018/cr18257.pdf.json)

---

### Preface and scope
- Partial re-assessment of Liechtenstein’s AML/CFT regime based on:
  - Forty Recommendations 2003 and Nine Special Recommendations on Terrorist Financing 2001 of the FATF.
  - AML/CFT Assessment Methodology 2004 and MONEYVAL “fourth evaluation round” rules.
- On-site mission: June 12–24, 2013; the assessment team had over fifty meetings, more than half with private sector entities.
- Reassessment focus (selected): Recommendations 1, 3, 4, 5, 10, 13, 17, 23, 26, 29, 30, 31, 35, 36 and 40; SR.I, SR.II, SR.III, SR.IV and SR.V.

### Executive summary — Key findings
- Progress since last mutual evaluation:
  - Legal framework more closely aligned with FATF recommendations.
  - Consolidation of institutional AML/CFT framework; move toward greater transparency.
- Effectiveness is uneven:
  - Strong civil in rem confiscation practice and emphasis on asset recovery.
  - Near absence of convictions for ML: only one conviction since 2007; domestic ML prosecutions rare.
  - Substantive MLA improvements; average implementation duration reduced from 91 to 59 days (2009→2012).
  - Increased onsite inspections by FMA but over-reliance on mandated audit firms, limited use of sanctions, and not fully risk-based supervision.
  - Preventive measures uneven across sectors; heavy reliance on TCSPs for CDD is a systemic vulnerability.
- Key sector vulnerabilities:
  - Business model: private banking/wealth management; mostly nonresident business; provision of foundations, companies, trusts; TCSP central role.
  - No bureaux de change, no notaries, and (at time of assessment) no casinos in operation.
- Main legal/institutional shortcomings:
  - Fragmented secrecy provisions; Art. 4(3) FIU Act and sector-specific secrecy may restrict FIU access and domestic sharing.
  - DDA blanket exemptions (Art. 10) and limits on delayed/updating CDD leave legacy-account and verification gaps.
  - Art. 98a CPC not covering certain categories (payment providers, e-money, insurance mediators, some DNFBPs).

*Source: Preface and Annex 1, cr18257*

### Legal framework — ML and TF criminalization, sanctions, and predicate scope
- Money laundering (Art. 165 PC):
  - Amended to include concealment, appropriation, safekeeping, conversion, transfer and to cover many predicate offenses.
  - Rating: PC (R.1) — factors: level of proof for predicate offense, only 1 conviction since 2007, no autonomous ML prosecutions.
- Terrorist financing (Arts. 278b–d PC):
  - Financing of individuals and groups criminalized; corporate criminal liability introduced (Arts. 74a–74g PC).
  - Sanctions: basic TF offense imprisonment six months to five years; financing as member 1–10 years.
  - SR.II rating: LC — factor: sanctions described as not proportionate/dissuasive.
- Predicate offenses:
  - Expanded list includes VAT fraud exceeding 75,000 francs affecting EU budget (Art. 165.3a PC) but other serious tax crimes not included as ML predicates.
  - Extraterritorial jurisdiction: ML conduct in Liechtenstein is actionable irrespective of where predicate committed, subject to Art. 64 PC rules.
- Recommendations (selected):
  - Pursue proactive, autonomous ML prosecutions to build jurisprudence on burden of proof.
  - Consider amending list-based ML offense to an all-crimes approach to reduce formal proof burden.
  - Increase penalties for TF to enhance deterrence.

### Asset recovery, seizure, in rem civil forfeiture
- Confiscation regime details:
  - Criminal forms: Abschöpfung der Bereicherung (Art. 20 PC), Verfall/forfeiture (Art. 20b PC), Einziehung (Art. 26 PC).
  - Civil in rem confiscation (Art. 356 CPC) systematically used, especially for foreign predicate proceeds.
- Performance and statistics (selected exact figures):
  - 2009 — Proceeds frozen: Cases 38; amount (in EUR): 57.5 Mio.- ; Proceeds confiscated: Cases 9; amount (in EUR): 55.6 M.
  - 2010 — Proceeds frozen: Cases 34; amount (in EUR): 104 M.- ; Proceeds confiscated: Cases 9; amount (in EUR): 194.35 M.*
  - 2011 — Proceeds frozen: Cases 26; amount (in EUR): 32.4 M.- ; Proceeds confiscated: Cases 4; amount (in EUR): 4.3 M.
  - 2012 — Proceeds frozen: Cases 21; amount (in EUR): 75.9 M.- ; Proceeds confiscated: Cases 6; amount (in EUR): 4 M.
  - *2010 high amount due to Abacha case (assets frozen years earlier).
- Identified limitations:
  - Art. 26.1 ambiguity on instrumentalities; Art. 98a CPC does not cover all relevant DNFBPs.
  - Procedural delays via Constitutional Court can impede confiscation; recommendation to balance rights protection with procedural expedition.
- Recommendations (selected):
  - Extend Art. 98a CPC coverage to include all persons subject to DDA (lawyers, auditors, trustees).
  - Consider extending reversal/sharing of proof rules to all serious offenses in in rem context.
  - Exclude auditors from legal privilege scope in Art. 108 CPC where inappropriate.

### Financial Intelligence Unit (FIU) — powers, operations, resources, and effectiveness
- Legal basis and mandate:
  - FIU Act (2002, amended); FIU receives/analyzes SARs on ML, predicate offenses, organized crime, and FT.
  - FIU structure: operational and strategic analysis departments; International Affairs unit.
- Access to information and limitations:
  - Art. 4 FIU Act: FIU may obtain information “subject to legal provisions relating to the protection of secrecy” — potential legal constraint.
  - Before onsite mission FIU lacked explicit power to request additional info from other reporting entities; DDO Art. 26 amended within two months post-visit to allow FIU to request additional information.
  - Concerns: Art. 4.3 FIU Act and sector-specific secrecy may restrict FIU’s access and exchange; recommendation to remove/severely clarify secrecy limitation.
- SARs and statistics (exact figures):
  - SARs (ML/FT) by year: 2009: 235; 2010: 328; 2011: 289; 2012: 317; 2013 Jan.–June: 145.
  - TOTAL SAR: 2009: 256; 2010: 347; 2011: 295; 2012: 325; 2013 Jan.–June: 163.
  - SARs on terrorism: 2012: 1; 2013 Jan.–June: 1.
  - SARs forwarded to PPO: 2009: 205; 2010: 292; 2011: 197; 2012: 200; 2013 Jan.–June: 87.
  - Suspicious reports by sector (selected): Banks 2012: 218; Professional trustees 2012: 83; Insurers 2012: 28.
- Processes and IT:
  - Analysts have three workstations (SAR data, state info network, open-source queries) and tools: I2, ARIS, World-Check, LexisNexis.
  - Case analysis timelines: expedited cases prioritized; non-expedited analyses “does not take longer than six months.”
- Operational/resourcing:
  - Total FIU staff: 10 (40 percent increase since 2008); budget line in Ministry.
  - FIU joined Egmont (2001); signed multiple MoUs; exchanges with foreign FIUs generally timely but some foreign feedback critical on quality/coverage.
- Effectiveness issues and recommendations:
  - R.26 rating: PC — key factors: FIU access to information subject to secrecy; limited FMA sharing; no clear obligation on authorities to provide info; requirement that FIU transmit SAR itself to PPO may expose reporting entity.
  - Recommendations: remove secrecy constraint in Art. 4.3; introduce express power for FIU to obtain confidential info and compel responses; include specific sanctions for failure to provide info; avoid FIU having to send SAR itself to PPO; implement electronic SAR intake.

### Preventive measures — Financial Institutions (FIs)
- Scope and CDD regime:
  - DDA/DDO set identification, verification, beneficial ownership, record keeping, STR obligations; Art. 10 DDA permits simplified CDD in enumerated cases.
- Key systemic problems (R.5–8 summary):
  - Verification of beneficial owners not always required to be based on reliable sources; minimum requirement often a signed declaration by contracting party.
  - Art. 10 DDA blanket simplified CDD exemption inconsistent with FATF; Art. 5(2) occasional transaction CDD limited to cash transactions.
  - No legal obligation to apply CDD to all existing customers at appropriate times or on basis of materiality; legacy accounts persist.
  - Art. 18(2) DDO permits delayed verification/identification in wide circumstances; recommended to limit delays to verification only and require prompt completion.
  - Politically exposed persons (PEPs): Art. 11 requires PEP treatment as high risk with management approval; no express legal obligation to establish source of wealth in all cases.
- Wire transfers and recordkeeping:
  - EC Regulation 1781/2006 implemented; PSPs must verify payer info before transferring where >= 1,000 euros (Art. 5(2)), and ensure “complete information” accompanies transfers.
  - Record retention: Art. 20 DDA requires records for minimum ten years; no explicit obligation to keep business correspondence; R.10 rated LC.
- Recommendations (selected):
  - Remove Art. 10 blanket exemption; permit simplified CDD only in proven low-risk cases; require minimum CDD always.
  - Revise Art. 5(2) to cover non-cash occasional transactions.
  - Require FIs to verify beneficial owners using reliable, independent sources (Art. 11 amendments).
  - Require periodic, risk-based reviews of existing customers; eliminate CHF 25,000 threshold allowing bearer passbook withdrawals without ID.
  - Extend cross-border correspondent obligations to EEA respondent institutions and require checks that respondent AML/CFT controls are adequate/effective.

### DNFBPs, TCSPs, casinos, lawyers, auditors, real estate
- DNFBP coverage and vulnerabilities:
  - DDA covers trustees, trust companies, persons with Art. 180aPGR certificate, lawyers, auditors, real estate brokers, dealers in goods, etc.
  - TCSP sector particularly vulnerable: services to nonresidents, intermediated business, role in creating complex legal persons; inspections only every three years; limited licensing/fit-and-proper for whole TCSP entities.
- Implementation weaknesses across DNFBPs:
  - Ongoing monitoring often ineffective; reliance on negative media/third-party intelligence triggers SARs; internal AML programs variable.
  - Delegation and reliance: Art. 14 DDA allows delegation to supervised foreign entities, but reliance on being “subject to” Third EU Directive not equivalent to ensuring FATF-level measures in practice (R.9 LC).
- Casinos (land-based and online):
  - CDD thresholds in CO and OGO often higher than EUR 3,000 (FATF R.12); not all transactions covered; identification of beneficial owners not required in all R.12 cases; recommendations to lower thresholds to EUR 3,000 and require beneficial owner verification.
- Recommendations (selected for DNFBPs):
  - Amend Art. 11 DDA so beneficial owner verification based on reliable sources, not signature only.
  - Remove Art. 10 blanket exemption; require DNFBPs to perform minimum CDD; allow simplified CDD for foreign customers only if Liechtenstein satisfied regulatory equivalence.
  - Require compliance officer at management level and active role in onboarding/monitoring.
  - Extend enhanced CDD to persons from as well as in high-risk countries.
  - Require casinos to identify/verify beneficial owners and PEP status for all R.12-relevant transactions.
- Key ratings:
  - R.12: PC — many deficiencies (beneficial ownership verification, legacy accounts, blanket exemptions, Art. 18(2) permissiveness, CHF 25,000 passbook threshold).
  - R.16: C for DNFBPs (issues include compliance officer management-level absence; tipping-off gap).

### Supervision — Financial Market Authority (FMA), mandated audit firms, and sanctions
- FMA mandate and resources:
  - FMA is integrated supervisor; DDA Art. 23 designates FMA as AML/CFT supervisor.
  - Staffing: 72.5 full-time equivalents end-2012 (75.6 at evaluation); budget increased (CHF 6.6 million in 2006 → CHF 19.32 million in 2012).
- Inspection model and delegated audits:
  - Heavy reliance on mandated private audit firms to conduct annual inspections across many sectors; FMA approves audit firms and can accompany inspections.
  - Annual inspection cycle often uniform, not risk-based; DNFBPs (e.g., TCSPs) often inspected every three years.
- Conflict of interest and effectiveness concerns:
  - Audit firms nominated by firms and paid by firms can create conflicts; FMA oversight of audit firms lacks systematic ratings, rotation, or benchmarking.
  - Low number of serious sanctions; FMA rarely imposes fines beyond written warnings.
- Sanctions specifics:
  - DDA Art. 31 administrative fines up to CHF 100,000; criminal fines for natural persons up to CHF 360,000 and legal persons up to CHF 600,000.
  - Assessors: maximum institutional fines “too small to be dissuasive”; R.17 LC (insufficiently proportionate/dissuasive).
- Recommendations (selected):
  - Adopt a fully risk-based supervisory approach: vary inspection frequency/scope by risk, increase FMA-led inspections, free resources by reducing mandated audit coverage for low-risk firms.
  - Mitigate audit firm conflicts: require rotation, systematic performance oversight, review working papers, accompany inspections more often.
  - Increase sanctioning use and consider higher fines for institutions where appropriate.
  - Clarify inspection powers and ensure statutory authority overrides secrecy provisions for AML/CFT supervisory purposes.

### Legal persons, trusts, bearer shares, and beneficial ownership transparency
- Commercial registry, deposited vs registered entities:
  - Total all legal entities (By 12/31/2011 | New entries | Deletions | By 12/31/2012): 58‘391 | 1‘455 | 6‘640 | 53‘206 (exact figures preserved).
  - Deposited foundations end-2012: 28,815 (new deposited foundations: 32,425 | 534 | 4‘144 | 28,815).
- Beneficial ownership access and challenges (R.33):
  - Public registry often does not contain beneficial ownership or beneficiaries; deposited documents not publicly accessible.
  - FMA supervisory powers (Art. 28.4 DDA) can compel information but are described as constrained to supervisory function; practical limits and legal uncertainty remain about sharing beyond supervision.
  - Nominee directors/shareholders widely used; no statutory requirement for nominees to disclose nominator.
- Bearer shares reform:
  - Law (entered March 1, 2013) requires immobilization/registration via custodian with register of shareholder details; transitional rules allow deposit by March 1, 2014 and a ten-year phase-out mentioned; assessors consider transition period overly long and custodian exemptions present risks.
  - Custodian requirements may permit non-DDA-covered custodians in some cases (Art. 326.b variants), weakening BO identification.
- Trusts and trust certificates:
  - Registered trusts: 2,666; Deposited trusts: 171 (end-2012).
  - Beneficial owner definitions extended but settlor not always explicitly included unless control powers; trust certificates (Art. 928 PGR) may create bearer-like creditor interests — ambiguity in coverage.
- Ratings and recommendations:
  - R.33: PC — system does not ensure timely access to adequate, accurate beneficial ownership info for all legal persons.
  - R.34: LC — restrictive FMA access to beneficial ownership info limits effectiveness.
  - Recommendations include: subject deposited foundations to same registration as registered foundations; require nominees to disclose nominator; require custodians to be licensed and DDA-covered; expand FMA powers to access information beyond narrow supervisory context; consider including settlor in BO definition for trusts; accelerate and tighten bearer share immobilization/registration regime.

### National and international cooperation, MLA, extradition, and FIU exchanges
- Domestic coordination:
  - PROTEGE AML/CFT working group established Jan 15, 2013; chaired by FIU; participants include FMA, Police, Public Prosecutor, Office of Justice, Tax Admin, Foreign Office; tasked with national risk assessment and coordinated AML/CFT strategy.
  - Recommendation: enhance FMA–FIU cooperation and harmonize secrecy provisions to facilitate domestic information exchange.
- Mutual Legal Assistance (MLA) — performance and statistics:
  - Incoming MLA requests (selected): 2009: 339 (avg 91 days); 2012: 333 (avg 59 days).
  - Seizure/confiscation implemented for incoming requests (selected): 2009: 2 requests; amount EUR 2,120,000; 2010: 3 requests; amount EUR 5,068,000.
  - MLA improvements: average duration reduced from 91 to 59 days; introduction of Art. 54a MLA for spontaneous information transmission.
  - Remaining gaps: Art. 98a CPC does not cover all DDA subjects; legal privilege and secrecy can hamper evidence gathering for certain professions.
- Extradition and prosecution transfer:
  - Extradition statistics: 2009: 6 requests (avg 19.5 days); 2012: 4 requests (avg 92 days); prosecutions transferred abroad: 2009: 18; 2010: 22; 2011: 31; 2012: 14.
  - Recommendation: adopt legislation introducing serious tax crimes as extradition grounds; extend extradition for serious VAT fraud beyond Schengen.
- FIU international exchange:
  - FIU exchanges via Egmont and bilateral MoUs; outgoing/incoming FIU requests: 2009 incoming 231 / outgoing 235; 2012 incoming 304 / outgoing 332.
  - Constraints: Art. 7 FIU Act includes condition not to violate “fiscal interests” and Art. 4(3) secrecy caveat; assessors recommend clarifying/removing fiscal/secrecy restrictions; enable FIU to request additional info from reporting entities upon foreign FIU request regardless of SAR status.
- Recommendation 40 / SR.V:
  - R.40: PC and SR.V: PC — key issues: DDA Art. 37 requiring equivalence to Art. 23 COPE and secrecy/fiscal references in FIU Act create unduly restrictive conditions for information exchange; harmonize and remove unreasonable equivalence/fiscal constraints.

### Cash controls (SR.IX)
- Police Act Art. 25e cash control provisions:
  - Threshold CHF 10,000 (or lower if suspicion); definition of “cash” includes bearer negotiable instruments.
  - Implementation: disclosure system operational January 2013; practically, no controls at Swiss border due to customs union; only one disclosure after onsite mission at Austrian border.
  - Sanctions for false/false information: CHF 5,000 (natural persons) or imprisonment up to one month alternative; not proportionate to amount; not applicable to legal persons.
  - SR.IX rating: PC — reasons: unclear coverage for containerized cargo/mail, seizure conditions more restrictive than FATF “stop or restrain,” sanctions not proportionate, inconsistent application at Swiss border, lack of training and SR.IX best practices.

### Law enforcement, prosecutions, and ML/FT statistics
- Judicial follow-up (selected aggregate ML stats 2008–2012):
  - ML Investigations (aggregate 2008–2012): Investigations: 61; Prosecutions: 2; Convictions (final): 1.
- Detailed ML case stats (selected years):
  - 2009 ML: Investigations Cases 50; Prosecutions Cases 0; Convictions (final) Cases 0; Proceeds frozen: Cases 38; amount (in EUR): 57.5 Mio.-; Proceeds confiscated: Cases 9; amount (in EUR): 55.6 M.
  - 2010 ML: Investigations Cases 58; Prosecutions Cases 1; Convictions (final) Cases 0; Proceeds frozen: Cases 34; amount (in EUR): 104 M.-; Proceeds confiscated: Cases 9; amount (in EUR): 194.35 M.
  - 2011 ML: Investigations Cases 55; Prosecutions Cases 1; Convictions (final) Cases 0; Proceeds frozen: Cases 26; amount (in EUR): 32.4 M.-; Proceeds confiscated: Cases 4; amount (in EUR): 4.3 M.
  - 2012 ML: Investigations Cases 56; Prosecutions Cases 1; Convictions (final) Cases 0; Proceeds frozen: Cases 21; amount (in EUR): 75.9 M.-; Proceeds confiscated: Cases 6; amount (in EUR): 4 M.
- FT statistics:
  - One FT investigation in 2011 (1 person) but no prosecutions or convictions; authorities consider TF risk low.
- Law enforcement capacity:
  - Police count: 120 staff, with 7 investigators assigned to financial and economic affairs.
- Observation: high number of FIU-triggered investigations but very few prosecutions/convictions domestically; frequent transfer/waiver of prosecutions to foreign jurisdictions.

### Summary of principal recommendations (selected consolidated list)
- Legal/policy changes:
  - Remove or clarify Art. 4.3 FIU Act secrecy restriction and Art. 7 fiscal/secrecy condition; empower FIU to obtain additional info and compel responses with specific sanctions for noncompliance.
  - Remove blanket simplified CDD exemptions in Art. 10 DDA; require minimum CDD in all cases and limit simplified CDD to proven low-risk scenarios and equivalent foreign jurisdictions assessed by Liechtenstein.
  - Amend Art. 18(2) to limit delayed measures to verification (not identification) and require timely completion.
  - Amend Art. 98a CPC to include all DDA subjects (lawyers, auditors, trustees) for ML/FT trace/compel powers.
  - Amend penalties (TF and administrative fines) to be proportionate and dissuasive; increase maximum institutional fines.
  - Clarify and harmonize secrecy provisions across sector-specific laws and DDA so FMA/FIU can share confidential information domestically and with foreign counterparts without undue restrictions.
  - Accelerate and tighten bearer share immobilization/registration regime; require custodians be licensed and DDA-covered and shorten transitional phase.
  - Consider transposing serious tax crimes as ML predicates and extraditable offenses.
- Supervisory and operational measures:
  - FMA: adopt a fully risk-based supervisory model, increase FMA-conducted inspections (esp. TCSPs), reduce over-reliance on mandated audit firms, require rotation and systematic oversight of mandated audit firms, strengthen guidance to FIs/DNFBPs.
  - FIU: implement electronic SAR intake, ensure SAR protective markings, maintain statistics on SARs related to intended transactions, request regular feedback from foreign FIUs on usefulness, avoid disseminating SAR itself to PPO where possible.
  - DNFBPs/TCSPs: strengthen supervision, require compliance officer at management level, require more frequent inspections based on risk, require robust CDD/beneficial owner verification from intermediaries and introducers.
  - Cash controls: apply disclosure requirements to containerized cargo/mail; align seizure powers with FATF “stop/ restrain”; introduce proportionate sanctions including for legal persons; ensure application at Swiss border.
- Judicial and legal practice:
  - Encourage autonomous ML prosecutions to create domestic jurisprudence and reduce dependence on foreign predicate prosecutions.
  - Streamline Constitutional Court procedural use where dilatory tactics impede asset recovery and extradition, balancing rights protection with procedural reasonableness.

*Source: Consolidated recommendations and analysis, cr18257*

*Source: cr18257 — IMF/MONEYVAL detailed assessment (PDF chapter).*

### Preface  ...............................................................................................................

### Preface

### Purpose and scope
- Partial re-assessment of Liechtenstein’s anti-money laundering (AML) and combating the financing of terrorism (CFT) regime.
- Based on the Forty Recommendations 2003 and the Nine Special Recommendations on Terrorist Financing 2001 of the Financial Action Task Force (FATF).
- Prepared using the AML/CFT assessment Methodology 2004 and following the MONEYVAL rules of procedures of the “fourth evaluation round” for identifying FATF recommendations subject to reassessment.

### Recommendations and reassessment focus
- The evaluation team focused on the effectiveness of implementation of the FATF’s main and other significant recommendations, specifically:
  - Recommendations 1, 3, 4, 5, 10, 13, 17, 23, 26, 29, 30, 31, 35, 36 and 40.
- Special Recommendations subject to reassessment:
  - SR. I, SR.II, SR.III, SR.IV and SR.V.
- The team also assessed compliance with and effectiveness of implementation of all other FATF recommendations that had been rated non-compliant or partially compliant in the third round.

### Materials, mission, and consultations
- Considered all materials supplied by the authorities and verifiable information subsequently provided.
- On-site mission: June 12–24, 2013.
- Meetings and stakeholder engagement:
  - The assessment team had over fifty meetings.
  - More than half of the meetings were with representatives of the private sector subject to the AML/CFT requirements.
  - During the mission the team met with officials and representatives of all relevant government agencies and the private sector.
- A list of the bodies met is set out in the report (annexes).

*Source: Preface, cr18257*

### Annex 1 to the detailed assessment report.

### Annex 1 to the detailed assessment report

### Executive summary — Key findings
- Liechtenstein has made significant steps and considerable progress since the last mutual evaluation, notably:
  - Legal framework more closely aligned with the Financial Action Task Force (FATF) recommendations.
  - Consolidation of an overall robust institutional framework for combating money laundering (ML) and terrorist financing (TF).
  - Movement towards greater transparency; domestic cooperation is robust and key stakeholders enjoy the trust of the financial and nonfinancial sectors.
- Effective implementation is uneven:
  - Proactive use of the in rem regime of confiscation of criminal proceeds is effective.
  - Near absence of convictions for ML and an exiguous number of ML stand-alone prosecutions (noted since the last mutual evaluation) raise questions on criminal approach effectiveness.
  - Substantive progress on mutual legal assistance (MLA), though feedback from some countries on MLA and FIU information exchange is critical.
  - Increase in onsite inspections by the Financial Market Authority (FMA), but over-reliance on external firms, lack of a fully fledged risk-based supervisory approach, and limited use of sanctions reduce supervisory effectiveness.
  - Preventive measures and suspicious transaction reporting are uneven across sectors and affected by over-reliance on trust and company service providers (TCSPs) for elements of customer due diligence (CDD).
- Remaining legal shortcomings:
  - Fragmented financial secrecy provisions that are not always fully coordinated and could impact FIU core functions and overall AML/CFT effectiveness.
  - Recommendation: review and harmonize secrecy provisions and ensure a clear provision stating that authorities’ powers with regard to AML/CFT supersede any secrecy provisions enshrined in other laws.
- Intrinsic sector vulnerabilities:
  - Business model focused on private banking, wealth management, and mostly nonresident business (high risk by FATF).
  - Provision of corporate structures (foundations, companies, trusts) for wealth management, asset structuring, and asset protection.
  - TCSP sector particularly vulnerable due to services offered, intermediated and nonresident customers, and central role in creating complex legal persons—this complicates tracing beneficial ownership.
  - Insurance sector shows increasing use of insurance products in STRs.
  - Real estate sector does not appear to pose particular risks given limited investment possibilities and inaccessibility for foreigners.
  - No bureaux de change, no notaries, and (as yet) no casinos in Liechtenstein.

### Legal systems and related institutional measures
- ML offense:
  - Brought fully in line with the relevant convention and FATF standards.
  - Substantial number of investigations rarely result in domestic ML prosecution; only one conviction since 2007.
  - Policy of transferring prosecutions to foreign judicial authorities when deemed more effective; recommendation from previous assessment to develop autonomous ML cases not followed up.
- TF and sanctions:
  - Technical implementation of CFT standards ensured; all FT Convention Treaties in force; sole financing of relevant offenses now punished as terrorist financing.
  - Financing of a terrorist individual or group penalized.
  - Imprisonment term described as rather low compared to most European jurisdictions, weakening deterrent effect.
  - Adoption of the Enforcement of International Sanctions Act (ISA) improved terrorist asset freezing regime but issues remain:
    - ISA restricts enforcement of sanctions to those adopted by the “most significant trading partners,” narrowing implementation of UNSCR 1373.
    - No determination in ISA or other texts on procedure in event of establishment of a domestic list.
- Asset recovery:
  - Strong focus on asset recovery with effective use of civil in rem confiscation and criminal confiscation; civil forfeiture procedure systematically used for foreign predicate proceeds and takes priority over criminal convictions.
  - Confiscation regime notable for number of conservatory measures, systematic use of in rem confiscation, and overall amount of forfeited criminal assets.
  - Performance can be hampered by dilatory procedures before the Constitutional Court; legislator should balance protection of fundamental rights with reasonable procedural application.
- FIU powers and information exchange:
  - FIU power to obtain additional information from any reporting entity strengthened right after the onsite visit.
  - FIU power under Article (Art.) 4.3. of the FIU Act is subject to secrecy provisions and could affect FIU’s ability to undertake core functions.
  - Certain sector-specific laws restrict FIU access to full range of information from the FMA.
  - Recommendations:
    - Ensure FIU powers to request and obtain information from domestic authorities and reporting entities are not subject to unduly restrictive conditions; amend Art. 4.3. of the FIU Act accordingly.
    - Introduce clear provisions to compel domestic authorities to provide information requested by the FIU.
    - Subject reporting entities to specific sanctions for failure to provide information to the FIU when requested.
  - Quality of FIU notifications to the Office of the Public Prosecutor (OPP) has improved due to enhancements in the analytical process; FIU should maintain vigilance to sustain improved quality.
  - FIU issued comprehensive guidelines on reporting, including standard reporting forms and procedure for Suspicious Activity Reports (SARs), and has continued training reporting entities.

### Preventive measures — Financial institutions
- Overall framework:
  - Legal framework for preventive measures significantly improved, but effectiveness hampered by business model characteristics and implementation issues across financial industry.
  - Over-reliance on professionals (mostly trustees) introducing contracting parties and representing legal structures distorts AML/CFT obligations, particularly identification and verification of beneficial owners.
  - Financial institutions (FIs) do not necessarily treat high risk activities and customers as such; uneven implementation of due diligence obligations across FIs.
  - Some FIs have thoughtful, risk-based policies and procedures; others rely on minimum statutory requirements without tailoring to institution-specific risks.
  - Deficiencies include lack of exhaustive customer profiles based on reliable and up-to-date information and documentation, particularly for higher risk legal entity customers with complex structures.
  - Documentation used to verify parties varies across industry.
  - Recommendation: FIs and DNFBPs should improve CDD effectiveness by developing thorough understanding of customers and related parties based on reliable and up-to-date information and documentation, with increased focus on beneficial owner(s).
- Technical deficiencies in preventive measures:
  - Verification measures for customers and beneficial owners do not have to be based on reliable sources in all instances.
  - Certain blanket exemptions under the Due Diligence Act (DDA) for simplified CDD are not permissible under international standard.
  - No requirement in the DDA that CDD measures be applied to all existing customers at appropriate times and on basis of materiality.
  - Cross-border correspondent relationships: unjustified presumption that all EU and EEA countries adequately apply FATF Recommendations.
  - Enhanced CDD required only for persons in, but not from, high risk jurisdictions.
  - DDA grants authorities only few countermeasures to apply to high risk jurisdictions.
  - Record keeping adequate, with minor deficiencies identified relating to business correspondence and transaction records.
- Reporting and freezing:
  - Reporting requirement aligned with the standard, particularly for terrorist financing and attempted (occasional) transactions.
  - Automatic five-day freezing mechanism retained; FIU empowered to release certain transactions before expiry of freezing period.
  - FIU’s requirement to submit SARs to the prosecutor’s office exposes reporting entity that filed the SAR.
  - Reporting entities aware of obligation but understanding of implementation not satisfactory in all cases.
  - Large majority of SARs triggered by negative information in media or commercial intelligence databases.
  - Main contributor of SARs is the banking sector.
  - FIU received five SARs on FT, none substantiated a concrete case of FT.
  - Recommendation: authorities should assess whether the number of FT SARs is commensurate with FT threat in Liechtenstein.
- Secrecy provisions and information sharing:
  - Secrecy provisions should be harmonized and revised to avoid affecting FIU core functions and domestic information sharing.
  - FMA has broad powers to access confidential information, but conflicting provisions in sector-specific laws and the DDA do not clearly allow domestic sharing, including with FIU.
  - No measures in place to ensure secrecy provisions in sector-specific laws do not inhibit FIs’ ability to share confidential information where required under FATF Recommendations 7 or 9.
  - Steps recommended:
    - Amend sector-specific laws such as the Banking Act or the DDA to clarify that FMA’s powers under the DDA supersede other secrecy provisions.
    - Clarify expressly that Liechtenstein FIs may share otherwise confidential information with other FIs where required under FATF Recommendations 7 or 9.
    - Clarify expressly that the FMA can share confidential information with the FIU regardless of existing secrecy provisions.

### Supervision and the role of auditors and TCSPs
- Supervisory framework and FMA:
  - FMA responsible for supervision of compliance by FIs and DNFBPs and has powers needed to undertake functions.
  - Effective implementation of AML/CFT supervisory regime needs enhancement.
- Use of private audit firms:
  - Over-reliance on private audit firms to conduct inspections may reduce inspection effectiveness and quality of supervision.
  - Potential conflict of interest: audit firms appointed by FMA but nominated and paid for by obligated firms.
  - Negligible number of sanctions and assessor interviews indicate audit firms’ reviews may not be sufficiently rigorous.
  - FMA accompanies audit firms on some inspections and conducts few itself, limiting FMA market experience.
  - Recommendation: FMA should conduct more inspections itself and strengthen measures to mitigate conflict of interest in mandated audit firms.
- Risk-based supervision:
  - Absence of a fully fledged risk-based approach to allocation of inspection resources affects effectiveness.
  - Annual inspections by audit firms produce information used by FMA for individual firms, but no routine off-site AML/CFT reporting and insufficient analysis of audit firm information to detect broader trends.
  - DDA/DDO obligations detailed but scope for more guidance to specify FMA expectations in context of prevailing business model risks.
  - Supervisory approach, including annual inspection cycle for FIs, does not focus on higher risk firms or business areas within firms.
  - DNFBP sector has three-year inspection cycle despite TCSPs being higher risk and source of risk for FIs.
  - Recommendation: FMA should adopt a risk-based approach, amend guidance to audit firms accordingly, conduct more risk-based and themed inspections targeting higher risk business, particularly TCSPs.

*Annex 1 to the detailed assessment report.*

### 18. The FMA has a range of sanctions available to enforce the AML/CFT measures, but

### 18. The FMA has a range of sanctions available to enforce the AML/CFT measures, but

### Sanctions and FMA enforcement
- The FMA has sanctions at its disposal against individuals, including fines.
- The maximum fine for institutions is described as "too small to be dissuasive" and should be increased.
- In practice, the FMA rarely imposes sanctions beyond written warnings and should make more effective use of its more serious sanctions.

### Preventive Measures — Designated Nonfinancial Businesses and Professions (DNFBP)
- All the DNFBP specified by the FATF Recommendations are covered by the DDA, and all obligations applicable to FIs extend to DNFBPs.
- Deficiencies noted for FIs equally apply to DNFBPs.
- Casinos are subject to additional laws and regulations, but Liechtenstein has not yet issued any licenses for casinos; practical application of these requirements could not be reviewed.
- DNFBPs, TCSPs in particular, do not effectively implement policies and procedures to manage AML/CFT risk or thoroughly understand customers, beneficial owners, related parties, and related legal structures based on exhaustive and credible documentation.
- Deficiencies include:
  - Ongoing monitoring procedures ineffective at identifying and investigating suspicious activity.
  - Uneven implementation of due diligence obligations across the sector.
- Concern: weaknesses cascade through the Liechtenstein financial system due to a culture of trust among TCSPs and FIs and common practice for FIs and other DNFBPs to rely on TCSPs for provision and certification of customer information.
- TCSP sector vulnerabilities:
  - Particularly vulnerable to ML and potentially FT, with far-reaching consequences.
  - Least regulated element of the system with no comprehensive licensing and prudential regime (at the time of the onsite visit).
  - AML/CFT inspections being carried out only every three years.
  - Authorities carry out onsite inspections at TCSPs every three years unless there is a reason for increasing the frequency.
  - Information held by Liechtenstein professional trustees may not always be accurate; trustees rely heavily on introducers, many foreign, and may rely on declarations from foreign introducers on beneficial owners.
  - TCSPs acting as representatives, shareholders, and managers of legal entities are also customers of FIs, so weaknesses can rapidly spread through the financial system.
- Recommendation: The FMA should consider increasing the frequency of the TCSP inspection cycle based on risk and conducting more targeted inspections.

### Legal Persons and Arrangements and Nonprofit Organizations (NPOs)
- Progress since the last Mutual Evaluation Report (MER) in improving transparency of legal persons and arrangements and NPOs, but weaknesses remain that may pose risk and affect effective implementation.
- Important legal changes:
  - DDO’s definition of beneficial owner amended to extend to those who control legal entities.
  - New law on foundations adopted in 2008.
  - New law (December 2012) introduced requirements concerning bearer shares and certificates and for certain types of companies to keep shareholders registers at the registered seat.
  - Art. 180aPGR ensures most legal entities have a director subject to the DDA.
- Remaining challenges and vulnerabilities:
  - Deposited foundations and anstalten can be used as placeholders for more complex structures and present challenges in identifying beneficial owners or beneficiaries.
  - Regime of access to beneficial owner information relies on TCSPs as main repository and on FMA and law enforcement access; effectiveness is questioned given trustee CDD and supervision issues.
  - Immobilization and registration system for bearer shares recently introduced; too early to form final opinion on effectiveness given absence of a specific risk assessment and that legal entities issuing bearer shares often do so for the totality of their shares.
- Recommendations to improve transparency of legal persons and arrangements:
  - (i) Strengthen supervision of TCSPs to ensure they obtain and maintain full, accurate, and up-to-date information on beneficial owners.
  - (ii) Clarify the powers of competent authorities to obtain, compel, and share confidential information, domestically and internationally, for the purpose of Recommendation 33.
  - (iii) Subject "deposited" foundations to the same registration requirements as "registered" foundations (also in light of the new FATF standard).

- Supervision of NPOs:
  - Foundation Supervisory Authority (FSA) established in 2009 to oversee foundations with a common-benefit purpose.
  - Associations with a common-benefit purpose are still not subject to any form of supervision.
  - Supervision of NPOs by the FSA, assisted by audit firms, does not adequately extend to FT issues.
  - No measures in place to sanction violations of measures applicable to NPOs.
  - Laws regulating NPOs were reviewed in June 2008 to strengthen founder responsibilities and governance, but the review was not preceded by an assessment of the NPO sector to determine FT risk.
  - Outreach by the FSA to the NPO sector to protect it from FT abuse was very limited.

### National and International Cooperation
- Domestic cooperation:
  - Creation of the PROTEGE working group, chaired by the FIU and consisting of major AML/CFT stakeholders, consolidates coordinated AML/CFT work and national preparation for new standards, including the national risk assessment (in progress at the time of the onsite visit).
  - Issues with financial secrecy laws may affect effectiveness of domestic exchange of information.
  - Cooperation and exchange of information between the FMA and the FIU should be enhanced.
- Mutual Legal Assistance (MLA) and international cooperation:
  - International cooperation is fundamentally important for Liechtenstein; MLA traffic is intense in both directions.
  - Figures indicate a generally responsive approach by Liechtenstein.
  - Improvements in MLA effectiveness include reducing dilatory tactics and shortening average implementation duration from 91 to 59 days.
  - Serious and organized fiscal fraud excluded from fiscal exception rule insofar as it relates to serious value-added tax (VAT) fraud affecting the EU budget.
  - Effectiveness of obtaining bank records could be challenged by dilatory tactics, as noted in the context of the confiscation regime.
  - Authorities should assess if legal privilege could impact effectiveness of international cooperation.
- Extradition:
  - Liechtenstein judiciary shows cooperative willingness.
  - Duration of extradition proceedings substantially reduced to a reasonable average of around three months.
  - Dilatory procedural tactics before the Constitutional Court have been met by prioritizing extradition matters.
- FIU international exchange:
  - FIU generally exchanges available information with foreign counterparts in a timely manner.
  - Restrictions on FIU powers to exchange information:
    - FIU can only obtain information from a reporting entity if a SAR has been submitted.
    - Power to obtain information indirectly through the FMA is limited.
  - These factors could impact constructive and effective information exchange with foreign FIUs.
  - Recommendation: Establish a clear power for the FIU to obtain confidential and other information from reporting entities and other authorities in response to foreign FIU requests.
- FMA and confidential information:
  - FMA can obtain confidential information for purposes of international cooperation and is obliged to provide information to foreign authorities, subject to certain conditions.
  - FMA’s power to obtain confidential information for foreign cooperation is clearly provided for FIs; position with respect to TCSPs is less clear.
  - Assessors accept that judicial decisions must be assumed to provide the FMA with the power to obtain confidential information from TCSPs and pass it to foreign authorities.
  - FMA can conclude cooperation agreements and can exchange confidential information in the absence of such agreements; it can protect confidential information received from foreign authorities.
  - Confidentiality equivalence provisions:
    - Sector-specific acts for FIs are less restrictive, but the DDA is the only statute available for exchanging confidential information relating to TCSPs.
    - Risk of challenge based on strict interpretation of the law.
    - Under the DDA, the FMA is obliged to apply a test relating to the protection of confidential information by a requesting country which, if interpreted strictly, could prevent exchange.
    - Recommendation: FMA should seek to remove this provision and replace it with a more general provision requiring adequate confidentiality protection by a recipient authority.

### General information and structural elements
- Geography and governance:
  - Area: 160 sq. km. (61.8 sq. miles).
  - Constitutional monarchy; Head of State HSH Prince Hans-Adam II von und zu Liechtenstein, who in 2004 entrusted Hereditary Prince Alois to exercise sovereign powers.
  - Parliament (Landtag) has 25 elected members serving four years; parliament nominates the five member government, appointed by the Prince for four-year terms.
  - To be valid, each new law enacted by the parliament requires the consent of the Prince.
- GDP and GNI (at current prices in 2010):
  - GDP: CHF 5.3 billion
  - GNI: CHF 4.5 billion
- Workforce and demographics:
  - Majority of workforce comprises persons living abroad: 52 percent in 2011.
  - Population: just over 36,000 inhabitants.
  - One third of population are foreign nationals.
  - Country divided into eleven communities; Schaan largest, Vaduz second and capital.
  - Unemployment rate in 2011: 2.5 percent (an increase of 0.3 percent over the previous year).
  - Services sector employed nearly 60 percent of the workforce in 2011; industrial sector nearly 40 percent; remainder in agricultural sector.
- GDP by sector [2010]:
  - Industrial production: approximately 39 percent of GDP.
  - Financial services: approximately 27 percent of GDP.
- Historical GDP (CHF billion):
  - 2006 — 5.0
  - 2007 — 5.5
  - 2008 — 5.5
  - 2009 — 4.9
  - 2010 — 5.3
- Trade in goods (without Switzerland), CHF million:
  - Exports and Imports by year:
    - 2007 — Exports: 4.182; Imports: 2.417
    - 2008 — Exports: 4..245; Imports: 2.461
    - 2009 — Exports: 3.081; Imports: 1.924
    - 2010 — Exports: 3.325; Imports: 1.882
    - 2011 — Exports: 3.329; Imports: 1.965
- Currency and international integration:
  - Customs and monetary union with Switzerland since 1923; Swiss National Bank responsible for the Swiss franc (CHF) currency area.
  - As an EEA member, Liechtenstein is fully subjected to the EU AML/CFT framework.
  - Party to international organizations and agreements including: Statute of the International Court of Justice (since 1950), Helsinki Final Act/OSCE (since 1975), Council of Europe (since 1978), United Nations (since 1990), European Free Trade Association (EFTA) full member (since 1991), World Trade Organization (WTO) (since 1995).
- International anti-corruption and transparency participation:
  - Joined GRECO partial agreement on January 1, 2010; joint evaluation (October 2011) concluded country in an "early stage when it comes to combating domestic corruption" and recommended improvement of preventive measures.
  - Submitted to Phase 1 review by the Global Forum on Transparency and Exchange of Information for Tax and requested supplemental review; Global Forum considered Liechtenstein to have taken adequate steps to remedy Phase 1 deficiencies and allowed progression to Phase 2.
  - Endorsed the UN Convention Against Corruption in December 2003 (ratified in 2010).
  - Provides financial and technical support to the International Center for Asset Recovery (ICAR) in Basel.
  - Not an OECD member and not party to the 1999 OECD Convention on Combating Bribery of Foreign Public Officials.
  - Signed (but not ratified) the Council of Europe Criminal Law Convention (ETS 173) and its Additional Protocol (ETS No. 191) on November 17, 2009; not ratified or signed the Civil Law Convention on Corruption (ETS174).

### General situation of Money Laundering (ML) and Financing of Terrorism (FT)
- Domestic crime:
  - Rate of domestic crimes is low due to small population and social control, but as a financial center with strict confidentiality rules, Liechtenstein is vulnerable to attracting criminal proceeds or undeclared assets, particularly tax related and predominantly of foreign origin.
- Predicate offenses:
  - White collar crimes are typical predicates, both domestic and foreign.
  - Authorities have noticed an increase in corruption related cases, attributed to sharper law enforcement focus abroad.
- Noted studies and incidents:
  - A World Bank/Stolen Asset Recovery Initiative study ("The Puppet Masters") indicated roughly 13 percent of grand corruption investigations studied involved misuse of foundations, anstalten, or other nonprofit corporate vehicle types; approximately half originated in Liechtenstein, skewed by the Ferdinand and Imelda Marcos scheme (15 anstalten).
  - Reference to the "2008 Liechtenstein tax affair" as evidence of vulnerability to tax-related undeclared assets.

*Source: cr18257 - 18. The FMA has a range of sanctions available to enforce the AML/CFT measures, but*

### 42. On domestic criminality, following statistics were provided:

### 42. On domestic criminality, following statistics were provided

### Major offenses prosecuted (predicates to money laundering)
- Sexual exploitation, including sexual exploitation of children: 2009: 1; 2010: 1; 2011: 3; 2012: 1
- Illicit trafficking in narcotic drugs and psychotropic substances: 2009: 1; 2010: 2; 2011: 1; 2012: 1
- Illicit trafficking in stolen and other goods: 2011: 1
- Corruption and bribery: 2009: 1; 2010: 3; 2011: 1; 2012: 2
- Fraud: 2009: 5; 2010: 6; 2011: 6; 2012: 6
- Environmental crime: 2010: 1
- Murder, grievous bodily injury: 2009: 1; 2010: 4
- Robbery or theft: 2009: 9; 2010: 10; 2011: 9; 2012: 7
- Extortion: 2009: 3; 2012: 1
- Money laundering (domestic category): 2010: 1; 2011: 1; 2012: 1
- Other offenses: 2009: 3; 2010: 8; 2011: 6

### Investigations, indictments, and convictions (Liechtenstein tax-evasion affair context)
- Yearly Investigations (cases): 2009: 521; 2010: 566; 2011: 576; 2012: 533
- Indictments/demand for a penalty (cases): 2009: 24/92; 2010: 32/141; 2011: 32/113; 2012: 19/87
- Convictions based on indictments/demands (cases): 2009: 25/76; 2010: 22/95; 2011: 27/92; 2012: 14/65

### Money laundering (ML) — structural vulnerabilities and sector exposure
- Main attractions of Liechtenstein: broad range of financial services, in particular wealth management and private banking services.
- Typical private banking features: large cash transactions uncommon; payments to and withdrawals from Liechtenstein accounts limited.
- Corporate structures: holding companies used for possession and administration of shares registered in different jurisdictions can be ML vehicles.
- Sectors exposed to ML:
  - Banks: offer a variety of products that can be abused for ML.
  - DNFBP (TCSP and lawyers): well established; corporate services face equal challenges.
  - Insurance sector: increasing use; a number of STRs submitted showing increasing use of insurance products.
  - Real estate sector: does not appear to pose particular risks given limited investment possibilities and inaccessibility for foreigners.
  - No bureaux de change, no notaries, and no casinos (yet) in Liechtenstein.
- Vulnerabilities identified by authorities:
  - offering private banking/wealth management financial services, in particular to clients resident or active in countries with high levels of crime;
  - offering multi-layered, complex corporate structures that favor protection of real ownership; and
  - circumvention of international sanctions, both in respect of ML and FT.

### Law enforcement approach and challenges
- Typical features:
  - Reactive character to external initiatives and sources such as mutual legal assistance requests.
  - Number of domestically triggered ML investigations is encouraging, but ML prosecutions are rare.
  - Authorities attribute low number of prosecutions and absence of convictions mainly to predicates occurring outside Liechtenstein jurisdiction.
  - No policy of pursuing autonomous money laundering apparent, presumably due to high burden of proof on specific predicate offense.
- Legal tools and practices:
  - Criminal procedure legislation provides measures: taking witness statements from intermediaries, production orders, seizure of documents (subject to legal privilege).
  - In rem confiscation procedure widely used.
  - FIU reports have contributed to prosecutions and convictions (although not for ML).
  - Police and judiciary commitment and professionalism noted as undeniable.

### Law enforcement results (statistics for 2008–2012 and detailed ML/FT results)
- Summary table (Investigations / Prosecutions / Convictions (final)) for ML and FT (2008–2012):
  - ML (aggregate line): Investigations: 61; Prosecutions: 2; Convictions (final): 1
  - FT: 0 / 0 / 0
- Detailed annual results (selected figures preserved exactly as presented):

2009 (ML)
- Investigations Cases: 50
- Investigations Persons: >50
- Prosecutions Cases: 0
- Prosecutions Persons: 0
- Convictions (final) Cases: 0
- Convictions (final) Persons: 0
- Proceeds frozen: Cases: 38; amount (in EUR): 57.5 Mio.-
- Proceeds seized: Cases: - ; amount (in EUR): - 
- Proceeds confiscated: Cases: 9; amount (in EUR): 55.6 M.

2010 (ML)
- Investigations Cases: 58
- Investigations Persons: >58
- Prosecutions Cases: 1
- Prosecutions Persons: 2
- Convictions (final) Cases: 0
- Convictions (final) Persons: 0
- Proceeds frozen: Cases: 34; amount (in EUR): 104 M.-
- Proceeds seized: Cases: - ; amount (in EUR): -
- Proceeds confiscated: Cases: 9; amount (in EUR): 194.35 M.

2011 (ML)
- Investigations Cases: 55
- Investigations Persons: >55
- Prosecutions Cases: 1
- Prosecutions Persons: 2
- Convictions (final) Cases: 0
- Convictions (final) Persons: 0
- Proceeds frozen: Cases: 26; amount (in EUR): 32.4 M.-
- Proceeds seized: Cases: - ; amount (in EUR): -
- Proceeds confiscated: Cases: 4; amount (in EUR): 4.3 M.

2012 (ML)
- Investigations Cases: 56
- Investigations Persons: >56
- Prosecutions Cases: 1
- Prosecutions Persons: 1
- Convictions (final) Cases: 0
- Convictions (final) Persons: 0
- Proceeds frozen: Cases: 21; amount (in EUR): 75.9 M.-
- Proceeds seized: Cases: - ; amount (in EUR): -
- Proceeds confiscated: Cases: 6; amount (in EUR): 4 M.

- FT (annual): 2009: 0 for all categories; 2010: 0 for all categories; 2011: 1 investigation case (1 person) but 0 prosecutions and 0 convictions; 2012: 0 for all categories.

### Observed ML pattern changes and emerging risks
- No significant changes in ML patterns since the last assessment, except:
  - Increase in corruption related cases.
  - Indications that Liechtenstein may be used to attract dubious investments in gold and other precious metals as a reaction to the financial crisis — no such instances of ML identified yet.

### Terrorism financing (TF)
- Investigations, prosecutions, convictions for TF:
  - Only one investigation in 2011; no prosecutions and no convictions.
- Authorities consider TF risk low.
- Challenges that could result in terrorist-related assets going undetected:
  - Complex legal structures;
  - Culture of confidentiality;
  - Extensive legal privilege protection;
  - Beneficial ownership identification issues.
- FIU activity: a few STRs related to suspected TF activities abroad were communicated to counterparts; one external case was picked up by the reporting system.

### Financial sector overview — size and composition (exact figures)
- Financial sector accounted for 9.1 percent of the workforce and 27 percent of GDP in 2010.
- Total banks: 17
- Total bank assets at end-2012: CHF 117.7 billion
- Total assets at end-2007: CHF 153.2 billion
- Total bank profits: CHF 861.6 million (2007); CHF 122.2 million (2011); CHF 388 million (2012)
- Three major banks account for just under 90 percent of total assets at end-2012.
- Bank employment (2011): 2,044 staff (full-time equivalent)
- Asset management companies: 109 (end-December 2012; 28 in 2006)
- Total client assets (asset management) at end-December 2012: CHF 23.52 billion
- Asset management employment: 436 people
- Collective investment funds (investment undertakings) total: 557 (December 2012) with total assets CHF 37.2 billion; in 2006: 276 funds and CHF 20.6 billion
- Fund management companies managing these funds: 20
- Insurance companies: 41 total (22 life, 14 non-life, 5 captive reinsurances)
- Total premium income (2012): CHF 4.2 billion; 79 percent from life insurance
- Insurance premium income by market: Italy: 58.2 percent; Germany: 16.9 percent; Switzerland: 7.4 percent
- Insurance sector employment (end-2011): 601 staff; supported by 49 insurance intermediaries
- Pension schemes (end-2012): 29 occupational pension schemes (pillar two) with CHF 4.35 billion in capital and technical provisions
- Private pension providers licensed (pillar three): 6

### Financial institutions and supervisory mapping (selected figures)
- Banks: Number: 17; Assets under management: 117.7 (billion CHF); AML/CFT + prudential Supervisor: FMA
- Asset management companies: Number: 109; Assets under management: 23.52 (billion CHF)
- Fund management companies:
  - Active fund management companies: 2
  - Active fund management companies (exempted from DDA): 18
  - Assets under management: 0.55 (billion CHF); 36.65 (billion CHF) [as presented]
- Life Insurance Companies: Number: 21; premiums: 3.3 (billion CHF)
- Life Insurance brokers: 49
- Liechtenstein Postal service (payment services): 1
- E-Money Institution: 1
- Non-life insurers and reinsurers: Number: 19; premiums: 0.9 (billion CHF)
- Pension schemes: Number: 29; Assets under management: 4.35 (billion CHF)
- Non-life insurance brokers: 16

### Types of financial activities and institutions (as per FATF 40+9 definition)
- Acceptance of deposits and other repayable funds from the public (including private banking): Banks; Postal Service AG; Supervisor: FMA
- Lending: Banks
- Financial leasing: Banks
- Transfer of money or value: Banks; Postal Service AG
- Issuing and managing means of payment: Banks; Electronic money institutions
- Financial guarantees and commitments: Banks
- Trading in money market instruments, foreign exchange, derivatives, transferable securities, commodity futures: Banks; Fund management companies
- Participation in securities issues and related financial services: Banks; Fund management companies
- Individual and collective portfolio management: Banks; Asset management companies

*Source: cr18257 - 42. On domestic criminality, following statistics were provided (PDF chapter).*

### 10. Safekeeping and administration of

### 10. Safekeeping and administration of

### Scope of licensed financial institutions and permitted activities
- Types of FIs that can obtain a license and operate financial activities in Liechtenstein: Banks and finance companies (Paragraph 59).
- Under the Banking Act (BA), dated October 21, 1992, as amended:
  - Only banks can collect deposits, provide safekeeping services, and issue electronic money; make off-balance sheet transactions, manage securities issuance, and provide securities services (Paragraph 60).
  - The BA provides the regulatory framework for investment firms, which are allowed to render investment services and ancillary services on a professional basis (no investment firm had been licensed at the time of assessment) (Paragraph 60).
  - The BA entrusts the FMA with supervisory powers; banking regulations are in the Banking Ordinance (BO), dated February 22, 1994, as amended (Paragraph 60).
  - The BA specifically addresses AML/CFT issues and requests banks and investment firms to set up internal guidelines to ensure adherence with customer due diligence obligations under the Due Diligence Act (DDA) (Annex 5 BO, Section 1.3.6.) (Paragraph 60).
- Cross-border provision:
  - Domestic banks may perform banking activities or provide investment services in an EEA member state through branches or directly by virtue of the free movement of services (Paragraph 61).
  - Banks and investment firms licensed and supervised in EEA member states may perform banking and securities-related activities in Liechtenstein through a branch or directly by virtue of the free movement of services (Art. 30d BA); such institutions are subject to the DDA (Paragraph 61).

### Postal service and money remittance activity
- Liechtenstein Postal Service provides financial services, accepts public deposits, offers some payment services on behalf of Swiss Post, and offers money transfer services on behalf of Western Union (Paragraph 62).
- Money remittance business by the Postal Service as agent for Western Union:
  - Approximately 2,500 transactions per year.
  - The average transaction amounts to CHF 400.
  - Internal rules require enhanced due diligence as soon as four linked transactions are carried out per month (irrespective of the value) or if the value of linked transactions is above CHF 5,000 per month (Paragraph 62).
- Money remittance services recently started by an agent for Moneygram; undertakes very limited business as yet (Paragraph 62).
- Money remitters are covered by the DDA (Paragraph 62).

### Asset management companies (AMCs)
- Legal framework:
  - Asset Management Act (AMA) effective January 1, 2006; AMCs are Investment firms within Directive 2004/39/EC (Paragraph 63).
- Services AMCs provide or arrange on a professional basis (Art. 3 AMA) (Paragraph 63):
  - portfolio management;
  - investment advice;
  - reception and transmission of orders concerning one or more financial instruments;
  - investment research and financial analysis.
- Restrictions and custody (Paragraph 64):
  - AMCs cannot accept or hold assets that belong to third parties (Art. 3.3 AMA).
  - AMCs cannot hold a trustee, lawyers, patent attorney, or auditor license (Art. 6.1.l AMA).
  - Assets managed must be holdings in financial instruments and must be deposited in a bank.
- Application of the DDA (Paragraph 64):
  - At time of assessment AMCs fell within scope of the DDA.
  - In practice they were subject to the DDA only for STR reporting, but not due diligence requirements, because all AMCs in Liechtenstein operate on the basis of a limited power of attorney for client accounts.
  - Outside a high risk scenario, all AMCs carried out simplified CDD scenarios under Art. 10 of the DDA.
- Cross-border operation (Paragraphs 65–66):
  - AMCs registered and licensed in Liechtenstein may conduct business in an EEA member state through a branch or as cross-border services, or in a third country after demonstrating to the FMA that they hold, or are not required to hold, a local license (Arts. 33 and 36 AMA) (Paragraph 65).
  - AMCs registered and licensed in an EEA member state may conduct business in Liechtenstein through a branch or cross-border services (Art. 34 AMA) (Paragraph 66).
  - AMCs or asset managers with registered office or residence in a non-EEA state must obtain an FMA license before operating in Liechtenstein (Art. 37 AMA) (Paragraph 66).

### Investment undertakings and fund management
- Investment Undertakings Act (IUA), dated May 19, 2005 (effective September 1, 2005), as amended, governs funds raising assets via units marketed to the public and managed by a management company (Paragraph 67).
- Licensing:
  - Both the investment undertaking and the management company must hold a license from the FMA (Paragraph 67).
  - Depositary functions are carried out by a bank holding a domestic license or by a domestic branch of a bank licensed in an EEA member country (Paragraph 67).
- DDA application (Paragraph 67):
  - Investment undertakings fall within the scope of the DDA under Art. 3.
  - Investment undertakings that do not maintain share accounts or distribute shares are exempted from the DDA under Art. 4.
  - At time of assessment only two licensed investment undertakings in Liechtenstein did not qualify under this exemption and were thus subject to the DDA.
- Fund management permissions and delegation (Paragraph 68):
  - If authorized by the FMA, a fund management company may manage individual portfolios and other assets such as pension funds or investment foundations (Art. 24.3.a IUA).
  - Subject to FMA authorization, it may delegate responsibilities to third parties domiciled in Liechtenstein or abroad, under effective monitoring and oversight (Art. 25 IUA).
- Cross-border marketing of units (Paragraphs 69–70):
  - Units of domestic investment undertakings can be marketed in an EEA member state for transferable securities if they conform to Directive 85/611 requirements or have FMA approval (Art. 93 IUA).
  - Units “for other values or for real estate” can be marketed if approved by the FMA (Art. 89 IUA).
  - Units of an EEA investment undertaking can be marketed in Liechtenstein if they conform to Directive 85/611; an FMA license is required to market units not in conformity or units of a third country investment undertaking (Arts. 93 and 94 IUA) (Paragraph 70).

### Insurance undertakings
- Insurance Supervision Act (ISA), dated December 6, 1995, as amended, governs direct insurance and reinsurance (Paragraph 71).
- Insurance undertakings must hold a license for each class of insurance they provide (Art. 12 ISA) and are prohibited from conducting noninsurance activities (Art. 20 ISA) (Paragraph 71).
- Cross-border activity and licensing (Paragraph 72):
  - Insurance undertakings located and licensed in Liechtenstein may conduct business in an EEA member state through an establishment or cross-border services (Art. 26 ISA).
  - In other states they must hold a local license (Art. 27.b ISA).
  - Insurance undertakings located and licensed in an EEA member state or Switzerland may engage in direct insurance business in Liechtenstein by establishment or cross-border services (Art. 28 ISA and Direct Insurance Agreement between Liechtenstein and Switzerland, 1996).
  - Undertakings with a head office in a third country must obtain a license in Liechtenstein and operate through a branch managed by a general agent (Art. 31 ISA) (Paragraph 72).

### E-Money institutions
- Governed by the E-Money Act and supervised by the FMA (Paragraph 73).
- Definition and limits of electronic money (article 3 (a) E-Money Act) (Paragraph 73):
  - If the device cannot be recharged, the maximum amount stored in the device is no more than 150 francs.
  - If the device can be recharged, a limit of 2,500 francs is imposed on the total amount spent or managed in a calendar year, except when an amount of 1,000 francs or more is redeemed in that calendar year by the bearer as referred to in Art. 10, paras. 2–4 of the E-Money Act.
- There is one e-money institution in existence in Liechtenstein (Paragraph 73).

### Risks and vulnerabilities
- Business model characteristics (Paragraph 74):
  - Liechtenstein’s financial center focuses on private banking and wealth management and is mostly nonresident business.
  - It includes provision of corporate structures such as foundations and other companies and trusts designed for wealth management, structuring of assets and asset protection.
  - “Asset protection” refers to protection of assets from liabilities arising elsewhere (Paragraph 74).
- FATF high-risk customer types present in Liechtenstein’s business (Paragraph 75):
  - Nonresident customers;
  - Private banking;
  - Legal persons or arrangements such as trusts that are personal assets holding vehicles;
  - Companies that have nominee shareholders or shares in bearer form.
- All of these examples are present in much of the business conducted in Liechtenstein (Paragraph 76).
- Organization and vulnerabilities of TCSP-driven structures (Paragraphs 77–83):
  - Typical model: foreign customer is beneficial owner of a foundation, company or trust established by a professional trustee (TCSP) in Liechtenstein; professional more often acts as member of council of a foundation or company director rather than trustee as such (Paragraph 77).
  - TCSPs form legal persons/arrangements on behalf of clients; clients often use similar professionals in other countries and may have a series of legal persons/arrangements worldwide; many professionals may not be subject to a licensing regime ensuring fitness and propriety (Paragraph 78).
  - The more complex the structure, the more remote the TCSP from the true client and the greater the risk that the person the TCSP believes to be the client is not the true beneficial owner (Paragraph 79).
  - Reliance: once the TCSP establishes to its satisfaction that the beneficial owner is a bank, and opens an account on behalf of the customer, it is entitled to rely on a signed declaration by the TCSP without being required to conduct further enquiries (Paragraph 80).
  - TCSP sector is subject to due diligence obligations but not a full licensing or prudential supervisory regime; at least one person in the TCSP must hold a license as a professional trustee, but the TCSP business as a whole and owners/controllers are not necessarily screened by authorities (Paragraph 81).
  - Onsite inspections of TCSPs are carried out only every three years unless increased frequency is warranted; inspections are by a mandated audit firm and paid for by the TCSPs (Paragraph 81).
  - Any weaknesses in the TCSP sector can rapidly spread through the financial system; the TCSP sector is the least regulated element of the system, heightening risk of compliance failures and vulnerability to abuse (Paragraph 82).
- Changing nature of business and tax-related pressures (Paragraphs 83–85):
  - Historically, primary business assisted clients in other countries to minimize tax payments; past techniques may have strayed into tax evasion.
  - International attention on offshore centers reduced scope for such business and lowered quantity of business.
  - Authorities adopted the Liechtenstein Declaration in 2009 pledging transparency, especially in tax matters, followed by signing tax information exchange agreements (Paragraph 85).
  - OECD noted Liechtenstein as having 24 tax information agreements in April 2013, of which 19 met OECD standards; authorities stated position changed to 34 tax information exchange agreements and double taxation agreements, 28 of which are in full compliance with the standards; agreement with Austria revised to enter into force on January 1, 2014; negotiations with Switzerland to revise the DTA are underway (footnote content excerpted in Paragraph 85).
- Strategic direction for sustaining the financial center (Paragraph 86):
  - Key elements of strategy to enhance competitiveness:
    - Rely on existing competitive advantages, in particular the ability to provide for the structuring and administration of wealth using Liechtenstein legal entities and arrangements;
    - Ensure legal framework for sectors such as insurance and alternative investment funds remains in line with international standards and attractive to foreign investors;
    - Emphasize strengths of Liechtenstein as a country with a stable political system, a high degree of legal certainty, membership of the EEA and the use of the Swiss franc;
    - Exploit ability to act quickly to meet international standards and customer needs;
    - Adopt international standards of transparency while preserving legitimate secrecy and asset protection.
- Assessment observations (Paragraph 87–88):
  - Authorities’ move toward transparency and international standards is appropriate, but legacy reputation for secrecy may continue to attract those seeking to abuse secrecy and legal forms.
  - The assessment team considers action is necessary to reinforce defenses, while acknowledging progress and strengths Liechtenstein has made.

### Overview of the DNFBP sector
- All DNFBPs in Liechtenstein are designated as such by FATF and are subject to obligations in relevant laws and supervised by the FMA; DNFBPs offer products and services integrated with traditional financial institutions (Paragraph 89).
- Categories of DNFBPs defined in the AML/CFT Law include trustees; trust companies; persons authorized to act as company directors for Liechtenstein registered firms but who do not have the right to form companies; lawyers; law firms; legal agents; auditors; audit firms; real estate brokers; dealers in goods; casinos; and a catch-all provision for other persons engaged in financial services (Paragraph 90).

### DNFBP counts subject to the DDA (December 2012)
- Trustees: 91
- Trust Companies: 287
- Persons with Certificate under Art. 180a PGR: 535
- Lawyers: 190
- Law Firms: 29
- Auditors: 33
- Audit Firms: 24
- Real Estate Brokers: 7
- Dealers in Goods: 4
- Casinos: 0
- Other Persons Subject to Obligations: 29

### Trustees and Trust Company Service Providers (TCSPs)
- TCSPs include trustees, trust companies, and persons with a certificate under Art. 180a PGR situated in Liechtenstein or any other EEA member state; they establish legal entities (foundations, companies, trusts) in Liechtenstein on behalf of customers, commonly non-residents, and often retain nominal control and act on their behalf (Paragraph 91).
- Trustees under the Professional Trustees Act:
  - Licensed by the FMA and covered under the DDA to the extent they pursue activities under Art. 7, paras. 1 (a), (b), (e), or audit activities under (f), or activities under Art. 7(2) of the Professional Trustees Act (Paragraph 92).
  - The FMA may issue two types of licenses:
    - First license category granted on basis of passing the trustee exam.
    - Second license type issued based on license under the Lawyers Act and passing an additional trustee exam (Paragraph 92).
  - Holders of a license in the first category are permitted to carry out a wide range of services on a professional basis (Art. 7, para. 1), including:
    - The forming of legal persons, companies and trusteeships for third parties, in the license holder’s own name and for the account of third parties, and related interventions with the authorities and administrative offices;
    - Assuming board mandates in accordance with Art. 180a PGR;
    - Assuming trusteeships;
    - Financial and business counseling;
    - Tax counseling;
    - Accounting and inspections, unless such activities are reserved to auditors and auditor companies (Paragraph 92).

*Source: cr18257 - 10. Safekeeping and administration of*

### 93. All activities except financial and business counseling are covered by the DDA.

### cr18257 - 93. All activities except financial and business counseling are covered by the DDA.

### Scope of the DDA and license categories
- All activities except financial and business counseling are covered by the DDA.  
- A second, more restrictive license permits only the carrying out of activities under the first and second bullet points, and the DDA applies in relation to both of these activities.  
- Art. 2 of the DDA defines “legal entity” to include legal arrangements. References to “TCSPs” encompass any natural or legal person carrying out the activities specified under the DDA.

### Licensing, supervision, and disciplinary measures
- Licensed trustees are subject to disciplinary powers of the Court of Appeal which may act on its own initiative or based on public information.  
- Disciplinary measures include:
  - reprimand;
  - a fine of up to CHF 50.000;
  - permanent or temporary withdrawal of the license.
- Trustees licensed under foreign law must obtain an FMA license under the Trustees Act and are subject to the DDA to the same extent as domestic trustees.
- Lawyers and law firms registered under the Lawyers Act and legal agents (Art. 67 Lawyers Act) are registered with the FMA and covered under the DDA to the extent they provide specified services (see below).
- Lawyers under the Lawyers Act are subject to disciplinary powers of the Court of Appeal. Disciplinary measures include:
  - reprimand;
  - a fine of up to CHF 50,000;
  - permanent or temporary withdrawal of the license.

### Natural and legal persons captured by the DDA (selected enumerated categories)
- Holders of a certification under Art. 180aPGR when acting as:
  - partner of a partnership;
  - a governing body or general manager of a legal entity on account of a third party;
  - or carrying out a comparable function on account of a third party.
  - Certification may be obtained by a Liechtenstein lawyer domiciled in Liechtenstein and licensed as a lawyer, legal agent, trustee, auditor, or government recognized business qualification, or a Liechtenstein resident working for such a person.
- Natural and legal persons providing, on a professional basis, registered office, business address, correspondence, administrative address and related services for a legal entity.
- Natural and legal persons acting as nominee shareholders for another person (except companies listed on a regulated market subject to disclosure requirements in conformity with EEA law or deemed by the FMA to impose equivalent international standards), or who provide the possibility for another person to carry out such function.
- Any natural and legal person who contributes to the planning and execution of financial or real estate transactions for clients concerning:
  - buying and selling of undertakings or real estate;
  - managing of client money, securities or other assets;
  - opening or management of accounts, custody accounts, or safe deposit boxes;
  - organization of contributions necessary for creation, operation or management of legal entities;
  - acting as partner of a partnership or a governing body or general manager of a legal entity on account of a third party, or carrying out comparable functions on account of a third party.

### Lawyers, accountants, auditors, and related professions
- Lawyers:
  - Subject to the DDA and FMA supervision when they carry out “financial transactions” as defined (aligned with FATF Recommendation 12).
  - Liechtenstein distinguishes resident and nonresident lawyers; nonresident EEA lawyers may be certified/registered or practice as an apprentice; all are subject to the DDA when carrying out financial transactions.
  - Under the 1992 Law on Trustees (Art. 1.3), lawyers can obtain a limited trustee license by special examination with one year of practical work. Art. 54.1 and 2 allows certain pre-1992 lawyers to continue forming companies.
  - Lawyers and law firms are covered under the DDA when they provide tax advice or assist in planning/execution of transactions concerning:
    - buying and selling of undertakings or real estate;
    - managing client money, securities or other assets;
    - opening or management of accounts, custody accounts, or safe deposit boxes;
    - organization of contributions necessary for creation, operation or management of legal entities;
    - establishment of a legal entity on account of a third party or acting as partner/governing body/general manager of a legal entity on account of a third party or comparable functions.
  - The Lawyers Act permits license holders to provide legal advice professionally and to represent parties in judicial and extrajudicial matters.
  - “Legal agents” under Art. 3 of the DDA are an extremely small class (two persons) registered in February 1958 or subsequently permitted before the Act on Lawyers entered into force in 1992.
- Accountants:
  - Not expressly referenced by name, but Art. 3(v) of the DDA’s catch-all provision captures natural and legal persons contributing to planning and execution of financial or real estate transactions for clients covering the same activities as lawyers.
- Auditors and audit firms:
  - Auditors perform both audit functions for customers and compliance examinations for the FMA.
  - Natural and legal persons licensed under the Auditors Act, Auditing Companies, and audit offices subject to special legislation require FMA licensing and are subject to the DDA.
  - Art. 7 of the Auditors Act permits the following professional activities:
    - Account and statutory audits;
    - Advice in finance and accounting, taxes, financing, organization and information technology.
  - The DDA also covers any other natural or legal person who, on a professional basis, accepts or keeps third-party assets, assists in acceptance, investment, or transfer of such assets, or carries out external statutory and other audits.

### Real estate brokers, dealers in goods, and casinos
- Real estate agents:
  - Not required to obtain an FMA license, but need a commercial license issued by the Amt fuer Volkswirtschaft.
  - Covered by the DDA and supervised by the FMA to the extent their activities cover the purchase or sale of real property.
  - The real estate market is very small and highly regulated; purchasers must demonstrate qualification to the land registry.
- Dealers in goods:
  - Covered by the DDA and supervised by the FMA when payment is in cash of CHF 15,000 or more in a single operation or several connected operations.
  - Industry size: four covered entities; assessed risk is low given industry smallness and minimal covered activity threshold.
- Casinos:
  - Land-based and online casino providers under the Gambling Act must obtain a government license and are subject to the DDA.
  - At the time of onsite visit, no licenses had been issued under the Gambling Act.
  - Authorities stated a moratorium on online gambling licenses until at least 2014 due to a pending European Court of Justice case; licensing requirements under the Gambling Act are very strict.
  - Government decided to issue only one land-based casino license and reassess further demand in 2016. Two applications were received and one license issued in 2012; this decision was appealed and pending before the Constitutional Court. Possible re-issuance in 2013 could allow operations no sooner than 2016.

### Other persons and professional coverage
- Art. 3.1 DDA: Any other natural or legal person who conducts financial transactions as defined in Art. 4 DDA on a professional basis is covered by the law.
- The DDA’s catch-all formulations extend coverage to multiple professional roles and functions that facilitate financial or real estate transactions.

### Risks and vulnerabilities from the DNFBP sector
- The DNFBP sector is particularly high risk due to services offered and client profiles (often nonresident, intermediated, and components of complex legal structures).
- Key risk drivers and vulnerabilities:
  - Shortcomings in implementation and understanding of preventive measures, including enhanced due diligence policies and procedures.
  - Lack of appreciation for the high-risk nature of the DNFBP sector.
  - Supervision shortcomings including:
    - absence of proper licensing requirements in certain circumstances (including trustees);
    - conflicting legal provisions regarding information access;
    - use of mandated audit firms for compliance examinations;
    - supervision processes and cycles that are not risk-sensitive;
    - lack of an off-site supervision regime;
    - imposition of very few sanctions.
- MONEYVAL procedures: Recommendation 24 has not been reassessed as part of this assessment.
- The central role of DNFBPs, specifically TCSPs, and reliance by financial institutions and other DNFBPs amplify sector risks; a tendency to prioritize confidentiality further increases residual risk.

### Overview of commercial laws, legal persons, arrangements, and statistical snapshot (as of 12/31/2012)
- Recent legal changes highlighted:
  - DDO’s definition of beneficial owner amended to extend to those who control legal entities;
  - new law on foundations in 2008;
  - December 2012 law introducing new requirements concerning bearer shares and certificates and, for certain companies, obligation to keep shareholders registers at the registered seat.
- Authorities note improvements in transparency and information exchange (agreements with U.S. and EU) but highlight remaining challenges in adequate, accurate, and timely access to beneficial ownership information.
- Table of registered/deposited entities (By 12/31/2011 | New entries | Deletions | By 12/31/2012):
  - Sole trader: 614 | 30 | 100 | 544
  - Collective partnership (Kollektivgesellschaft): 19 | 1 | 0 | 20
  - Joint Stock Company (AG): 6,573 | 266 | 583 | 6,256
  - Limited liability company (GmbH): 114 | 24 | 11 | 127
  - Co-operative: 19 | 1 | 2 | 18
  - Commercial or non-commercial association: 232 | 26 | 4 | 254
  - Registered foundation (Stiftung): 1,806 | 110 | 107 | 1,809
  - Limited partnership (Kommanditgesellschaft): 18 | 3 | 0 | 21
  - Limited partnership with share capital (KomAG): 0 | 0 | 0 | 0
  - Registered trust (eingetragene Treuhänderschaft): 2,764 | 212 | 310 | 2,666
  - Establishment (Anstalt): 11,486 | 222 | 1,125 | 10,583
  - European joint-stock company (SE): 5 | 0 | 0 | 5
  - European economic interest association (EWIV): 0 | 1 | 0 | 1
  - Trust Enterprise (Trust reg.): 2,018 | 15 | 222 | 1,811
  - European Cooperative: 1 | 0 | 0 | 1
  - Subsidiary of a enterprise with domicile within EEA: 5 | 4 | 0 | 9
  - Subsidiary of a enterprise with domicile outside of EEA: 95 | 3 | 3 | 95
  - New deposited foundations: 32,425 | 534 | 4‘144 | 28,815
  - Deposited trust: 197 | 3 | 29 | 171
  - Total all legal entities: 58‘391 | 1‘455 | 6‘640 | 53‘206
- Legal arrangements at end-2012:
  - Registered trust: 2,666
  - Deposited trust: 171
- Observations on risks and vulnerabilities:
  - High number of registered/deposited entities despite decrease since 2011; authorities attribute decrease to agreements on exchange of information and greater transparency.
  - Persistent challenges: creation of complex legal structures (deposited foundations, Anstalten) can obscure identification of beneficial owners or beneficiaries (use of agents, bylaws not registered/deposited, maintenance issues by TCSPs, especially with foreign introducers).
  - Effectiveness issues with trustees’ implementation of customer due diligence and FMA supervision compound ML/FT risks posed by legal persons and arrangements.

### AML/CFT strategy and priorities
- Pillars of Liechtenstein’s AML/CFT system:
  - Conformity with International Standards:
    - Liechtenstein is a MONEYVAL and EEA member; committed to implementing international standards.
    - Government strategy to fight international tax crimes and corruption.
    - Liechtenstein Declaration of 2009 commitment to apply global OECD standards of transparency and exchange of information.
    - Party to the UN Convention against Corruption and a GRECO member.
  - Dedication of sufficient resources:
    - Since 2000, government has systematically and continuously increased authorities’ capacities to combat ML and FT.
  - Proactive approach:
    - FIU has increased capacities and developed a strategic analysis function.
  - International cooperation:
    - Dependence on close cooperation with foreign countries at all levels (FIU, Office of the Public Prosecutor, police, Supervisor, Office of Justice Central Authority for Mutual Legal Assistance, other competent authorities).
    - Participation in EU FIU platform, FATF, MONEYVAL, Egmont Group; Schengen member.
  - Domestic cooperation:
    - Authorities and private sector representatives cooperate and collaborate as needed.
    - A special AML/CFT Working group (PROTEGE), chaired by the FIU, coordinates ML/FT efforts; members are Directors or Senior Officials of all agencies involved.

*Source: cr18257 - 93. All activities except financial and business counseling are covered by the DDA.*

### 123. The effectiveness of the measures is under regular review by the authorities concerned and

### cr18257 - 123. The effectiveness of the measures is under regular review by the authorities concerned and

### Effectiveness review and national risk assessment
- The effectiveness of the measures is under regular review by the authorities concerned and the AML/CFT Working Group PROTEGE.
- The process for a National Risk Assessment has been initiated, simultaneously reviewing the appropriateness of the existing measures.
- The AML/CFT Task Force has been tasked to propose measures to implement the new FATF standards in Liechtenstein law, taking into consideration the recommendations from the fourth round IMF/MONEYVAL assessment and the new fourth EU AML/CFT Directive, such as the inclusion of serious tax offenses as predicate offenses.

### Institutional framework for combating ML/TF — overview of authorities
- Ministry of Finance
  - Responsible for finances, budgets, taxes, and financial center policy, including countering abuse of the financial center for criminal purposes.
  - Within the Ministry, the FIU is responsible for AML/CFT policy and coordination; the Office for International Financial Affairs handles international cooperation in tax matters and the financial market strategy.
- Ministry of Justice
  - Responsible for civil law (including Law on Persons and Companies), criminal law, execution, estate and bankruptcy law, procedural law, data protection, mutual legal assistance, extradition and transit, enforcement of sentences, and foundation law.
  - Prepares and manages legislative texts and legislative amendment processes arising from EEA membership.
- Ministry of Interior
  - Exercises authority over the Liechtenstein National Police, governed by the 1989 National Police Act.
  - Tasks include conducting criminal investigations (including ML/TF), executing assignments at instructions of government offices/authorities/courts, supporting prevention of accidents and crime, and cross-border cash transportation control.
- Ministry of Foreign Affairs
  - Prepares and treats government matters relating to international agreements and treaties, bilateral and multilateral cooperation, European and international cooperation, international organizations and conferences, and diplomatic and consular relations.
  - In AML/CFT, involved in ratification of relevant treaties, implementation of UN and EU sanctions, and responsible for humanitarian aid.

### AML/CFT Working Group PROTEGE
- National AML/CFT working group created on January 15, 2013, responsible for coordination and cooperation in all areas relating to proliferation, FT, and ML (PROTEGE).
- Chaired by the FIU, participants include the FMA, national police, public prosecutor, Office of Justice, Office for International Financial Affairs, Foreign Office, Courts, and Tax Administration, represented by their directors or delegates.
- Prior to January 2013, three distinct working groups existed, one specifically focusing on terrorist financing.

### Financial Intelligence Unit (FIU / EFFI)
- Administrative analytical unit within the Ministry of Finance; central office receiving and analyzing information to identify indications of ML, predicate offenses of ML, organized crime, and FT.
- Office to which SARs are submitted, analyzed, and disseminated.
- Structure: two departments (operational and strategic analysis) and a designated staff for international affairs.
- The Head of the FIU chairs the AML/CFT working group PROTEGE and the country’s MONEYVAL delegation.

### Law enforcement and prosecution
- Liechtenstein National Police
  - In charge of criminal investigations including ML and FT; has an Economic Crime Unit dealing with financial and economic affairs.
  - Organizational structure: Safety and Traffic Division, Criminal Police Division (deals with ML/TF matters), and Command Services Division.
  - Chief of Police is head manager supported by Chief of Staff; Chief of Police and division heads constitute the Executive Staff.
  - The National Police counts about 120 officers and staff.
- Office of the Public Prosecutor
  - Prosecutes, indicts, and argues indictments before competent courts ex officio for reported offenses.
  - Investigative magistrates of the Princely Court can issue production orders, search and arrest warrants as required to investigate ML and FT.
  - Reviews all reports of punishable acts received and ex officio decides on prosecution or other measures; if sufficient grounds exist, submits application for initiation of an investigation or a writ of indictment.
  - Represents the state before the courts and safeguards state interests in administration of criminal justice and mutual legal assistance.
- Confiscated assets
  - In the absence of a specialized confiscation agency or criminal asset bureau, the management of confiscated assets falls under the general authority of the government.

### Customs and cross-border cash controls
- There is no customs department in Liechtenstein; all customs duties are taken up by the Swiss Customs under the Treaty of December 3, 2008 between the Principality of Liechtenstein and the Swiss Confederation.
- Cross-border cash transportation control at Liechtenstein borders, genuinely the responsibility of Customs authorities, is performed by the Liechtenstein National Police.

### Financial Market Authority (FMA)
- Supervision
  - Supervises financial market participants to ensure stability of FIs and the financial market and to protect clients.
  - In case of violations, the FMA takes necessary measures to safeguard client interests and the reputation of the financial center; addresses unlicensed activities.
- Regulation
  - Ensures implementation of international standards and participates in preparation of financial market laws on behalf of the government.
  - Issues guidelines and communications to specify laws and implementing ordinances.
- External relations
  - Represented in relevant supervisory organizations at global and European level.
  - As an equivalent supervisory authority, contributes to ensuring market access for Liechtenstein financial intermediaries.
  - Maintains close contact with business and professional associations at the national level.

### Office of Justice and the Commercial Registry
- Office of Justice (within the Ministry of Justice; presently three lawyers)
  - Prepares legislative proposals, handles the Land Registry (Cadaster) and the Commercial Registry.
  - Acts as the Central Authority in Mutual Legal Assistance context.
- Commercial Registry
  - Public register ensuring legal certainty of commercial transactions by disclosing arrangements under private law, especially liability and representation arrangements.
  - Registers businesses, foundations, establishments (anstalten), and other commercial entities; functions as depository of documents relating to foundations, trusts/settlements, and other instruments.
  - Registers public authorizations, clarification of names and business names, performs legally required announcements, various official acts (monitoring compliance with requirements such as submission of balance sheet), changes of domicile, and reviews.
  - Registered data have force of evidence.

### Approach concerning risk and risk-based supervision
- PROTEGE leads the overall approach to risk and has begun developing a National Threat Assessment.
- PROTEGE activities:
  - Examining alternative strategies, identifying gaps in current data set, holding “brainstorming” sessions to assess risk, and attending international workshops to consider methodologies for National Threat Assessments in comparable countries.
- Authorities have reinforced the general approach to risk by implementing the Third EU Money Laundering Directive and following its approach closely.
- PROTEGE preliminary risk findings:
  - Identified private banking and wealth management as high risk.
  - Risks higher where customers are resident in countries that have only recently become a market economy—such as Asia—and where customers are resident in high crime countries.
  - Jurisdiction has had no instances of terrorism and considers a relatively low risk of terrorist financing.
  - Main ML risk is at the layering and integration stages; little risk in terms of initial placement.
  - Identified increasing incidence of economic crime, investment fraud, and market abuse; some increase in corruption proceeds.
- Supervisory and preventative focus
  - Main focus has been on preventative measures imposed by the FMA.
  - The DDA presupposes a risk-based approach: frequency and intensity of inspections are based in part on risk posed by an institution; institutions subject to its provisions must adopt a risk-based approach (e.g., monitoring of transactions).
- Implementation gaps
  - In practice, the FMA has not yet fully adopted a risk-based approach to supervision.
  - Inspections of FIs are conducted annually and neither frequency nor intensity is substantially altered by reference to AML/CFT risk.
  - Allocation of resources within supervision does not appear to be related to AML/CFT risk of different businesses.
  - Guidance to FIs and DNFBPs primarily concerns interpretation of detailed and mandatory provisions in the DDA and the Due Diligence Ordnance (DDO); while advice on a risk-based approach exists, more detailed implementation guidance would encourage flexibility and innovation.
- Overall assessment
  - Some elements of a risk-based approach exist but it is not yet fully developed.
  - Authorities are seeking to conduct a full National Threat Assessment and are considering appropriate methodologies within the context of adoption of the EU Money Laundering Directives.

### Progress since last IMF/WB assessment or Mutual Evaluation
- Refer to analysis of individual recommendations for a description of progress since the last Mutual Evaluation vis-à-vis shortcomings noted in the 2008 MER.

### Legal system — Criminalization of money laundering (R1)
- Background: third round MER rated PC; summary of 2007 MER deficiencies included:
  - no offenses in the categories of environmental crimes, smuggling, forgery, and market manipulation were predicate offenses for money laundering;
  - no criminalization of self-laundering in relation to converting, using, or transferring criminal proceeds;
  - no prosecution possible for money laundering where the offender has been convicted for the predicate offense;
  - association or conspiracy of two persons to commit money laundering is not criminalized.
- Amendments to Art. 165 Penal Code (PC)
  - Art. 165 PC criminalizing money laundering underwent significant changes after the third round mutual assessment to complete the list of predicate offenses, remove clause restricting punishment of laundering by the author of the predicate offense, cover conversion/transfer/use by the author of the predicate offense, and criminalize association to commit money laundering.
- Legal framework cited:
  - Article 165 Penal Code (PC);
  - Article 5 and 7 PC;
  - Articles 12 and 15 PC;
  - Article 17, para. 1 PC;
  - Article 64, para. 1.9 PC;
  - Article 278, para. 2 PC.

### Criminalization details — Article 165 PC (physical and material elements)
- Art. 165 PC now criminalizes money laundering as follows (amendments indicated in the source):
  - “(1) anyone who hides asset components originating from a crime, a misdemeanor under Arts. 223, 224, 278, 278d, or 304 to 308, a misdemeanor under Arts. 83–85 of the Foreigners Act, a misdemeanor under the Narcotics Act, or an infraction under Art. 24 of the Market Abuse Act, or conceals their origin, in particular by providing false information in legal transactions concerning the origin or the true nature of, the ownership or other rights pertaining to, the power of disposal over, the transfer of, or the location of such asset components”
  - “(2) anyone who appropriates or takes into safekeeping asset components originating from a crime, a misdemeanor under Arts. 223, 224, 278, 278d or 304 to 308, a misdemeanor under Arts. 83–85 of the Foreigners Act,  a misdemeanor under the Narcotics Act, or an infraction under Art 24 of the Market Abuse Act, whether merely in order to hold them in safekeeping, to invest them, or to manage them, or who converts, realizes, or transfers such asset components to a third party.”
- Previous assessment already found Art. 165 PC complying with physical elements in the Vienna and Palermo Conventions (concealment, acquisition, possession, management and use).

### Mens rea and laundered property
- Mens rea
  - Art. 165 PC does not contain specific terminology on the moral element (mens rea); at minimum the “willful” standard applies.
  - Liechtenstein criminal law (Art. 5 PC) recognizes three forms of “mens rea”: “willfully,” “intentionally,” or “knowingly.”
  - When a criminal provision does not specify the mental element, such as in Art. 165, paras. 1 and 2 PC, the act is deemed “willful.”
- Laundered property
  - Art. 165, para. 4 PC: assets (“asset components”) originate from a criminal offense if the offender has either obtained the assets himself through the offense or for its commission or if the value of the originally obtained or received assets are embodied in it.
  - ML offense relates to all kinds of property, either obtained directly from the offense or indirectly through substitution (“embodied”), and covers interests and investment yields derived from criminal proceeds.

### Proving the property is proceeds of crime
- While proof of the predicate offense does not technically require a conviction, absence of jurisprudence on ML cases leaves uncertainty about the level of proof required by courts.
- Authorities refer to the common law concept of “beyond reasonable doubt,” but that term is foreign to the civil law tradition; the civil law judge is fully sovereign in assessing the value of the evidence (Art. 205 CPC).
- Proving an (unspecified) illicit origin appears insufficient for Liechtenstein courts because the predicate list approach requires identification of the proceeds originating offense as a constitutive element of the ML offense.
- For Liechtenstein courts, a formal proof of a specific predicate offense will likely be necessary, as in confiscation in rem.
- Consequence: because many predicate offenses are committed outside Liechtenstein, there is a tendency to (over)rely on foreign criminal investigation or prosecution to provide sufficient proof enabling an ML prosecution in Liechtenstein.

### Scope of predicate offenses
- Predicate offenses to ML fall under two categories:
  - all crimes that are intentional criminal offenses punishable by life imprisonment or a term of more than three years (Art. 17, para. 1 PC);
  - designated misdemeanors (penalty less than three years).
- Deficiencies from the previous assessment were addressed:
  - Inclusion in Art. 165 PC of misdemeanors of forgery (Arts. 223 and 224 PC) and market manipulation (Art. 24 Market Abuse Act).
  - Environmental offenses covered by Arts. 180, para. 2; 181a, para. 2; and 181c, para. 2 PC have been elevated to crimes in aggravating circumstances.
  - Smuggling reference made to specific Swiss Customs legislation applicable under the 1923 Customs Treaty by public notice.

*Source: cr18257 - 123. The effectiveness of the measures is under regular review by the authorities concerned and*

### 161. To be noted that a certain category of tax offenses that fall beyond the list of designated

### cr18257 - 161. To be noted that a certain category of tax offenses that fall beyond the list of designated

### Designated predicate offenses (Art. 165PC)
- A certain category of tax offenses beyond the list of designated predicate offenses has been introduced as predicate criminality for ML: VAT fraud exceeding 75,000 francs affecting the budget of the European Communities (Art. 165, para. 3aPC).
- Other categories of serious tax crimes such as large and organized income tax fraud are no predicate offense to ML.
- The designated predicate offenses are now fully covered as follows:
  - Participation in an organized criminal group and racketeering: Arts. 277, 278a, and 278b PC
  - Terrorism, including terrorist financing: Arts. 278b, c, and d PC
  - Trafficking in human beings and migrant smuggling: Arts. 104, 104a, and 217PC
  - Sexual exploitation, including sexual exploitation of children: Arts. 200, 201.2, 204, 205, 206, 208.3, 212.3PC
  - Illicit trafficking in narcotic drugs and psychotropic substances: All misdemeanors in the 1983 Narcotics Act are predicate offenses for money laundering, including the sale or procurement of narcotics, the financing of narcotic trafficking or the procurement of financing of narcotics
  - Illicit arms trafficking: Art. 60.3 Arms Act, Arts. 33.2–34 and 35 Swiss Act on War Material: Arts. 27.2, 28.1, 29.1 (LI) Act on War Material
  - Illicit trafficking in stolen and other goods: Art. 164.4PC: Art. 14.2 Swiss Act on the Control of Goods with Civilian and Military Application (GKG), Art. 21.2 (LI) KGG
  - Corruption and bribery: Arts. 153.2, 304–308PC
  - Fraud: Arts. 147, 148, 148a.2, 153.2, and 156PC
  - Counterfeiting currency: Arts. 232, 233.2, and 234PC
  - Counterfeiting and piracy of products: Art. 60.2. Law Concerning Brand Protection
  - Environmental crimes: Arts. 180, para 2; 181a, para 2; and 181c, para 2PC
  - Murder, grievous bodily injury: Arts. 75, 76, 77, 78, 79, 85, 86, 87, 92.3, 96.2, and 321 PC
  - Kidnapping, illegal restraint and hostage taking: Arts. 99.2, 100, 101, 102, 103, 104, and 106 PC
  - Robbery or theft: Arts. 128.2, 129, 130, 131, 132.2, 133.2, 142, and 143PC
  - Smuggling: Art. 14, para. 4 Swiss Federal Act on Administrative Criminal Law of March 22, 1974
  - Extortion: Art. 144 and 145PC
  - Forgery: Arts. 223 and 224PC
  - Piracy: Art. 185 and 186 PC (air piracy)
  - Insider trading and market manipulation: Arts. 23.1 and 24 2006 Market Abuse Act

- Note on piracy: the predicate offense of piracy (Art. 185PC) is about air piracy; naval piracy is not covered as such. Authorities contend criminal acts pertaining to naval piracy are covered by other offenses (theft, robbery, extortion, terrorism, murder, grievous bodily harm, etc.) to satisfy the predicate requirement of Art. 165PC.

### Threshold approach for predicate offenses (c. 1.4) and extraterritoriality (c. 1.5)
- The Liechtenstein approach is partly threshold, partly list-based:
  - Predicates to ML are all crimes (i.e. punishable by life or more than three years imprisonment) and a series of designated misdemeanors (less than three years imprisonment).
- Extraterritorially committed predicate offenses:
  - As long as Liechtenstein has jurisdiction over the ML activity itself ratione loci, it is irrelevant where the predicate offenses are committed, presuming the facts constitute a domestic predicate offense.
  - Liechtenstein assumes jurisdiction over the money laundering conduct in another country if the predicate offense has been committed in Liechtenstein (Art. 64, para. 1.9PC).
  - Art. 65, para. 3PC provides that, if there is no penal power at the place where the criminal act was committed (such as the Antarctic or high seas) it is sufficient that the offense is punishable in Liechtenstein.

### Laundering one’s own illicit funds (c. 1.6) and ancillary offenses (c. 1.7)
- Self-laundering:
  - A major improvement: abolition of para. 5 of Art. 165 PC prohibiting prosecution for money laundering of a person who had been punished for participation in the predicate offense (repealed by LGBI 2009, n° 49).
  - Art. 165, para. 2 in its present formulation refers to the conversion, use, and transfer of criminally obtained assets, so self-laundering is no longer excluded.
  - Criminalization of self-laundering in respect of “appropriation and taking into custody” remains precluded by the “ne bis in idem” principle.
- Ancillary offenses:
  - All relevant ancillary offenses are presently covered.
  - Association to commit money laundering is criminalized pursuant to Art. 278, para. 2PC, addressing FATF clarification on association/conspiracy.

### Additional element—acts overseas that are not offenses overseas but would be predicate if domestic (c. 1.8)
- Art. 64PC lists offenses falling under Liechtenstein jurisdiction if committed in a foreign country, even if not criminalized there.
- The list includes money laundering if the predicate has been committed in Liechtenstein, but does not cover all predicate offenses to money laundering according to Art. 165PC.

### Statistics on judicial follow-up (R.32)
- The following judicial follow-up statistics were provided by the Liechtenstein authorities:

- Table: Judicial Follow-up (selected years)
  - 2008
    - ML Investigations: Cases 61; Persons > 61
    - ML Prosecutions: Cases 2; Persons 3
    - ML Convictions (final): Cases 1; Persons 1
    - FT Investigations/Prosecutions/Convictions: 0 across all columns
  - 2009
    - ML Investigations: Cases 50; Persons >50
    - ML Prosecutions: Cases 0; Persons 0
    - ML Convictions (final): Cases 0; Persons 0
    - FT Investigations/Prosecutions/Convictions: 0 across all columns
  - 2010
    - ML Investigations: Cases 58; Persons >58
    - ML Prosecutions: Cases 1*; Persons 2
    - ML Convictions (final): Cases 0; Persons 0
    - FT Investigations/Prosecutions/Convictions: 0 across all columns
    - *Prosecution closed/suspended. One defendant was convicted for the predicate offense (drugs) in Sweden, whilst the whereabouts of the second defendant remain unknown. The criminal proceeds transited over Liechtenstein back to Sweden.
  - 2011
    - ML Investigations: Cases 55; Persons >55
    - ML Prosecutions: Cases 1*; Persons 2
    - ML Convictions (final): Cases 0; Persons 0
    - FT Investigations: Cases 1; Persons 1; Prosecutions/Convictions: 0
    - *Prosecution closed. Acquittal for ML. Predicate offense (fraud) in Germany (no prosecution).
  - 2012
    - ML Investigations: Cases 56; Persons >56
    - ML Prosecutions: Cases 1*; Persons 1
    - ML Convictions (final): Cases 0; Persons 0
    - FT Investigations/Prosecutions/Convictions: 0 across all columns
    - *Self laundering and breach of trust acquittal for the predicate offense and the ML aspect.

- Additional statistics on prosecutions transferred to foreign jurisdiction:
  - 2009: Total 18; Money Laundering 7
  - 2010: Total 22; Money Laundering 5
  - 2011: Total 31; Money Laundering 10
  - 2012: Total 14; Money Laundering 3

- Other statistics and observations:
  - Roughly 90 percent of the ML investigations were triggered by an FIU report to the Public Prosecutor, who is legally obliged to start an enquiry whenever there is indeed sufficient suspicion. The remainder was initiated by the police predominantly based on information received through Interpol or after a criminal complaint.
  - The statistics show no convictions apart from one case in 2008 when on July 15, 2008 the Court of Justice sentenced a German citizen to eight month imprisonment for third party ML after the predicate offender was convicted for fraud in 2005; the penalty was suspended subject to a probation period of one year.

### Effective implementation — findings and interpretation
- Legislative changes and scope:
  - The 2009 amendments to Art. 165PC addressed almost all third round recommendations, extended the list of predicate offenses (including VAT fraud), removed obstacles to criminalization of self-laundering, and broadened the ML offense to capture conversion, transfer, and use of criminal assets.
  - Some technical deficiencies remain that have varying impact on the effectiveness of the repressive approach.
- Object of the ML offense and derived income:
  - The object (corpus) of the ML offense (Art. 165.4PC) may include income derived from immediate and substitute proceeds, such as interests and dividends; doctrine and Art. 20bPC terminology indicate derived income is covered.
- Low prosecution and conviction rates:
  - Substantial number of investigations very rarely result in domestic ML prosecution.
  - Explanations include: not all FIU intelligence can be turned into evidence; investigations can lead to prosecution for other offenses; policy choice to waive jurisdiction in favor of foreign authorities dealing with the predicate offense.
  - The Prosecutor General pursues a policy of waiving jurisdiction and transferring prosecution to foreign authorities with jurisdiction over the predicate offense or who are already investigating.
- Reliance on foreign jurisdiction:
  - Transferring prosecutions to foreign judicial authorities is frequent. Downsides: results (convictions, asset recovery) are out of Liechtenstein’s control and depend on diligence/interest/capacity of foreign judiciary; can impede development of Liechtenstein jurisprudence.
- Jurisprudential and burden of proof issues:
  - No clear jurisprudential standard on what level of proof on a (foreign) basic offense suffices for an ML conviction absent a predicate conviction.
  - Courts’ conditions in in rem confiscation cases suggest a conservative approach; unclear rationale for requiring a “beyond a reasonable doubt” standard in Liechtenstein’s civil law system.
  - The list-bound character of Art. 165PC increases the burden of proof versus an all-crimes ML legal approach and limits proving ML based on an unspecified illegal origin of assets.
  - International tendency (and new FATF standards) is to make ML offense scope as wide as possible, including fiscal offenses.

### Risk factors
- Identification of beneficial owners is crucial; as a financial center managing foreign assets this depends on:
  - An effective preventive CDD system.
  - A solid arsenal of legal means for the judiciary to penetrate secrecy created by complex corporate structures and stringent confidentiality rules.
- Vulnerabilities in the preventive system affect law enforcement ability to rely on information from relevant sectors.
- Misuse of legal privilege by lawyers and auditors (protecting them from criminal procedure measures) when not acting in their professional capacity is a continuous challenge.
- Reliance on external factors and initiatives outside Liechtenstein prosecution office and courts creates risk of ineffective law enforcement outcomes due to inertia, disinterest, or capacity problems of foreign judicial authorities.

### Recommendations and comments (3.1.2)
- Progress:
  - Liechtenstein has made substantial progress aligning the ML offense with the Convention and FATF standards.
  - Extension of predicate criminality to VAT fraud is a positive sign of relaxation of strict fiscal exception rules.
  - Authorities should continue preparing for implementation of new FATF recommendations in this respect.
- Recommended actions to improve effectiveness:
  - Pursue proactively money laundering as an autonomous offense, in order to create jurisprudence on the burden of proof to establish the predicate offense.
  - Consider increasing the effectiveness of the repressive approach by attenuating the formal high level of proof by amending the list-based money laundering offense to an all-crimes offense.

### Compliance with Recommendation 1 (R.1) — Rating and effectiveness issues
- Rating: PC
- Summary of factors underlying rating / Effectiveness issues:
  - Level of proof required to establish the predicate offense.
  - Only 1 conviction since 2007.
  - No autonomous ML prosecutions.

*Prepared from chapter content of cr18257.*

### 183. In the previous MER, Liechtenstein was found deficient on following aspects:

### cr18257 - 183. In the previous MER, Liechtenstein was found deficient on following aspects:

### Previous MER deficiencies
- No explicit criminalization of the financing of individual terrorists and not all instances of such financing are currently covered under the legal framework as required under SR.II.
- The financing of terrorist organizations is not criminalized in all instances required by SR.II, Liechtenstein’s definition of “terrorist organization” referring to a definition of “terrorist acts” which does not cover all acts to be considered terrorist acts under the international standard.
- Reference in Art. 278d PC to “criminal offenses” does not cover any other acts committed with the required intent to be terrorist acts.
- No criminal liability of corporate entities.
- The lack of prosecutions and convictions for terrorist financing makes it difficult to assess the effectiveness of the legal framework.

### Legal amendments and legal framework (response to third round recommendations)
- Amendments introduced to include acts committed by an individual terrorist and to criminalize the financing of all offenses covered by the FT Convention related Treaties as financing terrorist acts.
- The generic offense now refers to “any act” instead of “criminal offenses.”
- Corporate criminal liability was introduced.
- Legal Framework references:
  - Arts. 278b, c, and d PC;
  - Arts. 5 and 7 PC;
  - Arts. 12 and 15 PC;
  - Art. 64, para. 1.11 PC;
  - Arts. 74a–74g PC.

### Criminalization of Terrorist Financing — scope and instruments
- Terrorist financing is criminalized by Art. 278d PC, as amended by LGBI 2009 N° 49.
- Amendments to Art. 278b (terrorist group) and Art. 278c (terrorist offenses) were made since the previous evaluation.
- Liechtenstein is party to all international instruments relevant to SRII, including:
  - International Convention for the Suppression of the Financing of Terrorism (entered into force in Liechtenstein on August 8, 2003);
  - International Convention for the Suppression of Acts of Nuclear Terrorism (entered into force in Liechtenstein on October 25, 2009);
  - Protocol to the Convention for the Suppression of Unlawful Acts against the Safety of Maritime Navigation (in force in Liechtenstein since July 28, 2010);
  - Protocol of 2005 to the Protocol for the Suppression of Unlawful Acts against the Safety of Fixed Platforms Located on the Continental Shelf (in force in Liechtenstein since July 28, 2010).
- Art. 278d, para. 1, a–g PC criminalizes the sole financing (collection and provision) with the intent that they be used, even only in part, for commission of the following offenses (summary):
  - a) Aircraft hijacking and endangering aviation safety;
  - b) Kidnapping, including threatening to;
  - c) Attacks against internationally protected persons;
  - d) Endangering through misuse of nuclear material;
  - e) Attacks against airports;
  - f) Offenses against maritime navigation safety and fixed platforms;
  - g) Terrorist bombings.
- Art. 278d, para. 1, point 1h PC criminalizes the generic offense of financing any act intended to cause death or serious bodily injury to civilians with the circumstances and intentions as specified in Art. 2 (ii) the FT Convention by substituting “criminal offense” with “an act.”

### Financing of individuals and groups; elements of the offense
- Art. 278d, para. 1, point 2 PC criminalizes the financing of an individual terrorist or a terrorist group in these terms: “Anyone who makes available or collects assets with the intent that they be used, even only in part...by a person or a group (§ 278b, para. 3) committing an act referred to in point 1 or participating in such a group as a member (§ 278b, para. 2), shall be punished...” The intent that the funds should be used for terrorist activity is no longer required.
- Financing of a terrorist group is covered by:
  - Art. 278b, para. 2 PC (financial support as a member carries distinct treatment but does not include sole collection of funds);
  - Art. 278d, para. 2 PC with reference to Art. 278b, para. 3 PC (defines such group as an affiliation of more than two persons intended to exist for an extended period of time and aimed at commission of one or more terrorist offenses (Art. 278c PC) by one or more of its members).
- Art. 278d PC does not require a connection between the funds and a terrorist act, perpetrated or not.
- The attempt to commit FT is criminalized by Art. 15 PC.
- Participation as an accomplice (aiding and abetting, facilitating and counseling) is covered by Art. 12 PC; more specific participation, organizing and directing others, contributing to commission by a group are covered by Arts. 12 and 278b PC combined.

### Predicate offense, jurisdiction, mens rea, and corporate liability
- FT is a predicate offense to ML; Art.165 PC explicitly references Art. 278d PC.
- Jurisdiction:
  - Financing activity taking place in Liechtenstein triggers jurisdiction irrespective of location of the person committing the offense or where the terrorist activity takes place (jurisdiction ratione loci).
  - Liechtenstein takes jurisdiction over FT committed in another country when conditions of Art. 64, para. 1.11 PC are met (Liechtenstein citizenship or foreigner in Liechtenstein who cannot be extradited).
- Mental element:
  - The free and sovereign appreciation of the evidence, including related to the moral/mental element or mens rea, is a fundamental principle; CPC Art. 205, para. 2 expressly confirms this rule.
- Corporate criminal liability:
  - Introduced in 2010 via Arts. 74a–74g PC, on top of and independent from individual criminal liability.
  - Liability applies when FT is committed for the purposes of the legal person by a person with a leading position (Art. 74a, para. 1 PC) or committed by a person under its authority due to lack of supervision by a person in a leading position (Art. 74a, para. 4 PC).
  - The legal person is liable if the leading person acted illegally and culpably (Art. 74a, para. 1 PC).
  - Corporate criminal liability does not exclude liability or parallel proceedings which may result from the unlawful act (Art. 74a, para. 5 PC).

### Sanctions and comparative assessment
- FT is punished with imprisonment of six months to five years, except if a different provision imposes a more severe sentence (Art. 278d, para. 1 and 2 PC).
- Financially supporting a terrorist group as a member carries a penalty of imprisonment of one to ten years (Art. 278b, para. 2 PC).
- Comparison with other European countries indicates many apply higher to significantly higher maximum sanctions for the basic offense; concerns raised about sanctions being proportionate or dissuasive.
- Specific comparative entries cited (examples include):
  - Austria: prison term ranging from 6 months to 5 years.
  - Belgium: imprisonment 5 to 10 years.
  - Bulgaria: imprisonment 3 to 15 years.
  - Cyprus: imprisonment up to 15 years.
  - Estonia: imprisonment 2 to 10 years.
  - Finland: imprisonment up to 8 years for individuals involved in terrorist financing.
  - France: imprisonment up to 10 years.
  - Greece: imprisonment up to 10 years.
  - Hungary: imprisonment between 10 to 20 years or life imprisonment.
  - Ireland: imprisonment for a term not exceeding 20 years.
  - Luxembourg: imprisonment of 15 to 20 years or life imprisonment if loss of life.
  - Portugal: imprisonment 8 to 15 years.
  - Romania: imprisonment 15 to 20 years.
  - Serbia: imprisonment of 1 to 10 years.
  - Sweden: imprisonment up to 2 years or 6 years (depending).
  - United Kingdom: imprisonment up to 14 years.

### Effectiveness, statistics, and practical implementation
- Statistics:
  - See statistical figures in section 1.2.2 above.
  - Beside one (closed) investigation in 2011, no other law enforcement initiatives have been taken. The 2011 investigation, triggered by an FIU report, related to a covert investigation in another country, which was discontinued there for lack of evidence.
- Effective implementation observations:
  - All FT Convention Treaties have entered into force in Liechtenstein and sole financing of all offenses covered by relevant treaties is punished as terrorist financing.
  - The exemption on political grounds does not apply here as criminal character outweighs political nature and the Convention takes precedence.
  - Minor technical shortcoming: transposition of offenses covered by the 1980 Convention on the Physical Protection of Nuclear Material—Art. 278d, para. 1)1d) relates to financing of acts of willful endangerment, threat, obtaining, theft or robbery of nuclear material, while Art. 7.1a of the Convention is more specific (“receipt, possession, use, transfer, alteration, disposal or dispersal”); governmental explanatory works considered the wording sufficiently broad.
  - Art. 278d, para. 1)2 PC penalizes sole financing of a terrorist individual or group without intent of funds being used for terrorist purposes (for instance for comfort or family support). Financing relates to an individual or group “committing” or “participating” in terrorist acts or groups (present and unconditional tense); authorities referenced FATF interpretative note on SRII, point 2b, using same wording.
  - No assessment can be made of effectiveness in absence of prosecutions and convictions. The only investigation was discontinued; the sole case of freezing of assets under the Taliban Ordinance ended in a de-listing.
  - Risk factors for AML apply to CFT; funds may have licit origin making detection more difficult. Complex legal structures, culture of confidentiality, extensive legal privilege protection, and beneficial ownership identification issues could result in terrorist-related assets going undetected.
  - Positive sign: relevant (though external) information was picked up by the reporting system in one case. Legal and institutional framework considered adequate to capture TF indications, but insufficient concrete elements to assess efficiency of proactive detection system.

### Recommendations and compliance conclusion
- Recommendation to enhance legal framework and potential effectiveness of criminal approach:
  - The penalties be increased to enhance their deterrent effect.
- Compliance with Special Recommendation II:
  - Rating Summary of factors underlying rating: SR.II — LC
    - Sanctions are not proportionate or dissuasive.

*Source: cr18257 - 183.*

### 208. The legal framework governing the Liechtenstein seizure and confiscation regime has

### cr18257 - 208. The legal framework governing the Liechtenstein seizure and confiscation regime has

### Legal framework overview
- Legal provisions referenced:
  - Art. 20, 20b, and 26 PC
  - Art. 92, 96, 97a, and 98a CPC
  - Art. 253a CPC
  - Arts. 353 to 357 CPC
  - Art. 18 DDA
  - Art. 879 CC
  - Art. 87.2 Organization of the Police Ordinance
- In principle confiscation is conviction based; civil in rem procedures are provided where criminal recovery is not possible.
- Forfeiture of the object of money laundering is specifically provided for.

### Forms of criminal confiscation (summary)
- The system distinguishes three distinct forms:
  1) Abschöpfung der Bereicherung (Art. 20 PC)
     - Relates to all “pecuniary benefits” derived from a criminal offense or received to perpetrate such act.
     - Value based (equivalent value confiscation). On conviction the offender is ordered to pay an amount of money equal to the “unlawful enrichment”.
     - If enrichment cannot be readily determined, the court decides at its discretion (ex aequo et bono).
  2) Verfall (forfeiture—Art. 20b PC)
     - Assets belonging to criminal or terrorist organizations (Art. 278a and 278b StGB) or made available/collected in the context of terrorism financing (Art. 278d StGB) must be confiscated (Art. 20b, para. 1 PC).
     - 2009 amendment explicitly provides for forfeiture of predicate offense proceeds as object of the money laundering offense (“involved in money laundering”) (Art. 20b, para. 2, point 1 PC).
     - Assets derived from criminal activity in a foreign jurisdiction are subject to confiscation even when the predicate offense is not punishable in Liechtenstein, except if it relates to a fiscal (tax) offense.
     - 2009 introduced possibility of forfeiture of proceeds of a VAT fraud affecting the EU budget (Art. 20b, para. 2, point 2 PC).
  3) Einziehung (Art. 26 PC)
     - Confiscation of objects intended to be or actually used to commit criminal acts (instrumenta sceleris), or produced by such activity (producta sceleris).
     - Applies only when these objects endanger the safety of persons, morality, or public order (Art. 26.1 PC as amended).
     - Seen predominantly as a security measure; confiscation mandatory also in absence of prosecution or conviction (Art. 26.3).
     - Instrumentalities rendered harmless or unusable, or where an innocent third party lays legal claim to them with guarantee they will not be used for criminal activity, are generally exempted (Art. 26.2).

### Limitations and jurisprudential interpretation of instrumentalities
- Amendment to Art. 26.1 PC followed prior deficiency finding, but new wording still appears to exclude “innocent” objects not dangerous per se (e.g., a car used by a money launderer to transport illegal assets).
- Authorities cite Swiss legal doctrine and jurisprudence as authoritative for interpretation; examples include cases where a car used to commit a crime and the house of a spy were confiscated.
- Supreme Court recognizes Swiss doctrine and jurisprudence as authoritative for provisions inspired by Swiss legislation.

### Civil forfeiture (in rem) procedures
- Art. 356 CPC provides special procedure for confiscation in absence of criminal conviction (forfeiture in rem) when criminal confiscation is not possible.
- Civil forfeiture systematically used for proceeds from a foreign predicate (when criminal confiscation was previously impossible) or when deprivation of enrichment (Art. 20 PC) is excluded by Art. 20a PC (payment of victims, legal elimination).
- Civil forfeiture or freezing orders issued by the Court of Justice upon application of the Office of the Public Prosecutor.
- Civil forfeiture orders may be obtained against individuals or entities.

### Confiscation of property derived from proceeds of crime
- Art. 20 PC covers all assets (“Vermögensvorteile” literally: “patrimonial advantages”) that are proceeds of crime.
- No formal statutory definition of “proceeds,” but wording is broad enough to encompass direct proceeds, indirect proceeds, substitute assets, and investment yields.
- ML offense text refers to assets that “represent the value of the asset originally obtained or received” as object of the offense (Art. 165.4 PC).
- Art. 20 PC formulated to translate every asset to its equivalent value; executed against all assets of the convicted.
- Since 2009 assets “involved” in laundering activity are expressly forfeitable as object of the offense (Art. 20b, para. 2 PC).

### Provisional measures to prevent dealing in property subject to confiscation
- Seizure regime incorporated in:
  - Art. 96 CPC (seizure of assets)
  - Art. 97a CPC (freezing)
  - Art. 98a CPC (seizure of objects and documents)
- Freezing (Art. 97a CPC) relates to assets; seizure (Arts. 96 and 98a CPC) relates to objects and documents.
- Freezing and seizure require involvement of the Court of Justice (investigating judge) pursuant to Arts. 92, 96, 97a, and 98a CPC.
- Freezing and seizure take items into judicial custody.

### Ex parte application for provisional measures
- Court of Justice issues freezing orders according to Art. 97a CPC without prior notification of the holder.

### Identification and tracing of property subject to confiscation
- Public Prosecutor can initiate an investigation on basis of simple suspicion from sources such as press articles, police intelligence, FIU reports, and foreign investigations.
- Legal basis for identifying and tracing assets: Arts. 92, 96, 97a, 98a, 105, and 108 CPC.
- Art. 92 CPC allows house search when there is a founded suspicion; “founded” suspicion exists when there are concrete indications or additional elements.
- Police empowered to immobilize assets, documents and objects as conservatory measure (Art. 25 National Police Act—NPA).
- FIU reports mostly contain indications of where suspect assets are or can be located.
- Search warrants issued by Investigative Judge under Art. 92 CPC.
- Art. 98a CPC empowers judge, in ML/FT/predicate/organized crime investigations, to query banks, investment firms, insurance companies, asset management companies, and management companies for all CDD information and compel surrender of documents and other CDD-related instruments.
- Any refusal to provide requested information triggers application of Art. 92 and 96 CPC (search and seizure), besides other sanctions.

### Identified vulnerabilities in information gathering and privilege
- Art. 98a CPC does not cover certain categories: payment system providers, e-money institutions, insurance mediators, and DNFBPs.
- Seizure under Art. 96 CPC does not fully cover this lacuna.
- Lawyers (acting as financial intermediaries or in nonlitigation/legal advice circumstances), auditors, and trustees may hold substantial information not captured in seizable documents.
- Authorities argue Art. 98a CPC targeted prudentially supervised institutions with electronic databases; refusal invokes Art. 96 CPC. Evaluators express concern about rationale, noting databases are also used by DNFBPs.
- Art. 108 CPC entitles “Defense counsel, attorneys at law, legal agents, auditors, and patent attorneys“ to refuse to give evidence regarding what became known to them in this capacity.
  - Judicial authorities may call them as witnesses under Art. 105 CPC to disclose necessary (nonprivileged) information, or use search and seizure under Arts. 92 and 96 CPC, discarding privileged pieces.
  - Endowing auditors with legal privilege is flagged as problematic given auditors do not engage in legal representation; this could hamper identification and tracing of property subject to confiscation.

### Protection of bona fide third parties
- Relevant provisions do not specify conditions as to location, possession, or ownership of assets subject to confiscation; in principle, irrelevant if they are in hands of third persons.
- Arts. 20c and 26 PC provide abstention from forfeiture/confiscation if:
  - Object/asset is legitimately claimed by a person who has not participated in the offense or criminal organization/terrorist association (Art. 20c PC).
  - For objects legitimately claimed by a person who did not participate in the offense, they will only be confiscated if the person does not guarantee the objects will not be used to commit the offense (Art. 26, para 2 PC).

### Power to void actions (preventing disposal to frustrate confiscation)
- Art. 20, para. 4 PC covers third persons benefiting unjustly and directly from an offense; such persons may be ordered to pay an amount equivalent to these profits without prosecuting them as accomplices. Applies to legal persons and partnerships.
- On death of the person who gained illegal profits, or if legal person/partnership ceased to exist, profits are to be deprived from the legal successor insofar as they still existed at moment of transfer of rights (Art. 20, para. 5 PC).
- Art. 879 Civil Code (CC) provides that contracts violating statutory laws or contra bonos mores are null and void (e.g., contracts intended to hinder state’s recovery of legitimate financial claims).
- Public Prosecutor has not used Art. 879 CC to void contracts; as a rule does not involve civil litigation office, relying on criminal law provisions/procedures.

### Statistics (R.32)
- Investigations and operational counts:
  - 2009: Investigations 521; Searches of premises 40; Seizures 94
  - 2010: Investigations 566; Searches of premises 46; Seizures 73
  - 2011: Investigations 576; Searches of premises 26; Seizures 75
  - 2012: Investigations 533; Searches of premises 21; Seizures 67
- Amounts resulting from search and seizures (not limited to ML/FT):
  - 2009 proceeds frozen: Cases 38; Amount (in EUR) 57.5 Mio
    - Proceeds seized: Cases 0; Amount (in EUR) 0
    - Proceeds confiscated: Cases 9; Amount (in EUR) 55.6 Mio
  - 2010 proceeds frozen: Cases 34; Amount (in EUR) 104 Mio
    - Proceeds seized: Cases 0; Amount (in EUR) 0
    - Proceeds confiscated: Cases 9; Amount (in EUR) 194.35 Mio*
    - *The high amount is the result of a final decision in the Abacha case, the assets having been frozen years before.
  - 2011 proceeds frozen: Cases 26; Amount (in EUR) 32.4 Mio
    - Proceeds seized: Cases 0; Amount (in EUR) 0
    - Proceeds confiscated: Cases 4; Amount (in EUR) 4.3 Mio
  - 2012 proceeds frozen: Cases 2; Amount (in EUR) 75.9 Mio
    - Proceeds seized: Cases - ; Amount (in EUR) -
    - Proceeds confiscated: Cases 6; Amount (in EUR) 4 Mio
- Explanations for divergence between amounts frozen and confiscated:
  - Freezing is rarely followed by confiscation in the same calendar year.
  - Threshold for freezing is low; conservation of suspect assets is priority. Authorities estimate approximately 40 percent of freezing measures end up in confiscation.
  - Freezing frequently executed at request of foreign judicial authority, which may not be followed up by the requestor.
- Majority of confiscation procedures are still in rem:
  - Authorities estimate over 80 percent of assets confiscated in 2009–2012 are in rem confiscations (in terms of number of cases the ratio in rem to conviction based confiscations is roughly 80/20).

### Additional elements (Rec 3)
- Confiscation of assets from organizations principally criminal in nature: Art. 20b, para. 1 PC.
- Civil forfeiture: Arts. 353–357 CPC authorize civil (in rem) forfeiture if no criminal conviction possible (e.g., author unknown or absconded).
- Confiscation provisions which partially reverse burden of proof:
  - Art. 20, para. 2 PC allows court to forfeit benefits that cannot be directly linked to a specified offense based on rebuttable legal presumption that assets a defendant holds derive from other, nonidentifiable offenses.
  - Application contexts:
    - Perpetrator who committed crimes such as ML (Art. 17 PC) continuously or repeatedly and has gained further economic benefits during same period; presumption that additional benefits derive from other crimes of same nature.
    - Perpetrator involved in criminal organization (Art. 278a) or terrorist group (Art. 278b) who, during membership period, has gained economic benefits where an obvious presumption exists that these profits derive from offenses and legal acquisition cannot be made credible (Art. 20, para. 3 PC).

### Effective implementation observations
- New wording to Art. 26.1 still leaves a restrictive legal condition for confiscation of instrumentalities.
- Legislator has not expressly lifted the restriction or left a decision margin to the judge.
- This restriction is viewed as underestimating the importance of instrumentalities as a criminal tool, undermining penalty value and deterrent effect.
- Swiss legal doctrine and jurisprudence provide broad interpretation recognizing instrumentalities can represent significant means/conduits enabling large scale money laundering and should be subject to confiscation.

*Source: cr18257 - 208. The legal framework governing the Liechtenstein seizure and confiscation regime has*

### 230. A strong point in the Liechtenstein approach is its focus on asset recovery. The statistics

### 230. A strong point in the Liechtenstein approach is its focus on asset recovery. The statistics

### Asset recovery focus and implementation
- Confiscation and forfeiture take priority over criminal convictions; civil in rem confiscation procedure is described as "a powerful and effective tool" in a system reliant on foreign investigations and prosecutions.
- Freezing and seizure tools are "systematically and proactively wielded" to prevent dealings with assets that could obstruct subsequent confiscation measures.
- There is a "notable discrepancy between the high number of conservatory actions and the actual confiscations," attributed partly to the high level of proof required for the originating offense when not based on a foreign order or conviction.
- Introduction of Art. 20b PC permitting confiscation of "assets as object of the offense" is identified as "a significant improvement" that strengthens future autonomous money laundering offense policy.
- Assessors note encouraging results: high numbers of conservatory measures, systematic use of in rem confiscation, and overall amount of forfeited criminal assets indicate a particular focus on asset recovery for proceeds-generating crimes.
- Statistics were not provided with specific regard to confiscation concerning ML; assessors could not conclude effectiveness for that specific aspect.

### Evidentiary burdens and scope of in rem procedures
- Courts require a "quite burdensome" proof standard to establish that assets were acquired by commission of a specific predicate offense.
- In some (mostly common law) jurisdictions the in rem procedure is accompanied by sharing or reversal of the burden of proof on illicit origin; in Liechtenstein this reversal applies only:
  - in the event of repeated and continuous behaviour involving crimes (Art. 17 PC), and
  - in relation with criminal organizations and terrorist groups (Art. 20, para. 2–3 PC).
- Recommendation noted: extend evidentiary rules (sharing/reversal of proof) to all serious offenses or crimes in all circumstances (repeated/continued or not) to align with similar systems and add value to the confiscation regime.

### Legal privilege, professional secrecy, and investigative powers
- Broad legal privilege scope includes auditors; lawyers in Liechtenstein often assume different roles (mostly trustee), which can hamper effective tracing and identification of criminal assets.
- Omission of lawyers, trustees, and auditors from Art. 98a CPC reduces ability to obtain relevant information from these professions.
- For trustees: secrecy obligations do not obstruct application of Arts. 105 and 108 CPC to be heard as a witness and give evidence.
- For auditors: they were "mistakenly included" in the Art. 108 exemption despite having no legal representation function; for lawyers and auditors distinct possibilities exist to wield legal privilege protection.
- Judiciary jurisprudence: a trustee cannot use a lawyer’s capacity to refuse to comply with production or information requests or orders, nor to refuse being heard as a witness (Constitutional Court Ruling of 17.9.2001, StGH 2000/25).
- Where Art. 98a CPC cannot be applied, judges rely on Arts. 92 and 96 CPC for search and seizure; lawyers and auditors may be heard as witnesses (Art. 105 CPC) on nonprivileged information or if they have not acted in their privileged capacity.
- Presumption: where a lawyer has double capacity, presumption is that he acted in his non-lawyer capacity until proof to the contrary.
- Private sector responses vary; assessors indicate the question of effectively countering abuse of legal privilege remains open.

### Procedural delays, appeals, and impact on confiscation
- Appeal procedures have been streamlined/simplified in MLA seizure and confiscation context, but ample possibilities for delaying tactics remain, especially in high profile cases.
- Dilatory recourse to the Constitutional Court is frequent, "also when no apparent constitutional or fundamental human rights are actually at risk."
- Interim decisions (e.g., sealing of seized documents) affected by Constitutional Court rulings may reintroduce burdensome past practices and open full procedural avenues from Court of Appeal to Supreme Court to Constitutional Court.
- Concern: Art. 15 on jurisdictional competence of the Constitutional Court is interpreted broadly, potentially turning the Court into an alternative Court of Appeal judging factual arguments.
- Effect: such procedural uses negatively impact duration and effectiveness of the seizure/confiscation regime; legislator urged to balance protection of fundamental rights with reasonable procedure application.

### Risks and international cooperation challenges
- General law enforcement risk factors apply to the confiscation regime as part of the AML/CFT repressive framework.
- Procedural incidents and delaying tactics combined with high evidentiary requirements on illicit origin may undermine long-run asset recovery approach.
- Identification and tracking of criminal assets in the international context is challenged by corporate structures/arrangements that shield assets, posing significant challenges for foreign law enforcement authorities.

### Recommendations and comments (3.4.2)
- Address incomplete coverage of Art. 98a CPC to include all persons and entities subject to the DDA, "more in particular lawyers, auditors and trustees."
- Examine effective countermeasures against abuse of legal privilege protection in cases of dual capacity.
- Develop autonomous procedures for money laundering as a correction to reliance on foreign factors.
- Consider extending the principle of sharing or reversal of proof (now in Art. 20, paras. 2–3 PC) to all serious offenses or crimes in all circumstances in the context of an in rem procedure.
- Exclude auditors, "who have no legal representation function," from the scope of the legal privilege regime envisaged by Art. 108 CPC.

### Compliance with Recommendation 3 (summary)
- Rating: R.3 LC
- Factors underlying rating (selected):
  - Art. 98a CPC does not cover information gathering for some relevant categories such as payment system providers, e-money institutions, insurance mediators and DNFBPs.
  - Scope of legal privilege capturing auditors is too broad and could hamper authorities’ powers to identify and trace property subject to confiscation or suspected proceeds of crime.
- Effectiveness issues:
  - Confiscation hampered by high burden of proof to establish the link between illegal assets and specific predicate offenses.
  - Delaying procedural tactics and abuse of legal privilege concerns (dual capacity).

### Freezing of funds used for terrorist financing (SR.III) — summary of legal framework and implementation
- Previous assessment (2007 MER) found deficiencies in implementing UNSCRs and recommended review of response to UNSCR 1373 and development of a balanced freezing system outside UNSCR 1267 context.
- Legislation introduced with clearer procedural appeal rules for de-listing, review, and related requests for both UNSCR 1267 and 1373 regimes.
- Legal instruments:
  - Enforcement of International Sanctions Act (ISA), December 10, 2008;
  - Ordinance on Measures against Individuals and Entities associated with the Taliban (Taliban Ordinance), October 4, 2011;
  - Ordinance on Measures against Individuals and Entities associated with Al-Qaida (Al-Qaida Ordinance), October 4, 2011.
- ISA in force since March 1, 2009, replaces the Law of May 8, 1991 on Measures Concerning Economic Transactions with Foreign States.
- 2011 Ordinances:
  - All funds and economic resources in possession or under direct or indirect control of designated persons/groups are immediately frozen de jure and implicitly without prior notice (Art.2. 1).
  - Transfer of funds or otherwise making funds/resources available to designated persons/groups is prohibited (Art. 2.2).
  - Persons/institutions holding or knowing economic resources that may fall under measures must report to the FIU without delay (Art. 6.1).
- FIU role: receives freezing reports (Art. 6.1), monitors execution of compulsory measures, advises on exemption requests (Art. 5.1); DDA suspicious transaction disclosure obligations remain concurrent.
- ISA Art. 1 includes a reference allowing compulsory measures to enforce sanctions adopted by "the most significant trading partners of the Principality of Liechtenstein" — described as controversial and potentially narrowing application of UNSCR 1373.
- Liechtenstein has not established its own terrorist list; no specific procedure exists for creating a domestic list; responsibility likely to fall to AML/CFT Working Group PROTEGE if needed.
- Where suspicion assets relate to terrorists, DDA and CPC provisions trigger a five-day freezing together with an SAR to the FIU or a denunciation to law enforcement.
- Cross-border and foreign freezing actions:
  - Liechtenstein observes and implements relevant EU regulations by ordinances; banks generally adopt the U.S. OFAC list voluntarily.
  - No formalized procedure historically for handling requests from other countries; on August 5, 2013 PROTEGE drafted a formalized procedure for incoming requests under SR.III which requires immediate forwarding to the PROTEGE Chair and possible measures including requesting additional information, alerting financial institutions via the FIU, sending name lists to reporting entities via the FMA, publishing names, or requesting government inclusion on an official freezing list. If assets are frozen, an annual review must be conducted.
- Dissemination and execution:
  - Publication in the Liechtenstein Law Gazette and dissemination via FMA website/newsletter to reporting entities; affected entities obligated to immediately freeze assets.
  - ISA Art. 3 imposes a general duty on persons affected by compulsory measures to disclose relevant information to the competent executing authorities "on request"; FIU is designated as executing authority for monitoring implementation.
- Definitions and control:
  - ISA did not define "funds"; 2011 ordinances explicitly define funds and economic resources (Art. 3) and clarify "control" as covering direct and indirect control (Art. 2).
  - Amendment of August 13, 2013 to the 2011 ordinances (entered into force on August 16, 2013) confirmed indirect control including persons acting on behalf or direction of designated entities.

*Source: IMF assessment text.*

### 255. The legislator still has not explicitly specified the term “possession” in the ordinances as also

### 255. The legislator still has not explicitly specified the term “possession” in the ordinances as also

### Definition of “possession” and legislative amendments
- Liechtenstein law has a legal concept of “possession” including also “joint” possession (Liechtenstein Property Law (“Sachenrecht”), Arts. 25–33 of the Property Law (“Gemeinschaftliches Eigentum”)), so single person and joint possession are both covered by the term “possession” as referred to in Art. 2 of the ordinances.
- The concept also covers “partial” possession, which is explicitly provided for in Art. 2.1 of the Amendment of August 13, 2013 to the 2011 ordinances (“teilweise”), in force since August 16, 2013.
- Technical deficiency noted in the previous MER (lack of explicit specification of “possession” including partial and co-ownership) is addressed by the August 13, 2013 amendment.

### Communication to the financial sector (c. III.5)
- UNSCR 1267 and Taliban/Al Qaida Ordinances lists and changes are first published in the national newspapers and the Liechtenstein Law Gazette.
- All relevant information is immediately communicated by the FMA to the professional associations for distribution to their members.
- The FMA publishes all lists relating to the implementation of UNSCR 1267, UNSCR 1373, and the EU Regulations on its website and sends e-mail messages (FMA Newsletter) in the case of amendments to the lists.
- The FMA Newsletter currently has 1,287 subscribers, including all professional associations.
- The FIU website also refers to the sanctions lists.

### Guidance to financial institutions (c. III.6)
- Since the previous assessment and the adoption of the ISA the authorities did not feel the necessity to give further guidance, as the freezing rules were considered sufficiently ingrained in the system.
- Newsletters sent out by the FMA and the FIU guidance papers, such as on reporting requirements and NPOs (2013), occasionally contain references to the freezing regime.

### De-listing requests and unfreezing funds (c. III.7 & c. III.8)
- ISA 2008 provides for appeal procedures against administrative and governmental decisions and orders (Art. 9); these theoretically apply in relation to decisions taken in the framework of UNSC Res. 1373 (domestic lists) and can be used in a UNSC Res. 1267 context only regarding validity of administrative measures transposing the UNSCR lists.
- Fundamental right to directly address the Constitutional Court (Art. 15, para. 3 Constitutional Court Act) on violation of human or constitutional rights grounds exists.
- De-listing itself falls outside the jurisdiction of the Liechtenstein Courts.
- Requests for de-listing from the Al-Qaeda and Taliban UN list follow UNSCR 1904 of December 17, 2009 as updated; all requests to be removed from the UN Consolidated list are addressed to the Office of the Ombudsperson at the UN.
- Liechtenstein citizens or residents, including legal persons, affected by freezing measures can directly address the Ombudsperson, who will help them follow the appropriate procedure.
- Requests related to other sanctions lists would be addressed to the Focal Point (UNSCR 1730 2006) or processed by the Ministry of Foreign Affairs for potential referral to the Ombudsperson or Focal Point.
- No public guidance on the de-listing procedure exists yet.
- Confusion or errors prejudicing innocent third parties can be brought before administrative or judicial authorities depending on the nature of the freezing.
- Administrative measures can be appealed with the government or Administrative Court within 14 days (Article 9 ISA).
- Lifting of judicial freezing requires intervention of the investigating judge or the Court of Justice, according to the CPC rules.

### Access to frozen funds and humanitarian exceptions (c. III.9 & c. III.15)
- Art. 2 ISA gives the government the power to make exceptions to the freezing regime out of humanitarian considerations or in the interest of Liechtenstein; applies in both UNSC Res. 1267 and 1373 contexts.
- For UNSC Res. 1267, the 2011 ordinances provide for exceptions on humanitarian grounds (Art. 2.3) to be requested to the FIU, in conformity with the conditions set out in UNSC Res 1452 (2002) and its successors.
- Access to funds on humanitarian grounds and for basic expenses is provided for in Art. 2 ISA and the ordinances.

### Review of freezing decisions (c. III.10)
- Individuals or entities included on the list of the 2011 Taliban/Al Qaida Ordinances may lodge an individual complaint with the Constitutional Court under Art. 15, para. 3 of the Constitutional Court Act on fundamental principle grounds.
- Persons or undertakings included on the Al-Qaida/Taliban Ordinance list may demand a copy of an order confirming they are affected by blocking of assets; this can be appealed to the Administrative Court (National Administration Act and Art. 9 ISA).
- These procedures relate to administrative decisions transposing the UNSC list and procedural issues, not to the listing by the UNSC.
- Requests amounting to de-listing from the UNSC list must follow the ombudsperson process (UNSCR 1904).
- For UNSC Res. 1373 related freezing, reviews in principle fall under the jurisdiction of the Liechtenstein Administrative Court if based on a government decision; if based on the DDA or CPC regime, the Court of Justice takes jurisdiction.

### Freezing, seizing, and confiscation in other circumstances (c. III.11)
- Code of Criminal Procedure (Art. 97a CPC) and the Criminal Code (Art. 20b PC) apply to freezing, seizure, confiscation, and forfeiture of assets used for purposes of terrorist financing or other terrorist related funds.

### Protection of rights of third parties (c. III.12)
- Art. 20c, para. 1(1) PC excludes forfeiture of assets to the extent that persons not involved in the punishable act, the criminal organization, or the terrorist group have legal claims in respect of the assets concerned.
- Outside criminal procedure based seizure, there are no specific provisions on such protection in the ISA or Ordinances.
- Bona fide third parties can challenge administrative freezing measures via administrative review procedures (SRIII.7 and SRIII.10).

### Enforcing obligations and sanctions (c. III.13)
- ISA subjects must cooperate with competent authorities to enable comprehensive assessment and supervision (Art. 3 ISA).
- Executive authorities identified in the ordinances have power to enter and inspect business premises of persons under disclosure obligation; FMA (also on behalf of the FIU) uses this power for due diligence inspections.
- Sanctions in Arts. 10–13 ISA:
  - Willful violation of provisions of an ordinance related to punishable acts: up to three years imprisonment or fine of up to 360 daily rates; halved in case of negligent noncompliance (Art. 10);
  - Refusal to cooperate with competent authorities and making false or misleading statements (Art. 11.1.a): Violation of provisions of an ordinance related to punishable acts if not punishable under another penal provision: 100,000 SFr or imprisonment up to six months (Art. 11.1.b); halved in case of negligence;
  - Corporate criminal liability alongside personal liability of the representative (Art. 12);
  - Confiscation of the relevant property and assets, even outside the scope of criminal proceedings, if so imposed by international law (Art. 13).
- DDA, PC, and CPC provisions on noncompliance and sanctions apply in all instances related to other terrorism related assets.

### Statistics (R.32)
- As of January 2009, the overall amount of funds frozen pursuant to UNSC Resolution 1267 was CHF 90,200 (the measure was provoked by a bank receiving information of an on-going Swiss investigation).
- Due to removal of the person from the list by the UN in May 2011, no assets are still frozen or have been frozen since.

### Implementation, effectiveness, and risk
- Adoption of the Enforcement of ISA significantly amended and improved the legal framework governing the terrorist asset freezing regime in Liechtenstein; clear-cut procedures in place for challenging or reviewing administrative measures and governmental decisions on freezing listed terrorists’ assets in both UNSCR 1267 and 1373 contexts.
- Limitation: ISA’s restriction to enforce sanctions adopted by the “most significant trading partners” is inconsistent with UNSCR 1373 and unduly narrows implementation of the resolution.
- For UNSCR 1267: initial technicality on definition of “possession” (partial possession) addressed; August 13, 2013 amendments, in force since August 16, 2013, clarified “partial possession” and reference to “indirect control” including control by persons acting at the behalf or direction of designated entities.
- For UNSCR 1373: appeal procedures and explicit provision on humanitarian aid exist, but neither ISA nor any other legal text determines how to proceed in the event of establishment of a domestic list; procedures for domestic transposition of foreign lists were put in place as a result of the PROTEGE decision of August 5, 2013.
- Effectiveness assessment limited by absence of actual cases of freezing (except one instance in 2009, later de-listed) and transposition.
- Interested parties appear sufficiently informed of their duties; the one case of freezing under UNSCR 1267 since the last round was treated appropriately.
- Risk of noncompliance appears relative in terms of observance of the lists, but deficiencies in CDD application, particularly regarding beneficial ownership, and existence of complex legal structures and weaknesses under R33 and 34 increase the possibility of targeted terrorist assets going undetected.

### Recommendations and comments (3.5.2)
- The authorities should:
  - Remove the general clause from the ISA so that the scope of application of the ISA 2008 is not restricted to certain countries;
  - Issue guidance on the procedures for de-listing from the Al-Qaeda and Taliban UN list;
  - Elaborate procedures to be followed for drafting domestic lists.

### Compliance with Special Recommendation III (3.5.3)
- SR.III rating: PC
- Factors underlying rating:
  - Scope of application of ISA 2008 restricted in relation to UN Res. 1373.
  - No procedures in place for domestic designations.
  - No public guidance on the procedures for de-listing from the Al-Qaeda and Taliban UN list.
- Effectiveness issues:
  - Effectiveness affected by deficiencies in CDD application and transparency of legal persons and arrangements.

### The Financial Intelligence Unit and its functions (R.26) — key points (3.6 and following)
- 2007 MER deficiencies: law did not expressly provide for FIU’s access to all relevant information held by reporting entities; FIU Act had not been amended to include financing of terrorism.
- FIU Act amended to include financing of terrorism.
- FIU issued consolidated written guidelines on reporting and sector-specific reporting forms for banks, trustees, and insurance businesses.
- Training and awareness-raising activities continued, especially in nonbanking sector.
- Within two months from the onsite visit, the DDO was amended to empower the FIU explicitly to issue guidelines and to request additional information from reporting entities and other concerned parties in the case of a SAR.

### Legal framework for the FIU
- Laws and instruments cited:
  - Law of March 14, 2002 on the Financial Intelligence Unit (FIU Act);
  - Law of December 11, 2008 on Professional Due Diligence to Combat Money Laundering, Organized Crime, and Terrorist Financing (DDA);
  - Ordinance of February 17, 2009 on Professional Due Diligence to Combat Money Laundering, Organized Crime, and Terrorist Financing (DDO);
  - Law of November 24, 2006 against Market Abuse in Trading of Financing Instruments (MAA);
  - Guideline for submitting reports to the Financial Intelligence Unit issued on April 1, 2013 (FIU Guideline);
  - Law of April 21, 1922 on General Administrative Matters.

### Establishment, mandate, and functions of the FIU (c. 26.1)
- FIU is an independent administrative agency within the Ministry of Presidency and Finance; established in 2001, governed by FIU Act of 2002.
- Art. 3 FIU Act: FIU is central administrative office responsible for obtaining and analyzing information necessary to detect money laundering, predicate offenses of money laundering, organized crime, and terrorist financing.
- Arts. 4 and 5 FIU Act: FIU receives and analyzes SARs on suspicions of money laundering, predicate offenses, organized crime, and financing of terrorism; also receives reports on market abuse (Art. 4, para. 4 FIU Act).
- FIU conducts analysis (Art. 4, para. 2 FIU Act) and compiles analytical reports for dissemination to the Office of the Public Prosecutor where analysis substantiates suspicion.
- FIU collects information necessary for detection of ML, TF, organized crime, and predicate offenses and cooperates with domestic and foreign authorities.
- Additional FIU responsibilities: administration of data processing systems, compiling strategic reports for government and other authorities, providing feedback to reporting entities and public, training public servants and reporting entities, providing technical assistance to lower capacity countries, and chairing the national AML/CFT working group (PROTEGE).

### Guidelines to financial institutions on reporting STR (c. 26.2)
- On April 1, 2013, FIU issued consolidated guidance on reporting, including standard reporting forms and submission procedures for suspicious activity (and other) reports.
- Legal status of the FIU Guideline was unclear at the time of the onsite mission because FIU Act did not empower FIU to issue guidance; issue addressed by DDO amendment within two months following the onsite visit (Ordinance of August 20, 2013 on the amendment of the Due Diligence Ordinance).
- Prior to April 2013, guidance was provided via annual reports, meetings with professional organizations, public training, in-house training, public statements; standard reporting form was available prior to April 2013.
- FIU Guideline details:
  - Elaborates on conditions triggering a SAR; potential link between activity and a predicate offense is sufficient to trigger reporting obligation.
  - Obligation may arise even if specific predicate offense from which assets originate is not known.
  - No special preconditions (such as a justified suspicion) required for SAR submission.
  - Reporting entity is not required to determine whether the suspicious activity could lead to coercive measures by law enforcement authorities.
  - Sets out measures to be taken by reporting entity after reporting.
  - Provides detailed explanation of ‘suspicion’ within context of ML, predicate offenses, organized crime and TF.
  - Specifies that a SAR must contain all information required for the FIU to evaluate the matter (Art. 17, para. 1 DDA and Art. 26, para. 3 DDO).

*Source: cr18257 - 255. The legislator still has not explicitly specified the term “possession” in the ordinances as also (PDF chapter/section).*

### 290. As to the form of reporting, the guidelines require reporting entities to submit reports by

### cr18257 - 290. As to the form of reporting, the guidelines require reporting entities to submit reports by

### Form of reporting and submission modalities
- Reporting entities must submit reports by completing a standard form in writing and send it by post, courier, fax or e-mail.
- A clear indication of the postal and electronic addresses of the FIU and other useful contact information of the FIU are provided.
- Various reporting forms are available on the website of the FIU.
- Banks, insurance companies, trustees, and lawyers are required to complete a sector-specific form.
- Art. 26(3) of the DDO empowers the FIU to issue a standardized report form.

### Contents and attachments of reporting forms
- Reporting forms contain information fields that must be completed, including:
  - details of the reporting entity;
  - an explanation of the facts which raised the suspicion;
  - details on the type of business relationship, and the contracting party;
  - information on all beneficial owners involved;
  - total amount of assets involved in the business relationship;
  - details on the accounts and financial transactions; and
  - the clarifications carried out by the reporting entity before submitting the report.
- The reporting form is to be accompanied by all CDD documentation obtained by the reporting entity when establishing the business relationship/carrying out the occasional transaction.

### Flexibility in form usage
- Although use of reporting forms is standard, upon consultation with the FIU it may be determined that the quality of the report can be improved if a standard form is not used.
- In such cases, all the records required in a reporting form must be submitted.

### Receipt, completeness, confirmation, and reference
- A report is considered submitted if it is complete and has been confirmed by the FIU.
- The FIU Guideline provides that as soon as the SAR reaches the FIU, receipt of the SAR is confirmed in writing.
- The confirmation includes a reference number, the name of the responsible officer, and an indication of when the freezing of assets ends.
- The FIU reviews the contents of the report to ensure that it is complete and requests missing records, where necessary.
- The reference number must always be quoted in communications with the FIU.
- Pursuant to Art. 18, para. 2 of the DDA, following submission of a SAR, reporting entities shall refrain from carrying out any actions which might obstruct or interfere with a restraining order issued in terms of Art. 97a of the Criminal Code of Procedure, unless such actions have been approved in writing by the FIU.

### Access to Information on Timely Basis by FIU (c. 26.3)
- Legal basis and limits:
  - Art. 4 of the FIU Act: “the FIU shall obtain information necessary to detect money laundering, predicate offenses of money laundering, organized crime and terrorist financing, subject to legal provisions relating to the protection of secrecy.”
  - Art. 5: FIU responsible for obtaining information from publicly available and nonpublicly available sources and to cooperate with the National Police.
  - Art. 6: FIU empowered to request domestic authorities to transmit information necessary to combat ML, predicate offenses, organized crime, and FT.
- DDA provisions and limits:
  - Art. 36 of the DDA requires domestic authorities to provide and transmit all information and records necessary for enforcement of the DDA, but its scope may be limited to enforcement of the DDA and not explicitly to FIU functions.
  - Doubts exist whether the FMA may share information with the FIU, potentially limiting FIU access to structure and activities of licensed entities and AML/CFT supervisory findings.
- Timeliness:
  - No legal stipulation that information be provided on a timely basis; assessors informed response time is extremely short and in a large majority of cases information is received on the same day.
- Direct online access (Art. 9, para. 1):
  - Article provides for FIU’s direct online access to certain registers, but the government must specify by ordinance which registers the FIU may access; no such ordinance has been issued.
  - In practice, FIU established direct online access to the Zentrales Personenverzeichnis containing:
    - Commercial registry data: data on legal entities (company name, legal form, address, status). More detailed extracts require phone/e-mail/fax and are usually delivered very shortly (within hours).
    - Citizens’ registry data: complete data of natural persons resident in Liechtenstein (surname, first name, date and place of birth, place of civil origin, citizenship and address).
    - Employers’ records: employment data of natural persons (current employer, former employer).
  - FIU also has direct online access to the CARI system containing data on vehicles.
- Requests to law enforcement and other authorities:
  - FIU may request information from the Liechtenstein National Police pursuant to Art. 6 (criminal records, information on ongoing and concluded investigations, assets frozen or seized by the police, formal and informal requests for international cooperation).
  - Discussions were taking place to install an IT “hit-no-hit solution” between the FIU and the police for mutual access to determine registrations and request further information where a hit is identified.
  - FIU can request data from the Steuerverwaltung (tax administration); exchange limited to date because a high percentage of SARs concern foreign residents and limited predicate tax offenses (only VAT fraud to the detriment of an EU country is considered a predicate offense).
  - FIU may obtain immoveable property information indirectly from the property registry and business entity information indirectly from the FMA (for licensed entities) or the Office of Economic Affairs.
- Practical relevance and legal constraints:
  - Domestic databases are very rarely relevant for FIU analytical work because Liechtenstein residents are rarely the subject of SARs; no statistical data maintained on online requests.
  - The evaluation team views that FIU Act provisions are restricted by Art. 4 (protection of secrecy), limiting FIU access to financial, administrative, and law enforcement information.
  - Authorities argue FIU’s power derives from combined reading of Art. 4, para. 1 and Art. 5, para. 1(c); assessors concluded Art. 4, para. 3 sets general competence and other provisions set specific responsibilities.
- Conclusion on access limitations:
  - Legal framework could limit FIU access because of:
    - (i) express limitation in Art. 4 to obtain information “subject to legal provisions relating to the protection of secrecy”;
    - (ii) limitations that the FMA has in providing confidential information to the FIU;
    - (iii) absence of obligation for the FMA or law enforcement to provide the FIU with requested information.

### Additional Information from Reporting Parties (c. 26.4)
- Legal amendment and scope:
  - Prior to onsite visit, power to request additional information from parties other than the SAR submitter was not expressly in law.
  - Amendment to Art. 26 of the DDO within two months of the onsite visit now allows the FIU to request additional necessary information in relation to a SAR from the reporting entity and from other parties concerned after receipt of the SAR.
  - Such information is to be submitted without undue delay; the FIU can set a deadline for submission.
- Interpretation of “parties concerned”:
  - Examples: banks to which a payment has been made from another bank that submitted a SAR; a trustee involved in a Liechtenstein company featured in a SAR; an insurance company from where payments have been made to a bank that submitted the SAR.
  - The term “concerned” is interpreted broadly to encompass any entity possessing information needed for FIU analysis, including reporting entities only indirectly concerned.
- Practical testing and reporting entities’ responses:
  - Provision enacted recently and was not tested in the period under review.
  - Prior to amendment, FIU had regularly requested information from other reporting entities; sanitized examples provided to assessors.
  - Most reporting entities interviewed stated they had never received such requests; some stated they would not provide requested information.
- Legal secrecy constraint and recommendation:
  - Art. 4, para. 3 of the FIU Act (protection of secrecy) may restrict FIU ability to obtain information subject to secrecy from reporting entities and should be removed to avoid legal challenge.
- Sanctions for failure to provide requested information:
  - No specific sanctions in the DDO for failure to provide additional information under Art. 26.
  - Art. 48 of the Law on General Administrative Matters would apply: FIU would issue a formal decision ordering the reporting entity to provide the requested information.
  - In terms of Art. 117:
    - failure to comply may be subject to a fine of up to CHF 5,000;
    - where a legal person is concerned, the competent organ (e.g. Board of Directors) may also be subject to the fine (Art. 117(2));
    - where the law is breached repeatedly, the fine may be increased to CHF 10,000 or to imprisonment of up to three months (Art. 117(3)).
  - Evaluation team view: a specific provision dealing with failure to provide information as requested under Art. 26 should be provided, given specific sanctions exist for other DDA and DDO breaches.
- Indirect information channels:
  - Additional information may be obtained indirectly through the FMA under Art. 36 of the DDA, but doubts exist whether this is practicable because pursuant to Art. 28, para. 4 of the DDA the FMA may only obtain information from persons subject to due diligence for supervisory purposes and confidentiality provisions may impede exchange with the FIU.

### Dissemination of Information (c. 26.5)
- Forwarding to prosecutors:
  - Where, after analysis, suspicion of ML, a predicate offense, organized crime, or FT is substantiated, an analytical report together with the SAR itself is forwarded to the Office of the Public Prosecutor for investigation (Art. 5, para. 1, letters b and g of the FIU Act).
- Assessors’ concern:
  - Assessors consider the FIU should not be required to transmit the SAR itself to the PPO because it may expose the identity of the reporting entity and discourage SAR submission, potentially impacting effectiveness of the FIU receipt function.
- Decision-making process:
  - Following analysis, the case analyst together with the Deputy Head of the FIU (or, in his absence, the Head) determines whether the case is to be sent to the Office of the Public Prosecutor.
  - Final decision is taken by the deputy director or, in his absence, the director, in accordance with internal FIU procedures.

### Operational independence (c. 26.6)
- Institutional placement and budget:
  - The FIU is a government agency within the operational structure of the Ministry of Presidency and Finance.
  - FIU Law does not expressly provide for independence, but the FIU has a separate budget, detached premises, and its own IT infrastructure.
  - The FIU budget is a separate line in the Ministry for Presidential Affairs and Finance budget, elaborated by the head of the FIU and agreed by the prime minister.
  - Annual budgets of all public entities, including the FIU, are published in the annual activity report of the government.
- Appointment and reporting:
  - The Director of the FIU reports directly to the prime minister.
  - Director, deputy director, and heads of departments are appointed by government through a public administrative procedure.
  - Other nonmanagerial staff are formally employed by the Public Office of Human and Administrative Resources through procedures initiated and elaborated by the FIU director.
- Assessors’ view:
  - The FIU has sufficient operational independence and autonomy and is free from undue influence and interference in performance of its functions.

### Protection of Information Held by FIU (c. 26.7)
- Data systems and security measures:
  - FIU has established and maintains its own data processing systems.
  - Various security measures are in place to protect information at the FIU premises.
  - In 2011, the government invested a substantial amount of funds to increase physical security of FIU premises and to provide a fully autonomous FIU database.
  - The FIU database is integrated in a confidential internal operational IT concept.
- On-site assessment:
  - Premises and FIU database were inspected by the assessor on-site and assessed as having satisfactory security measures implemented.

*Source: cr18257 - 290. As to the form of reporting, the guidelines require reporting entities to submit reports by*

### 316. Every analyst has individual access to three separate workstations: one for SAR data which

### cr18257 - 316. Every analyst has individual access to three separate workstations: one for SAR data which

### Workstations and confidentiality (paras. 316–317)
- Every analyst has individual access to three separate workstations:
  - one for SAR data which is completely autonomous from the other networks,
  - one for access to the state information network,
  - and another one for queries to be conducted on open source which is programmed to ensure that any footprints left cannot be traced back to the FIU.  
- Art. 38 of the State Personnel Act: government employees, including FIU staff, are required to maintain confidentiality concerning matters relating to their service where such matters are to be kept secret by their nature or according to special provisions; the requirement applies indefinitely, even after termination of service.
- Art. 310 of the Criminal Code: disclosure of confidential information by government employees constitutes a criminal offense punishable by up to three years imprisonment.
- FIU Act dissemination provisions:
  - Art. 10 (right to information): upon application and in accordance with the Public Information Act, the FIU shall release information to affected parties regarding data stored about their person only to the extent that no predominating public or private interests oppose the release of such information.
  - Release under Art. 10 is subject to strict conditions set out under Art. 11; information may not be disclosed where FIU functions or information sources would be jeopardized or the release would endanger public security or otherwise harm the welfare of the country.

### Publication of Annual Reports (c. 26.8) (paras. 318–319)
- The FIU issues reports on its activities on an annual basis that include information on statistics and typologies.
- Annual reports are released via a press conference hosted by the prime minister and the director of the FIU.
- Distribution on the day of the press conference (hard copies):
  - all business associations (11),
  - all licensed banks (17),
  - neighboring and German-speaking FIUs (Swiss, Austrian, German, and Luxembourg),
  - all Liechtenstein embassies and Permanent Missions worldwide (8),
  - a few selected authorities from neighboring countries as well as NGOs (13).
- On the same morning, soft copies are made available as PDF downloads on the FIU’s website.
- Reporting entities regularly refer to the annual report, especially typologies provided in the report.

### Membership of Egmont Group and principles of exchange (c. 26.9–26.10) (paras. 320–325)
- The FIU joined the Egmont Group in 2001 and participates actively, including chairing working groups and sponsoring membership for other FIUs.
- The FIU may request information from foreign FIUs for any purpose referred to under the FIU Act and may provide official, nonpublicly available information to foreign counterparts on a reciprocal basis, subject to conditions in the FIU Law.
- Art. 7, para. 2, lett. a) conditions include that requested information:
  - must be in accordance with the provisions of the FIU Act,
  - must not violate ordre public, other essential national interests, and matters subject to secrecy or fiscal interests.
- Authorities’ clarification:
  - the fiscal interest condition is intended to protect the fiscal interests of Liechtenstein and not those of the person subject to the request;
  - Art. 7, para. 2, lett. a) is intended to protect state secrets rather than financial or other information concerning a person subject to request.
- Evaluation team view: the reference to secrecy conditions in Art. 7 should be clarified further (with a specific reference to “state or official secrecy”).
- Conditions applicable to the requesting FIU before exchange:
  - requesting FIU would grant a similar request from Liechtenstein,
  - guarantee that information will only be used to combat ML, predicate offenses of ML, organized crime, and FT,
  - information exchanged will only be forwarded after consultation with the Liechtenstein FIU,
  - requesting FIU is subject to official and professional secrecy.
- Requests for information may only be acceded to where the Law on International Mutual Legal Assistance in Criminal Matters does not apply.
- Restriction from Art. 4(3) of the FIU Act on obtaining information subject to legal secrecy protections could impact adherence to Egmont Principles, notably paras. 12 and 13.

### Memoranda of Understanding (MoUs) and information sharing (para. 325)
- Director of the FIU may, after consultation with the Minister of Finance and subject to government approval, conclude MoUs with other FIUs to facilitate exchange; MoUs are not a prerequisite for exchange.
- FIU has signed MoUs with: Belgium, Monaco (2002); Slovakia, Croatia, Lithuania (2003); Poland, San Marino (2004); Georgia (2004); Switzerland, Russia (2005); Romania, Chile (2006); France (2007); Ukraine, Canada (2008); South Africa, Japan (2013).
- FIU is negotiating MoUs with Australia, Serbia, Singapore, Republic of Moldova, and Bosnia and Herzegovina.
- The FIU is not subject to any compliance procedure in Egmont and has full capacity to share financial and other kinds of information with other Egmont FIUs.

### Adequacy of Resources—FIU (R. 30) (paras. 326–334)
- Structure and staffing:
  - FIU headed by the director with assistance of the deputy director.
  - Main units: Strategic Analysis Unit and Operational Analysis Unit.
  - Operational Analysis Unit: headed by the deputy director and composed of four analysts.
  - Strategic Analysis Unit: composed of two analysts.
  - An analyst from each unit is also assigned responsibilities within the other analysis unit.
  - International Affairs Unit: composed of one person.
  - Secretariat: one administrative officer.
  - Total number of persons employed by the FIU is 10.
  - Current staff constitutes a 40 percent increase since the last evaluation in 2008.
- Organizational status and budget:
  - Internal structure defined by the director and endorsed by the prime minister; incorporated within overall government agency structures by the Office of Personnel.
  - FIU is an organizational unit (agency) with same status as Public Prosecutor’s Office, Office of Justice, Office of Foreign Affairs, and National Police.
  - FIU budget is a separate line in the budget of the Ministry for Presidential Affairs and Finance; elaborated by the head of FIU and agreed by the prime minister.
  - Budget for every subsequent year is discussed and agreed upon six months in advance.
  - No cuts were imposed on the FIU’s budget; annual budgets are published in the annual activity report of the government.
  - Rent of premises is paid by the government from the central budget.
  - Evaluators inspected premises and found FIU provided with sufficient technical and other resources.
- Personnel and tools:
  - All FIU employees are public officials employed on an indefinite basis.
  - FIU has access to commercial databases: LexisNexis, World-Check.
  - Developed, jointly with the Basel Institute on Governance, the Asset Recovery Intelligence System (ARIS) for additional use of open source information and detection of relevant networks.
  - FIU conducts a pre-selection procedure and can conduct background checks with the police.
  - Formal hiring via Office of Human and Administrative Resources; recruitment is merit based and open to foreign citizens.
  - Current and all previous FIU directors and deputy directors were Swiss nationals.
  - Staff backgrounds: lawyers, economists, police officers, experts with university degrees in international affairs, staff with compliance experience in private sector.
  - Staff fluctuation is low; some staff members predate establishment of the FIU.
  - Foreign languages spoken by staff: English, French, Spanish, Bosnian.
  - Compensation of Liechtenstein public servants is adequate; no competition with private sector salaries.

### Training and outreach (paras. 331–334)
- FIU regularly conducts internal training courses for staff.
- Operational analysts attended Swiss Criminal Analysis Course and Swiss Police Institute in Neuchâtel (Switzerland).
- In 2012, in-house training organized (also attended by AML professionals of other agencies):
  - Insurance Wrappers and related AML/CFT risks;
  - Alternative Investment Funds Mechanisms (AIFM);
  - Interbank Bank’s payment systems;
  - Asset Recovery Intelligence System (ARIS).
- Analysts attended third-party training on:
  - Business English;
  - Open Source Intelligence.
- On March 14, 2013, ICQM jointly with the FIU organized the Liechtenstein “Due Diligence Day” with presentations from the FIU, the FMA, the Office of the Public Prosecutor, a judge, and representatives of the private sector; event concluded by the Prime Minister. FIU intends to organize this conference annually.

### Statistics for Suspicious Activity Reports (R.32) (table data)
- Suspicious activity reports (SAR DDA 17) by year:
  - 2009: 235
  - 2010: 328
  - 2011: 289
  - 2012: 317
  - 2013 Jan.–June: 145
- Suspicious activity report DDA 17 (terrorism):
  - 2009: 0
  - 2010: 0
  - 2011: 0
  - 2012: 1
  - 2013 Jan.–June: 1
- Thereof: attempted transactions:
  - 2009: 18
  - 2010: 21
  - 2011: 19
  - 2012: 17
  - 2013 Jan.–June: 10
- Market Manipulation (MMA 6/1):
  - 2009: 21
  - 2010: 19
  - 2011: 6
  - 2012: 7
  - 2013 Jan.–June: 7
- TOTAL SAR:
  - 2009: 256
  - 2010: 347
  - 2011: 295
  - 2012: 325
  - 2013 Jan.–June: 163
- International Sanctions Act (ISG) Reports (selected lines):
  - Request for Transaction Approval (Iran): 2009: 0; 2010: 2; 2011: 32; 2012: 3; 2013 Jan.–June: 2
  - Money Transfer Report (Iran): 2009: 0; 2010: 0; 2011: 29; 2012: 12; 2013 Jan.–June: 6
  - ISG Egypt: 2009: 0; 2010: 0; 2011: 4; 2012: 0; 2013 Jan.–June: 0
  - ISG Belarus: 2009: 0; 2010: 0; 2011: 0; 2012: 2; 2013 Jan.–June: 1
  - ISG Iran: 2009: 0; 2010: 0; 2011: 0; 2012: 2; 2013 Jan.–June: 1
  - ISG Libya: 2009: 0; 2010: 0; 2011: 4; 2012: 0; 2013 Jan.–June: 0
  - ISG Zimbabwe: 2009: 0; 2010: 0; 2011: 1; 2012: 0; 2013 Jan.–June: 1
  - ISG Syria: 2009: 0; 2010: 0; 2011: 2; 2012: 0; 2013 Jan.–June: 0
  - ISG Tunisia: 2009: 0; 2010: 0; 2011: 2; 2012: 0; 2013 Jan.–June: 0
  - Others: 2009: 1; 2010: 1; 2011: 0; 2012: 0; 2013 Jan.–June: 0
  - Total ISG Reports: 2009: 1; 2010: 3; 2011: 74; 2012: 19; 2013 Jan.–June: 11
- Total Reports received by FIU:
  - 2009: 257
  - 2010: 350
  - 2011: 369
  - 2012: 344
  - 2013 Jan.–June: 174
- Suspicious activity and ISG reports by sector (selected sectors):
  - Banks: 2009: 155; 2010: 231; 2011: 167; 2012: 218; 2013 Jan.–June: 98
  - Professional trustees: 2009: 82; 2010: 88; 2011: 106; 2012: 83; 2013 Jan.–June: 38
  - Lawyers: 2009: 5; 2010: 6; 2011: 6; 2012: 2; 2013 Jan.–June: 4
  - Insurers: 2009: 9; 2010: 15; 2011: 37; 2012: 28; 2013 Jan.–June: 12
  - Postal Service: 2009: 0; 2010: 0; 2011: 0; 2012: 0; 2013 Jan.–June: 15
  - Authorities: 2009: 1; 2010: 2; 2011: 21; 2012: 3; 2013 Jan.–June: 3
  - Auditors: 2009: 1; 2010: 2; 2011: 31; 2012: 4; 2013 Jan.–June: 0
  - Investment undertakings: 2009: 1; 2010: 1; 2011: 0; 2012: 0; 2013 Jan.–June: 1
  - Asset Management Companies: 2009: 0; 2010: 0; 2011: 1; 2012: 3; 2013 Jan.–June: 1
  - Dealers in precious goods: 2009: 0; 2010: 0; 2011: 1; 2012: 1; 2013 Jan.–June: 2
  - Others: 2009: 3; 2010: 5; 2011: 1; 2012: 0; 2013 Jan.–June: 0
- Suspicious activity reports forwarded to competent authorities:
  - Forwarded: 2009: 205; 2010: 292; 2011: 197; 2012: 200; 2013 Jan.–June: 87
  - Not forwarded: 2009: 52; 2010: 58; 2011: 172; 2012: 144; 2013 Jan.–June: 79

### Case handling and operational procedures (paras. 335–340)
- FIU has well-established procedures and sufficient resources; staff is highly experienced and professional and FIU has evolved since establishment in response to ML/FT developments.
- SAR receipt and submission:
  - Most SARs are received either by registered mail or delivered manually by the reporting entity.
  - Envelope containing the report does not always contain protective markings.
  - FIU Guideline provides postal address and reporting procedure information; FIU Guideline issued in April 2013.
  - Previous ad hoc guidance was effective; reporting entities met onsite were aware of reporting procedure.
- Intake, assignment and case management:
  - Upon receipt, report passed to deputy director or, in his absence, the director.
  - Deputy director conducts brief database search to determine connection to previous or ongoing case.
  - If connected, SAR assigned to the analyst working on that case; otherwise assignment depends on analyst presence and workload.
  - Analyst inputs case in the case management system which generates a reference number used in all communications.
  - A case is opened for every SAR received, even where another case relating to same persons or transactions is ongoing.
  - SAR is reviewed in detail and searches conducted in the FIU database to establish links.
- Prioritization and urgency:
  - Preliminary analysis carried out to prioritize case using various criteria (not reproduced for confidentiality).
  - Prioritization determines urgency and timeframe for conclusion; high priority cases are brought to attention of director and deputy director.
  - One main criterion used for prioritization is the possibility that a court order be issued to freeze funds or assets.
  - Reporting entity is required to freeze any account it holds for the customer and prohibited from taking measures prejudicing an eventual freezing order for a five-day period from receipt of the SAR by the FIU unless FIU decides to lift the freeze.
  - Within the five-day period, primary concern is to determine whether suspicious funds or assets are at risk of being transferred out of Liechtenstein; expedited analysis is carried out and may involve gathering information from foreign FIUs to substantiate suspicion and forward case to the OPP for an application for a freezing order to the investigating judge.

*Italic: cr18257 - 316. Every analyst has individual access to three separate workstations: one for SAR data which*

### 341. Where the SAR does not trigger an expedited analysis, the analysis is conducted in

### 341. Where the SAR does not trigger an expedited analysis, the analysis is conducted in

### Analysis process and timelines
- Within the same day of receipt of the SAR, a confirmation is sent to the reporting entity having filed the SAR and an indication of the expiry of the five-day freezing period is included.
- Analysis of cases not assigned a high priority: "does not take longer than six months."
- Where additional information is requested, Art. 26, para. 2 states that such information shall be submitted "without delay."
- The FIU indicated it had "never encountered instances" where requested additional information was not provided within the time required.

### Information handling and IT tools
- Information received in the SAR and any subsequent additional information is input manually in the database; manual input can be laborious, especially with bank account information.
- Manual input may benefit analysts by familiarizing them with and assimilating the data during the process.
- Analysis is initiated during data input and includes gathering information from different public and confidential sources, profiling customers, establishing links between entities, analyzing transaction flows, and identifying links to predicate offenses where clear.
- IT tools available to analysts: I2, ARIS, WorldCheck, and LexisNexis.
- In most cases, data entered in the FIU databases is migrated into I2 to create visualization charts.

### Challenges and cooperation
- Major challenge: significant reliance on information from foreign FIUs; such information is not always provided on a timely basis and may delay case conclusions.
- Prior to an amendment two months after the onsite visit, the FIU "did not have an express power to obtain additional information from other reporting entities"; FIU maintained previous provision was sufficient but statistics on regularity of such requests were not maintained.
- Example provided: reporting entity replied within seven days to a request for additional information.
- Most reporting entities interviewed during the onsite mission stated they had "never received such requests" from the FIU and indicated they would not have provided information due to unclear legal basis prior to the August 2013 amendment of Art. 26.

### Internal coordination and analyst support
- The deputy director holds weekly meetings with all analysts to discuss ongoing analyses, case progression, and warranted measures.
- Analysts have varied backgrounds (banking, economics, law enforcement, law, accountancy); pooling of ideas enhances analysis.
- Meetings also discuss new ML/FT trends, typologies, and vulnerabilities.

### Analytical reporting and dissemination
- Upon conclusion of analysis, the analyst drafts an analytical report using a template divided into sections: facts of the case, reference to additional information, analysis, and conclusion.
- Analysis part includes FIU evaluation, indication of possible predicate offenses, and possible methods and trends.
- Conclusion contains validation of suspicion and recommendations/requests (e.g., open a criminal investigation, freeze an account).
- Analytical report is discussed between the analyst and the deputy director; ultimate decision to forward a case to the OPP rests with the deputy director.
- Some suspicions are based on transaction pattern analysis without direct link to criminal activity but "clearly indicated that existence of ML activity."
- When disseminated to the OPP, analytical reports are accompanied by annexes: visualization charts, transaction overviews, and FIU research documents.

### Statistics on SARs and outcomes (as presented)
- The table indicates number of cases forwarded by the FIU to the Office of the Public Prosecutor. Key figures by year:
  - 2009
    - SARs (ML/FT): 235
    - Cases opened (ML/FT): 235
    - SARs forwarded to PPO: 205 (ML/FT: 183; ISA: 0; MA: 22)
    - Percentage of SARs forwarded: 87%
    - Not forwarded to PPO: 52
    - Investigations: 50
    - Indictments: 0
    - Convictions: 0
  - 2010
    - SARs (ML/FT): 328
    - Cases opened (ML/FT): 328
    - SARs forwarded to PPO: 292 (ML/FT: 273; ISA: 1; MA: 18)
    - Percentage of SARs forwarded: 89%
    - Not forwarded to PPO: 58
    - Investigations: 50
    - Indictments: 2
    - Convictions: 0
  - 2011
    - SARs (ML/FT): 289
    - Cases opened (ML/FT): 289
    - SARs forwarded to PPO: 197 (ML/FT: 189; ISA: 0; MA: 8)
    - Percentage of SARs forwarded: 68%
    - Not forwarded to PPO: 172
    - Investigations: 55
    - Indictments: 2
    - Convictions: 0
  - 2012
    - SARs (ML/FT): 318
    - Cases opened (ML/FT): 318
    - SARs forwarded to PPO: 200 (ML/FT: 197; ISA: 0; MA: 8)
    - Percentage of SARs forwarded: 62%
    - Not forwarded to PPO: 144
    - Investigations: 50
    - Indictments: 1
    - Convictions: 0
  - Jan–March 2013
    - SARs (ML/FT): 61
    - Cases opened (ML/FT): 61
    - SARs forwarded to PPO: 31 (ML/FT: 30; ISA: 0; MA: 1)
    - Percentage of SARs forwarded: 51%
    - Not forwarded to PPO: 36
    - Investigations: N/A
    - Indictments: 1
    - Convictions: 0
- Observations:
  - High percentage of SARs forwarded in 2009 and 2010 (87% and 89% respectively).
  - Percentages decreased in successive years but remain "relatively substantial."
  - FIU explanation: in 2009–2010, filtering was insufficient and many SARs generated analytical reports submitted to the OPP despite analysis not substantiating ML/FT to the required degree.
  - Since 2011, analytical process enhanced after discussions with the OPP, resulting in fewer, higher-quality analytical reports disseminated to the OPP.
  - OPP representatives indicate their statistics are case driven and that "90 percent of the SARs lead to an investigation," explaining differences in counts between investigations and FIU notifications.
  - OPP provides systematic written feedback on every case opened; regular bimonthly formal meetings are held between OPP and FIU.

### Effectiveness concerns and international feedback
- Assessors expressed concerns about number of indictments and absence of convictions resulting from FIU notifications.
- Authorities cited absence of territorial jurisdiction for many cases because large majority concern foreign persons and offenses abroad.
- FIU view: effectiveness should be measured also by successful pursuit of criminal activity by foreign authorities after FIU assistance.
- FIU does not regularly request feedback from foreign FIUs to determine usefulness of information provided.

### Strategic analysis and resources
- Strategic Analysis Department consists of two analysts; strategic analysis conducted on an ongoing basis.
- All cases are reviewed to identify links; linked cases are extracted for detailed analysis to identify emerging patterns, typologies, methods, jurisdictional or reporting-entity connections, and predicate offense patterns.
- Strategic reports are confidential, issued regularly, and communicated to the government; outcomes generally shared with OPP, police, and FMA.
- Reporting entities sometimes alerted to risks and vulnerabilities via training programs, meetings, and annual reports.
- Assessors satisfied FIU is properly structured, funded, staffed, and provided with sufficient technical and other resources.
- Staff found to be appropriately skilled, maintain high professional standards, and employment procedures ensure high integrity and suitable qualifications.
- Adequate ongoing training provided to FIU officers.
- Statistics maintained by the FIU are in line with requirements under Recommendation 32.

### Recommendations and Comments (from source)
- The FIU should take measures to ensure that when SARs are submitted they always contain protective markings;
- The provisions in the FIU Act which deal with the FIU’s access to information from other competent authorities should require that such information is provided on a timely basis;
- The provisions (in sector-specific laws) restricting the exchange of information between the FMA and the FIU should be revised;
- Art. 6 of the FIU Act should be amended to clearly state that competent authorities are required to provide information to the FIU when they are so requested;
- The reference in Art. 4, para. 3 of the FIU Act which restricts the power of the FIU to obtain only information which is not subject to legal provisions relating to the protection of secrecy should be removed to avoid any ambiguity. The authorities should also consider introducing a provision in the law which states that any information that is provided by reporting entities to the FIU for any purpose shall not be subject to any legal provisions on secrecy;
- The authorities should consider including specific sanctions in the DDO for failure to provide additional information when requested by the FIU;
- The FIU should consider implementing a system whereby information provided by reporting entity is submitted electronically and integrated automatically into the IT system of the FIU;
- The FIU should not be required to disseminate the SAR itself to the OPP as stated in Art. 5, para. 1, lett. b) of the FIU Act;
- Authorities could consider conducting a review to determine whether the low number of prosecutions and absence of convictions resulting from FIU notifications is related to the quality of the disseminated reports. The FIU should regularly request feedback from foreign FIUs on the quality and usefulness of information provided;
- Reference to secrecy and fiscal matters within the power of the FIU to exchange information with foreign FIUs should be clarified.

### Compliance with Recommendation 26
- Rating: R.26 PC
- Summary of factors relevant to s.2.5 underlying overall rating:
  - The FIU’s access to information it requires to properly undertake its function (criterion 26.3) could be hindered as a result of the following restrictions in the law:
    - (i) the power to obtain information is subject to secrecy provisions;
    - (ii) the power to obtain information indirectly is affected by the limitations that the FMA has in providing confidential information to the FIU;
    - (iii) no clear obligation for the FMA or law enforcement to provide the FIU with the requested information.
  - The FIU’s power to obtain additional information from reporting entities (criterion 26.4) could be restricted by Art. 4(3) of the FIU Act.
  - The restriction on the FIU’s ability to obtain information subject to legal provisions relating to the protection of secrecy has an impact on the FIU’s adherence to the Egmont Group’s Principles for Information Exchange (paras. 12–13).
- Effectiveness issues:
  - The FIU’s unclear authority to request additional information in the period under review could have had an impact on the FIU’s ability to obtain information from reporting entities other than the reporting entity submitting the SAR.

*Source: Excerpt from cr18257 - 341. Where the SAR does not trigger an expedited analysis, the analysis is conducted in (IMF report).*

### 362. The Police Act (Art. 25e) has introduced cash controls and empowered the National Police to

### cr18257 - 362. The Police Act (Art. 25e) has introduced cash controls and empowered the National Police to

### Cash controls: scope and legal basis
- Art. 25e empowers the National Police to demand from any person information on:
  - the person questioned;
  - the import, export, and transit of cash in the amount of at least CHF 10,000 or the equivalent in a foreign currency;
  - the origin and intended use of the cash; and
  - the beneficial owner.
- Art. 25e, para. 2: in case of suspicion of money laundering or terrorist financing, information may be demanded even if the amount of cash does not reach CHF 10,000.
- The disclosure system became operational in January 2013.

### Definition of “cash” and coverage questions
- The definition of “cash” (Art. 25e, para. 5) includes:
  - banknotes or coins, irrespective of the currency, provided they are circulated as means of payment; and
  - transferable bearer instruments, stocks, bonds, cheques, and similar securities (i.e., “bearer negotiable instruments”), in line with the FATF Glossary.
- Unclear application:
  - It is not clear whether the disclosure system applies to shipment of currency through containerized cargo or to the mailing of currency.
  - Authorities stated all incoming/outgoing mail and freight go through Swiss mail/freight distribution centers, but there is no clear legal requirement underpinning this interpretation.

### Forms, data collection, and delegation to Swiss authorities
- A required control form exists that includes identification data and the amount/type of currency.
- Under the 2008 and 2012 execution/implementation agreements with Switzerland, and the framework treaty on police cooperation, the National Police delegated cash control powers to the Swiss Border Guard Corps (SBGC).
  - Art. 1(c) of the 2012 implementing agreement empowers the SBGC, pursuant to Art. 25e, to carry out cash controls along the Liechtenstein border with Austria and to apply SBGC service regulations.

### Practical application at borders
- No cash controls are made by the SBGC at the border with Switzerland.
  - Authorities explain this is because of the 1923 customs treaty, which considers Liechtenstein a Swiss “Canton” for customs purposes.
  - The customs treaty contains no provision preventing or explicitly prohibiting cash controls, and the Police Act envisages cash controls as ML/FT prevention rather than customs requirements; de facto, disclosure requirements are not applied at the Switzerland border.
- Only one disclosure case was reported after the onsite mission; otherwise no disclosures until that time.
- No statistics available on the number of times SBGC asked persons crossing the border to disclose currency in excess of the threshold.

### Seizure, restraint, and retention of data
- Art. 25e, para. 3: National Police may seize cash for the purpose of securing evidence for criminal proceedings as well as in view of expected confiscation in accordance with Art. 25c.
- Seizure provisions are more restrictive than the broader FATF/SR.IX concept to “stop or restrain”; scope differs from SR.IX circumstances.
- Practical testing: only one tested case where two foreigners were stopped with 25,000 euros and released because police could not confirm proceeds of crime.
- Retention: implementing agreement (Art. 1(c)(2) and (3)) requires that truthful disclosure control forms are transmitted to the National Police (stored in a database and may be used as appropriate); false or lack of disclosure requires National Police involvement.
- Refusal or false provision of information results in charges filed with the Office of the Public Prosecutor (Art. 36(c) of the Police Act); these data become available to prosecution authorities and are reported by the National Police to the FIU.

### FIU access and notification
- Art. 25e, para. 4 requires the National Police to notify the FIU without delay of all suspicious cases and to report such cases to the Office of the Public Prosecutor.
  - “Suspicion” is not defined; authorities clarified this applies to lack/false disclosure as well as suspicions of ML/FT.

### International cooperation frameworks
- Broad international cooperation exists:
  - Tri-lateral police cooperation treaty among Liechtenstein, Switzerland, and Austria (April 27, 1999) covers prevention and suppression of crime, including controlled delivery (e.g., of cash and bearer negotiable instruments) and information transmission.
  - 2009 framework treaty between Liechtenstein and Switzerland and associated execution agreement govern border police cooperation and mutual exchange of information with SBGC.
- Art. 35 et seq. of the Police Act authorizes the National Police to exchange information with competent foreign law enforcement authorities on findings of cash controls (except pure fiscal matters).
- No specific international measures exist to ensure cash disclosure information is shared internationally; no concrete SR.IX examples tested given limited disclosures.

### Sanctions, confiscation, and proportionality
- Refusal or false information: National Police files charges under Art. 36(c) of the Police Act for an infraction.
  - Penalty for natural persons: CHF 5,000 or, if funds are uncollectible, an alternative term of imprisonment of up to one month.
  - Sanctions are not applicable to legal persons (legal persons are subject only for criminal responsibilities concerning crimes and misdemeanors).
  - Sanctions are not proportionate as they do not take into account the amount of undeclared or falsely declared funds.
  - No practical testing of sanctions (no violations detected since operationalization in January 2013, except the post-onsite disclosure).
- If cross-border transportation constitutes criminal conduct under CC provisions on ML or FT, criminal proceedings and ML/FT sanctions apply.
- Powers to freeze and confiscate currency related to ML/FT follow CC and CPC provisions in criminal cases.

### Safeguards, training, and data protection
- Police information systems protection:
  - Must be protected by technical and organizational measures per article 9 of the data protection/security act in connection with Art. 9–12 of the Data Protection Ordinance.
  - National Police issued Police Instruction No. 2011-006 (October 27, 2011) on “The Use of IT-Information Systems, Data Safeguards and Data Protection”.
- Training:
  - No specific targeted training programs for cash couriers.
  - Two designated National Police Officers have been trained on AML/CFT.
- SR.IX best practices: none implemented.
- Database: incoming cash control data are to be maintained by the FIU and the National Police in a database.

### Effectiveness, risks, and observed practices
- Effectiveness issues:
  - Requirements not applied at the border with Switzerland.
  - Only one disclosure at the border with Austria (after the onsite visit).
  - Insufficient statistics; no sanctions (no cases to test), no specific training, no SR.IX best practices.
- Authorities’ view: physical transportation of currency is rare; private sector indicates cash use is not uncommon in legal entity formation where nonresidents sometimes bring startup capital in cash.
  - Example: required minimum capital for foundations is CHF 30,000.
  - Authorities state they have no evidence this often occurs and note the number of new foundations has been drastically reduced in recent years.
- Conclusion: system not effectively applied; risk of cash being transported into Liechtenstein is not negligible.

### Recommendations (as stated)
- Apply the disclosure requirements to containerized cargo and to the mailing of currency.
- Align seizure requirements to fully comply with the power to stop or restrain currency when there is suspicion of ML/FT or when there is a false disclosure.
- Introduce sanctions proportionate to the undeclared amount of funds (for example, add to the existing fixed sanction a pecuniary sanction expressed as a percentage of the undeclared amount) and establish sanctions applicable to legal persons.
- Ensure effective implementation of the disclosure requirements at the border with Switzerland.
- Establish a training program and implement SR.IX best practices.

### Compliance assessment and summary of deficiencies
- SR.IX rating: PC
- Key factors underlying the rating:
  - Unclear application to containerized cargo and mail.
  - Seizure conditions are more restrictive/different than FATF requirement to “stop or restrain.”
  - Sanctions are not proportionate and do not apply to legal persons.
  - Shortcomings related to R.3 and SR.III apply in SR.IX context.
- Effectiveness summary:
  - Requirements not applied at Switzerland border, only one disclosure at Austria border, insufficient statistics, no sanctions tested, no specific training, no SR.IX best practices implemented.

*Source: cr18257 - 362. The Police Act (Art. 25e) has introduced cash controls and empowered the National Police to*

### 393. Liechtenstein has previously prescribed the scope of the DDA based on a two-pronged test.

### cr18257 - 393. Liechtenstein has previously prescribed the scope of the DDA based on a two-pronged test.

### Scope of the DDA and DDO (paras. 393–395)
- Historical two-pronged test:
  - First prong: law only covered persons/institutions that held one of the licenses specified in the law.
  - Second prong: an otherwise covered person/institution would be subject to the law only when carrying out or facilitating a specified activity/transaction.
- Change in 2008:
  - In most cases, the application of the law is now determined based on the type of license a person/institution holds.
  - Only in few instances is application limited to circumstances where an otherwise covered FI/DNFBP carries out specific transactions or provides specific services.
- Scope of the DDO:
  - Defined widely to cover any person who is licensed to carry out financial activities as defined under the FATF standard.
- Mapping of financial activities to types of financial institutions (as presented):
  - Acceptance of deposits and other repayable funds from the public (including private banking):
    - Banks; Postal Service AG
    - AML/CFT + prudential Supervisor: FMA
  - Lending (including consumer credit; mortgage credit; factoring, with or without recourse; and finance of commercial transactions (including forfeiting)):
    - Banks
  - Financial leasing (other than financial leasing arrangements in relation to consumer products):
    - Banks
  - The transfer of money or value (including financial activity in both the formal or informal sector (e.g. alternative remittance activity), but not including any natural or legal person that provides financial institutions solely with message or other support systems for transmitting funds):
    - Banks; Postal Service AG
  - Issuing and managing means of payment (e.g. credit and debit cards, checks, traveler's checks, money orders and bankers' drafts, electronic money):
    - Banks; Electronic money institutions
  - Financial guarantees and commitments:
    - Banks
  - Trading in:
    - i. money market instruments (checks, bills, CDs, derivatives etc.);
    - ii. foreign exchange;
    - iii. exchange, interest rate and index instruments;
    - iv. transferable securities; and
    - v. commodity futures trading:
    - Banks; Fund management companies
  - Participation in securities issues and the provision of financial services related to such issues:
    - Banks; Management companies
  - Individual and collective portfolio management:
    - Banks; Asset management companies
  - Safekeeping and administration of cash or liquid securities on behalf of other persons:
    - Banks; Fund management companies; Asset management companies
  - Otherwise investing, administering or managing funds or money on behalf of other persons:
    - Banks; Management companies; Asset management companies
  - Underwriting and placement of life insurance and other investment related insurance (including insurance undertakings and to insurance intermediaries (agents and brokers)):
    - Life insurance companies; Life insurance intermediaries
  - Money and currency changing:
    - Banks; Foreign exchange offices

### Financial institutions subject to the DDA — counts and assets (December 2012, para. 395)
- Banks:
  - Number: 17
  - Assets under management (billion CHF): 117.7
- Asset management companies:
  - Number: 109
  - Assets under management (billion CHF): 23.52
- Fund Management companies:
  - Active fund management companies: 40
  - Active fund management companies (exempted from DDA): 41
  - (Additional numeric entries as presented)
    - 2
    - 18
    - 0.55
    - 36.65
    - 40
- Management companies keeping unit accounts or issuing physical units (see Art. 4 (b) DDA): 119
- Life Insurance Companies:
  - Number: 21
  - premiums: 33
- Life Insurance Intermediaries: 49
- Liechtenstein Postal service (payment services): 1
- E-Money Institution: 1

### Scope limitations and exemptions (paras. 396–399)
- Art. 4 DDA scope limitations — entities/persons/activities not falling under the DDA:
  - Paragraph (a): An institution/person that is otherwise covered under the law but operates exclusively in the field of occupational old age, disability, and survivors provision;
  - Paragraph (b): contractual relationships of a management company of an undertaking for collective investment in transferable securities or of an investment undertaking for other values or real estate which neither keeps unit accounts nor issued physical units and thus does not itself accept any assets;
  - Paragraph (c): persons who engage in activities referred to in Art. 3 only on an occasional and very limited basis and where the risks of ML and FT are low, provided that:
    - the activity carried out is not the main activity, but is supplementary to the main activity,
    - the activity is only offered to contracting parties in connection with the main activity but is not offered to the public in general,
    - the individual activity does not exceed the value of CHF 1,000 and no more than 100 transactions per year are carried out.
- Practical effect of exemptions:
  - Exemption under para. (b) excludes all but two investment undertakings from obligations under the DDA, as the majority do not maintain share registers and client accounts.
  - Exemption under para. (c): authorities indicated only one case in which an Art. 4 exemption was claimed; considered not very relevant in practice.
- Art. 10 DDA (“simplified CDD”) — substance:
  - Language goes beyond establishing simplified CDD procedures.
  - Persons subject to the law are exempted from:
    - carrying out identification and verification measures on the contracting party and beneficial owners,
    - establishing a risk profile,
    - monitoring the business relationship in accordance with Art. 5 (1) of the DDA.
  - Art. 10 effectively sets out a blanket exemption for application of CDD measures for listed cases and is treated as a scope limitation for parts of the DDA.
  - Exception: a person subject to the law under Art. 10 must apply full CDD measures in case of suspicion of ML, a predicate offense, organized crime or FT, or in cases involving a higher risk pursuant to Art. 11 of the DDA.
  - Assessors questioned the practical likelihood that a person subject to the law could form a grounded suspicion or identify high risk situations in absence of any CDD information.
- Origins of exemptions:
  - Authorities indicated Arts. 4 and 10 exemptions were taken over from relevant EU Directives rather than defined on basis of a national or sector-specific risk assessment.
  - Authorities’ position: based on Liechtenstein’s size, more efficient to adopt findings of an EU-wide risk assessment rather than carry out an isolated Liechtenstein risk assessment.
  - Assessors’ view: important that Liechtenstein reviews and, if necessary, custom tailors any potential scope limitations in light of specific features of Liechtenstein’s financial service industry; simply adopting supranational findings does not seem in line with the FATF standard.
  - Art. 10 omission relative to EU Directive: ignores the safeguard that FIs and DNFBPs must first gather sufficient information about a potential customer to establish whether exemptions for CDD apply; under the Directive all customers are subject to a certain minimum CDD process.

### Risk-based framework and indicators (paras. 400–403)
- Risk-related requirements (DDA, DDO, FMA Guideline 2013/1):
  - Persons subject to law must:
    - establish a risk-based business profile for each customer,
    - categorize each customer and transaction as low, medium, or high risk,
    - monitor each business relationship and transaction based on the risks involved.
  - Risk-based elements apply to identification and verification measures for beneficial owners.
  - FMA-nominated auditors in onsite inspections must determine whether risk assessments conducted by FI/DNFBP are appropriate.
    - FMA indicated few instances of inappropriate risk assessment but room for improvement in auditors’ experience.
- Mandatory high-risk cases per DDA:
  - Non-face-to-face customers,
  - PEPs,
  - Cross-border correspondent banking relationships and business relationships,
  - Transactions with contracting parties or beneficial owners in high-risk countries,
  - Transactions involving complex structures,
  - Complex and unusual transactions,
  - Transactions without any apparent or visible lawful purpose.
- Art. 23 DDO — higher risk scenario identification factors:
  - registered office or place of residence of contracting party or beneficial owner, or their nationality;
  - contracting party’s or beneficial owner’s business activity;
  - nature of the products or services requested;
  - level and type of assets deposited;
  - level of inflows and outflows of assets;
  - country of origin or destination of payments;
  - whether contracting party or beneficial owner is a PEP.
- FMA guideline minimum categories for risk analysis:
  - “countries,” “customers,” and “products/services.” Further categories encouraged.
- Risk indicators categorization:
  - “general indicators,” “cash indicators,” “bank accounts and custody accounts,” “fiduciary accounts,” “insurance transactions,” and “terrorist financing.”
  - Some indicators are phrased in very specific terms; examples of specificity:
    - Foreign asset management vehicles or companies with nominee shareholder or bearer shares are not per se listed as high risk indicators, but only where a legal entity is not entered in the public registry and no certification or other document of probative value of its existence can be obtained.
    - Private banking relationships are not listed as high risk indicators.
- CDD requirements compared to international standard:
  - FMA stated basic CDD under Art. 5 of the DDA goes beyond international standard for “normal risk scenarios.”
  - Example: FATF would require source of wealth and source of funds only for customers and beneficial owners identified as PEPs; DDA requires such information for all contracting parties and beneficial owners.
  - Result: Minimum CDD procedures applied to all parties amount to “enhanced due diligence measures.”
- Country risk lists:
  - FMA Communication 1/2012 provides list of countries subject to Directive 2005/60/EC or considered to have AML/CFT measures equivalent to Directive.
  - Annex 2 of the DDO lists countries Liechtenstein considers to have high risk of ML/FT or strategic deficiencies: the list includes 15 countries.
  - Authorities stated list revised every time FATF issues a public statement; last revision took place in February 2013.
- Use of risk indicators in practice:
  - Private sector participants seemed aware of and relied on country risk indicators.
  - Other risk indicators in Annex 2 DDO less frequently used because they target very specific situations and are only marginally helpful for establishing broad risk categories.
  - Assessors’ view: Liechtenstein’s higher-risk business necessitates formulation of highly practical and more broadly defined risk indicators to aid consistency and understanding across industry.

### Customer Due Diligence challenges and sector characteristics (paras. 404–408)
- Legal framework revisions and context:
  - Relevant laws: Due Diligence Act (DDA) and Due Diligence Ordinance (DDO).
  - DDA and DDO revised since 2007; last revision in February 2013 (latest round related mostly to penal and administrative sanctioning powers; earlier revisions aimed to address 2007 assessment recommendations and implement Third EU Directive, Commission Directive 2006 on definition of PEP and technical criteria for simplified CDD and occasional/very limited activity exemption).
  - DDA and DDO provide comprehensive identification/verification measures, record keeping, suspicious transaction reporting, and internal control obligations.
- Financial system characteristics:
  - Banking sector dominates Liechtenstein’s financial landscape; asset management companies, investment undertakings and life insurance businesses are active but their total share of assets under management is less than the share held by the banking sector individually.
- Client introduction dynamics (trustees and TCSPs):
  - Significant part of banking business introduced by trustees or trust and company service providers or persons with a certificate under Art. 180a PGR (referred to as TCSPs) situated in Liechtenstein or other countries.
  - Typical scenario:
    - Customer of an FI (contracting party) is a natural or legal person often introduced by a lawyer, trustee, or other TCSP.
    - For legal persons or arrangements (foundation, company, anstalt, or trust) these structures often form part of a broader legal structure set up in different jurisdictions and typically set up by a trustee or TCSP who also acts as director or administrator.
    - Trustee generally represents the legal structure, opens bank account in name of trust or foundation (the “contracting party”), and obtains information regarding the beneficial owner.
  - CDD implications:
    - FI very seldom meets beneficial owner and relies on trustee for information.
    - Trustee may provide only a declaration of who is beneficial owner (Art. 6(1)(a) DDO) without detailing how the Liechtenstein foundation fits into larger corporate structure.
    - This can prevent the FI from truly understanding the customer relationship and potential risks.
    - Partial mitigation exists when TCSP is a Liechtenstein entity subject to DDA, but does not apply to foreign TCSPs or to situations where TCSPs rely on business introduced by foreign TCSPs.
    - Domestic TCSPs are not subject to a full prudential regulatory regime and therefore not subject to a fit and proper test.
    - This issue has grave implications for effectiveness of R.5 and cascades through implementation of other preventive measures.

*Source: cr18257 - 393. Liechtenstein has previously prescribed the scope of the DDA based on a two-pronged test.*

### 409. Art. 13 of the DDA sets out a prohibition for persons subject to the law to keep passbooks,

### cr18257 - 409. Art. 13 of the DDA sets out a prohibition for persons subject to the law to keep passbooks,

### Passbooks, bearer instruments, and observed trends
- Art. 13 of the DDA prohibits persons subject to the law from keeping passbooks, accounts, or custody accounts that are anonymous or issued in bearer form, or that are issued in a fictitious name.
- Authorities reported bearer passbook counts and deposit amounts:
  - 398 bearer passbook still existed as of 2011, with a total amount of approximately CHF 8 million of deposits.
  - The authorities indicate that the average amount per passbook is CHF 20,424.
  - Historical comparisons provided by the authorities:
    - 789 passbooks with CHF 19 million in 2007.
    - 2,098 passbooks with CHF 45 million in deposits in 2002.
- Operational vulnerability: when a bearer presents a passbook, the FI may have no insight into the history of physical transfer of the passbook; only interaction occurs when the prevailing bearer presents it.

### FI procedures for bearer passbook outflows
- Where the balance exceeds CHF 25,000, the FI is expected to identify and verify the identity of the bearer and the beneficial owner before transferring the assets.
- Interviewed FIs stated their policy is to perform due diligence when a passbook is presented, regardless of the balance.
- FI practice includes inquiring with the bearer as to the history of the passbook.

### Numbered accounts: legal status and implementation
- The law does not address or prohibit numbered accounts.
- Authorities indicated numbered accounts still exist; in practice these accounts:
  - Are treated like any other account and are thus subject to all customer due diligence (CDD) measures.
  - Often are not “numbered accounts” in the traditional sense: the file is maintained under a number and access to the full CDD information is limited to certain employees (including compliance) and, as warranted, authorities and auditors.
- Assessors could not obtain estimate data points on the quantity or aggregate value of numbered accounts.
- Auditors and authorities have access to underlying due diligence information and documentation associated with numbered accounts when performing inspections.

### When CDD is required (Art. 5 (2) of the DDA) (c. 5.2)
- CDD must be carried out whenever a person subject to the law:
  - Establishes a business relationship. “Business relationship” (Art. 2) extends to any “business, professional or commercial relationship which is connected with the professional activities” and which is “expected, at the time when the contract is established, to have an element of duration;”
  - Carries out an occasional transaction amounting to 15,000 Swiss francs (approximately US$16,000 or 12,000 euros) or more, whether the transaction is carried out in a single or several operations that appear to be linked. “Occasional transaction” (Art. 2) is any “cash transaction, especially money exchange, cash subscription of medium-term notes and bonds, cash buying or selling of bearer securities, and cashing of checks, unless the transaction is carried out via an existing account or custody account;”
  - Where there are doubts about the veracity or adequacy of previously obtained data on the identity of the contracting party or the beneficial owner;
  - Where there is a suspicion of ML, a predicate offense, organized crime, or FT, regardless of any derogations, exemptions or threshold.
- Regulation (EC) No 1781/2006 (directly applicable in Liechtenstein) requires FIs to undertake CDD measures when carrying out occasional transactions that are wire transfers.

### Limitations and assessors’ observations on CDD scope
- Assessors noted the obligation to carry out CDD on occasional transactions under the DDA is limited to cash transactions and is thus narrower than the FATF standard, which encompasses all types of occasional transaction.
- In practice, given Liechtenstein’s financial landscape, this limitation seems materially irrelevant because it is difficult to imagine occasional transactions that can be carried out without using cash in the DDA definition. However, the DDA could exclude certain transactions such as those carried out with prepaid credit cards or purchases via personal check or credit card from Art. 5 (2) coverage.

### FI on-boarding and ongoing due diligence practices (implementation)
- FI on-boarding processes generally include identification and verification of the customer and beneficial owner, and collection of documentation at relationship establishment.
- Relationship managers typically manage customer relationships and facilitate interactions; customers often are represented by professionals (e.g., TCSP, lawyers).
- Some FIs accept nonresidents only if referred from existing customers, business relationships, trustees, or lawyers.
- FIs reported in-person contact with customers at relationship establishment; relationship managers often have at least one in-person contact per year, with more frequent non-face-to-face interactions.
- Industry practice relies on relationship managers for maintaining up-to-date due diligence; assessors noted a potential vulnerability if institutions do not adopt a sufficiently broad view of what information might change over time and when re-performance of due diligence is required.
- If new or updated due diligence information is required during transaction investigations, institutions would approach the customer to obtain it.

### Identification measures and verification sources (c. 5.3)
- Art. 6 of the DDA requires identification of the contracting party and verification by means of documents with probative value; measures must be repeated if doubts arise.
- Arts. 6–10 of the DDO specify information to obtain for natural and legal persons and list documents considered to have “probative value.” Art. 6 applies to both permanent and occasional customers.
- For natural persons (Arts. 6 and 7 of the DDO), required information: full name, date of birth, address of residence, and nationality; verification must be based on a valid official identification document with a photograph (passport, driver’s license, or identity card). The document must entitle the contracting party to enter the Principality of Liechtenstein at the time of identification and verification to be considered “valid.”
- For legal persons (Arts. 6 and 8 of the DDO), required information: name or company name, legal form, address of domicile, date of formation, date and place of incorporation, and names of the bodies or trustees formally acting on behalf of the legal entity.
- Verification for legal entities registered in a public register must be based on:
  - An extract from the public register issued by the public register authority; or
  - A written extract from a database maintained by the public register authority; or
  - A written extract from a trustworthy privately maintained directory or equivalent database.
- For legal entities not entered in a public register, verification may rely on:
  - An official certificate issued in Liechtenstein; the statutes, formation documents or formation agreement; a certification by an appointed auditor to the annual accounts; an official license to conduct its activities; or a written extract from a trustworthy privately maintained directory or equivalent database.
- All documents used for verification must be provided as originals or certified copies. Copies may be certified by specified categories (persons subject to the law or affiliates/branches; a foreign FI, lawyer, trustee, auditor, or asset manager subject to the EU Directive or equivalent and supervised; or a notary public).
- Persons subject to the law must make a copy of the document used to verify identity, confirm inspection of original or certified copy on the copy, sign and date the copy, and include it in the contracting party’s due diligence file.
- Certificates of authenticity, register extracts and confirmations by appointed auditors used for verification purposes cannot be older than 12 months.

### Implementation observations on identification and verification
- For natural persons, FIs obtain required information and verify via photographic identification documents and sometimes utility bills; expired passport copies are required to be replaced.
- Verification processes vary across institutions; many rely heavily on relationship managers and referrals from lawyers and TCSP.
- For legal persons (companies, trusts, foundations), FIs obtain required identification information; verification commonly includes extracts from public registers for Liechtenstein entities or organic documents (articles of incorporation, foreign public registry extracts) for foreign entities. Documentation practices vary across institutions.

### Identification of legal persons or other arrangements (c. 5.4)
- Art. 6 (2) of the DDO requires verification that any person purporting to act on behalf of a legal person is authorized to do so and verification of that person’s identity based on documents with probative value or signature authenticity confirmation per Art. 9 of the DDO.
- “Legal entity” (Art. 2 of the DDA) includes any “legal person, company, trust or other collective or asset entity, irrespective of its legal form,” thus encompassing legal arrangements.
- Where a natural person acts as trustee of a legal arrangement, no specific provision mandates obtaining trust deed, letter of wishes, or provisions regulating binding decision-making powers; authorities stated these documents would be required as part of the obligation to identify the beneficial owner when applicable.
- Implementation: FIs typically verify good standing and authority to act by obtaining public registry excerpts and, depending on the entity and risk, may obtain board resolutions, articles of incorporation, power of attorney, or other organic documents. Practices vary across the industry.

### Identification of beneficial owners (c. 5.5, 5.5.1, 5.5.2)
- Art. 7 of the DDA requires persons subject to the law to identify the beneficial owner and, based on risk, take adequate measures to verify the identity of the beneficial owner. For legal entities, this includes taking adequate measures to determine ownership and control structure.
- Identification and verification measures must be repeated whenever there are doubts about the identity of the beneficial owner.
- Authorities indicated “risk-based measures” means measures should be reasonable and proportionate to the risks involved; waiving verification based on low risk is not permitted—the minimum requirement is to obtain a signature of the contracting party as to who the beneficial owner is in all cases. Higher risk requires additional verification measures.
- Definition of “beneficial owner” (Art. 2 of the DDA) aligns with FATF: a natural person on whose initiative or in whose interest a transaction or activity is ultimately carried out or a business relationship is ultimately constituted; for legal entities, the natural person who ultimately owns or controls the legal entity. The term “legal person” includes legal arrangements.
- Art. 3 of the DDO specifies for corporations and companies without legal personality the beneficial owner includes any natural person who:
  - directly or indirectly hold or control shares or voting rights of 25 percent or more of a corporation or company;
  - receive 25 percent or more of the profits of such corporations or companies;
  - otherwise exercises control over the management of such legal entities.
- “Control” under Art. 3 includes the ability to:
  - dispose of the assets of the legal entity;
  - amend the provisions governing the nature of the legal entity;
  - amend the beneficiaries;
  - influence the exercise of any of the named control powers.

*Source: cr18257 - 409. Art. 13 of the DDA sets out a prohibition for persons subject to the law to keep passbooks,*

### 437. For foundations, trusts, and establishments, the term shall include named beneficiaries of

### cr18257 - 437. For foundations, trusts, and establishments, the term shall include named beneficiaries of

### Definition of beneficial owner and related legal provisions
- For foundations, trusts, and establishments, the term shall include named beneficiaries of 25 percent of the assets or more, or in case where no individual persons have been named beneficiaries, those natural persons in whose interest the legal entity was mainly established, and any natural person who ultimately exercises direct or indirect control over the assets of the legal entity.
- The definition of “beneficial owner” as set out in the DDA and DDO does not include the settlor unless the settlor is granted express power to influence the exercise of control.
- Good practice: extend CDD requirements to include the settlor explicitly, as the settlor may exercise influence in practice. The FATF Methodology provides that identification of the settlor of a trust is amongst the measures to satisfactorily identify the beneficial owner.
- Art. 11 of the DDO specifies obligations under Art. 7 of the DDA: persons subject to the law must collect and document required beneficial ownership information and have accuracy confirmed through signature by the contracting party or an authorized person. Exceptions to the signature requirements exist for collective accounts, deposits or policies.
- For legal entities with no beneficial owner, the person subject to the law shall obtain a statement from the contracting party confirming this situation and providing information on:
  - the effective depositor,
  - the persons authorized to issue instructions to the contracting party or its bodies,
  - the persons eligible as beneficiaries.
- The same provision applies to NPOs.
- The assessors note that the FATF standard requires explicit legislative treatment of whether a customer is acting on behalf of another person; Liechtenstein’s law implies this via required data collection but would be improved by explicit statutory wording.

### Identification and verification practices (current implementation)
- No express statutory requirement under the DDA or DDO to determine whether a customer is acting on behalf of another person; authorities rely on implied obligations to collect name, date of birth, address of residence, and nationality of the beneficial owner and to have the contracting party verify by signature.
- FIs interviewed reported:
  - Rare or no instances of a natural person opening an account in their own name while acting for an undisclosed third party.
  - Participation in account activities by anyone other than identified and authorized persons raises suspicion and instigates review (example: payment of an insurance premium by someone other than the policy holder).
- For contracting parties that are legal persons or arrangements, persons subject to the law must take risk-based and adequate measures to determine ownership and control structure.
- FIs generally rely on documents demonstrating authority of the representative (e.g., excerpt from public registry) which often:
  - Do not identify the beneficial owner.
  - Do not reveal legal structures or layers between representative and beneficial owner.
- Means of identifying and verifying beneficial owner varied:
  - Some FIs accept a declaration of beneficial ownership signed by the customer.
  - Some obtain a copy of the beneficial owner’s valid passport.
  - Additional documents (articles of formation, deed, by-laws) are collected only in very specific and infrequent cases, usually when higher risk is perceived.
- TCSPs report that FIs generally accept signed declarations from intermediaries and seldom request further documents; some TCSPs would refuse to provide deeds or by-laws if requested.
- Assessors’ synthesis:
  - Provision, certification, and verification of beneficial ownership information are generally entirely reliant on information provided by the party representing the customer (often a TCSP).
  - In many circumstances the only evidence connecting a beneficial owner to a customer that is a legal person or arrangement is a self-certified declaration by the intermediary.

### Information on origin, purpose, and intended nature of business relationship (c. 5.6)
- Art. 8 of the DDA requires persons subject to the law to establish a profile for each business relationship that includes information on the origin of the assets and the purpose and intended nature of the business relationship.
- Implementation as described by FIs:
  - Customer onboarding includes obtaining information on origin of funds, reason for establishing relationship, and purpose and intended nature of relationship.
  - For legal entities and arrangements, this information is provided by the representative of the customer.
  - Verification practices vary: internet searches, requests for additional documentation when information cannot be confirmed, and requests for supporting documentation in higher-risk cases (e.g., description of business activities, employment background).
- Risk assessment criteria used by FIs include:
  - Jurisdiction of domicile and nationality.
  - Complexity of customers that are legal entities or arrangements (some FIs define complex structures as those involving more than two jurisdictions or more than one layer).
  - Jurisdictional risk factors such as a country’s corruption index rating and countries on the FATF noncompliant list published by the FMA.
- Vulnerability identified:
  - Reliance on unsubstantiated information provided by intermediaries creates a serious vulnerability.
  - FIs often lack verifiable information necessary to effectively assess risk, including understanding layers of legal entities and the relationship between beneficial owner and customer.
  - Guidance highlights “complex structures” as an indicator of risk, but FIs cannot determine complexity without a broad view of organs and layers of legal entities and arrangements.

### Ongoing due diligence on business relationships (c. 5.7, 5.7.1, 5.7.2)
- Art. 8 of the DDA and Arts. 20 and 28 of the DDO require updated profiles for each business relationship including:
  - contracting party and beneficial owner,
  - authorized agents and bodies authorized to act,
  - economic background and origin of assets deposited,
  - profession and business activity of the effective depositor,
  - intended use of assets.
- Art. 9 of the DDA and Art. 21 of the DDO require transaction monitoring based on risks and that monitoring be carried out using state-of-the-art computerized systems as far as possible.
- Implementation described by FIs:
  - Transaction monitoring combines automated and human review.
  - Customers receive a risk rating tied to transaction parameters and thresholds; deviations trigger investigations of varying depth based on risk profile, value, and deviation magnitude.
  - Internal procedures vary widely: some institutions process lower-risk deviations and investigate later; others freeze transactions over certain thresholds until justification and approvals are provided (possibly requiring compliance department, relationship manager, and executive-level approval).
  - Relationship managers often personally accept transaction instructions and compare them to customer profiles; such transactions are also monitored automatically.
- Requirement gap:
  - Art. 8 (2) DDA requires updated profiles but does not explicitly require periodic reviews of existing records, particularly for higher-risk customers. The FMA Guideline 2013/1 addresses risk-based reviews but is not enforceable statute and thus cannot be relied upon for FATF compliance.
- Practice vulnerabilities:
  - Updating CDD for “existing” or “legacy” customers is uneven; institutions obtain updates on an ad hoc basis when relationship managers are made aware of changes.
  - For legal entities/arrangements, FIs rely on customer notification of changes.
  - Few FIs have set schedules for periodic review of CDD information and documentation.
  - Some institutions “favor” annual personal contact by relationship managers, others have no such policy.
  - Assessors recommend scheduled periodic profile reviews to augment ad hoc frameworks.
  - Certain FIs reported as much as five percent of their customers fall into the category of legacy customers with outdated due diligence information—a concern assessors highlight.

### Risk—Enhanced due diligence for higher-risk customers (c. 5.8)
- Art. 11 of the DDA requires persons subject to the law to:
  - establish high risk criteria,
  - categorize business relationships and transactions according to these criteria,
  - apply more intensive monitoring and other measures to high-risk relationships.
- Art. 23 of the DDA specifies that “other measures” shall include:
  - further verification of identities of contracting parties and beneficial owners,
  - clarification of the origin of assets deposited,
  - clarification of intended use of assets withdrawn,
  - clarification of professional and business activity of the contracting party and beneficial owner.
- Business relationships/transactions mandatorily to be classified as high risk:
  - those established non-face-to-face,
  - those involving PEPs,
  - cross-border correspondent banking relationships,
  - business relationships and transactions with contracting parties or beneficial owners in high risk countries,
  - those involving complex structures,
  - complex and unusual transactions,
  - transactions without any apparent or visible lawful purpose.
- In all other cases (including nonresident customers and private banking relationships), it is within the FI/DNFBPs discretion to determine the risk and apply enhanced measures.
- Art. 11 of the DDA sets out specific enhanced due diligence requirements for categories related to Recommendations 6, 7, and 8.

*Source: cr18257 - 437. For foundations, trusts, and establishments, the term shall include named beneficiaries of (excerpt).*

### 469. Art. 23 of the DDO further elaborates on the requirements under the DDA by setting out a list

### cr18257 - 469. Art. 23 of the DDO further elaborates on the requirements under the DDA by setting out a list

### Risk indicators and Art. 23 / Annex II of the DDO
- Art. 23 of the DDO sets out a list of criteria for classifying a business relationship or transaction as high risk, including:
  - geographic location or nationality of contracting parties or beneficial owners;
  - types of products and services requested;
  - amount of assets deposited or transferred;
  - country of origin or destination of payments.
- A comprehensive list of red flag indicators for potential ML or FT risks is set out in the annex to the DDO.
- Observed limitations:
  - Private sector participants relied on country risk indicators but used Annex II indicators less frequently because they cover only very specific situations and are not helpful for broadly setting up risk categories.
  - Given Liechtenstein’s higher risk private banking and asset management business involving legal entities and structures, more practical and broadly defined risk indicators are deemed crucial to ensure even the slightest indication of risk triggers a review of customer categorization and encourages consistent FI approaches.

### Implementation of risk categorization by Financial Institutions (FIs)
- FIs stated they have policies to assess customer risk and apply enhanced measures for higher risk customers.
- Only some FIs described having an internal institution risk assessment to identify FI-level exposure and tailor customer risk categorization.
- Factors used by FIs to determine higher risk include:
  - implication of higher risk jurisdictions;
  - complexity of customer structure;
  - asset turnover;
  - business type for legal entities.
- Typical descriptions of higher risk customers: implicating high risk jurisdictions, operating in industries considered higher risk (e.g. natural resources), or having complex structures (e.g. multiple layers and jurisdictions).

### Enhanced due diligence (EDD) and monitoring practices
- EDD procedures vary across institutions and situations.
  - FIs may request additional documentation in higher risk instances; the specific information varies by customer type, business, jurisdiction, etc.
  - Monitoring under EDD includes heightened scrutiny of transactions according to narrower parameters, may involve management approval, and at some institutions includes more frequent customer profile reviews.
- Transaction approvals for high risk customers:
  - Some institutions require management (and possibly compliance) approval in every instance.
  - Other institutions allow transactions under a lower threshold without such approvals.
- Politically exposed persons (PEPs):
  - FIs treat PEP customers as high risk and apply EDD procedures.
  - FIs generally do not establish relationships without contact with the customer.
  - FIs stated they do not offer cross-border FIs outside Liechtenstein.

### Simplified/Reduced CDD Measures (Art. 10 of the DDA) — scope and statutory exemptions
- Art. 10 prescribes cases where persons subject to the law are exempted from applying identification and verification measures, establishing a business profile, or monitoring transactions/business relationships under Art. 5 (1) (a)–(c), when:
  - The contracting party is a stock-listed company whose shares are publicly traded and is not acting in the interest of a third party;
  - The contracting party is a domestic authority;
  - The contracting party is itself subject to CDD obligations under the third EU Directive or an equivalent regulation, is supervised and is not acting in the interest of a third party;
  - In the case of a life insurance premium which has an annual premium of CHF 1,000 or less, or a single premium of CHF 2,500 or less;
  - In the case of a life insurance policy for a pension scheme that does not have a surrender clause and cannot be used as a collateral;
  - In the case of insurances for old age provision benefits where the contributions are deducted by the employer and the beneficiary rights are not transferable;
  - A rental deposit account for rental property located in an EEA member state or Switzerland is established and the deposit is CHF 15,000 or less;
  - E-money is spent or managed through use of a device that is not rechargeable and the amount stored is CHF 150 or less; or that is rechargeable, and the total limit on annual spending is CHF 2,500 or less;
  - Where the contractual relationship is an exclusive asset management mandated with a limited power of attorney for an individual bank account or custody account that is kept with a bank that is subject to the third EU Directive or equivalent regulation and is supervised;
  - Transactions constitute external statutory or other auditing for a legal entity that is already monitored by a person subject to the law.
- Additional exemptions:
  - Certain persons subject to the law (banks, insurance companies, exchange offices, insurance brokers, e-money institutions and other PSPs) are exempt from identifying and verifying beneficial owners where the contracting party is a notary, lawyer, or legal agent of an EEA Member State or Switzerland who keeps an account or custody account for his client within the scope of a forensic activity or as an executor, escrow agent, or similar capacity.
  - Identification and verification measures do not apply where the contracting party was previously identified by the same undertaking group or conglomerate; however, copies of original identification documents must be enclosed in the customer file maintained in Liechtenstein.

### Concerns about simplified measures and compliance with FATF standards
- Observations on legal transposition and FATF alignment:
  - Some important safeguards in the EU Directive provisions pertaining to simplified CDD have not been transposed in the DDA.
  - The FATF 40+9 Recommendations allow limited reduced or simplified CDD but do not permit blanket exemptions from the majority of key CDD elements as set out under Art. 10 of the DDA.
- Practical concerns:
  - Removal of the obligation for institutions to undertake ongoing monitoring of accounts could affect the ability to identify unusual or suspicious transactions.
  - The exemption may apply even where there are doubts about the veracity or adequacy of identifying information for the customer or beneficial owner.
- Recommendation-like observation:
  - While adopting findings of EU-wide or Swiss risk assessments may be efficient given Liechtenstein’s size, Liechtenstein should review and, if necessary, customize simplified requirements under its AML/CFT framework to reflect features of Liechtenstein’s financial services industry rather than automatically adopting other assessments.

### Implementation of simplified measures by FIs and asset management firms
- General FI practices:
  - FIs reported availing themselves of simplified due diligence measures in the DDA/DDO.
  - Although DDA’s simplified measures constitute an exemption from due diligence (not aligned with FATF), FIs reported that their simplified measures include identifying and verifying the contracting party but not the beneficial owner.
  - Representatives stated they perform ongoing monitoring of accounts subject to simplified measures, in accordance with obligations.
  - Some FIs claimed a basic standard of due diligence on all customers and do not subject any customers to simplified measures.
- Asset management firms:
  - Some described their entire business as qualifying for simplified measures, identifying customers and creating profiles but not identifying or verifying beneficial owners; they described ongoing monitoring that includes criteria for suspicions triggering investigation and documentation by relationship managers.
  - Firms generally aware that simplified measures are prohibited for higher risk clients; however, many firms stated they would usually not know if a customer’s risk profile increased to high risk, risking inappropriate continued use of simplified measures.
  - Procedures to ensure relationships do not become higher risk varied:
    - Some firms rely completely on the customer (who may not be the beneficial owner).
    - Some require annual contact by a firm representative to check for changes.
  - There is no legal requirement that FIs or intermediaries notify one another of changes in underlying customer information.
  - Firms engaging in activities subject to full due diligence described measures to identify/verify customers and beneficial owners, maintain customer profiles, and monitor transactions; nevertheless, usual lack of knowledge about an increase to high risk remains a vulnerability.

### Simplified CDD for overseas residents (c. 5.10)
- Statutory provision:
  - Simplified CDD can be applied to nonresident customers only where AML/CFT measures in line with or equivalent to the third EU Directive are applied and the contracting party is not acting on behalf of a third party.
  - Exemption is broader where customer identification/verification was already carried out by another member of the financial group; in such cases, the foreign institution’s CDD must be carried out “in an equivalent manner,” seemingly leaving the FI discretion to determine equivalence.
- Implementation observations:
  - FIs interviewed did not describe simplified measures as applying to customers situated in countries not compliant with FATF standards.
  - Asset managers that do not identify beneficial owners may effectively apply simplified measures to overseas customers.
  - Some FIs employ the exemption from identifying/verifying beneficial owners where the contracting party is a notary, lawyer, or legal agent of an EEA member state or Switzerland who keeps an account or custody account for his client in forensic, executor, escrow, or similar capacities.

### Prohibition of simplified CDD in high-risk or suspicious scenarios (c. 5.11)
- Art. 10 clarifies that simplified measures may never be applied:
  - in cases of occasional transactions under Art. 5 (2)(d) when enhanced CDD under Art. 11 applies;
  - where there is suspicion of ML or FT; or
  - if there is a high risk scenario under Art. 11.
- FI practice:
  - FIs stated they do not apply simplified due diligence where there is suspicion of ML or FT or other high risk scenarios.
  - FIs monitor transactions in accordance with due diligence obligations; reviews from transaction monitoring or other sources could trigger investigations and reassessment of customer risk.
  - Ongoing monitoring is often primarily software-based, and FIs did not note instances where transaction monitoring led to a reassessment of risk.

### Risk-based approach guidance and FI application (c. 5.12)
- FMA issued guidance on a risk-based approach to CDD, instructing FIs on establishing risk categories and carrying out risk-based monitoring and ongoing due diligence.
- Observed FI practices:
  - FIs described due diligence policies sensitive to risk; many apply exhaustive due diligence to all customers and enhanced measures for higher risk customers as determined by their customer risk assessment.
  - Only some institutions described internal policies for undertaking an institution-wide risk assessment of all business relationships and transactions, as suggested by the guidance.
- Guidance reiterations:
  - FIs are obligated to undertake risk assessments of their customers.
  - Enhanced due diligence must be taken in higher risk cases, simplified measures in lower risk cases, and normal measures otherwise.
  - Simplified measures cannot be applied in high risk scenarios.
  - The FATF list, FMA advisories, and UN and EU sanctions must be considered when assessing country risk.
  - Higher country risk may arise where credible sources indicate considerable corruption or support for terrorist activity or where terrorist organizations operate.

### Timing of verification of identity (c. 5.13, 5.14)
- General rule:
  - Art. 5 of the DDA and Art. 18 of the DDO require that all identification and verification information for the contracting party and beneficial owner be obtained at the time the business relationship is initiated or the occasional transaction is carried out.
  - If due diligence requirements cannot be met, the person subject to the law may not establish the business relationship or carry out the transaction and must determine whether filing an STR is necessary.
  - If identification/verification measures are being applied due to suspicion of ML or FT, or doubts about previously obtained CDD information, the person subject to the law must terminate the existing relationship, document the outflow of assets, and, if necessary, file an STR.
- FI practice:
  - FIs stated policies generally require identification and verification of the customer and beneficial owner at relationship initiation.
  - Deficiencies in understanding legal entity/arrangement structures can negatively affect compliance with timing requirements.
- Exceptional circumstances (Art. 18 (2) of the DDO):
  - CDD information and documentation may be made available after establishment of a business relationship if necessary to maintain normal business.
  - In such cases, the person subject to the law must ensure that no outflows of funds take place until identification/verification has been completed.

*Source: cr18257 - 469. Art. 23 of the DDO further elaborates on the requirements under the DDA by setting out a list*

### 494. Art. 18 (2) is more permissive than the FATF standard, which allows for verification to be

### cr18257 - 494. Art. 18 (2) is more permissive than the FATF standard, which allows for verification to be

### Verification timing and CDD requirements (Art. 18 (2) and FATF comparison)
- Art. 18 (2) of the DDO allows for any information and documents, including identification information, to be obtained after a business relationship has been established.
- The FATF standard permits delayed verification only under specific circumstances; Art. 18 (2) is more permissive than that standard in allowing post-establishment collection of CDD information.
- Art. 18 (2) is more restrictive than the FATF standard in that it:
  - Does not leave discretion to persons subject to the law to permit use of a business relationship prior to verification.
  - Prohibits in all cases the outflow from such accounts prior to verification.
- The measure targets risks associated with the “integration” phase of ML but not the “placing” phase.
- Recommendation for full FATF compliance:
  - The DDA and DDO should limit the possibility to delay certain CDD measures to situations where it can be assured that the delayed measures are carried out as soon as reasonably practicable.
  - All aspects of the ML risks must be effectively managed when delays are permitted.

### Financial institutions’ policies and operational practices
- FIs reported policies that:
  - Allow establishment of a relationship only after all due diligence information is obtained, but before verification documentation is submitted.
  - Permit an account to be funded, with funds frozen until necessary verification information is obtained and due diligence is completed.
  - Require verification and completion of due diligence “immediately after the account is opened.”
- Criterion noted: 15.14.1
- There is no legal requirement for FIs to adopt risk management procedures specifying conditions under which a customer may utilize a business relationship prior to verification.

### Completion of CDD relative to business commencement (criteria c. 5.15, c. 5.16)
- Reference: See criterion 13 above; Liechtenstein law is in technical compliance with the FATF standard on this point.
- FIs stated policies prohibiting establishment of relationships without necessary due diligence information.
- FIs have filed suspicious activity reports when suspicions arose related to attempts to establish relationships, generally linked to suspicious circumstances rather than mere refusal to provide information.
- Industry practice is to maintain up-to-date customer due diligence information; some institutions exit relationships due to lack of information.
- Concern: institutions continue to maintain legacy accounts with outdated and/or insufficient due diligence information.

### Existing customers—transitional provisions and requirements (c. 5.17)
- Art. 39 of the DDA (transitional provisions) applies to business relationships existing at entry into force of the Act.
  - Art. 39 (3) requires persons subject to the law to investigate and examine existing business relationships that give rise to suspicions of ML, FT, organized crime, or predicate offenses.
  - Art. 39 (6) requires persons subject to the law to designate high risk customers and relationships within one year of the entry into force of the DDA, and to take additional measures under Art. 11(2), including repetition of certain CDD measures.
- Legal gap: The law does not require CDD to be carried out on existing customers at appropriate times and on the basis of materiality.

### Implementation concerns: legacy customers and proactive collection
- Some FIs maintain “legacy customers” established before enactment of the DDA without adequate and updated due diligence information.
- Some institutions have terminated relationships for due diligence issues, yet legacy accounts persist without adequate customer information—this is a concern.
- Current obligation/practice places onus on the customer to provide necessary due diligence information when approaching the FI, rather than proactive collection by the FI.
- Potential root causes: supervisory shortcomings, implementation weaknesses, or industry attitudes.
- Recommendation: Authorities should address this issue via guidance and supervisory practices.

### Existing anonymous/fictitious-name account customers (c. 5.18)
- Under Art. 39 of the DDA (entered into force in 2004):
  - Existing contractual relationships relating to anonymous passbooks, accounts, or custody accounts issued on bearer or in a fictitious name must be dissolved immediately or as soon as possible.
  - Outflow of funds from such instruments is permitted only in the context of dissolution.
  - If the instrument balance exceeds CHF 25,000, full identification and verification measures must be applied before the deposit can be withdrawn.
  - If the balance is below CHF 25,000, the balance may be withdrawn without having to identify the beneficial owner.
- Assessors’ observation: The threshold of CHF 25,000 is rather high, especially since a customer may hold multiple passbooks, etc.

### Effectiveness of the due diligence framework—systemic risks and implementation gaps
- Financial sector characteristics:
  - Dominated by high risk activities and customers.
  - Majority of services relate to private banking.
  - Customer base involves nonresidents, complex legal structures, and customers introduced by foreign and domestic intermediaries.
  - Business culture highly values confidentiality and relies heavily on trust between FIs and intermediaries.
- Private sector familiarity:
  - Representatives generally knowledgeable of legal obligations and AML/CFT concepts.
- Key effectiveness weaknesses observed:
  - Failure to consistently treat activities/customers identified by FATF and BCBS as higher risk as such by authorities or FIs.
  - General lack of exhaustive customer profiles based on reliable and up-to-date information and documentation.
    - Reliance on information provided by intermediaries.
    - Legacy accounts may lack reliable or valid information.
  - Institutional policies often fall short of creating a complete view of the relationship:
    - Insufficient insight into how the immediate legal entity fits into a broader legal structure.
    - Insufficient understanding of the broader business purpose and relationship to the beneficial owner.
  - Beneficial owner identification and verification practices:
    - Policies described to identify and sometimes verify beneficial owners rarely confirmed identity and relation with reliable documentation.
  - Uneven implementation of due diligence across FIs:
    - Some FIs have thorough policies; others merely transpose minimum legal requirements without tailoring to institution-specific risks.
  - Relationship characteristics between TCSPs and between TCSPs and FIs adversely affect effectiveness (see paras. 378 and 379).
  - Weak risk assessments by some FIs despite high risks, and risk assessments not always targeted to particular business risks.
  - Lack of sufficiently comprehensive understanding of business relationships hampers effective ongoing monitoring.
- Overall assessment: Combination of high risk activities/customers, prevalent use of professional intermediaries who both represent clients and are relied upon by FIs for CDD, calls into question the effectiveness of the due diligence framework in Liechtenstein.

### Politically Exposed Persons (PEPs) — summary of changes and implementation (R.6)
- 2007 weaknesses: Lack of requirement for enhanced CDD for business involving PEPs, including lack of requirement for senior management approval and to establish source of wealth for PEPs.
- DDA revisions addressed most, but not all, deficiencies. Notably:
  - No express requirement to establish the source of wealth of PEPs.

Key legal provisions and definitions:
- Art. 11 (4) of the DDA:
  - Business relationships and transactions involving PEPs must in all cases be considered high risk and subject to more intensive monitoring.
  - Persons subject to the law must have adequate, risk-based procedures to determine whether a contracting party or beneficial owner is a PEP.
- Art. 2 (1) (h) of the DDA defines “politically exposed person” (PEP) to cover natural persons who are or have been (for the period of one year, beginning the day the person exits the public function) entrusted with prominent public functions in a foreign country and immediate family members of persons known to be close associates of such persons.
- DDO definitions of “prominent public functions,” “immediate family members,” and “close associate” specify positions and relationships included.
- Difference from FATF standard:
  - FATF covers persons “who are or have been entrusted with public functions” without a time limit.
  - Liechtenstein applies a one-year time limit but applies enhanced monitoring to former PEPs where they present higher risk beyond one year.

Implementation by FIs:
- Identification and treatment:
  - FIs include identification of foreign PEPs in due diligence and treat identified PEPs as high risk with enhanced due diligence.
  - FIs maintain accounts for PEPs.
- Identification processes:
  - On-boarding questions to customers, consultation with commercial databases, independent public internet searches.
  - Heavy reliance on commercial databases; assessors note over-reliance may be problematic and create vulnerability.
- Risk management (Art. 11 (4)(b)):
  - Obligation to obtain approval of at least one general manager before establishing or continuing a business relationship with a PEP.
  - Annual approval by one general manager required to continue such relationships.
  - FIs report processes aligning with these obligations.
- Source of wealth/funds:
  - Art. 8 (1) of the DDA requires persons subject to the law to obtain information about the origin of assets for all business relationships.
  - Art. 20 (1)(c) of the DDO requires establishing the economic background of the contracting party and origins of deposited assets; DDA requirements are more extensive and require source of wealth for all customers.
  - FIs report policies to understand source of funds of PEP customers, generally relying on customer-provided information and augmenting with internet and commercial database searches.
- Ongoing monitoring:
  - FIs apply enhanced monitoring for PEPs, including lower or zero transaction thresholds requiring justification, documentation, and manager/compliance approvals.
  - Some FIs perform internet and database searches more frequently to detect negative news or changes in PEP status.
- Domestic PEPs:
  - Liechtenstein does not extend measures to domestic PEPs; FIs do not consider PEPs to include individuals holding prominent public functions domestically.
  - Some FIs were aware of the change in the international standard.
- Merida Convention:
  - Liechtenstein signed (2003) and ratified (2010) the Merida Convention.

Effectiveness considerations for PEP regimes:
- FIs knowledgeable about PEP risks and describe processes to mitigate those risks.
- Effectiveness potentially undermined by:
  - Over-reliance on commercial databases and the internet.
  - Infrequent reviews to identify changes in a relationship’s PEP status.
- Recommended enhancements:
  - Augment identification programs with additional research performed periodically to minimize risk of an unidentified PEP relationship.

*Source: cr18257 - 494. Art. 18 (2) is more permissive than the FATF standard, which allows for verification to be*

### 526. Art. 11 (5) of the DDA and Art. 16 of the DDO limits the application of cross-border

### 526. Art. 11 (5) of the DDA and Art. 16 of the DDO limits the application of cross-border

### Scope and Legal Requirements
- Art. 11 (5) of the DDA and Art. 16 of the DDO limit the application of cross-border correspondent banking relationships to respondent institutions in non-EEA countries; other types of correspondent relationships (e.g., those related to securities or funds transactions) are not covered by these provisions.
- Art. 11 (5)(a) prescribes that cross-border banking relationships are in all cases to be considered as high risk and thus subject to more intense monitoring.
- Persons subject to the law entering into cross-border correspondent banking relationships are required to:
  - obtain sufficient information about the respondent institution to understand the nature of that institution’s business;
  - determine from publicly available sources the reputation of the institution and the quality of supervision that it is subject to.
- Art.16 (2) of the DDO clarifies that obtaining information on reputation includes determining whether the respondent institution has been investigated or been subject to supervisory measures for ML or FT.

### Implementation: Correspondent Relationships in Practice
- FIs interviewed hold correspondent accounts with financial institutions outside Liechtenstein, but do not offer cross-border correspondent accounts to foreign FIs.
- FIs generally do not offer domestic correspondent accounts.
- Authorities believe Liechtenstein to host only respondent institutions.

### Assessment of AML/CFT Controls in Respondent Institutions (c. 7.2)
- Art. 11 (5)(b) DDA obliges persons subject to the law to assess the respondent institutions AML/CFT controls before entering into a cross-border banking relationship.
- There is not a specific requirement to ascertain that such controls be adequate and effective.
- Implementation note: FIs interviewed generally stated they are only respondent institutions, with correspondent accounts outside of Liechtenstein.

### Approval of Establishing Correspondent Relationships (c. 7.3)
- Art. 11 (5)(c) requires persons subject to the law to obtain approval from at least one general manager before a new cross-border correspondent banking relationship may be established.
- Implementation note: FIs stated their policy includes a process for establishing a correspondent relationship, which includes approval of the board of the institution.

### Documentation of AML/CFT Responsibilities (c. 7.4)
- Art. 11 (5)(d) requires the respective responsibilities with respect to the fulfillment of CDD requirements to be documented by the correspondent and respondent institution.
- Implementation note: FIs described the relationship as governed by a contract delineating responsibilities of each institution.

### Payable-Through Accounts (c. 7.5)
- Art. 16 (1) of the DDO requires that where payable through accounts are involved, correspondent institutions in Liechtenstein must satisfy themselves that the respondent institution in another country has:
  - verified the identity of all persons with direct access to that account;
  - continuously monitors these persons; and
  - is in a position to submit the relevant information to the correspondent institution in Liechtenstein upon request.
- Effective implementation: Recommendation generally applies to FIs interviewed insofar as they are respondent institutions; representatives described policies in line with the DDA/DDO and the FATF standard and were aware of the higher-risk nature of correspondent banking activity.

### New Technologies and Non-Face-to-Face Transactions (R8)
- Background:
  - Liechtenstein’s PC rating in 2007 was based on lack of comprehensive requirement to prevent misuse of new technologies and to address risks in non-face-to-face transactions and business relationships.
  - More stringent measures now in place for non-face-to-face business relationships, but provisions on new technologies can be further improved.
- Misuse of New Technology for ML/FT (c. 8.1):
  - Art. 9(2) of the DDA: obligation to pay special attention to threats from the use of new technologies.
  - FATF standard: requires FIs to have in place policies or measures to prevent use of technological developments for ML/FT (a broader obligation than Art. 9(2) currently imposes).
  - E-money: institutions that provide e-money services are governed by the E-Money Act and supervised by the FMA.
- Implementation (technology):
  - Internet banking is the most advanced new technology offered by the FIs interviewed and is offered by very few institutions.
  - Internet banking described as providing account information and a means of communicating transaction instructions; institutions asserted new relationships cannot be established via the internet.
  - Transactions initiated through the internet are given the same review and scrutiny as other channels and often include review by the relationship manager and applicable due diligence processes.
  - One FI offers an internet banking platform tailored to smart phones with capabilities and policies the same as standard internet banking.
  - E-money industry in Liechtenstein is very small, with one entity engaged in such services; rules and industry size result in low associated risk.
- Risk of Non-Face-to-Face Business Relationships (c. 8.2 and 8.2.1):
  - Art. 11(1) in combination with Art. 11(3) of the DDA: business relationships where the contracting party is not personally present for identification are in all cases to be considered high risk, subject to more intense monitoring, and require additional identification measures.
  - Art. 6(3) of the DDO: where a business relationship is established by correspondence, identification and verification must be based on original documents with probative value or certified copies, and the CDD information must be signed by the contracting party.
  - Once a non-face-to-face business relationship is established, Art. 11(1) requires enhanced monitoring.
  - No provisions require FIs to implement policies and procedures to address risks associated with non-face-to-face transactions (as opposed to business relationships) as part of ongoing due diligence.
- Implementation (non-face-to-face):
  - FIs generally noted they do not establish relationships with customers who are not present in person; internet banking does not allow establishment of new relationships.
  - One FI establishes relationships without personal contact in very narrow circumstances and obtains necessary due diligence information.
  - Customers generally initiate transactions by means other than in-person (e.g., via phone); FIs described processes for processing, verifying, and monitoring transactions.
- Effective implementation assessment:
  - Limitation of new technologies to internet banking, limited offering by a few FIs, and very limited services lead to assessment that current landscape regarding new technologies is not particularly high risk.
  - Authorities should remain cognizant that FIs might broaden technologically advanced products and must understand and mitigate associated risks.
  - Intermediated arrangements where intermediaries with pre-existing relationships can establish new accounts on behalf of different customers without in-person contact could pose additional risk.

### Recommendations and Comments (selected)
- Formulate more practical and broadly defined risk indicators to:
  - ensure even the slightest indication of risk results in review of categorization for a customer, business relationship, or service;
  - promote better understanding among industry of what “risk” is;
  - assist in applying more consistent approach by FIs to defining risk categories.
- Revise Art. 5(2)(b) of the DDA to require application of CDD measures also to occasional transactions that are not cash transactions.
- For natural person customers, introduce an express legal obligation for FIs to determine in all cases whether a customer is acting on behalf of another person and take reasonable steps to obtain sufficient identification data to verify that other person.
- Strengthen verification measures for legal persons and incorporate methods suggested in the General Guide to Account Opening and Customer Identification.
- Amend Art. 11 of the DDO to require verification measures for beneficial owners be based on relevant data and information obtained from reliable sources.
- Revise Art. 8(2) of the DDA to impose an obligation to carry out reviews of existing records as part of ongoing CDD.
- Remove blanket exemption for CDD under Art. 10 of the DDA; permit simplified CDD only in proven low risk cases and require minimum CDD in all cases.
- For foreign customers, allow simplified CDD only where Liechtenstein is satisfied that the country in which the customer is located complies with and effectively implements the FATF standard.
- Art. 18(2) should allow only verification, not identification, measures to be delayed and limit delayed verification to situations where timely completion is assured and ML risks are managed.
- Eliminate the threshold of CHF 25,000 for identification of existing anonymous or bearer passbooks, accounts, or custody accounts.
- For PEPs or beneficial owners that are PEPs, consider aligning DDA and DDO to set an express obligation for FIs to establish source of wealth in all cases.
- Extend Art. 11(5) of the DDA and Art. 16 of the DDO to correspondent relationships with respondent institutions in other EEA member states.
- Amend Art. 11(5)(b) of the DDA to require FIs to ensure respondent institutions’ AML/CFT controls are adequate and effective before entering relationships.
- Revise Art. 9(2) of the DDA to require FIs to have policies or measures to prevent use of technological developments for ML/FT.
- Require provisions for FIs to implement policies and procedures addressing risks associated with non-face-to-face transactions as part of ongoing due diligence.
- Consider revising beneficial owner definitions under Art. 2 of the DDA and Art. 3 of the DDO to expressly cover the settlor of trusts.
- The FMA should compel Liechtenstein FIs to increase due diligence focus on beneficial owners, including verification measures.
- Ensure FIs develop more thorough customer profiles based on reliable information and documentation and understand legal entity customer structures and relationships to beneficial owners.
- Clarify information and documentation necessary to understand relationships among legal entity customers, intermediaries, and beneficial owners, particularly for foreign parties.
- Ensure FIs can compel relevant due diligence documentation from customers represented by intermediaries.
- Consider requiring periodic reviews of CDD information based on risk rather than ad hoc review procedures.
- Consider requiring compliance function within an FI to take an active role in customer on-boarding and transaction monitoring and require compliance and management approval according to risk.
- Require FIs applying simplified due diligence to obtain beneficial ownership information, client structure information, and conduct periodic customer reviews.
- Require FIs to undertake internal institution risk assessments of all customer relationships and transactions on a periodic basis to inform internal policies.
- Require FIs to proactively apply complete CDD on legacy customers.

### Compliance with Recommendations 5–8 (summary)
- R.5: PC. Key deficiencies:
  - Verification measures for beneficial owners not required to be based on reliable sources; verification for legal persons not always required to be based on reliable sources.
  - No obligation to carry out reviews of existing records as part of ongoing CDD, including for higher-risk categories.
  - Blanket exemptions for CDD under Art. 10 of the DDA are not permissible under the FATF standard.
  - Art. 18(2) allows delayed identification measures too broadly without requirement to carry out delayed measures as soon as reasonably practicable.
  - No express requirement to apply CDD measures to all existing customers at appropriate times, resulting in legacy accounts with incomplete CDD.
  - High threshold of CHF 25,000 for identification of existing anonymous or bearer passbooks, accounts, or custody accounts.
  - CDD obligation for occasional transactions only extends to cash transactions.
- R.6: LC. Effectiveness issues:
  - General reliance on commercial databases for identification of PEPs, sometimes with infrequent reviews and minimal other means.
- R.7: LC. Issues:
  - Provisions on cross-border correspondent banking do not apply for respondent institutions in other EEA member states.
  - No requirement for Liechtenstein correspondent institutions to ensure respondent institutions’ AML/CFT controls are adequate and effective.
- R.8: LC. Issues:
  - No express obligation for persons subject to the law to have policies or measures to prevent use of technological developments for ML/FT.
  - No provisions requiring FIs to implement policies and procedures addressing risks associated with non-face-to-face transactions as part of ongoing due diligence.

### Effective Implementation Issues (selected)
- Inconsistent application of due diligence measures across FIs, with limited access to CDD information and documentation held by TCSPs, including information necessary to understand the customer and beneficial owner(s).
- Due diligence measures fall short of enhanced due diligence required for higher-risk categories, including issues related to verification.
- Lack of emphasis on understanding the nature and purpose of the relationship, including understanding related legal structures and relationships to beneficial owners.
- Risk indicators issued to assist FIs in defining risk categories are not seen as practical.

*Source: cr18257 - 526. Art. 11 (5) of the DDA and Art. 16 of the DDO limits the application of cross-border*

### 548. Art. 14 of the DDA and Art. 24 of the DDO regulate the delegation of CDD obligations.

### 548. Art. 14 of the DDA and Art. 24 of the DDO regulate the delegation of CDD obligations

### Scope and conditions for delegation (Arts. 14 DDA; 24 DDO)
- Art. 14 of the DDA permits the delegation of certain due diligence measures (identification and verification for the contracting party and beneficial owner, and establishment of a business profile) by a person subject to the law, provided the delegate is:
  - a person subject to due diligence under Liechtenstein law; or
  - a natural or legal person abroad that is subject to the third EU Directive and is supervised; or
  - a natural or legal person abroad that is subject to an regulation equivalent to those contained in the third EU Directive, and is supervised.
- Delegation requirements and restrictions:
  - The delegation has to be documented, and sub-delegation by delegates is not permitted (para. 549).
  - Agent relationships are expressly exempted from the scope of Art. 14 based on para. (4), which states that Art. 14 does not apply to outsourcing or representation arrangements in which the outsourcing service provider or representative is to be regarded as part of the person subject to the law (para. 550).
  - Art. 24 of the DDO requires that where identification/verification or business profile measures are carried out by a delegate, the person relying on the delegate must ensure the delegate obtains or prepares all documents and information required under the DDA and transfers them without delay to the person in Liechtenstein relying on the delegate; information on the identity of the delegate must be included (para. 551).
  - Art. 24(b) requires the delegate to confirm with his signature that any copies of identification and verification documents match the originals or certified copies, and that the contracting party has provided a signature verifying the identification and verification information for the beneficial owner (para. 551).

### Consistency with FATF standards and practical application
- Art. 24 of the DDO is consistent with the FATF standard in that para. (a) imposes a requirement on the person subject to the law to obtain from the delegate in all cases both the information and the documentation required under the DDA, including copies of identification data and other relevant documentation pertaining to CDD (para. 552).
- Practical observations and implementation risks:
  - Business relationships introduced by foreign TCSPs, lawyers, and other intermediaries are generally handled as the foreign intermediary being the contracting party and their client as the main beneficial owner; the foreign TCSP is identified and verifies beneficial owner information with signature (para. 558).
  - Under the DDA, no other verification measures have to be taken in relation to the client of the foreign intermediary for the purpose of the foreign TCSP’s business relationship with its client; the foreign law determines how much information the foreign trustee must obtain, verify, and keep (para. 558).
  - Financial institutions must ensure information provided by the intermediary is sufficient to fulfill the applicable CDD requirements under the DDA (para. 558).
  - Such de facto intermediated relationships can mean specific rules governing intermediated relationships are not applied and parties lack clear grounds to compel information necessary to understand the customer and assess customer risk; nonetheless, FIs are not permitted to establish a business relationship where CDD requirements may not be complied with (para. 559).
  - The DDA permits foreign FIs to serve as delegates if they are subject to AML/CFT requirements under the third directive or are from a country determined by EU member states to have an equivalent AML/CFT regime; this creates risk because the assumption that a foreign delegate meets FATF Recommendations 5 and 10 solely based on EU Directive subjectivity or EU equivalency list is not sufficient (para. 560).

### Regulation and supervision of third parties (R. 23, 24, and 29)
- Art. 14(3) of the DDA assigns the FMA responsibility to issue a list of countries considered to have AML/CFT regimes in place equivalent to those under the Third EU Directive; the FMA has relied on a Common Understanding Between Member States on Third Country Equivalence (para. 553).
- As of February 2012, the FMA listed 12 countries outside the EU as countries with AML/CFT measures equivalent to those under the Third EU Directive: Australia, Brazil, Hong Kong, India, Japan, Canada, Mexico, Switzerland, Singapore, South Africa, South Korea, and the USA. In addition, a number of crown dependencies and overseas territories of various EU member states as well as countries that are part of the EU membership of France and the Kingdom of the Netherlands are listed (para. 553).
- Language difference with FATF standard:
  - Art. 14 of the DDA refers to “countries that are subject to” the Third EU Directive, whereas the FATF standard requires that FIs/DNFBPs satisfy themselves that the third party “has measures in place to comply with” requirements under FATF Recommendations 5 and 10. The difference matters because EU Directives must be transposed into national law and being “subject to” a Directive does not ensure full compliance with the Directive (para. 554).
- Adequacy of application:
  - The FMA Communication’s enumerated countries correspond to the common understanding of EU member states on third country equivalence plus the member states of the EU/EEA and French and Dutch overseas territories and U.K. Crown Dependencies; the list was drawn up by EU member states based on information on whether those countries adequately apply the FATF Recommendations and Methodology (para. 555).
  - However, the authorities’ determination was not based on an assessment as to whether that foreign country adequately applies the FATF Recommendations (para. 556).

### Responsibility and enforcement
- Ultimate responsibility for CDD:
  - Art. 14(2) of the DDA expressly stipulates that in case of a delegation, the ultimate responsibility for compliance with the CDD obligations under the law remains with the person subject to the law. Authorities stated that if both intermediary and person relying on the intermediary are based in Liechtenstein and are persons subject to the law, the obligation would be on both parties (para. 557).
- Documentation and non-permitted sub-delegation:
  - Delegations must be documented and sub-delegation is prohibited; authorities expect domestic FIs to reflect this prohibition in contracts with foreign intermediaries (para. 549).
- Effective implementation concerns:
  - The application of Art. 14 is not common in practice, limiting confirmation of supervisory views with FIs (para. 549).
  - The assumption that a foreign delegate meets required criteria solely because their country is “subject to” the EU Directive or appears on the EU equivalency list is insufficient; Liechtenstein should take additional verification measures (para. 560).

### Recommendations and compliance outcome
- Recommendations (para. 4.7.2):
  - Liechtenstein should take a more independent approach to determining from which countries intermediaries may be for purposes of introduced business and reliance on the introducers CDD measures.
  - The authorities should conduct an assessment of the supervisory framework and of the CDD measures in place in the concerned countries where the third parties are located and limit the location of third parties to those countries that have a satisfactory supervisory framework and CDD measures.
- Compliance with Recommendation 9:
  - Rating Summary: R.9 LC
  - Factor underlying rating: Presumption that all EU and EEA countries adequately apply the FATF Recommendations (para. 4.7.3).

### Financial institution secrecy and information access (R.4) — selected points
- Historical context and legal amendments:
  - In 2007 Liechtenstein was rated LC on Recommendation 4 due to reliance on case law to override statutory secrecy and limitations on prosecution access to confidential information; in 2009 the DDA revisions allowed exchange of information including where secrecy provisions or fiscal interests are violated and imposed an obligation on the FMA to exchange information internationally, including where there is no reciprocity (para. 561).
- Secrecy provisions and supervisory access:
  - Secrecy provisions are enshrined in Art. 14 of the BA, Art. 44 of the ISA, Art. 21 of the AMA, Art. 25 of the UCITSG, Art. 18 of the EIA, Art. 5 of the PSL, Art. 4a of the IMA, and Art. 15 of the IUA (para. 564).
  - Secrecy provisions under the BA, ISA, UCITSG, EIA, PSA, and IMA require employees and governing bodies to keep secret all facts entrusted or accessible due to client business relations; failure may result in criminal responsibility; these provisions explicitly grant power to share confidential information with foreign supervisors (para. 565).
  - The provisions of the AMA and the IUA are slightly narrower and do not expressly override banking secrecy for cooperation with supervisory authorities; Art. 27h of the FMAA can take precedence over the AMA and IUA to allow the FMA to share otherwise confidential information with foreign supervisors in certain situations (para. 565, footnote 42).
- FMA, FIU, and LEA access to information:
  - Art. 28(4) of the DDA grants the FMA access to any information held by persons subject to the law needed to carry out its supervisory functions; FMA requests are issued as an order under the Administrative Proceedings law and are subject to appeal; failure to provide requested information may result in an administrative fine (para. 566).
  - Art. 4 of the FIU Act provides that the FIU shall obtain information necessary for its functions subject to legal provisions relating to the protection of secrecy; authorities asserted this does not prejudice FIU access in practice but there is no firm legal ground for that view (para. 567).
  - Authorities stated the FIU would have indirect access to confidential information through the FMA, but assessors noted doubts whether the FMA could seek information on behalf of the FIU using Art. 28(1)(c) absent clear supervisory purpose; practical examples confirming such use were not provided (para. 568).
- Domestic information sharing:
  - Art. 36 of the DDA requires domestic competent authorities (courts, Office of the Public Prosecutor, FMA, FIU, National Police, and other authorities responsible for combating ML, FT, or organized crime) to provide all information and transmit all records to each other necessary for enforcement of the DDA; Art. 6 of the FIU Act empowers the FIU to cooperate and exchange information and documents with other competent domestic authorities (para. 570).
  - Uncertainty remains whether the FMA can share information subject to confidentiality with domestic counterparts because sector-specific laws permit sharing only with other supervisory authorities or if more specific legal provisions allow it; Art. 31a(1) of the BA subjects the FMA to official secrecy but Art. 31a(2) allows sharing if more specific legal provisions permit (para. 571).

*IMF assessment excerpt (paragraphs 548–571) from the provided PDF content.*

### 572. Since Art. 36 of the DDA does not specifically override the secrecy provisions in the BA,

### cr18257 - 572. Since Art. 36 of the DDA does not specifically override the secrecy provisions in the BA,

### Conflict between DDA and sector-specific secrecy provisions
- There is a legal conflict because Art. 36 of the DDA does not specifically override secrecy provisions in the BA.
- Authorities expressed inconsistent views on whether the DDA or sector-specific laws are lex specialis:
  - In some meetings the FMA indicated the DDA would be the more specific law for domestic exchange of confidential information for combating ML or FT (e.g., FMA permitted under Art. 31a(2) to exchange confidential banking information with other domestic authorities).
  - In other meetings it was stated that sector-specific laws constitute the more specific provisions, so the FMA would be prohibited from sharing confidential banking information under the general secrecy provision Art. 31a(1) of the BA.
- The Supreme Administrative Court (in an appeals decision) expressed the nonbinding view that the DDA is lex specialis over the Law on Trustees and Law on Lawyers, and that DDA provisions allowing the FMA to compel confidential information from trustees and lawyers prevail — this view:
  - Is nonbinding (the Court of Justice is competent to rule on possible violations of secrecy provisions).
  - Is limited to relations between the DDA and the Law on Trustees and the Law on Lawyers.
  - Does not, however, extend the FMA’s power to obtain information for the purpose of sharing it with domestic authorities; scope remains limited to fulfillment of the FMA’s supervisory function.
- The decision does not provide a ground for the FMA to share information domestically with regard to other sector-specific laws that contain specific confidentiality requirements.
- Recommendation: authorities should clarify that sector-specific laws do not limit the FMA’s power to share confidential information with other domestic authorities competent in AML/CFT to avoid legal challenges.

### Practical incidence and sensitivity
- The FMA stated that, in practice, it never encountered a case where the FIU or any other competent authority requested it to share confidential information; the issue appears mostly legal rather than practical.
- Given the sensitivity of secrecy provisions in Liechtenstein and to avoid legal challenges, the law should expressly override confidentiality provisions under sector-specific laws.

### Sharing of information with foreign competent authorities
- Both the DDA and sector-specific laws grant the FMA power to exchange information with foreign counterparts, including information covered by financial secrecy.
- Art. 37 of the DDA requires that, to share information, the foreign supervisor must be subject to the same secrecy provisions as contained in Art. 23 of the COPE — this may pose an obstacle to effective international exchange of confidential information.
- The FIU may share information with foreign counterparts based on Art. 7 of the FIU Act, but confidential information is expressly exempted from this power, creating ambiguity (see Recommendation 26).

### Sharing of information between financial institutions (FIs)
- Neither the DDA nor sector-specific laws set out an express power for FIs to share confidential information in situations required under Recommendations 7 and 9.
- Authorities stated that FIs, through their General Terms, advise contracting parties that customer data is provided to a third party when required under Liechtenstein law (i.e., the DDA). Given conflicting provisions and confidentiality concerns, it is unclear that confidential information could be shared as required under Recommendations 7 and 9.
- Wire transfers: EU Regulation 1781/2006 applies directly in Liechtenstein. Arts. 5(1) and 7(1) require provision of complete payer information (name, address, and account number) with wire transfers. For domestic or intra-EU transfers where complete payer information might not be supplied, Art. 6 requires that an institution make complete payer information available to the payment services provider of the payee on request within three days.

### Effective implementation and operational concerns
- Inconsistencies and lack of clarity in secrecy provisions pose challenges and may inhibit effective implementation of FATF recommendations, especially given a culture of confidentiality observed among private sector stakeholders.
- In criminal cases, financial secrecy does not inhibit FATF Recommendations implementation (except auditors who benefit from legal privilege even if they do not represent clients in proceedings).
- Outside criminal cases:
  - The FMA has access to confidential information for all types of FIs and may share such information with foreign supervisors, though under unduly restrictive conditions.
  - Concerns remain about the FIU’s access to confidential information: Art. 4 of the FIU Act subjects the FIU’s power to obtain information relevant to its functions to “legal provisions relating to the protection of secrecy.”
  - Legal provisions are not clear on whether the FMA may share confidential information with other competent authorities (notably the FIU). At the time of the onsite visit this legal uncertainty had not had a negative practical impact because the FMA had never been requested to share confidential information.
- Orders issued by the FMA, including for access to confidential information, can be subject to a rather lengthy appeals process (see Recommendation 3), which could be a concern where timely access is essential.
- Implementation feedback from FIs:
  - Most FIs believe implementation and compliance with legal obligations is not inhibited by secrecy provisions.
  - Most reported they had never received requests from the FIU for confidential information; some stated they would not provide requested information to the FIU.

### Recommendations and Comments (4.8.2)
- Undertake a review of all secrecy provisions and harmonize them with AML/CFT-related requirements and responsibilities to avoid conflicts or ambiguities. Clarify that DDA overrides all secrecy provisions of sector-specific laws.
- Eliminate any reference to secrecy as a condition for obtaining information (Art. 4) and for the exchange of information with foreign FIUs (Art. 7).
- Clarify that secrecy provisions in sector-specific laws do not inhibit FIs’ ability to share confidential information with other FIs where required under FATF Recommendation 7 or 9 (e.g., where a Liechtenstein FI is a respondent institution or is relied upon by a foreign FI to carry out some CDD measures).
- Expressly grant the FMA the legal power to share otherwise confidential information domestically for AML/CFT purposes, either by amending sector-specific laws or by clarifying in the DDA that the FMA’s powers under Art. 36 supersede secrecy provisions in other laws.
- Remove the reference under Art. 37 of the DDA requiring the foreign supervisor to be subject to the same secrecy provisions as contained in Art. 23 of the COPE.
- Determine whether the lengthy appeals process for FMA orders to provide confidential information could constitute an obstacle to effective FATF Recommendations implementation and, if so, take measures to address this issue.

### Compliance with Recommendation 4 (4.8.3)
- R.4 rating: PC
- Summary of factors underlying rating:
  - Secrecy conditions under the FIU Act and restrictions on the FMA’s power to access and share confidential information domestically could limit the FIU’s ability to properly undertake its functions.
  - No measures to clarify that secrecy provisions in sector-specific laws do not inhibit FIs’ ability to share confidential information where required under FATF Recommendation 7 or 9.
  - The reference under Art. 37 of the DDA requiring the foreign supervisor to be subject to the same secrecy provisions as in Art. 23 of the COPE for the FMA to exchange confidential information is too restrictive.

### Record Keeping and Wire Transfer Rules (R.10 and SR.VII)
- Record keeping legal framework: Due Diligence Act; Person and Company Act (PGR).
- Art. 20 of the DDA sets a general record keeping obligation; Art. 27 of the DDO prescribes the obligation in greater detail; Art. 28 of the DDO sets out detailed requirements for how records are to be kept.
- Requirements:
  - All documents and records are to be maintained in Liechtenstein, match the document on which they are based, be accessible and available at all times, and be renderable readable at any time and in a speedy manner (Art. 28 DDO).
  - Transaction-related records, receipts, clarifications, and STRs must be maintained for a minimum of ten years from the conclusion of the transaction or from the preparing of the transaction (Art. 20 DDA).
- No specific mechanisms ensure records permit reconstruction of individual transactions; authorities state Arts. 1045 and 1046 of the PGR would ensure necessary components for reconstruction, but those provisions do not impose a requirement to ensure reconstruction of all individual transactions carried out by or on behalf of a client.
- Client identification data and business profile must be kept for a minimum of ten years from the end of the business relationship or from the occasional transaction (Art. 8 DDA). There is no specific legal obligation to keep business correspondence as required under the FATF standard.
- Neither the FMA nor the courts have an express power to extend record keeping beyond the statutory period under Art. 20 DDA; authorities consider FMA’s power implied in Art. 28 DDA. In practice, the FMA has never issued an order to maintain records beyond the statutory period. Prosecutor stated records would be seized under StPO where the record keeping period is about to expire.
- Implementation evidence:
  - FIs reported policies to maintain due diligence and transaction records for at least ten years; representatives noted information maintained would allow reconstruction of individual transactions.
  - Art. 28 DDO requires records to be kept so requests from competent domestic authorities can be fully met within a reasonable period of time; FIs stated information is stored physically or digitally and can be made available in a timely manner.
  - Assessors believe recordkeeping is effectively implemented in practice.

### Wire transfers (SR VII)
- History: In 2007 Liechtenstein implemented only few wire transfer requirements; EC Regulation 1781/2006 has since entered into force in Liechtenstein and comprehensively regulates wire transfers.
- Liechtenstein filed an application with the EFTA Surveillance Authority (ESA) for authorization to treat transfers between Switzerland and Liechtenstein as domestic under Regulation (EC) 1781/2006; ESA is still assessing the application. Due to technical restrictions and currency union, the FMA already accepts treating wire transfers to Switzerland as domestic wire transfers.
- Legal framework: Due Diligence Act; EC Regulation 1781/2006 of the European Parliament on Information on the Payer Accompanying Transfers of Funds (“The Regulation”).
- DDA and DDO provisions:
  - Art. 12 DDA requires PSPs to “provide sufficient information on the payer accompanying transfers to funds.” Art. 17 DDO provides that money transfers must be supplemented with the name, account number, and address of the payer; where no account number is available, an identification number linked to the client must be provided. Address may be replaced by date and place of birth, client number, or national identity number. Obligation applies regardless of threshold and equally to domestic and international transfers.
- EC Regulation:
  - Applies to transfers of funds, in any currency, sent or received by a PSP established in the EU (Art. 3).
  - Scope excludes certain transfers (credit/debit card, electronic money, telephone/digital/other IT devices, or transfers between two PSPs acting on their own behalf).
  - Art. 5 requires the payer’s PSP to ensure transfers are accompanied by complete payer information; Art. 4 defines “complete information” in principle as name, address, and account number. Address may be substituted with date and place of birth, customer identification number, or national identity number. Where no account number exists, PSP must substitute with a unique identifier traceable to the payer.

*Source: cr18257 - 572. Since Art. 36 of the DDA does not specifically override the secrecy provisions in the BA,*

### 602. Under Art. 5(2), before transferring the funds, the PSP has to verify the complete information

### 602. Under Art. 5(2), before transferring the funds, the PSP has to verify the complete information

### Legal requirements for originator and payer information
- Art. 5(2): Before transferring funds, the PSP must verify the complete information on the payer on the basis of documents, data, or information obtained from a reliable and independent source. Exemption: does not apply where the value of the transfer is less than 1,000 euros, unless the transaction is carried out in several smaller transactions that appear to be linked.
- Art. 5(3) of Regulation 1781/2006: For transfers from an account, verification may be deemed to have taken place if:
  - a. A payer’s identity has been verified in connection with the opening of the account and the information obtained by this verification has been stored in accordance with the obligations set out in Arts. 8(2) and 30(a) of the Third EU Money Laundering Directive;
  - b. The payer falls within the scope of Art. 9(6) of the Third EU Money Laundering Directive (i.e., customer who existed prior to implementation of the Directive’s provisions, but has been subject to verification on a risk-based approach).
- EC Regulation (Art. 7(1)/(2), 8, 9, 10, 11, 12, 13, 15(3)):
  - Art. 7(1): Transfers where the payer’s PSP is situated outside the EU must be accompanied by complete information on the payer (as defined in Art. 4). Transfers between EU member states are not considered cross-border for the Regulation.
  - Art. 7(2): For batch files from a single payer where the payee’s PSP is outside the EU, complete information need not be required for each individual transfer if the full information accompanies the batch and each individual transfer has an account number or unique identifier.
  - Art. 8: Payee’s PSP must have procedures to detect missing payer information (different rules depending on payer’s PSP inside vs outside the EU; batch-file specifics).
  - Art. 9/10: If information is incomplete, the recipient service provider should ask for the information or reject the payment; missing/incomplete information is a factor in assessing suspicion and reporting to the FIU.
  - Art. 11/12: Payee’s and intermediary PSPs must retain payer information with the transfer and make it available on request.
  - Art. 13: Intermediary PSPs inside the EU may use payment systems with technical limitations only under specified conditions and must provide all information received within three working days upon request (Art. 13(4)). Records of information received must be kept for five years (Art. 13(5)); payee’s PSP must also keep records for five years (Art. 11).
  - Art. 15(3): EU member states must appoint competent authorities to monitor compliance with the Regulation.

### Implementation by financial institutions (FIs) and payment service providers (PSPs)
- FIs interviewed:
  - Process wire transfers only on behalf of established customers and have access to customer information.
  - Include originator name, address, and account number, as well as receiver name and other information, in both domestic and cross-border transfers.
  - Wire processing programs will not allow transmittal of transfers lacking required information; this is required for screening purposes both at the Liechtenstein institution and at correspondent institutions.
- For transfers within the EU:
  - Only account number or unique identifier needs to accompany the transfer, provided full payer information can be provided within three working days of request from the payee’s PSP.
- For batch transfers from a single payer when payee’s PSP is outside the EU:
  - Full batch-level information suffices if each transfer includes an account number or unique identifier.

### Maintenance of originator information (“Travel Rule”) and technical limitations
- DDA/DDO:
  - Art. 17(3) and (4): PSPs receiving or processing a money transfer must ensure all originator information required under paras. (1) and (2) are provided together and retained with a money transfer when forwarded.
  - If originator information is missing or partial, payee’s PSP must reject the transfer or request complete originator information from the payer’s PSP.
- EC Regulation:
  - Art. 12: Intermediary PSP must ensure all information received on the payer is maintained with the transfer.
  - Art. 13(1)-(4): If intermediary PSP uses payment system with technical limitations, must inform payee’s PSP and make available all information received (complete or not) within three working days upon request; keep records for five years.
- Implementation note: FIs reported they do not offer correspondent accounts and therefore do not act as intermediary FIs; nonetheless their wire programs prevent transmission of transfers lacking required information.

### Risk-based procedures and handling of incomplete originator information
- Art. 8: Payee’s PSP must detect missing information depending on payer’s PSP location (EU vs outside EU) and batch-file scenarios.
- Art. 9: Recipient service provider should request information or reject payment if incomplete.
- Art. 10: Missing/incomplete payer information is a factor in assessing whether the transfer is suspicious and whether to report to the FIU.
- Art. 9(2): For payer PSPs who regularly fail to provide information, payee’s PSP should (after warnings and deadlines) consider rejecting all transfers; such termination should be reported.
- Implementation: FIs state policy prohibits processing wire transfers lacking necessary information; wire processing systems enforce this.

### Monitoring, record-keeping, and sanctions
- Monitoring:
  - Art. 15(3) of the Regulation: Member states must appoint competent authorities to monitor compliance; the FMA has an implied power to supervise implementation by persons subject to the law.
- Record-keeping requirements:
  - Art. 13(5) and Art. 11: Intermediary and payee’s PSPs must keep records of all information received for five years.
  - Art. 20 DDA: Client-related records and receipts must be kept for at least ten years from the ending of the business relationship or conclusion of the occasional transaction. Transaction-related records and receipts must be kept for at least ten years from the conclusion of the transaction or from their preparation.
- Sanctions:
  - Pursuant to Art. 31 of the DDA, the FMA may apply a sanction of up to CHF 100,000 for violations of Arts. 5–14 of EC Regulation 1781 (failure to collect, keep, verify, or transmit required information; breaches of record keeping or reporting duties). The FMA does not have sanctioning powers for breach of the DDA provisions relating to wire transfers (note distinction).

### Thresholds, exemptions, and special cases
- Exemption threshold in Art. 5(2): transfers less than 1,000 euros are exempt from full payer verification, unless several smaller linked transactions.
- DDA/DDO: All incoming wire transfers must be accompanied by complete originator information; otherwise they must be rejected by the Liechtenstein payment service provider. Relevant DDA/DDO provisions apply regardless of any thresholds, including outgoing cross-border transactions of less than EUR/USD 1000.
- Batch-file transfers: full batch information may substitute for individual transfer information where payee’s PSP is outside the EU and each transfer has account number/unique identifier.
- Intermediary PSPs with technical limitations must still make available information within three working days upon request.

### Effective implementation, deficiencies, and practical observations
- Assessors’ view: Program descriptions provided by FIs lead assessors to believe recommendation is being effectively implemented in practice.
- FIs’ practices:
  - Wire processing programs block transfers lacking required information.
  - Transaction parameters and monitoring are set according to customer risk assessment.
- Related findings elsewhere in the document:
  - Some institutions set internal thresholds for additional investigation (example threshold value provided: CHF 1 million).
  - Effective implementation of R.11 and related DDA provisions is undermined by deficiencies in (i) identification of unusual or complex transactions (criteria for “complex” often limited to high-risk jurisdictions or complex legal structures) and (ii) investigations into such transactions (type and quality of supporting documentation and involvement of compliance function).
  - No express obligation to keep business correspondence; gaps in ensuring transaction records permit reconstruction of individual transactions in all cases.

### Recommendations and required legal revisions
- Recommendation 10 (summary):
  - Revise the legal framework to also require the keeping of business correspondence;
  - Consider revising the legal framework to include an express power by the FMA or another competent authority to extend the record retention period;
  - Revise the legal framework to ensure that transaction records are detailed enough to permit the reconstruction of individual transactions in all cases.

### Ratings noted in this section
- R.10: LC (factors: No express obligation to keep business correspondence; No measures to ensure transaction records permit reconstruction of individual transactions in all cases)
- SR.VII: C

*Source: cr18257 - 602. Under Art. 5(2), before transferring the funds, the PSP has to verify the complete information*

### 639. For all transactions provided under Art. 11(6) DDA as described above, the background and

### cr18257 - 639. For all transactions provided under Art. 11(6) DDA as described above, the background and

### Implementation of Art. 11(6) DDA and recordkeeping
- For all transactions provided under Art. 11(6) DDA, the background and purpose must be clarified and recorded in writing, regardless of whether the transaction has an apparent economic or legal purpose or not.
- Records obtained pursuant to Art. 11(6) DDA are considered transaction-related records under Art. 20 of the DDA and must be maintained so that requests from competent authorities can be complied with within a reasonable period of time.
- FIs interviewed stated their monitoring procedures include criteria to flag transactions with no apparent economic or lawful purpose, regardless of the country implicated, and that similar investigation procedures would be employed as previously described.

### Ability to apply countermeasures for high-risk jurisdictions (c. 21.3)
- Art. 11(7) of the DDA grants the government of Liechtenstein the power to impose notification requirements for business relationships and transactions with contracting parties or beneficial owners from or in countries permanently included on the list of high risk jurisdictions.
- Apart from notification requirements, no other provisions grant the government or any authority in Liechtenstein the power to issue and enforce countermeasures in relation to transactions or business relationships involving high risk countries.
- Effective implementation note: FIs in Liechtenstein are heavily reliant on country lists (including the FATF list of countries not sufficiently applying the recommendations) to develop risk indicators and generally understand and utilize these lists.

### Recommendations (4.12.2)
Recommendation 11:
- Consider further clarifying what types of transactions might be considered “complex;”
- Consider requiring an FI’s compliance function to approve transactions requiring investigation or clarification;
- Consider requiring incoming transactions incongruent with the customer profile be frozen until investigated and cleared; and
- Consider requiring documenting all transactions and associated clarifications with the customer profile, or, if maintained in a separate system, referenced in the customer profile and immediately accessible.

Recommendation 21:
- Art. 11(6) of the DDA should be further revised to require enhanced CDD not only with respect to persons in but also to persons from high risk countries;
- Ensure that FIs understand the obligation to carry out enhanced CDD under Art. 11(6) of the DDA as mandatory; and
- Grant the government or any authority in Liechtenstein a broader power to issue and enforce countermeasures in relation to transactions or business relationships involving high risk countries.

### Compliance with Recommendations 11 and 21 (4.12.3)
- R.11: LC
  - Lack of clear guidance and criteria pertaining to complex transactions.
  - Issues of effectiveness.
- R.21: LC
  - Art. 11(6) of the DDA does not require enhanced CDD with respect to persons from (as opposed to in) high risk countries.
  - No sufficiently broad power to issue and enforce countermeasures in relation to transactions or business relationships involving high risk countries.

### Suspicious Transaction Reports and Other Reporting — context (R.13-14 and SR.IV)
- R.13 & SR.IV were rated PC in the 2007 MER.
- Since the last MER, measures were taken to increase reporting effectiveness, including granting the FIU the power to allow certain transactions to be carried out within the five-day freezing period which automatically applies upon submission of a SAR.

### Legal framework for STRs (4.13.1)
- Relevant instruments:
  - Law of December 11, 2008 on Professional Due Diligence to Combat Money Laundering, Organized Crime, and Terrorist Financing (DDA);
  - Ordinance of February 17, 2009 on Professional Due Diligence to Combat Money Laundering, Organized Crime, and Terrorist Financing (DDO);
  - Law of November 24, 2006 against Market Abuse in Trading of Financing Instruments (MAA);
  - Guideline for submitting reports to the FIU issued on April 1, 2013 (FIU Guideline).

### Requirement to make STRs on ML to FIU (c. 13.1 and IV.1)
- Where a suspicion of ML, a predicate offense of ML, organized crime, or FT exists, FIs are required to immediately report in writing to the FIU (Art. 17 of the DDA).
- The reporting requirement is a direct mandatory obligation and is based on a subjective test of suspicion. The objective test does not apply.
- Art. 17 appears broader than criterion 13.1 because it requires reporting suspicion of ML, a predicate offense, organized crime, and FT even where no funds are involved.
- The obligation to report under criterion 13.1 is met because all predicate offences required under the standards are covered.
- Art. 18(1) requires reporting entities to refrain from executing any transactions they know or suspect to be related to ML, predicate offenses, organized crime, or FT and to report to the FIU. If refraining is impossible or would frustrate pursuit, the entity must submit a report immediately after execution.
- Reporting entities may not terminate the business relationship when reporting conditions apply and must refrain from actions that might obstruct orders pursuant to Article 97a of the Criminal Code for a period not exceeding five days from FIU receipt of the SAR unless the FIU approves in writing before expiry or until an order from the responsible prosecution authority is served.

### STRs related to terrorism and attempted transactions (c. 13.2, c. 13.3, IV.1)
- Art. 17 requires reporting when suspicion of financing of terrorism and predicate offenses exists; terrorist acts and organizations are criminal acts and predicate offenses to ML in Liechtenstein.
- All suspicious transactions must be reported to the FIU irrespective of the amount involved.
- Art. 18, para. 1 and Art. 17 together appear to cover attempted transactions.
- The FIU Guideline states the obligation to report also exists if a business relationship has not yet been established or the transaction has not yet been executed, provided sufficient details of the prospective business relationship or transaction exist.

### Making ML and TF STRs regardless of tax matters (c. 13.4, c. IV.2) and reporting all criminal acts (c. 13.5)
- The reporting requirement contains no restrictions relating to tax matters.
- FIs are required to report to the FIU when a suspicion that any criminal activity which constitutes a predicate offense domestically exists.

### Effective implementation and reporting patterns
- All FIs interviewed were aware of their reporting obligation, but assessors were not convinced the level of understanding and implementation is sufficiently adequate given Liechtenstein’s risk profile (nonresident customers, private banking, legal persons/arrangements, nominee shareholders, bearer shares).
- Some FIs did not fully appreciate the extent of inherent risks; the nature of reports submitted by some institutions did not always reflect activities expected to raise suspicion.
- Main contributor of ML disclosures is the banking sector; average number of reports submitted by the banking sector every year is 122.
- Notable annual counts for SARs submitted by banks and other FIs:
  - Banks: 2008: 136; 2009: 116; 2010: 210; 2011: 126; 2012: 199; Jan.-Jun. 21, 2013: 68
  - Insurers: 2008: 9; 2009: 9; 2010: 14; 2011: 37; 2012: 28; Jan.-Jun. 21, 2013: 11
  - Insurance Mediators: 2008: 0; 2009: 0; 2010: 0; 2011: 0; 2012: 1; Jan.-Jun. 21, 2013: 0
  - Postal Service: 2008: N/A; 2009: N/A; 2010: N/A; 2011: N/A; 2012: N/A; Jan.-Jun. 21, 2013: 15
  - Investment undertakings: 2008: 0; 2009: 1; 2010: 1; 2011: 0; 2012: 0; Jan.-Jun. 21, 2013: 0
  - Asset Management Companies: 2008: 0; 2009: 0; 2010: 0; 2011: 1; 2012: 3; Jan.-Jun. 21, 2013: 0
- FIU view: level of reporting by each type of FI corresponds to market share; assessors note banks dominate the sector and therefore produce the most SARs.
- Potential deterrents to reporting:
  - Requirement for the FIU to disseminate the SAR itself to the OPP when it substantiates a suspicion could expose the identity of the reporting entity to law enforcement and potentially the suspect.
  - Not every bank’s understanding of their reporting obligation is sufficiently adequate.
- FIU classification of SARs indicates most FI-filed SARs arise from internal compliance procedures, which FIU interprets as effective implementation of CDD by FIs (assessors are not entirely convinced).
- Onsite findings: majority of suspicions triggering SARs were from negative information obtained via media or commercial intelligence databases rather than from scrutiny of transaction patterns or unusual activities.
  - Systems to flag transactions that deviate from customer business and risk profiles exist in all FIs, but alerts rarely resulted in SAR submission.
  - Insufficient information sometimes prevents meaningful business and risk profiles, reducing ability to detect suspicious transactions via ongoing monitoring.
  - Some FIs still assume suspicions require clear links to specific criminal activity.
- FIU actions to improve reporting:
  - Elevated a list of indicators from FMA guidance to an annex in the DDO, giving it force of law.
  - Issued the FIU Guideline on reporting in April 2013, providing practical guidance on reporting and emphasizing that reporting is not subject to special preconditions and that entities should not refrain from reporting simply because a clear link cannot be established.
  - Guideline contains explanations on identification of suspicions through ongoing monitoring and was subject to private sector consultation prior to issuance.
  - The FIU had not yet assessed the extent to which reports were submitted solely due to negative information; regular meetings with banks to discuss reporting issues had been initiated.

*Source: IMF assessment text (excerpts).*

### 666. Other important factors in the formulation of a suspicion are mentioned in the Guideline

### 666. Other important factors in the formulation of a suspicion are mentioned in the Guideline

### Formulation of suspicion and reporting obligations
- The Guideline ensures that FIs have access to clear and precise instructions on formulation of suspicions.
- Obligation to report arises even where the FI is not in a position to identify the specific predicate offense generating the assets.
- The obligation to report is triggered if there is an objective reason to assume the existence of a suspicion, even if the FI subjectively believes that the contracting party is not at fault.
- The obligation to report arises even if a business relationship has not yet been established or a transaction has not yet been executed.
- The Guideline provides a suggestion of the minimum information to be submitted to the FIU in such pre-relationship or pre-transaction situations.
- A brief description of what constitutes ML, FT, predicate offenses, and organized crime is included in the Guideline.

### Timing of SAR submission
- No general timeframe can be provided; each case must be decided on a case by case basis, but there must be no delays (e.g. due to the holiday absence of an employee).
- As a rule, reporting in the case of ongoing business relationships occurs right after the clarifications pursuant to Art. 9 of the DDA.
- As soon as a suspicion exists, the report must be submitted, even if special clarifications have not yet been concluded.
- FIs must design internal organization so the decision to report can be made immediately by the competent organ within the institution.
- The FIU reported that it had never come across cases where the submission of a SAR had been delayed by an FI.

### Freezing mechanism and its effects
- Following the submission of a SAR, FIs are not permitted to carry out any actions that might obstruct or interfere with any freezing orders issued in terms of Art. 97a of the Criminal Code for a period of five business days. This could potentially result in the customer’s account(s) being frozen for five business days.
- The automatic five-day freeze on filing a SAR was criticized in the Third Round Evaluation for potentially undermining the effectiveness of the reporting system and leading to tipping off.
- Assessors noted it is likely to increase the suspicion threshold as FIs may seek to avoid the burden of the freezing provision and only report where they have sufficient information indicating criminal activity.
- Art. 18(2) of the DDA was amended following the third evaluation to empower the FIU to approve a transaction before the expiry of the freezing period, to avoid alerting the reported customer.
- Despite the amendment, assessors retained concerns from the Third Round. FIs interviewed expressed a strong preference for removal of the mechanism, considering it unnecessarily complicating the reporting regime.

### FT reporting, case example, and FIU practice
- The FIU received five SARs on FT in the period under review.
- The FIU has never carried out a formal assessment to determine whether the volume of reporting is adequate in light of the risk of FT in Liechtenstein.
- Authorities consider the risk of FT to be minimal and the number of FT reports to be adequate, since none of the cases indicated that Liechtenstein played a role in FT.
- Sanitized FT case provided by the FIU:
  - A transfer of funds was made through a bank account in Liechtenstein by a Liechtenstein foundation whose nonresident beneficial owner was a sympathizer of an extremist group situated in an EU country.
  - Funds were transferred to a lawyer representing a member of the extremist group in court proceedings on a count of terrorism.
  - The beneficial owner’s and lawyer’s links to the terrorist group were identified by the bank through media reports, prompting submission of the SAR.
  - The funds transferred by the foundation were neither directly linked to a terrorist act nor to a terrorist group; nonetheless the bank submitted a SAR on suspicion of FT.
  - Following FIU analysis, the report was sent to the Public Prosecutor who forwarded the information to prosecutorial authorities in the EU country where the person was being prosecuted.
  - The accounts of the foundation in Liechtenstein are currently frozen pending the outcome of the case in the EU country.
- The FIU maintains statistics on the number of SARs received, including a breakdown by type of financial institution.

### Tipping-off and protection from civil and criminal liability (R.14)
- Art. 19 of the DDA protects persons subject to the law and their general managers or employees from any civil or criminal liability if they have reported a SAR to the FIU and it later turns out that the report was not justified, provided the person did not act willfully.
- During the onsite mission it was pointed out that Art. 19 is not entirely in line with c. 14.1, since c. 14.1 refers to exemption from liability when a report is submitted in good faith. The FIU explained that the German translation of “willfully” is more akin to the good faith principle; under the German text a reporting entity would not be held civilly or criminally liable unless the person knew the report was not warranted and acted in bad faith.
- Tipping-off prohibition:
  - Pursuant to Art. 18, para. 3 of the DDA, persons subject to the law may not inform the contracting party, beneficial owner or third party that they have submitted a SAR to the FIU pursuant to Art. 17 of the DDA.
  - This provision does not explicitly cover directors, officers, and employees (permanent or temporary) as required under c.14.2; authorities explained Art. 18, para. 3 is interpreted by practitioners to include directors, officers, and employees.
  - A court judgment confirmed interpretation: director of a trustee company was fined CHF 7,500 for disclosing to a third party that a SAR had been submitted to the FIU.
  - The prohibition only applies to the SAR and not to related information as required by Criterion 14.2.
- Exemptions and permitted disclosures:
  - The FMA may be informed by the reporting entity of the submission of a SAR.
  - Art. 18, para. 4 permits communication on SARs between specified groups of institutions and persons (a, b, c), provided conditions (e.g., subject to Directive 2005/60/EC or equivalent regulation, involvement in same fact pattern, equivalent obligations on professional secrecy and data protection) are met.
  - The FMA shall establish a list of countries with equivalent regulations.
- Confidentiality of FIU reporting staff:
  - Under Art. 10 of the FIU law the obligation to release information in accordance with the Public Information Act does not extend to the origin of the data and the recipients of transmissions.
  - Pursuant to Art. 5, para. lett. b), the FIU is required to submit a copy of the SAR to the Office of the Public Prosecutor; the names and personal details of FI staff are not contained within the reporting form.

### Recommendations on reporting, freezing mechanism, and tipping-off
- Recommendation 13 and Special Recommendation IV:
  - The FIU should continue to undertake a thorough analysis of banks’ level of reporting to identify concretely which issues inhibit reporting and, where necessary, implement targeted measures to resolve these issues. The FIU should also continue organizing awareness raising activities, already an integral part of the FIU’s activities, as a matter of priority to further enhance the reporting regime.
  - Banks’ reporting patterns should be subject to greater attention by the FIU to determine to what extent banks submit SARs only when information gathered from public sources indicates that a customer may have been involved in criminal activities. The assessors encourage the FIU to continue holding meetings with banks on an individual basis to discuss issues relating to reporting. Special emphasis should be made on the identification of suspicious activities or transactions that are not necessarily linked, either directly or indirectly, to a particular criminal activity.
  - The FIU should review the automatic freezing mechanism which applies upon the submission of a SAR. The review should include extensive consultation with all reporting entities. This review should inform the FIU on how the relevant legal provisions are to be amended.
  - The FIU should consider conducting a formal assessment to determine whether the reporting of FT suspicions should be higher.
  - The FIU should consider maintaining statistics on the number of reported SARs related to a suspicious transaction which is to be executed. This would enable the FIU to determine the extent to which Art. 18, para. 1 of the DDA is being complied with.
- Recommendation 14:
  - Art. 18, para. 3 of the DDA should be amended to extend the tipping off prohibition to persons’ directors, officers and employees (permanent or temporary) of a reporting entity as required under c.14.2. Additionally, the prohibition should explicitly apply not only to the SAR but also to related information.

### Ratings and effectiveness issues (R.13, R.14, SR.IV)
- R.13: LC
  - Effectiveness Issues:
    - The automatic five-day freeze on filing a SAR may have an adverse effect on the reporting mechanism.
    - Requirement to submit SARs to the OPP by the FIU hinders the effectiveness of the reporting obligation, as it exposes the reporting entity that has filed the SAR.
    - Inadequate understanding of the reporting requirement by some financial institutions.
- R.14: LC
  - The tipping-off prohibition does not apply to information related to a SAR.
- SR.IV: LC
  - Effectiveness Issues:
    - Inadequate understanding of the reporting requirement by some FIs.

### Foreign branches and subsidiaries (R.22)
- Art. 16 of the DDA and Art. 25 of the DDO regulate application of Liechtenstein’s AML/CFT regime to subsidiaries and branches of domestic financial institutions in any foreign country.
- Art. 16(1) of the DDA:
  - FIs must ensure foreign branches and majority owned subsidiaries apply measures to combat money laundering, organized crime, and terrorist financing at least equivalent to those laid down in this Act, to the extent permitted under foreign law.
  - Special attention must be paid to countries who do not or only insufficiently apply the international standard.
- Practical application:
  - FIs reported they have policies to ensure foreign branches and subsidiaries observe at minimum the Liechtenstein framework; where discrepancies exist the more stringent obligations apply.
  - Group-wide policies are developed and approved by the board; Liechtenstein headquarters must review and approve policies of each branch and subsidiary.
- Requirement to inform home country supervisor if foreign branches/subsidiaries cannot implement measures (Art. 16(2)):
  - Domestic institution must inform the FMA and take additional measures to address and mitigate increased risk. No additional guidance was provided on what such measures could be.
  - Representatives stated institutional policy requires reporting when branches or subsidiaries are unable to implement necessary measures.
- Additional element—consistency of CDD measures at group level (Art. 16(3)):
  - Banks with branches abroad or that lead a financial group with foreign companies must, at a global level, assess, limit, and monitor risks connected with money laundering, organized crime, and financing of terrorism. Further requirements are in Art. 25 of the DDO.
  - FIs noted they do not consider clients across jurisdictions; customers of foreign branches wishing to establish a relationship with the branch in Liechtenstein would be subject to local due diligence procedures.
- Implementation view:
  - Program descriptions from FIs with foreign branches or subsidiaries led assessors to believe this recommendation is being effectively implemented.
- Recommendation:
  - Provide guidance to FIs to clarify what additional measures could be taken when a foreign branch or subsidiary is not in a position to comply with DDA provisions.
- R.22: C

### Supervisory and oversight system—competent authorities and SROs (R.23, R.29, R.17)
- Progress since 2007 MER:
  - Art. 16 of the DDA requires application of Liechtenstein AML/CFT due diligence standards to foreign branches and subsidiaries.
  - The DDA was amended to rectify gaps in administrative sanctions.
  - The Penal Code was amended to clarify legal entity liability along with the individual responsible for regulatory breaches.
  - Staff increased from 29 at the time of the MER to 75 at the time of the current evaluation (with insurance receiving the largest increase).
  - FMA staff have conducted their own on-site inspections and accompanied audit firms on onsite inspections.
- Legal framework includes:
  - Financial Market Authority Act 2004 (FMAA);
  - Due Diligence Act 2008 (DDA);
  - Due Diligence Ordnance (DDO);
  - Banking Act 1992 (BA);
  - Insurance Supervision Act 1995 (ISA);
  - Investment Undertakings Act 2005 (IUA);
  - Asset Management Act 2005 (AMA);
  - E-Money Institutions Act 2011 (EIA);
  - Public Enterprise Act, Article 23;
  - Data Protection Act.
- The FMA:
  - Established by the FMAA which came into force on January 1, 2005.
  - An independent, integrated supervisor responsible for overseeing the financial market in Liechtenstein with aims including safeguarding financial center stability, protecting customers, and preventing abuses.
  - Responsible for supervising AML/CFT obligations of all FIs and DNFBPs and execution of a substantial range of financial sector laws listed in Art. 5 of the FMAA (including the DDA, ISA, Banking Act, PTA, AMA, IMA, EIA, UCITS Act).

*Source: cr18257 - 666. Other important factors in the formulation of a suspicion are mentioned in the Guideline*

### 693. The DDA imposes obligations on FIs to take due diligence measures. Art. 23 states that the

### 693. The DDA imposes obligations on FIs to take due diligence measures. Art. 23 states that the

### Independence, mandate, and funding of the FMA
- The FMA is responsible for the execution of the Act.  
- The laws relating to the supervision of specific financial sectors also stipulate that the FMA is responsible for implementation.  
- The FMAA states that the FMA shall be independent in the exercise of its activities and shall not be bound by any instructions.  
- The FMA’s budget is approved by the Parliament of Liechtenstein and almost half of the budget is in the form of a direct contribution from the state.  
- The FMA increased its resources from CHF 6.6 million in 2006 to CHF 19.32 million in 2012.  
- Assessors found no indication that the FMA was inhibited in carrying out its functions by any limitation on its independence.  
- Assessors concluded that the practice of using mandated audit firms for much of the onsite inspection work could compromise the independence of that inspection function.

### EU/EEA obligations
- As a member state of the EEA, Liechtenstein must implement in its legislation all relevant EU Directives including those relating to ML and FT.  
- Relevant EU Regulations are directly applicable in Liechtenstein, once incorporated into EEA Agreements.

### Organization and supervisory structure (R.30 — criteria 30.1–30.3)
- Funding: the FMA is funded by a direct contribution from the state (49 percent) and the remainder covered by supervisory levies, fees, and services.  
- The amount of the government grant is established in primary legislation.  
- The FMA’s annual budget is approved by the government (Art. 33a, FMA).  
- Fees and supervisory levies are set by the FMA within parameters and overall limits established in the FMAA.  
- Board composition: The Board of Directors has three to five members who, between them, must have competence in banking, securities trading, insurance, and fiduciary (and other) services (Art. 7 FMAA). Board members and Executive Board must have an impeccable reputation, expertise and practical experience.  
- Confidentiality: requirements for other staff are covered by the Staff Regulation, except for the confidentiality requirement in Art. 23 of the Public Enterprise Act. Art. 3 of the Act states that this provision does not apply where there is other relevant legislation. A discussion of interpretation in the context of cooperation is at Recommendation 40.

### FMA structure and AML/CFT governance
- The FMA is organized into four supervision divisions: Banking Division, Insurance and Pensions Division, Securities Division, and Other Financial Intermediaries Division.  
- “Other Financial Intermediaries” includes licensing and AML/CFT supervision of professional trustees and trust companies, auditors and audit companies, lawyers and law firms, exchange offices, real estate brokers, dealers in goods and services, and other persons subject to due diligence. There is no prudential supervision of these groups.  
- Representatives of each division together with two representatives from the Executive Office form an AML/CFT Committee to review and assess AML/CFT risks and to form the basis of the FMA’s understanding and application of international standards in the context of Liechtenstein.

### Staffing levels, trends, and turnover
- Total staff employed within the FMA was 72.5 full-time equivalents at the end of 2012 (75.6 at the time of the evaluation). This compares with 29 staff (plus eight trainees) at the time of the 2007 MER.  
- Number of positions approved in the four main supervisory divisions since 2007:
  - Banking: 22.1 (2008); 32.1 (2009); 8.1 (2010); 10.1 (2011); 10.6 (2012)
  - Securities: 11.6 (2009); 12.8 (2010); 12.8 (2011)
  - Insurance and Pensions: 12 (2008); 14 (2009); 14 (2010); 14.9 (2011); 14.3 (2012)
  - DNFBPs: 8.8 (2009); 11.9 (2010); 11.0 (2011); 11.6 (2012); 12.3 (2012)
  - Total Supervision: 42.9 (2008); 58 (2009); 44.7 (2010); 49.4 (2011); 50 (2012)
- The data shows that a substantial increase in staff over the period. The number of front line supervisory staff has doubled.  
- Staff turnover typically between 17 percent and 20 percent with voluntary turnover between 12 percent and 14 percent.  
- There was a spike in turnover in 2010 arising from a reorganization that created separate securities and banking divisions.

### Staff expertise and training
- FMA staff receive training in AML/CFT matters annually either in the form of internal or external training.  
- The AML/CFT Committee provides AML/CFT expertise, discusses recent cases and technical questions, shares conclusions via weekly minutes, and updates staff on international standard setters and bodies.  
- Many FMA employees formerly worked with local or foreign FIs or trust companies.  
- Several employees pursue postgraduate studies in company law, tax law, banking and financial management, and other areas touching AML/CFT issues.  
- FMA staff benefit from experience and know-how shared among EU supervisory authorities (EGMLTF and ESA’s Subcommittee on Anti-Money Laundering (AMLC)).  
- The FMA increased staff substantially in response to recommendations of the previous MER.

### Resource allocation and risk focus
- Allocation of resources within supervisory divisions does not appear to reflect AML/CFT risk.  
- The MER recommended additional resources to insurance supervision; insurance now has higher staff numbers than banking. This distribution does not appear to reflect relative AML/CFT risks of those two sectors.  
- The lower frequency of mandated onsite inspections of the highest risk sector (trust companies) is attributed to lack of resources in the “Other Financial Intermediaries” division. The number of staff in the division dealing with DNFBPs is no greater than that in banking despite DNFBPs being a very high risk sector.  
- Recommendation: increase number of inspections by FMA staff and review appropriate resources to support greater onsite involvement.

### Training adequacy and monitoring
- It is not possible to assess effectiveness of staff training without further data on quantity and quality of training.  
- General expectation: all supervisory staff should have at least one day’s AML/CFT training every year, monitored at divisional level.  
- The AML/CFT Committee records and coordinates training in its weekly minutes; staff returning from training events should provide others with training materials.  
- There is no overall policy on the quality and extent of AML/CFT training, no systematic evaluation or appraisal of minimum AML/CFT training needs, nor of staff training needs.  
- Recommendations:
  - FMA should review number of staff in light of current needs and recommendations, particularly to develop a more fully developed risk based approach, including a risk assessment and a clearly articulated AML/CFT policy.  
  - Assessment of staffing needs should account for different AML/CFT risk profiles of business sectors and focus staff in areas of highest risk.  
  - Maintain data on quality and quantity of training to enable monitoring of adequacy.  
  - Establish a policy on quality and quantity of AML/CFT training and monitor implementation, preferably within overall FMA training policy.

### Legal basis, supervisory powers, and scope (c.29.1–29.3)
- Pursuant to Art. 5(1) of the FMAA, the FMA is responsible for supervision and execution of sector specific acts regulating various types of FIs and DNFBPs and certain substantive laws, including the Due Diligence Act (DDA). Art. 23 of the DDA stipulates the FMA shall be the competent authority to supervise execution of the Act, without prejudice to the powers of the FIU.  
- Pursuant to Arts. 26 and 27a of the FMAA and Arts. 24 and 28 of the DDA, the FMA has the following powers.

Ordinary Powers (deployable without cause):
- To carry out or delegate ordinary inspections on a regular, spot-check basis with respect to compliance with the provisions of the Act, whereby frequency of such inspections shall be determined based on risk, scope, type of FI/DNFBP, and complexity of the business activities undertaken (Art. 24 DDA).  
- To demand from any person subject to the law any information or records it requires to fulfill its supervisory mandate for purposes of the DDA (Art. 28 DDA). This includes any type of information and documents, including account and CDD files, and internal policies and procedures. A court order is not needed for this purpose.

Extraordinary Powers (usable only when there is a suspicion of a breach):
- To initiate procedures to ascertain certain facts, and to obtain all necessary records and information in cases where the reputation of the financial center appears to be at risk or if there is a founded suspicion that any of the laws the FMA is required to supervise has been violated; and to demand the same type of information and records from entities or persons not licensed/registered but carrying out activities referred to under Art. 5 of the FMAA (Art. 26 FMAA).  
- To carry out extraordinary inspections or delegate such inspections in case of an indication or doubts as to whether due diligence obligations have been complied with, or where the reputation of the financial center may be at risk (Art. 28 DDA).

### Practical effect and delegation of inspections
- These powers provide the FMA authority to obtain any information, documents or other records necessary to assess compliance with the DDA, including beneficial ownership of legal persons and arrangements. The powers have been used extensively to collect such information.  
- The powers specifically give the FMA the power to conduct inspections. They can, and in practice do, delegate the conduct of most inspections to mandated audit firms under Art. 24 DDA.

### Legal clarity and risks regarding inspection powers
- The meaning of the inspection power is not defined in the DDA. International standards treat inspection as a uniquely intrusive power, and there is advantage in making explicit in law the extent of this power. The DDA does not explicitly cover:
  - What premises may be inspected—whether limited to those occupied by the person subject to the inspection or extending to premises reasonably believed to contain relevant information (e.g., holding companies, subsidiaries, affiliates).  
  - Obligations of those subject to an inspection—whether required to facilitate the inspection by making documents, personnel and records available in a timely manner and how rights to avoid self-incrimination may apply.  
  - Whether inspection powers apply to former license holders as well as current license holders (where inspection concerns compliance when license was current).  
  - Whether the power to inspect includes the power to copy documents or to seize them and, if seized, what obligations the FMA has to return them in a timely manner.

### Practice and potential challenges
- The FMA has rarely been challenged on use of powers to collect information. Where challenged (e.g., right to mount an inspection or examine files allegedly outside DDA scope), the Criminal Complaints Tribunal ruled in their favor. The FMA is subject to review by the Administrative Court.  
- Some powers have rarely been tested in practice: the FMA has not sought to carry out inspections in premises of former license holders or premises owned by another person that may hold relevant documents. Some private sector institutions have questioned whether the FMA would have the power to copy and take away confidential customer information, although the FMA has done so in practice.  
- Conclusion: in practice the FMA has powers to compel production of documents and has successfully resisted attempts to prevent exercise of this power. However, conflicts between collection powers and secrecy provisions in other laws, and lack of specificity in inspection power description, could lead to legal challenges. This suggests advantage in:
  - Making explicit that FMA powers override any confidentiality provisions in any other law.  
  - Making explicit the extent of inspection powers and rights and obligations of the FMA and those subject to inspections.

### Sanctions, enforcement powers, and appeal
- Under Art. 25 of the FMAA and Art. 28 of the DDA, the FMA has express powers to issue decrees, guidelines, and recommendations.  
- Decrees imposing a monetary fine on FIs/DNFBPs are considered legally binding and may be directly enforced by the courts, if necessary. Such decrees may be appealed to the FMA Complaints Commission, whose decision may in turn be appealed to the Administrative Court.  
- A decision to conduct an ordinary or extraordinary inspection would generally not be taken in the form of a formal decree. Only in exceptional cases (e.g., where a person resisted an inspection) did the FMA order such an inspection in the form of a decree; these orders were appealed and the FMA’s Complaints Commission rejected the appeals on the grounds that an order to conduct an inspection is not subject to an administrative appeal under Art. 29 of the DDA as it does not interfere with personal rights or legally protected interests of the applicant.

Sanctioning powers (Art. 31 DDA and related):
- The FMA may apply a fine of up to CHF 100,000 on anyone who commits an administrative offense under the law, including a violation of CDD, monitoring, record keeping or STR obligations, or a failure to provide requested documents or information.  
- The FMA has the power to prohibit the initiation of new business relationships for a limited period of time in case of a repeated or serious violation and to prevent further violations (Art. 28 DDA).  
- The FMA may request responsible authorities to apply disciplinary measures and to keep the FMA abreast on the status of such proceedings (Art. 28 DDA).

*Source: cr18257 - 693. The DDA imposes obligations on FIs to take due diligence measures. Art. 23 states that the*

### 725. Under the various sector specific laws, the FMA has additional sanctioning powers available

### cr18257 - 725. Under the various sector specific laws, the FMA has additional sanctioning powers available

### Sanctioning powers under sector-specific laws and the DDA
- The FMA has additional sanctioning powers under various sector-specific laws in case of a systematic or serious violation of the law by a specific FI or DNFBP, or failure to comply with the FMA’s demands to restore a lawful state of affairs.
- Example: Under the Banking Law the FMA may withdraw, terminate, cancel, amend, or revoke a license of a bank. Similar provisions exist in other acts regulating various types of FIs and DNFBPs.
- Practical application:
  - The FMA can issue written warnings for breaches of the DDA.
  - There is little practical experience of imposing other sanctions under the DDA.
  - There is apparent ambiguity about which laws apply in what circumstances and whether the FMA could impose a sanction provided for in a sector-specific law when the breach relates to the DDA.

### Violations sanctionable under Article 31 of the DDA
- Article 31 of the DDA sanctions anyone who:
  - refuses to give information, makes incorrect statements, or withholds significant facts vis-à-vis the FMA, an auditor, an auditing company, or an audit office subject to special legislation;
  - fails to comply with an order to restore the lawful state or any other order issued by the FMA in the course of enforcing this Act;
  - permits the outflow of assets, in violation of Art. 35 DDA;
  - in violation of Arts. 5–14 of Regulation (EC) No. 1781/2006 fails to collect, keep, verify, or transmit the required information, carries out or receives transfers of funds, or breaches record keeping or reporting duties;
  - fails to establish and update the profile of the business relationship in accordance with Art. 8 DDA;
  - fails to carry out risk adequate monitoring of a business relationship in accordance with Art. 9 DDA;
  - fails to meet the enhanced due diligence obligations in accordance with Art. 11 DDA;
  - maintains a prohibited business relationship in violation of Art. 13(1), (3), and (4) DDA or fails to take appropriate measures in accordance with Art. 13(2) DDA;
  - delegates compliance with due diligence obligations to third parties in violation of Art. 14(1)–(3) or outsources them in violation of Art. 14(4) DDA;
  - fails to ensure global application of due diligence standards in accordance with Art. 16 DDA;
  - fails to keep or maintain due diligence files in accordance with Art. 20 DDA;
  - fails to ensure internal organization in accordance with Art. 21 DDA;
  - fails to ensure internal functions in accordance with Art. 22 DDA; and
  - fails to have the inspection pursuant to Art. 28 (1) (b) or (c) DDA carried out as a whole or in regard to individual areas of the persons subject to due diligence.

- Note: The list does not specifically include the provisions in the DDO or guidelines; the FMA indicates that DDO provisions or guidelines are linked to specific provisions of the DDA and therefore a breach of the DDO or guidelines would necessarily be a breach of the DDA.

### Range of sanctions — scope, proportionality, and statistics (c. 17.4)
- Observed sanctions on banks and insurance undertakings (2009–2012):
  - Explanation of categories:
    - “A” denotes remedial instructions or written warnings
    - “B” denotes administrative sanctions
    - “C” denotes criminal complaints
  - Banks:
    - 2009: A 34, B 1, C 1
    - 2010: A 19, B 0, C 0
    - 2011: A 31, B 1, C 1
    - 2012: A 20, B 1, C 1
  - Insurance:
    - 2009: A 46, B 0, C 1
    - 2010: A 75, B 0, C 0
    - 2011: A 107, B 0, C 1
    - 2012: A 97, B 0, C 0

- Assessment of adequacy and proportionality:
  - Powers available:
    - Criminal sanctions for failing to comply with the DDA include imprisonment for up to six months and fines:
      - Natural person: up to CHF 360,000 (US$400,000)
      - Legal person: up to CHF 600,000 (US$670,000)
    - Administrative measures: warnings, impose license conditions, remove senior officers, apply administrative fines, limit areas of business, withdraw licenses.
  - Concern: Administrative fines upper limit of CHF 100,000 is substantial for an individual but modest for a large financial institution.
    - Recommendation: The FMA should seek power to impose larger fines on institutions that are more substantial than CHF 100,000 where appropriate.
  - Observations:
    - Number of sanctions (apart from private written warnings) is negligible; the handful imposed have been fines.
    - The FMA should review internal guidelines regarding use of sanctions to ensure powers are used appropriately.
    - Overall conclusion: Powers of enforcement are generally adequate, apart from the level of fines on institutions.

### Market entry, fit and proper criteria, and prevention of criminal control (c. 23.3, 23.3.1)
- Licensing requirement:
  - All financial institutions require a license; licensing provisions include fit and proper criteria.
- Measures to prevent criminals owning FIs are set out in various sectoral laws (examples cited include Art. 17(5) BA in combination with Art. 27a and the Annex to the Banking Ordinance (BO), Arts. 15(1)(d) and 19 of the UCITSA in combination with Art. 23 of the UCITSO and the Annex to the BO, Arts. 24 and 67 of the IUA in combination with Art. 32 of the IUO and the Annex to the BO, Art. 10a of the AMA in combination with Art. 8 of the AMO and the Annex to the BO, Art. 9 of the EIA, and for insurance companies Art. 18a of the ISA in combination with Arts. 59–61 of the ISO).
- Shareholder thresholds and reporting:
  - Any shareholder directly or indirectly holding voting rights or capital of a financial institution of 10 percent or more, or who has significant control power, must meet demands to ensure sound and prudent management.
  - Intended changes in ownership must be reported to the FMA where the change would result in holdings of 20 percent, 33 percent, or 50 percent, or cause subsidiary status (Annex 8 BO).
- Criteria used by the Annex to the BO for shareholders (banks, investment firms, e-money institutions, investment undertakings under the IUA and UCITSG, and Asset Management Companies):
  - the reputation of the proposed acquirer;
  - the reliability of any person that will manage the institution after the proposed acquisition;
  - the financial stability of the acquirer;
  - whether the financial institution is and will remain able to meet supervisory requirements and whether the relevant financial group is structured to warrant effective supervision, effective determination of competences and exchange of information between the FMA and other competent authorities;
  - whether there are reasonable grounds to suspect that, in connection with the proposed acquisition, money laundering or terrorist financing is being or has been committed or attempted, or that the proposed acquisition could increase the risk thereof.
- Powers and remedies:
  - The FMA may oppose a proposed acquisition on reasonable grounds or where information provided is incomplete (interpreted as a right to veto a specific acquisition).
  - For insurance companies, the FMA may order already completed acquisitions declared void if the acquirer does not meet criteria; no comparable provision for other sector laws, but license withdrawal is available.
- Fit and proper for managers and board members:
  - Fit and proper criteria apply under multiple sector laws (explicit articles cited).
  - Managers and board members cannot take up appointment unless FMA agrees they meet criteria; applies even if located outside Liechtenstein (obligation placed on the institution in Liechtenstein).
  - The FMA publishes on its website a list of documents to be provided for the fit and proper test, including:
    - Signed and dated curriculum vitae;
    - Employer’s references;
    - Education/career credentials;
    - Extract from the Criminal Register (not older than six months);
    - Confirmation of residence;
    - Any other references;
    - Information on any other professional obligations, especially other seats on boards of directors or management (with indication of the company name, purpose, and domicile);
    - Written declaration concerning any pending criminal and administrative criminal proceedings and concerning freedom from collection and bankruptcy.
  - Notification obligations:
    - Art. 26 BA, Art. 29(4) IUA, Art. 10 AMA, Art. 19 IMA require FIs to notify the FMA of composition of managerial organs and bodies and to immediately notify any changes. No such provisions in the EIA, the UCITSG, and the ISA.
  - Practical application:
    - The FMA has used powers to require prior notification of board and management appointments and to deny approval where criteria are not met; can withdraw approval if a person no longer meets criteria and force removal as a sanction.
    - Administrative fines can apply to individuals as well as institutions.
    - Approximately half of board members and directors of Liechtenstein FIs are recruited from outside Liechtenstein (mostly Austria and Switzerland); background checks include public databases, further checks on a risk basis, consultation with foreign regulatory authorities as necessary.
- Source of funds/wealth checks:
  - FMA practice includes checking source of funds and source of wealth of qualifying owners as part of approval, though documents evidencing source of funds and wealth are not included in the list of required documents published on the FMA website.
  - Recommendation: Strengthen provisions by including documents evidencing source of funds and wealth in the list of required documents on the FMA website and include a specific and explicit requirement in FMA internal procedures manuals that source of wealth and funds should normally be checked.
- Overall conclusion: Powers regarding ownership and control appear to be adequate and are being used effectively, with limited expected frequency of use.

### Licensing or registration of payment services and other financial institutions (c. 23.5, c. 23.7)
- Payment Services Act (PSA) — Art. 7:
  - Anyone intending to provide domestic payment services not already licensed as a bank, e-money institution, or post office must obtain a license as payment institution from the FMA.
  - Exemptions: the European Central Bank, central banks of EEA member states, and public authorities of an EEA member state.
  - Art. 7(2): No other entity or person may provide payment services under Liechtenstein law.
- Definition of “payment services” under Art. 3(20)(f) PSA includes:
  - services enabling cash to be placed on a payment account or operations required for operating a payment account;
  - services enabling cash withdrawals from a payment account as well as all the operations required for operating a payment account;
  - execution of payment transactions, including transfers of funds on a payment account with the user’s payment service provider or with another payment service provider;
  - Execution of the payment transactions pursuant to (c) where the funds are covered by a credit line for a payment service user;
  - issuing and/or acquiring of payment instruments;
  - money remittance;
  - execution of payment transactions where the consent of the payer to execute a payment transaction is given by means of any telecommunication, digital, or IT device and the payment is made to the telecommunication, IT system, or network operator, acting only as an intermediary between the payment service user and the supplier of the goods and services.
- Other authorizations:
  - Provision of currency changing services, unless provided by a bank, requires a business authorization by the Office of Economic Affairs.
- Due diligence:
  - Art. 3, para 1, lett. h imposes due diligence obligations on payment services providers.
- Practical note:
  - In practice the only institutions other than banks providing payment services are the post office and, more recently, the e-money institution. Banks, post office, and e-money institutions are all covered by the DDA.
- Licensing of other FIs:
  - Art. 5 of the FMAA: all FIs licensed in Liechtenstein are supervised by the FMA, including for AML/CFT purposes (Art. 23 DDA).

### Ongoing AML/CFT supervision and supervisory practices (c. 23.1, 23.4, 23.6, 23.7)
- Scope:
  - AML/CFT obligations are set out in the DDA and DDO and apply to all categories of FIs and DNFBPs that conduct financial activities as defined under the FATF standard.
  - Art. 23 DDA: the FMA is the designated supervisor for all categories of FIs and DNFBPs for ensuring compliance with the DDA and the DDO.
- Supervisory approach:
  - The FMA relies almost exclusively on onsite inspections to carry out its supervisory task.
  - The FMA does not require FIs subject to due diligence obligations to make periodic reports to the FMA on AML/CFT obligations for off-site analysis (although it has the power to do so and does require periodic reports on prudential matters).
  - Instead, the FMA relies on information obtained annually from obligated institutions as a result of inspections; mandated audit firms provide wide-ranging information that supports desk-based analysis.
- Use of audit firms:
  - The FMA uses audit firms to conduct financial and compliance audits on its behalf; these audit firms are required to be independent.
  - Each FI submits a list of two or three audit firms for approval by the FMA; the FMA decides whether to approve the appointment.
  - For larger firms, the auditor of financial accounts often also audits compliance with regulatory obligations; for smaller firms there may be separate firms.
  - Mandated audit firms conduct AML/CFT inspections separately from the audit of accounts and usually separately from examination of prudential matters; where conducted simultaneously, the AML/CFT examination is conducted separately and by a specialist examiner.

*Italic: IMF assessment chapter excerpt.*

### 753. Mandated audit firms are required to review compliance with the DDA and DDO (taking

### cr18257 - 753. Mandated audit firms are required to review compliance with the DDA and DDO (taking

### Mandated audit firms — scope and frequency
- Mandated audit firms are required to review compliance with the DDA and DDO, taking account of guidance issued on the risk-based approach and sector-specific guidance issued to most individual sectors except banks.
- Annual inspections: banks, investment firms, e-money institutions, payment service providers, management companies, asset management companies, life insurance undertakings, branches of foreign life insurance undertakings, and branches of foreign banks, investment firms, e-money institutions, management companies, and payment service providers.
- Post office: inspection every three years.
- Inspections must follow detailed guidance given by the FMA and use a report template issued by the FMA.
- Working papers are kept in Liechtenstein and are available to the authorities on request.
- Inspection reports are submitted to the FMA by June in the year following the inspection; serious violations must be reported immediately.

### Inspection procedures, guidance, and annual cycle
- FMA holds workshops for all mandated audit firms: two workshops for all mandated audit firms and one for each group of sector-specific auditors.
- FMA communicates annual risk priorities (example for 2013: trading in precious metals, particularly gold).
- Bilateral meetings: FMA conducts bilateral meetings with each mandated audit firm to discuss performance, results, and institution-level risks.
- Typical inspection timing: mandated audit firms tend to conduct inspections between March and June to use annual compliance reports prepared under Art. 30 of the DDO and to meet the June 30 deadline imposed by the DDA guidance 2013/2.

### Inspection content and required actions (guidance 2013/2)
- Mandated audit firms are required by guidance to:
  - Describe the risks faced by the institution subject to examination;
  - Sample due diligence files to review compliance with due diligence obligations including:
    - effectiveness of the customer take on procedures;
    - implementation of an appropriate risk classification;
    - identification of those subject to enhanced due diligence (Art. 11, DDA) and those subject to simplified due diligence (Art. 10, DDA);
  - Review internal policies, controls, risk management systems and organization of the institution (inspection template references Art. 31 DDO on internal controls).
- Normal practice (though not specifically required) includes:
  - Review board papers and minutes to determine if the compliance report and any relevant internal audit reports have been discussed and appropriate action taken;
  - Review any relevant internal audit reports and discuss due diligence compliance with internal auditors;
  - Review training materials used by financial institutions to assess the quality and quantity of training (requirement to describe the training concept);
  - Review monitoring systems, especially IT systems;
  - Interview senior executive staff, staff with responsibilities for client contact and compliance officers (requirement to name the compliance officer and state if he or she are meeting their legal responsibilities).

### Foreign branches and subsidiaries inspections
- Audited firms review due diligence application to foreign branches and subsidiaries by visiting them or asking foreign partner audit firms to do so.
- Foreign subsidiaries and branches of Liechtenstein banks:
  - 54 subsidiaries and four branches of Liechtenstein banks in foreign countries; All but three subsidiaries and two branches are from the three largest Liechtenstein banks.
  - Foreign subsidiaries by country:
    - Switzerland (20);
    - Caribbean–Cayman Islands and British Virgin Islands (15);
    - the EU, UK, Ireland, Luxembourg, Austria, and Germany (10);
    - Hong Kong (4);
    - Singapore (2);
    - USA, Japan, and UAE (1 each).
  - Four branches: UK, Ireland, Austria, and Hong Kong.
- FMA undertook visits to foreign branches and subsidiaries in 2011 (Singapore), 2012 (Austria), and 2013 (Luxembourg).
- Inspections of foreign branches and subsidiaries are undertaken on the same basis as domestic inspections; majority by mandated audit firms, a small number by the FMA itself.

### Reporting content and remedial measures
- Reports use an FMA template and include detailed descriptions and assessments of policies, procedures and controls.
- Reports provide detailed indicators, including:
  - the total number of business relationships subject to due diligence obligations;
  - the number of business relationships initiated by correspondence;
  - the number of PEPs;
  - the number of correspondent banking relationships;
  - the number of business relationships regarded as complex;
  - the number of business relationships where the contracting party or beneficial owner is from a country not applying international AML/CFT standards;
  - the number of business relationships where the due diligence was delegated to a third party, or monitoring was outsourced;
  - the number of reports of suspicions of money laundering or terrorist financing made under Art. 17 DDA.
- Reports must identify complaints (breaches not regarded as sufficient to attract sanctions) and violations (may justify a sanction).
- Audit firms must state concrete measures to remedy violations and prevent reoccurrence; reports should also recommend measures to address perceived weaknesses even if no specific complaints or violations arose.
- FMA analyzes inspection reports, updates institution risk profiles, holds management meetings with FIs, and may issue instructions to enforce corrective action.

### Quantitative inspection activity (excerpted figures)
- The report provides year-by-year inspection counts for selected sectors (Auditor / FMA):
  - Banks:
    - 2009: Auditor 15, FMA 0(4)
    - 2010: Auditor 15, FMA 0(4)
    - 2011: Auditor 15, FMA 2(0)
    - 2012: Auditor 17, FMA 1(2)
    - June 2013: Auditor 17, FMA 4
  - Management of IU:
    - 2009: Auditor 2, FMA 0
    - 2010: Auditor 2, FMA 0
    - 2011: Auditor 2, FMA 0
    - 2012: Auditor 2, FMA 0
    - June 2013: Auditor 2, FMA 1
  - Asset Management:
    - 2009: Auditor 102, FMA 0
    - 2010: Auditor 102, FMA 0
    - 2011: Auditor 107, FMA 0
    - 2012: Auditor 107, FMA 0
    - June 2013: Auditor 107, FMA 5
  - Life Insurance:
    - 2009: Auditor 18, FMA 8
    - 2010: Auditor 20, FMA 5
    - 2011: Auditor 20, FMA 4
    - 2012: Auditor 20, FMA 11
    - June 2013: Auditor 20, FMA 6
  - Insurance Intermediaries:
    - 2009: Auditor -, FMA 4
    - 2010: Auditor 10, FMA 1
    - 2011: Auditor 20, FMA 3
    - 2012: Auditor 10, FMA 7
    - June 2013: Auditor 10, FMA 5
- Note: Figures in brackets indicate FMA accompanying an inspection by a mandated audit firm.

### Application of prudential powers to AML/CFT
- FMA powers to impose prudential standards are provided in sector-specific acts for banking, insurance, insurance intermediaries, asset managers, investment undertakings, and UCITS funds.
- These powers include licensing (fit and proper), setting standards, onsite inspections, off-site reporting, and sanctions.
- DDA provides comparable powers specifically for imposing due diligence obligations; sector-specific powers are mainly relevant for licensing.
- FMA uses DDA powers to require internal controls (Arts. 21 and 22, DDA), risk management processes (guidance on risk-based approach issued in 2013), and global application of due diligence standards (Art. 16, DDA).
- FMA has the power to conduct inspections of foreign branches and subsidiaries and does so itself to some degree and also requires mandated audit firms to do so.

### Effectiveness, risks, and identified shortcomings
- Aggregate data on remedial actions does not reveal severity of findings; relatively small number of sanctions suggests matters requiring remedial actions were not regarded as very serious.
- Private sector anecdotal evidence: many representatives suggested mandated audit firms were not finding significant failings; caveat that private firms may underreport.
- Common findings by audit firms and the FMA relate to failures to identify the source of assets of the contracting party as required by the DDA, Art. 20 para. 1.
- Concerns:
  - Given high-risk nature of much Liechtenstein business (many relationships require enhanced due diligence per FATF methodology), low number of sanctions raises concern that findings may be neither extensive nor serious.
  - FMA does not fully use all supervisory tools effectively: onsite inspections are not risk based; potential of guidance is not fully exploited; there is no off-site reporting on AML/CFT matters; minimal use of sanctions.
- Onsite inspections not risk based:
  - DDA states frequency and intensity of inspections should depend on type, scope, complexity, and risk level, but practice shows inspections are largely across-the-board annual examinations regardless of FMA risk assessment.
  - Guidance to audit firms does not indicate how intensity or focus should be tailored to risk beyond minimum sampling tied to size and category.
  - Reliance on mandated audit firms allows broader inspection coverage but creates potential conflicts of interest because firms are paid by and to a great extent chosen by the obligated firm (subject to FMA approval).
- Identified risks from mandated audit firm model:
  - Potential conflict of interest: audit firm paid by and chosen in practice by the obligated firm may be less inclined to identify costly weaknesses.
  - Instances where regulatory risk was not identified by audit firms (e.g., systems to detect changes in status of beneficial owners when simplified due diligence or exemptions applied).
  - Limited number of serious compliance failures found by mandated audit firms and very limited number of consequential sanctions may indicate insufficient rigor.
- Mitigating factors and FMA oversight of audit firms:
  - FMA must approve appointment of audit firm; audit firm is mandated and the FMA is the contracting party.
  - Each obligated firm must propose two possible audit firms; final choice is made by the FMA.
  - Independence governed by Guideline 2013/2 and general independence requirements for auditors.
  - FMA provides guidance, annual workshops, reviews inspection reports, discusses work with audit firms, holds bilateral discussions with obligated institutions, accompanies audit firms on some inspections, analyzes performance of audit firms, gives feedback, and has taken action against audit firms it considers failing.

*Source: cr18257 (excerpts from PDF chapter content).*

### 776. However, these measures to mitigate the risk may not be fully effective in practice. Private

### cr18257 - 776. However, these measures to mitigate the risk may not be fully effective in practice. Private

### Oversight of mandated audit firms and conflict of interest
- FMA oversight of audit firms:
  - FMA staff attendance at inspections: private sector respondents indicated FMA staff "did not attend for the whole inspection," while the FMA stated their staff "usually attended for the whole inspection."
  - Oversight does not include formal ratings of audit firms.
  - No systematic procedure for regular assessments of effectiveness through:
    - examination of working papers;
    - conducting post inspection interviews with FIs about mandated audit firms’ effectiveness;
    - benchmarking performance or comparing firms’ performance.
  - FMA does not insist on rotation of mandated audit firms, arguing long association increases auditor knowledge.
- Consequences and risks:
  - Potential conflict of interest remains and the risk of regulatory capture of audit firms by financial institutions persists (para. 777).
  - In-depth knowledge gained by inspections is retained by audit firms, not FMA staff (para. 778).
  - Audit firms may allow FIs to address some complaints prior to report completion, with the possibility that some complaints are not included in the report (para. 778).
  - Use of audit firms at the scale adopted by the FMA is uncommon elsewhere due to these risks (para. 780).

### Risk-based approach to inspections and resource allocation
- Current practice:
  - Blanket obligation to inspect all institutions in every respect of all their DDA and DDO obligations every year is "clearly not a risk-based approach" (para. 781).
  - Cost of across-the-board inspections is borne by institutions, but FMA remains responsible for considering cost and effectiveness (para. 781).
- Observations from private sector and assessors:
  - Some businesses pose lower risk and could be inspected less frequently (para. 782).
  - Trust company business poses much greater risk and justifies more frequent inspections (para. 782).
  - FMA’s resource allocation not being deployed on basis of risk, partly justified by inadequate resources in the relevant FMA division (para. 782).
- Recommendations for risk-based supervision:
  - AML Committee should prepare an annual review of risk for board endorsement; risk assessment should be available to all staff and inform an AML/CFT supervisory policy adopted by the board (para. 783).
  - Risk categorization of FIs should determine a variable cycle of inspections with frequency and scope tailored to risk, across prudential and AML/CFT risks (para. 784).
  - Reducing inspections by audit firms for lower-risk institutions would free FMA resources to inspect higher-risk institutions and increase FMA-conducted inspections (para. 785).
  - FMA might seek to ensure its staff had the objective of inspecting each institution "no less frequently than once every four years" (para. 780).

### Off-site monitoring and information collection
- Current state:
  - Off-site reporting is "a valuable tool" but currently not used for assessing compliance with due diligence obligations (para. 787).
  - FMA receives some information through inspection reports but does not always collate to identify aggregate trends or outliers (para. 789).
- Suggested off-site reporting items (para. 788):
  - A copy of the risk assessment made by the institution;
  - A copy of key internal controls such as the customer acceptance procedure and the effect of different risk categories on internal procedures;
  - The number of business relationships in each of the institution’s risk categories;
  - The number of business transactions involving cash or bearer instruments above a specified level;
  - The number of reports made within the FI to the compliance officer but not submitted to the FIU;
  - The number of complaints made by customers to financial institutions about due diligence matters;
  - The number of disciplinary actions taken against staff for failing to comply with internal controls on due diligence matters.
- Recommendation:
  - Institute an off-site reporting regime requiring regular submission of the above and other information the FMA considers appropriate; essential if FMA moves to a more risk-based approach (paras. 789–790).

### Guidance and supervisory expectations
- Current guidance:
  - Sector-specific guidance offers interpretation of DDA and DDO for different sectors (except banks) but largely repeats statutory provisions (para. 792–793).
  - FMA states guidance cannot add to DDA or DDO obligations and risks narrowing the impact by indicating what might be acceptable (para. 793).
- Recommended improvements:
  - Review sector-specific guidance to go beyond restating DDA and DDO and identify nonbinding best practices to assist institutions in meeting obligations (para. 794).
  - Extend guidance to banks and clarify status of guidance and expectations: if an institution does not follow guidance, it must explain how arrangements meet DDA and DDO to avoid sanctions (para. 794).
  - Guidance on risk-based approach should be more detailed and could cover (para. 794):
    - How risk categorization should affect institutional policies and procedures;
    - FMA expectations for establishing and verifying beneficial owner identity and when stronger measures than a signed statement are expected;
    - Issues when beneficial owner is the main economic actor while contracting party is a professional intermediary;
    - Actions for higher risk customers: clarifying "stricter rules," "closer and more intensive monitoring," and "additional measures required";
    - Minimum AML/CFT training expected for different employee categories;
    - More detailed role definitions for compliance officer and internal audit with respect to due diligence and board reporting;
    - How to monitor outsourced compliance departments;
    - Extent and frequency of senior management reviews of higher risk customer relationships not covered by Arts. 11(4) and (5).
  - Adopt a more formal and extensive approach allocating FMA resources according to risk to govern staff allocation, sector resources, inspection scope/frequency, guidance focus, and off-site regime (para. 795).

### Recommendations and comments (R.23 and R.29) — selected items
- Consider amending the DDA to clarify inspection and information powers override confidentiality obligations in other legislation (R.29).
- Consider providing further detail on the meaning of "inspection" to clarify rights and obligations of FMA, mandated audit firms, and subjects of inspections (R.29).
- Amend guidance to mandated audit firms to require best practices regarding reviews of board papers and minutes, training, monitoring and IT systems, and internal control documents (R.23).
- Introduce procedures to mitigate regulatory capture of audit firms, including:
  - rotation requirement;
  - more systematic FMA oversight with regular performance reviews, ratings, benchmarking, accompanied inspections, and review of working papers (R.23).
- Include documents evidencing source of funds and wealth in the list of required documents on the FMA website and internal procedures (R.23).
- Consider extending sector-specific guidance to banks (R.23).
- Increase the number of inspections undertaken by FMA staff (R.23).
- Develop the risk-based approach by having the AML Committee prepare an annual risk assessment for board adoption to inform supervisory strategy, inspection scope/frequency, a more comprehensive off-site reporting regime, FMA resource allocation by risk, and more detailed guidance focused on higher-risk products and services (R.23).
- Amend the definition of control in sector-based laws to capture persons exercising substantial influence regardless of shareholding or title, requiring prior FMA approval based on integrity and competence (R.23).
- Review the upper limit on fines for companies to ensure proportionate and dissuasive penalties (R.17).
- Review FMA resources and allocate within FMA on the basis of risk, taking account of potential savings to regulated firms and the FMA from a risk-based inspection approach (R.23).

### Compliance ratings and effectiveness issues (R.17, R.23, R.29)
- R.17: LC
  - Administrative fines for institutions are not proportionate or dissuasive.
  - Effectiveness issue: Use of sanctions too limited to act as effective, dissuasive, and proportionate deterrence to noncompliance.
- R.23: LC
  - Effectiveness issues:
    - Over-reliance on audit firms to conduct majority of inspections with insufficient mitigation of conflicts of interest undermines effectiveness of inspections and reduces FMA’s ability to disseminate best practices;
    - Absence of a risk-based approach to allocation of inspection resources reduces effectiveness of supervision;
    - Limited aggregate off-site analysis of trends and patterns from annual inspection information.
- R.29: C

*Source: https://www.imf.org/-/media/files/publications/cr/2018/cr18257.pdf*

### 797. TCSPs operating in Liechtenstein serve to establish various forms of legal entities for resident

### TCSPs operating in Liechtenstein serve to establish various forms of legal entities for resident

### TCSPs role, practices, and risks
- TCSPs establish foundations, companies, or Ansltalt in Liechtenstein on behalf of resident and nonresident customers, who may be represented by resident or nonresident intermediaries.
- Entities set up in Liechtenstein by TCSPs are often part of larger structures or series of structures involving different jurisdictions; the Liechtenstein entity can be the parent.
- In cases involving foreign professionals as introducing contracting parties:
  - TCSPs generally rely on the introducing contracting party for information and documentation necessary to perform CDD.
  - The TCSP might rely entirely on the introducing contracting party throughout the life of the relationship.
  - The TCSP may or may not meet the beneficial owner.
- When the TCSP does not have direct contact with the underlying customer and the representative fails to provide adequate and verified information:
  - The TCSP is prevented from thoroughly understanding the customer and effectively assessing and managing risk.
  - The TCSP might be considered part of the larger legal structure but lack adequate insight into the entire structure and into the beneficial owner.
  - The introducing professional might provide a beneficial ownership declaration signed by the professional with no information regarding the larger legal structure.
  - Resulting consequences include inability to identify and verify the beneficial owner or a limited/skewed understanding of customer risk to the TCSP, the DNFBP sector, and the financial system.
- Accountants are not expressly referenced in Art. 3 of the DDA but are covered through the catch-all provision relating to “any natural or legal person to the extent that they contribute to the planning and execution of financial or real estate transactions for their clients” concerning activities that would also subject lawyers to the AML/CFT framework.

### DNFBP coverage, licensing, and supervision
- Liechtenstein applies the DDA and DDO to FIs and to designated nonfinancial businesses and professions (DNFBPs). For casinos, the Casino Ordinance applies in addition to the DDA and DDO.
- The DDA covers licensed DNFBPs (e.g., auditors and licensed trustees) and in some instances any other natural or legal person carrying out a relevant activity “on a professional basis.” Courts have interpreted “on a professional basis” widely to include acting for profit or economic benefit on a regular and independent basis.
- For this report, references to “TCSPs” encompass any natural or legal persons holding a license under the Act on Trustees, or carrying out activities specified under the TCSPs heading.
- Supervision:
  - Pursuant to Art. 23 of the DDA, the FMA is competent to supervise or monitor all types of DNFBPs, whether licensed or not.
  - Art. 3(3) DDA requires persons who fall under the DDA based on acting on a professional basis but are not licensed to immediately inform the FMA.
  - In practice, the FMA carries out inspections of all types of DNFBPs whether licensed by the FMA or not.
- DNFBPs subject to the DDA (December 2012) — number of licensed DNFBPs under Art. 3 of the DDA:
  - Trustees 91
  - Trust companies 287
  - Persons with certificate under Art. 180a PGR 535
  - Lawyers 190
  - Law firms 29
  - Auditors 33
  - Audit firms 24
  - Real estate brokers 7
  - Dealers in goods 4
  - Others 29

### Customer Due Diligence (CDD) legal framework and identified shortcomings
- Historic context:
  - In 2007, Liechtenstein’s PC rating for Recommendation 12 was based on shortcomings: obligation to identify and verify the beneficial owner; lack of requirement to transmit originator information with domestic wire transfers; failure to apply enhanced CDD for high risk customers; over-reliance by domestic DNFBPs on foreign third party intermediaries to carry out CDD without treating introduced business as high risk; and exemptions to CDD not allowed under the FATF standard.
  - The DDA and DDO have been revised since 2007 to provide more comprehensive identification and verification measures, record keeping obligations, suspicious transaction reporting and internal control obligations.
- Legal instruments referenced:
  - Due Diligence Act;
  - Due Diligence Ordinance;
  - Gambling Act (GA);
  - Online Gambling Ordinance (OGO);
  - Casino Ordinance (CO).
- Key CDD shortcomings applicable to DNFBPs (as applied from Recommendation 5 discussion):
  - Verification measures for beneficial owners are not required to be based on reliable sources.
  - The DDA does not set out an obligation for DNFBPs to carry out reviews of existing records as part of ongoing CDD, including for higher risk customers or business relationships.
  - The blanket exemption for CDD under Art. 10 of the DDA is not permissible under the FATF standard.
  - The definition of “beneficial owner” in the DDA and DDO aligns with the FATF definition; consideration should be given to include settlors of a trust arrangement that have no express control powers.
  - Art. 18(2) scope is too broad: it allows identification and verification measures to be delayed in certain circumstances without an express requirement that delayed verification be carried out “as soon as reasonably practicable” and that ML risks are effectively managed.
  - An express requirement to apply CDD to all existing customers on the basis of materiality is missing.

### Casinos: CDD requirements and application (land-based and online)
- Prohibition of anonymous accounts:
  - Art. 67 OGO prohibits establishment of anonymous online gambling accounts.
  - For land-based casinos, prohibition under Art. 13 DDA to open anonymous accounts or accounts in fictitious names applies.
- When CDD is required — Land-based Casinos (Art. 136 ff. CO):
  - CDD must be taken when an ongoing business relationship is established through:
    - Providing the player with a chip or player account;
    - Providing the player with an electronic carrier medium for game credit used for more than one gaming day and which has credit on it of more than CHF 5,000 (4,046 euros);
    - Issuing the player a client card recognized by the casino as evidence of identity.
  - Depending on license, CDD for occasional players must be applied either when players first enter the casino or when processing any of:
    - Selling or buying back chips or gaming plaques of CHF 3,000 (2,427 euros) or more;
    - Machine payouts of CHF 5,000 (approximately 4,046 euros) or more;
    - Exchanging currency denominations and foreign currency and other cash transactions of CHF 5,000 (approximately 4,046 euros) or more;
    - Issuing and cashing checks.
  - Authorities noted some thresholds are slightly higher than the 3,000 euro threshold in FATF R.12; a 2012 license provides the option to carry out CDD on all occasional customers upon entering the casino and in practice threshold would not be relevant for the time being.
- Player-related documentation (Art. 143 CO) — transactions to be linked to CDD file:
  - Buying back chips or gaming plaques of CHF 15,000 (approx. 12,000 euros) or more;
  - Machine payouts including pay out credit on electronic carrier media for machine gambling credit of CHF 15,000 (approx. 12,000 euros) or more;
  - Issuing and cashing non-negotiable checks for CHF 15,000 (approx. 12,000 euros) or more;
  - Exchanging currency denominations and foreign currency of CHF 5,000 or more;
  - All transfers in the framework of a chip or guest account;
  - All transactions via electronic carrier medium used for longer than one gaming day and have credit on them in excess of CHF 5,000.
  - Note: thresholds under Art. 143 are not aligned with the 3,000 euros threshold under R.12; not all transactions listed fall within scope of R.12.
- Online casinos (Arts. 124, 125, 126 OGO):
  - Providers must open a client account for each player; no player may hold more than one client account (Art. 68(1) GA).
  - Identification requirements when:
    - Accepting payments from the player of CHF 25,000 (approx. 20,000 euros) or more, including payments by debit/credit cards, bank/postal accounts, e-wallets, whether direct or processed indirectly or in apparent connected transactions (Art. 124);
    - Making payments to the player in excess of CHF 5,000 (approx. 4,000 euros) Swiss francs (Art. 124);
    - Issuing and cashing checks (Art. 124);
    - When the balance on the client account amounts to CHF 25,000 (approx. 20,000 euros) or more (Art. 125);
    - Providing the player with an electronic carrier medium for game credit used for more than one gaming day and with credit of more than CHF 5,000 (approx. 4,000 euros) (Art. 125);
    - Issuing the player a client card recognized as evidence of identity (Art. 125).
  - The threshold for application of CDD in many instances is higher than the 3,000 euros threshold of the FATF standard; not all listed transactions fall within Recommendation 12.
  - Neither land-based nor online casinos are permitted to carry out wire transfers.
  - Casinos must carry out CDD where there is suspicion of ML or FT, or doubt about adequacy/accuracy of previously obtained CDD information.
- Identification and verification sources:
  - CO and OGO require identification and verification of the player based on “documents with probative value.”
  - For land-based casinos, “documents with probative value” set out under Art. 25 GA include: official picture identification that allowed entry to Liechtenstein territory; other official picture identification determined by the Liechtenstein Amt fuer Volkswirtschaft indicating name, date of birth, and citizenship; or casino internal player cards approved by Amt fuer Volkswirtschaft.
  - For online casinos, Art. 126 OGO refers to Arts. 7 and 10 of the DDA for what constitutes a document with probative value.
- Identification of legal persons and beneficial owners:
  - Legal persons cannot be clients of land-based or online casinos.
  - Art. 58(2) OGO clarifies that payment by cards/accounts in the name of a legal person may not be accepted.
  - Arts. 139 CO and 128 OGO permit casinos to assume the player is the beneficial owner; the assumption does not apply for ongoing relationships, certain transactions (Art. 143 CO and Art. 124 OGO), indications amounts used are not in line with player’s financial situation, unusual findings, or for land-based bank transfers in favor of the player.
  - Both CO and OGO require a written declaration by the player to establish and verify identity of the beneficial owner (Art. 129 OGO and Art. 140 CO); accuracy must be confirmed by handwritten signature or secure electronic signature. Relevant DDA and DDO provisions apply (in particular Art. 7 DDA).
  - There is no requirement for casinos to identify and take reasonable measures to verify the identity of the beneficial owner in all cases.
- Business purpose and ongoing due diligence:
  - No specific requirement in CO or OGO for casinos to determine purpose and intended nature of business relationships; authorities consider purpose for gambling games to be winnings and amusement.
  - Both land-based and online casinos must ensure ongoing business relationships are monitored in a risk-adequate manner and must document all transactions in course of an ongoing relationship (Art. 144(1) and (2) CO; Art. 133(1) and (2) OGO).
  - A requirement to set up a business profile for each ongoing business relationship is set out in CO and OGO. DDA and DDO provisions also apply.
- Risk-based measures:
  - Casinos must categorize ongoing relationships and occasional transactions with higher risks per internal instructions.
  - Higher-risk relationships must be more intensively monitored (Art. 145(1) CO; Art. 134(1) OGO). DDA/DDO, particularly Art. 11 DDA, apply.
  - GA, CO, and OGO provide no simplified due diligence obligations and none of the cases in Art. 10 DDA apply to gambling games.
- Timing of verification:
  - Land-based casinos must identify players either upon entry to the casino or upon reaching CDD thresholds (Art. 25(2) GA). Casinos may assume player is beneficial owner except for ongoing relationships or specified transactions.
  - For online casinos, Art. 67(2) GA and Arts. 124 and 125 OGO state player identification must take place before a person may be admitted to online gambling games.
  - There are no provisions under CO or OGO for delayed verification of the player; DDA and DDO provisions apply.

*Source: IMF report section provided (cr18257 - 797. TCSPs operating in Liechtenstein serve to establish various forms of legal entities for resident).*

### 827. There are no provisions under the CO or OGO addressing the failure to satisfactorily

### cr18257 - 827. There are no provisions under the CO or OGO addressing the failure to satisfactorily

### Legal and regulatory gaps in CDD for DNFBPs and casinos
- There are no provisions under the CO or OGO addressing the failure to satisfactorily complete CDD; the provisions of the DDA and DDO thus apply (para. 827).
- At the time the new legislation came into effect no licenses were issued; there were neither existing customers of casinos nor of providers of online gambling games (para. 828).
- Provisions discussed under Recommendations 6 and 8–11 apply equally to DNFBPs, so shortcomings identified under Recommendation 5 are equally applicable to DNFBPs (para. 829).
- Specific deficiencies noted:
  - No express obligation for DNFBPs to establish the source of wealth of contracting parties or beneficial owners that are PEPs (para. 829).
  - No express obligation for DNFBPs to have policies or measures to prevent use of technological developments for ML/FT (para. 829).
  - In the context of intermediaries or introduced business, no direct obligation for DNFBPs to satisfy themselves that the third party being relied upon has measures in place to comply with the CDD requirements set out in R.5 and 10 (para. 829).
  - For domestic delegating relationships, the law is not entirely clear on who is ultimately responsible for CDD (para. 829).
- Record keeping shortcomings:
  - Record keeping requirements are in place, but no express obligation by DNFBPs to keep business correspondence, or to keep transaction records that are detailed enough to permit the reconstruction of individual transactions (para. 830).
- Casinos:
  - Obligation to identify PEPs extends to the actual player and the beneficial owner as far as an ongoing business relationship is established (para. 831).
  - Online casinos need to determine whether a player or beneficial owner is a PEP only for transactions under Art.125 OGO, and land-based casinos only with respect to transactions under Art. 136 of the CO (para. 831).
  - Record keeping requirements are set out under the CO and OGO, with cross references to the DDA and DDO (para. 831).
  - For Recommendations 8, 9, and 11, and in the absence of specific provisions in the CO and OGO, the provisions of the DDA and DDO apply to casinos (para. 831).

### General findings on DNFBP sector risk and awareness
- The DNFBP sector in Liechtenstein is particularly high risk given the services offered and the types of customers served, which are often intermediated, nonresident, and components of existing legal structures (para. 832).
- Industry participants do not sufficiently appreciate the high risk nature of the business; level of comfort with preventive measures was not commensurate with the sector risk (para. 832).
- Representatives from DNFBPs were generally aware of the DDA/DDO, but working knowledge of specific obligations was not commensurate with the high risk nature of the industry (para. 832).

### Real estate agents — implementation and findings
- Real estate representatives:
  - Do not consider their client relationships to be “business relationships” as defined in the DDA, DDO, and industry-specific guidance, viewing relationships as lasting only for a single transaction; therefore they consider themselves required to perform DDA/DDO due diligence only for occasional transactions (para. 833).
  - Do identify their customer and the beneficial owner (rarely different from the customer) as part of the land transfer process, ask if a customer is a PEP, and described having an internal AML program (para. 833).
  - Deposit good faith client funds into an account at an FI and provide necessary due diligence information to the FI (para. 834).
  - Use standard legal forms rather than local lawyers for legal contracts; this can support statements that lawyers generally do not engage in real estate-related DDA activities (para. 834).
- Assessment: The level of CDD implementation by real estate agents appears to be adequate (para. 835).

### Auditors — implementation and findings
- Auditors described due diligence policies as forensic auditors covered by the DDA/DDO (para. 836).
- Some auditors apply simplified due diligence to the majority of customers when the customer is a regulated domestic entity (e.g., a Liechtenstein TCSP) and asserted procedures for identifying the customer and obtaining information to create a customer profile (para. 836).
- Auditors inquire whether the customer is a PEP but did not express additional procedures for verifying the information provided (para. 836).
- Under simplified measures, auditors stated their policies do not include procedures for identifying or verifying the identity of the beneficial owner of their regulated customers (para. 836).
- Risk assessment and monitoring:
  - Auditors use information to develop a risk assessment incorporating factors including jurisdictional risk, corruption index, and the FATF noncompliant list published by the FMA (para. 837).
  - Unclear if this risk rating informed ongoing monitoring; auditors monitor customer relationships and transactions for suspicious activity but unclear if back-office monitoring procedures exist or whether information is kept up-to-date (para. 837).
- Recordkeeping: auditors keep digital copies of documents for at least ten years (para. 837).
- Some firms identify and verify the identity of the customer and beneficial owner (para. 838).
- Deficiencies:
  - Mechanisms for confirming and verifying customer-provided information are weak (para. 839).
  - Questions remain on capabilities to monitor transactions and lack of clear correlation to customer risk; procedures lack mechanisms for identifying suspicious activity (para. 839).

### Lawyers — implementation and findings
- Lawyers consider themselves covered under the DDA only in very narrow circumstances and many law firms state they do not engage in DDA-covered activities (para. 840).
- Many law firms are associated with a separate but related TCSP; lawyers may service both entities and may perform fiduciary activities under the TCSP (para. 840).
- Lawyers generally file annual reports to the FMA stating they engage in no activity covered by the DDA (para. 840).
- Many lawyers could not describe relevant due diligence procedures for covered activity; some lawyers advise on structuring legal entities but do not create them and do not consider such activities covered by the DDA/DDO (paras. 841–842).
- One lawyer who engages in DDA-covered business identified and verified customers and beneficial owners using documents (extract from the register, trust deed, passport), asks about PEP status, keeps information for at least ten years, and noted criminal law requires retention of records for thirty years (para. 842).
- Overall: industry awareness of the DDA/DDO exists but working knowledge is limited; deficiencies relate to understanding interests behind a customer, assessing/managing risk, and ongoing monitoring (para. 843).
- Lawyers tend to associate suspicion with payment by an existing or prospective client rather than with ongoing relationships (para. 843).

### TCSPs — implementation and findings
- TCSPs describe due diligence policies to identify and verify customer and beneficial owner identity and to obtain elements necessary to create a customer profile (para. 844).
- Customers often described as the “contracting party”; beneficial owner as the interested party fronted by the contracting party; any or all can be nonresidents (para. 844).
- Documentation used: excerpt from public registry for Liechtenstein entities; for foreign entities, local registry excerpt, board resolution, power of attorney, or articles of incorporation (para. 845).
- Verification of beneficial owner: some TCSPs accept a beneficial ownership declaration signed by the contracting party; some request passport copy and additional documents in certain circumstances (para. 845).
- Identification of PEPs and risk profiling:
  - TCSPs include PEP identification and asserted they have PEP customers (para. 846).
  - TCSPs develop risk profiles using country of nationality and domicile; country risk is based on public lists including the corruption index and the FATF noncompliant list published by the FMA (para. 846).
- Transaction monitoring:
  - TCSPs monitor customer transactions according to customer risk ratings using transaction parameters assigned by risk level (para. 847).
  - Transaction requests are compared against customer profiles; inconsistencies investigated and justified by relationship managers; compliance function monitors incoming/outgoing transactions and flagged transactions require investigation, documentation, or compliance approval (para. 847).
- Recordkeeping: TCSPs maintain customer files, including identification and verification documents, for at least ten years (para. 848).
- Internal controls: TCSPs have internal AML policy, AML training, and a designated compliance function (para. 849).
- Deficiencies and sector-wide concerns:
  - TCSPs did not appear to appreciate the high risk nature of their industry, services, or customers (para. 850).
  - Awareness of DDA/DDO exists but working knowledge and implementation of obligations varied across TCSPs; some have comprehensive programs, others less familiar (para. 850).
  - Deficiencies include insufficient development of thorough profiles of the entire customer and related parties/structures, unclear understanding of interests behind a customer and beneficial owner, inadequate ongoing monitoring procedures, and weak procedures for identifying and investigating suspicious activity (para. 850).

### Effective implementation — overall assessment
- DNFBP sector dominated by potentially high risk customers and relationships, and dominated by TCSP activity; TCSPs often create and represent legal structures and may take management roles, establishing relationships with FIs and other DNFBPs while entering into a relationship with the customer (para. 851).
- Customers of TCSPs are often nonresidents, may be introduced by intermediaries, and can be part of complex structures; risk amplified by prioritization of confidentiality (para. 851).
- Sector risk characterizations by assessors:
  - Auditors: assessors believe risk is generally not high risk, predominantly due to domestic nature of business (para. 852).
  - Real estate: assessors view risks as not high risk due to very small and highly regulated market (para. 852).
  - Lawyers: not considered high risk because they generally limit activities to civil and criminal legal work, but general lack of knowledge of DDA/DDO policies and procedures is of concern (para. 852).
  - TCSPs: pose a high risk due to engagement with high-risk customers, inconsistent implementation of due diligence across the sector, and a general culture of confidentiality (para. 852).
- Factors undermining effective implementation:
  - Lack of understanding of DDA/DDO obligations and requisite implementing policies among some auditors and lawyers (para. 853).
  - Auditors’ limited understanding of customer relationships undermines effectiveness similar to issues affecting FIs (para. 853).
  - For real estate agents and lawyers, implementation appears commensurate with obligations and sector risk (para. 853).
  - For TCSPs, failures to use reliable information and documentation to understand customer relationships, related legal structures, and relationships to beneficial owners reduce effectiveness (para. 854).
  - Relationships between TCSPs and between TCSPs and FIs can result in incomplete understanding of beneficial ownership, customer fit in larger legal structures, and connecting layers of legal entities/arrangements, causing inability to effectively assess and manage risk (para. 854).
- Reliance and declarations:
  - TCSPs may rely on professionals acting on behalf of a legal entity; a declaration of beneficial ownership provided to the TCSP may itself be based on a declaration from a third party (para. 855).
  - Sector-specific guidance issued by the FMA entitles a trustee to regard a structure as not complex based on certain criteria, including if he or she is involved in its creation (para. 855).
  - Neither the DDA, nor the DDO or the guidance suggest these kinds of structures necessarily pose a high risk, and they are not necessarily subject to enhanced due diligence (para. 855).

*Source: cr18257 (selected excerpts, paragraphs 827–855).*

### 856. Although this assessment did not include Recommendation 24, it was noted that issues

### cr18257 - 856. Although this assessment did not include Recommendation 24, it was noted that issues

### Findings: TCSPs, supervision, and AML framework effectiveness
- Issues related to supervision further undermine the effectiveness of the system, including:
  - Overall allowance for nonlicensed practitioners to operate under a TCSP’s license, which could result in unsuitable people remaining at the helm of a trust company.
  - Infrequent examination cycle with no off-site reporting requirement.
  - Use of audit firms, which creates a potential conflict of interest, which could discourage the audit firm from providing recommendations for improvement if costly to the client.
- The effectiveness of the AML framework is undermined by TCSPs operating in a sector characterized by high risk due to multiple factors including high risk clients and the involvement of foreign intermediaries, that do not effectively implement the policies and procedures necessary to thoroughly understand their customer, beneficial owner, related parties and related legal structures based on exhaustive and credible documentation.
- Ongoing monitoring procedures are ineffective in identifying and investigating suspicious activity.
- Effectiveness is further weakened by issues related to supervision and by uneven implementation of due diligence obligations across the sector.
- Weaknesses with respect to TCSPs have a cascading effect throughout the Liechtenstein financial system due to the culture of trust amongst TCPs and financial institutions, specifically common practice for financial institutions and other DNFBPs to rely on TCSPs for provision and certification of customer information.

### Recommendations and comments (section 5.2.2)
- Consider revising the definition of beneficial owners under Art. 2 of the DDA and Art. 3 of the DDO to expressly cover the settlor of trusts, regardless of whether they maintain express control powers;
- Art. 11 of the DDA should be amended to clearly require verification measures for beneficial owners to be based on reliable sources and not merely on the signature of the contracting party;
- Both for land-based and online casinos, the requirement to link certain transactions to the customer due diligence file should at a minimum apply to all transactions covered under Recommendation 12 that are equal to or in excess of 3,000 euros;
- Require both land-based and online casinos to identify and take reasonable measures to verify the identity of the beneficial owner as required under Recommendation 12;
- Art. 8(2) of the DDA should be revised to impose an obligation on persons subject to the law to carry out reviews of existing records as part of their ongoing CDD, in particular for higher risk categories of customers or business relationships. Such an obligation would augment the industry practice of ad hoc reviews;
- For customers that are natural persons, introduce an express legal obligation for DNFBPs to determine in all cases whether a customer is acting on behalf of another person and to take reasonable steps to obtain sufficient identification data to verify the identity of that other person;
- The blanket exemption for CDD under Art. 10 of the DDA should be removed. Simplified CDD measures should be allowed only in cases of proven low risk, and in all cases at least some minimum level of CDD should be carried out by the DNFBPs in Liechtenstein. Simplified CDD in relation to foreign customers should be allowed only in cases where Liechtenstein (as opposed to the DNFBP) is satisfied that the foreign country in which the foreign customer is located complies with and effectively implements the FATF standard;
- Art. 18(2) should be amended to allow only for verification but not identification measures to be delayed in certain circumstances, and should limit the possibility to delay such verification measures to situations where it can be assured that the delayed measures are carried out as soon as reasonably practicable, and all aspects of the ML risks are effectively managed;
- The legal framework under the DDA should set out an express requirement to apply CDD measures to all existing customers on the basis of materiality;
- Art. 9(2) of the DDA should be rephrased to set out an obligation for persons subject to the law to have in place policies or measures to prevent use of technological developments for ML/FT;
- Consider the need for revising Art. 5(2)(b) of the DDA to require the application of CDD measures also to occasional transactions that are not cash transactions;
- For business relationships with PEPs or beneficial owners that are PEPs, consider aligning the provisions of the DDA and DDO to set out an express obligation for DNFBPs to establish the source of wealth in all cases;
- Consider revising the legal framework to include an express power by the FMA or another competent authority to extend the record retention period; to also require the keeping of business correspondence; and to ensure that transaction records are detailed enough to permit the reconstruction of individual transactions in all cases.
- Require land-based and online casinos to determine in all cases required under Recommendation 12 whether a customer or beneficial owner is a politically exposed person;
- Consider requiring DNPFBPs to increase their due diligence focus towards the beneficial owner of the customer;
- Consider means of ensuring DNPFBPs develop more thorough customer profiles based on reliable information, understanding and documenting how a legal entity customer fits into a broader structural framework and the relationship to the beneficial owner and other relevant parties;
- Regarding information and documentation necessary to understand the relationship amongst legal entity customers, intermediaries, and beneficial owners, particularly in the case of foreign parties, consider clarifying what information and documentation is necessary to effectively undertake this task; and
- Consider requiring the compliance function within a DNPFBP to take an active role in the customer on boarding and transaction monitoring and review processes, and to require compliance and management approval according to risk.

### Compliance with Recommendation 12 (section 5.2.3)
- Rating: R.12 — PC
- Summary of factors relevant to s.4.1 underlying overall rating:
  - Verification measures for beneficial owners and for customers that are legal persons are not in all cases required to be based on independent source documents, data, or information.
  - No obligation to carry out reviews of existing records as part of the ongoing CDD, including for higher risk categories of customers or business relationships.
  - The blanket exemption for CDD under Art. 10 of the DDA is not permissible under the FATF standard.
  - Art. 18(2) is too broad in that it allows not only for verification but also for identification measures to be delayed in certain circumstances. No provision that delayed verification is only allowed where it can be assured that the delayed measures are carried out as soon as reasonably practicable, and the ML risks are effectively managed. No express requirement to apply CDD measures to all existing customers on the basis of materiality.
  - No express obligation to have in place policies or measures to prevent use of technological developments for ML/FT.
  - No obligation for DNFBPs to satisfy themselves that the third party has measures in place to comply with the CDD requirements set out in R.5 and 10.
  - No express obligation to keep business correspondence.
  - No specific requirement that records need to be sufficient to permit the reconstruction of individual transactions.
  - Both for land-based and online casinos, in many instances the threshold for carrying out customer due diligence on transactions is too high.
  - Land-based and online casinos are not required to identify and take reasonable measures to verify the identity of the beneficial owner in all cases required under Recommendation 12.
  - Land-based and online casinos are not required to determine whether a customer or beneficial owner is a politically exposed person in all cases required under Recommendation 12.
- Effectiveness issues:
  - Inconsistent application of due diligence measures across DNFBPs, with gaps in implementation of essential measures.
  - Implementation of due diligence measures falls short of the enhanced due diligence measures required for higher risk categories, which are characteristic of the financial system.
  - Lack of emphasis on understanding the nature and purpose of the relationship, including understanding related legal structures and the relationship to the beneficial owner.
  - Reliance on foreign intermediaries and introducing parties, without appropriate mechanisms in place to ensure access to complete and verified information and documentation regarding the relevant parties.

### Suspicious Transaction Reporting (R.16 — description and analysis, section 5.3)
- Summary of 2007 MER factors and progress:
  - In 2007, Liechtenstein law did not require reporting of attempted suspicious transactions, or of transactions suspected to be linked or related to, or to be used for terrorism, terrorist acts, or by terrorist organizations. The SAR reporting rates for DNFBPs was low. The tipping-off provision applied only for a maximum of 20 days and did not cover directors, officers, and employees. There was no explicit requirement to pay special attention to business relationships and transactions with persons from or in countries which do not or insufficiently apply the FATF Recommendations.
  - The DDA and DDO have been revised since 2007 and now provide for more comprehensive suspicious transaction reporting and internal control obligations.
- Legal framework:
  - Due Diligence Act (DDA);
  - Due Diligence Ordinance (DDO);
  - Gambling Act (GA);
  - Online Gambling Ordinance (OGO);
  - Casino Ordinance (CO).
- Scope and reporting obligations:
  - Provisions discussed under Recommendation 13–15 apply equally to DNFBPs.
  - For real estate agents, the DDA only applies when they are involved in the purchase or sale of real estate; this limitation is acceptable for CDD under R.12 but the FATF standard for R.16 does not provide such a restriction.
  - For lawyers and legal agents, auditors, auditing companies and audit offices under special legislation, Art. 17(2) of the DDA limits the obligation to submit STRs to exclude situations where information is received from or on a client in the course of ascertaining the legal position for their client or while performing their task of defending or representing that client in or concerning judicial proceedings. Such a limitation is in line with the FATF Recommendations.
- Casinos:
  - The GA, the OGO and the CO set out specific CDD requirements that apply in addition to those under the DDA and DDO.
- Requirement to make STRs on ML and TF to FIU (applying c. 13.1 and IV.1 to DNFBPs):
  - Where a suspicion of ML, a predicate offense of money laundering, organized crime, or FT exists, DNFBPs are required to immediately report in writing to the FIU (Art. 17 of the DDA).
  - The reporting requirement is a direct mandatory obligation and is based on a subjective test of suspicion. The objective test does not apply.
- STRs related to terrorism and its financing (applying c. 13.2 to DNFBPs):
  - Art. 17 of the DDA requires DNFBPs to report in writing to the FIU when, inter alia, a suspicion of FT and predicate offenses exists. The reference to predicate offenses covers all the circumstances covered under this criterion since terrorist acts and organizations are criminal acts and predicate offense to ML in Liechtenstein.
- No reporting threshold for STRs (applying c. 13.3 and IV.2 to DNFBPs):
  - All suspicious transactions must be reported to the FIU irrespective of any the amount involved.
  - Art. 18(1) of the DDA prohibits DNFBPs from executing any transactions which they know or suspect to be related to ML, predicate offenses of ML, organized crime, or FT. Such transactions must be reported pursuant to Art. 17. A combined reading of these two articles appears to sufficiently cover the requirement to report attempted transactions.
- Making of ML and TF STRs regardless of possible involvement of fiscal matters (applying c. 13.4 and c. IV.2 to DNFBPs):
  - The reporting requirement does not contain any restrictions relating to tax matters.
- Additional element—reporting of all criminal acts (applying c. 13.5 to DNFBPs):
  - DNFBPs are required to report to the FIU when a suspicion that any criminal activity which constitutes a predicate offense exists domestically. Classification as an offense committed in Liechtenstein requires that the act is also considered a predicate offense under Liechtenstein law, even if the punishable act is considered a predicate offense only in Liechtenstein.
- Protection for making STRs (applying c. 14.1 to DNFBPs):
  - Art. 19 of the DDA protects persons DNFBPs or managers or employees from any civil or criminal liability if they have reported a SAR to the FIU, and it later turns out that the report was not justified, provided the person did not act willfully.
  - During the onsite mission, it was pointed out that Art. 19 is not entirely in line with c. 14.1 since the latter refers to exemption from liability when a report is submitted in good faith. The FIU explained that the German translation of the word “willfully” is more akin to the good faith principle. Under the German text, a reporting entity would not be held civilly or criminally liable, unless the person knew that the report was not warranted and acted in bad faith.
- Prohibition against tipping-off (applying c. 14.2 to DNFBPs):
  - Pursuant to Art. 18, para. 3 of the DDA, DNFBPs may not inform the contracting party, beneficial owner or third party that they have submitted a SAR to the FIU pursuant to Art. 17 of the DDA.
  - This provision does not cover directors, officers and employees (permanent or temporary) as required under c.14.2. Additionally, the prohibition only applies to the SAR and not to related information.
  - Authorities explained that Art. 18, para. 3 is interpreted by all practitioners to also include directors, officers, and employees. This was confirmed by a court judgment where the director of a trustee company that had submitted a SAR was fined CHF 7,500 for having disclosed to a third party that a SAR had been submitted to the FIU.
  - The tipping-off prohibition is subject to a number of exemptions. The FMA may be informed by the reporting entity of the submission of a SAR. Art. 18, para. 4 further permits communication on SARs between:
    - members of the same financial group;
    - trustees, lawyers, accountants, and auditors within the same legal person or within a network; and
    - trustees, lawyers, accountants, and auditors, provided they are involved in the same fact pattern and the information may only be used to combat ML/FT.
- Additional element—confidentiality of reporting staff (applying c. 14.3 to DNFBPs):
  - Under Art. 10 of the FIU law the obligation to release information does not extend to the origin of the data and the recipients of transmissions.
  - Pursuant to Art. 5, para. lett. b), the FIU is required to submit a copy of the SAR to the Office of the Public Prosecutor. In those cases where the DNFBPs submitting the report are natural person, this would result in their names and personal details being disclosed.
- Establish and maintain internal controls to prevent ML and TF (applying c. 15.1; 15.1.1; and 15.1.2 to DNFBPs):
  - Arts. 30 and 31 of the DDO require DNFBPs to have in place internal controls and procedures, including in relation to CDD, record keeping, and the detection of unusual or suspicious transactions and the reporting obligation to the FIU.
  - Art. 22 of the DDA and Arts. 34 and 36 of the DDO further require that every DNFBP appoints a compliance officer. There is no specific obligation for the compliance officer to be at a management level.
  - Art. 28(6) of the DDA grants the compliance officer access to any CDD files, transaction records or other relevant information.
- For casinos, Art. 149 of the CO and Art. 138 of the OGO set out a specific obligation to issue internal instructions on how to implement the obligations under the GA and DDA, and to make these instructions known to all employees of the casino.
- Independent audit of internal controls to prevent ML and TF (applying c. 15.2 to DNFBPs):
  - For casinos, both the CO and OGO require casinos to have in place an audit function.
- Ongoing employee training on AML/CFT matters (applying c. 15.3 to DNFBPs):
  - Art. 32 of the DDO requires DNFBPs to ensure that employees involved with business relationships receive comprehensive and up-to-date basic and continuing training, including on regulations concerning AML/CFT and the obligations arising out of the DDA and DDO, and the relevant provisions of the Criminal Code, and the DNFBPs internal instructions.
  - For casinos, both the CO and OGO require casinos to have internal policies in place for ongoing employee training.
- Employee screening procedures (applying c. 15.4 to DNFBPs):
  - Art. 31 provides that the internal procedures and guidelines must set out adequate verification measures to be applied when hiring new employees in order to ensure high standards in regards to their reliability and integrity.
  - For casinos, both the CO and OGO require casinos to have internal policies in place for screening procedures for new employees.
- Additional element—independence of compliance officer (applying c. 15.5 to DNFBPs):
  - The DDA or DDO do not expressly require that the compliance officer be independent but indicate that the compliance manager shall support and advise management in the implementation of the DDA and DDO and develop the relevant internal procedures to implement the law.
- Special attention to countries not sufficiently applying FATF Recommendations (c. 21.1 and 21.1.1):
  - Art. 11 of the DDA provides that enhanced CDD and more intense monitoring needs to be applied to business relationships and transactions with contracting parties or beneficial owners in countries whose measures to combat ML or FT do not or do not sufficiently meet the international standard.
  - The provision is in need of further revision to require enhanced CDD not only with respect to persons in but also to persons from high risk countries.
- Examinations of transactions with no apparent economic or visible lawful purpose from countries not sufficiently applying FATF Recommendations (c. 21.2):
  - For all transactions provided under Art. 11(6) DDA as described under Section 3, the background and purpose has to be clarified and recorded in writing, regardless of whether the transaction has an apparent economic or legal purpose or not.
  - Records obtained pursuant to Art. 11 (6) DDA are considered transaction-related records under Art. 20 of the DDA and must thus be maintained in such a manner that requests from competent authorities can be complied with within a reasonable period of time.

*Source: cr18257 - 856. Although this assessment did not include Recommendation 24, it was noted that issues (PDF).*

### 882. Art. 11(7) of the DDA grants the government of Liechtenstein the power to impose

### cr18257 - 882. Art. 11(7) of the DDA grants the government of Liechtenstein the power to impose

### Implementation — Sectoral findings
- Art. 11(7) of the DDA grants the government of Liechtenstein the power to impose notification requirements for business relationships and transactions with contracting parties or beneficial owners from or in countries permanently included on the list of high risk jurisdictions. Apart from such notification requirements, no other provisions grant the government or any authority in Liechtenstein the power to issue and enforce countermeasures in relation to transactions or business relationships involving high risk countries.

Real Estate Agents
- Representatives were aware of the obligation to report suspicious activity to the FIU when it suspects funds are related to illicit activity or FT as it relates to activities covered by the DDA/DDO.
- The FIU has never received a SAR from real estate agents.
- Representatives discussed having an internal compliance policy and providing training as necessary, but were not audited.

Auditors
- Auditors interviewed were aware of the obligation to report suspicious activity to the FIU and had policies in place to do so.
- Annually, the FIU generally receives a low number of SARs from auditors.
- SARs filed generally involved information regarding the customer of an auditor’s customer, arising during an onsite audit.
- Some audit firms reported internal written procedures, a dedicated audit function, and periodic training. Others reported no formal internal AML program and no training.

Lawyers
- Lawyers interviewed generally stated they do not engage in activities covered by the DDA/DDO, but were aware of the obligation to report suspicious activity to the FIU when suspecting funds related to illicit activity or FT.
- Annually, the FIU receives few SARs from lawyers, commensurate with the sector’s risk level; SARs generally involve suspicions regarding payments for services rendered.
- Lawyers not engaged in DDA/DDO activities were aware of their obligation to submit annual reports to the FMA declaring as such, but did not describe internal policies, training, or audit.
- Lawyers engaged in activities covered by the DDA/DDO (although small) asserted having a policy and conducting training as necessary.

TCSPs
- TCSPs described procedures for identifying, investigating, and reporting suspicious activity to the FIU.
- Similar to FIs, triggers for investigating a transaction tend to stem from news reporting rather than ongoing monitoring.
- Annually, the FIU receives a consistent number of SARs from TCSPs, which is less than half of those submitted by banks.
- TCSPs stated they have an internal AML policy provided to employees, internal procedures for AML training, and a designated compliance function.

Reported SAR counts by DNFBP sector (as presented)
- Professional trustees: 2009 748; 2010 767; 2011 76; 2012 Jan.-June 38
- Lawyers: 2009 56; 2010 52; 2011 4
- Auditors: 2009 123; 2010 14; 2011 0
- Dealers in precious goods: 2009 0; 2010 0; 2011 1; 2012 2
- Real estate agents: 2009 0; 2010 0; 2011 0; 2012 0

### Effective implementation — assessors’ observations
- Authorities indicated TCSP business has diminished considerably in recent years due to external economic factors; number of reports from the sector has remained constant, indicating proportionate increase in reporting.
- Assessors expressed concern regarding triggers for filing SARs: TCSPs and other DNFBPs often reference external news reports as the trigger rather than monitoring or suspicious behavior in the business relationship.
- Representatives were generally unable to provide examples of SARs resulting from monitoring of a business relationship or from suspicious behavior displayed by the customer.
- Internal AML programs varied across DNFBP sectors according to the amount of DDA-covered activities undertaken.
- Inconsistencies in internal programs can negatively affect the overall framework’s effectiveness.

### Recommendations and comments (section 5.3.2)
- Art. 11(6) of the DDA should be further revised to require enhanced CDD not only with respect to persons in but also to persons from high risk countries;
- Ensure that DNFBPs understand the obligation to carry out enhanced CDD under Art. 11(6) of the DDA as mandatory;
- There should be a specific obligation for the compliance officer to be at a management level;
- Grant the government or any authority in Liechtenstein the power to issue and enforce a wider range of countermeasures in relation to transactions or business relationships involving high risk countries;
- Art. 18, para. 3 of the DDA should be amended to extend the tipping-off prohibition to a person’s directors, officers, and employees (permanent or temporary) of a reporting entity as required under c.14.2. Additionally, the prohibition should apply not only to the SAR but also to related information;
- Review the level and type of reporting by DNFBP sectors and institutions to identify challenges related to reporting, and, where gaps are identified, take measures necessary to facilitate effective reporting;
- Consider means of facilitating and clarifying reporting with respect to suspicious activities or transactions not associated with any criminal activity;
- Consider removing the automatic asset freezing mechanism that accompanies reporting;
- Consider means of promoting the development of useful internal policies, accompanied by training, in all DNFBPs;
- The FIU should not be required to disseminate the SAR itself to the OPP as stated in Art. 5, para. 1, let. b) of the FIU Act.

### Compliance with Recommendation 16 — summary (section 5.3.3)
- Rating: R.16 C
Factors underlying overall rating
- There is no specific obligation for the compliance officer to be at a management level.
- Art. 11(6) of the DDA does not require enhanced CDD with respect to persons from (as opposed to in) high risk countries.
- No sufficient wide power to issue and enforce countermeasures in relation to transactions or business relationships involving high risk countries.
- The tipping-off prohibition does not apply to information related to a SAR.

Implementation observations
- Inadequate understanding of reporting requirements by DNFBPs.
- Low number of SARs, except for TCSPs.
- Internal programs are not developed by all DNFBPs.
- Training is not undertaken by all DNFBPs.
- Audit functions to test compliance are not utilized by all DNFBPs.

### Legal persons and arrangements — access to beneficial ownership and control information (beginning of section 6)
- The 2007 MER identified issues: beneficial ownership notion not extending to controllers without economic rights; lack of obligation for intermediaries to verify beneficial ownership information; no measures ensuring information on beneficial ownership and control of legal entities commercially active in the domiciliary state is obtained, verified, and kept in all cases.
- Since the previous MER: DDO definition of beneficial owner amended to extend to controllers of legal entities; Law on Foundation (2008) revised; reform of bearer shares and certificates; requirements introduced for certain types of companies to keep shareholders registers at the registered seat of the company (December 2012).
- Issues remain regarding adequacy, accuracy, and timely access to beneficial ownership information.

Legal framework cited
- Persons and Companies Act (PGR);
- Professional Trustees Act (PTA);
- Customer Due Diligence Act (DDA).

Measures to prevent unlawful use of legal persons (c. 33.1)
- Liechtenstein implements R33 requirements:
  - system of central registration of legal entities;
  - TCSPs’ implementation of preventive measures under the DDA and DDO (including identification and verification of beneficial owners, although verification of the beneficial owner is not based on documents);
  - Art. 180a PGR requires that entities not commercially active have at least one member authorized to manage and represent the legal entity licensed as a trustee (180a PGR Director) and hence subject to the DDA/DDO;
  - reliance on FMA powers to demand from persons subject to preventive measures “all information and records it requires to fulfill its supervisory activities for the purpose of the DDA” (Art. 28.4 DDA). Where legal entities are not subject to the DDA, authorities can rely on investigative and prosecutorial measures under Recommendation 3.

Central registration (Office of Justice / Commercial Registry)
- The OJ maintains a Commercial Registry (CR). The PGR requires certain data concerning legal entities to be notified to the OJ and entered in the CR. This information is publicly available.
- Certain information is “deposited” with the OJ but not entered in the CR; deposited information is not publicly accessible but can be requested by any member of the public who can assert a legitimate interest or with authorization of the legal entity concerned.
- For nonregistered foundations (or notifications of formation and amendments for foundations not entered in the CR), inspection of deposited files and documents can only be demanded by the depositor, the person empowered for this purpose, and universal successors. The OJ can confirm the existence of a foundation or trust not entered in the CR.
- Art. 120 PGR and other PGR provisions require notification of changes of information required to be provided to the OJ. Deliberate failure to register or to notify required information is punished with an administrative fine up to CHF 5,000.
- The report includes a detailed breakdown by type of entity of what information is entered in the CR or deposited with the OJ, obligations to notify changes, sanctions for non-compliance, and conditions to access the information.

*Source: IMF assessment document (excerpts).*

### 953.5 PGR)

### 953.5 PGR)

### Registration requirements and scope
- With the notable exception of private purpose foundations and some types of associations, all other legal persons are required to register in the public registry (CR) (paragraph 899).
- Formal legal ownership (members/owners) is available in the CR only for:
  - Limited Liability Company,
  - Limited Partnership with share capital (but only members bearing unlimited liability),
  - Cooperatives (only members bearing unlimited liability),
  - Associations (paragraph 899).
- Foundations:
  - The certification required for “deposited” foundations was introduced with the reform of 2008 and is not applicable to foundations established prior to the entry into force of the reform (the OJ estimates these foundations are approximately 3,000; the new “deposited” ones are 28,815) (paragraph 899 and note).
- No information on beneficial ownership or beneficiaries is entered in the CR or deposited with the OJ (paragraph 900).
- Deeds of foundations subject to registration or anstalten may contain beneficiaries, but this is very seldom the case; beneficiaries or classes of beneficiaries are typically named in regulations/bylaws that are not required to be entered in the CR or deposited with the OJ (paragraph 900).

### Typical practices for founders, trustees, and nominees
- It is common practice that a trustee or lawyer acting as trustee forms an establishment (anstalt) in a fiduciary capacity; in such cases the trustee’s name appears in the register as founder (paragraph 900).
- The “real” or “de facto” founder (person funding the foundation or anstalt) is recognized in law, and founder’s rights are typically transferred by cession of title to the real founder; this transfer is not subject to submission to the OJ (paragraph 900).
- If no third parties are appointed as beneficiaries of an anstalt, it is assumed that the bearer of the founder’s rights is the beneficiary (Art. 545.1 bis PGR) (paragraph 900).
- There is no requirement to enter the settlor of the trust enterprise in the CR (paragraph 900).

### Accessibility, notification obligations, and sanctions
- Registered information accessibility varies by entity type:
  - All registered information accessible to the public without need of justified interest in some cases (Art. 953.5 PGR) (table entries).
  - Registered files are not accessible to the public, except when there is justified interest substantiated by prima facie evidence (Art. 953 PGR) (table entries).
  - Documents submitted to the OJ are generally not accessible to the public, except when there is justified interest substantiated by prima facie evidence (Art. 953 PGR) (multiple table entries).
- Obligation to notify CR of any changes: Art. 120 PGR; Art. 965 PGR; Art. 41 HRV (repeated across entity types in table).
- Sanctions for noncompliance: administrative fines (Art. 968 PGR, Art. 977 PGR and § 65 SchlTPGR) (table entries).
- Implementation realities:
  - The Office of Justice (OJ) is staffed with 17 persons and there are more than 53,000 entities registered in the CR or otherwise deposited or notified with the OJ (paragraph 901).
  - No sanctions have ever been issued for failure to comply with notification/registration requirements; authorities state they would request firms to comply rather than impose sanctions (paragraph 901).
  - Sanctions are limited in amount (up to CHF 5,000) and appear not dissuasive (paragraph 901).
  - Authorities do not perform active controls regularly due to limited resources and reliance on legal certainty of registration (paragraph 901).
- Supervision of common-benefit foundations:
  - The FSA inspects approximately 50 foundations per year, selecting them randomly but ensuring the sample covers small, medium and large offices (footnote 58 / paragraph 901).

### Share registers and company-level requirements
- Joint Stock Companies and Limited Partnerships with share capital (for registered shares) are required to record the names of shareholders; PGR amendments adopted on December 21, 2012 came into force on March 1, 2013 and made it compulsory for these companies to maintain at the company’s headquarters a register of the owners of the shares (Art. 329a PGR; Art. 328 PGR) (paragraph 902).
- Share register must contain:
  - name of the shareholder,
  - birth date,
  - nationality,
  - place of residence,
  - or legal business name and place of business (Art. 328 PGR) (paragraph 902).
- For companies subject to mandatory audit requirements, compliance with the duty to maintain the share register must be examined as part of the annual audit or review (Art. 326a PGR). The reviewer must report deficiencies immediately to the Office of Justice (Art. 326i.2 PGR), which must request remediation and fix a deadline; the Office of Justice must report to the Regional Court if deficiencies are not remedied (Art. 326i.2 PGR) (paragraph 902).

### Reliance on TCSPs, DDA coverage, and challenges
- Authorities rely on TCSP to obtain, verify and retain records of the beneficial ownership and control structure of legal persons; there are legal and effectiveness challenges to this approach (paragraph 903).
- Noncommercially active entities are required to have an Art. 180a PGR director, triggering CDD requirements of the DDA/DDO through the mandatory licensing regime as a professional trustee; this requirement does not apply to commercially active companies (paragraph 903 and footnote 59).
- Every legal entity that operates a commercial business is required by Art. 192(8) PGR to have accounts audited by external auditors or prepared by external accountants, who are also covered by the DDA/DDO (paragraph 903).
- The DDA applies to persons who provide a registered office, business address, correspondence, or administrative address and other related services on a professional basis; limitation to professional basis could leave private trustees or private providers outside the DDA, although jurisprudence interprets “professional basis” broadly (paragraph 904 and footnote 61).
- The DDA applies to natural and legal persons acting as nominee shareholder for another person, with exceptions for listed companies subject to EEA or equivalent international standards (footnote 62 / paragraph 904).
- Business practice for trustees:
  - Liechtenstein trustees are often introduced to new clients through foreign counterparts (trustees, lawyers, TCSPs, FIs).
  - In practice Liechtenstein trustees often accept a declaration from the foreign counterpart on beneficial ownership plus a copy of an identification document of the person identified as beneficial owner; obtaining such documents does not strictly require more verification (paragraph 905).
  - This practice may not be sufficient to identify the real beneficial owner in complex ownership structures (example given of multi-jurisdictional layered foundations) (paragraph 905).

*Source: cr18257 - 953.5 PGR) PDF chapter/section*

### 906. An additional challenge is that, in this scenario in which foreign trustees, lawyers or other

### 906. An additional challenge is that, in this scenario in which foreign trustees, lawyers or other

### Access to Information on Beneficial Owners of Legal Persons (c. 33.2)
- Liechtenstein relies on supervisory powers of the FMA to obtain or have access to beneficial ownership information, envisaged by Article 28.4 of the DDA: the FMA may demand “all information and records it requires to fulfill its supervisory activities for the purposes of this Act” (the DDA).
- The power can only be exercised to fulfill the supervisory responsibilities of the FMA, which narrows the scope.
- Authorities can also rely on search and seizing powers under the CPC, with issues noted elsewhere that may affect those powers.

### Legal and implementation issues (access to BO information)
- Information can only be requested for the purpose of supervisory activities, limiting the scope of the power.
- The FMA has successfully compelled information, including information subject to confidentiality, in the context of supervisory functions; assessors have reservations about exercising those powers outside that context (for example to exchange information with domestic counterparts).
- No practical cases exist demonstrating use of the power outside supervisory context.

### Nominee directors and shareholders
- Nominee directors and shareholders are permitted and frequently used, especially for foundations and anstalten.
- Natural and legal persons who act as nominee shareholders are subject to the DDA (Art. 3.1.s) and to the requirement to identify and verify beneficial owners, but:
  - The law does not require a nominee shareholder to disclose that he acts on behalf of the beneficial owner.
  - The register of shareholders does not identify nominee shareholders.
  - The DDA exempts application if the professional nominee shareholder holds shares in a company listed on a regulated market in conformity with EEA law or equivalent international standards, or to the extent they provide the possibility for another person to carry out that function.
- DDA provisions do not specifically apply to nominee directors. Authorities consider nominee directors would be covered by Art. 3.1.t (covering natural and legal persons who, on a professional basis and on the account of a third party, act as governing bodies or comparable functions), but Art. 3.1.t does not specifically refer to nominees.
- No obligation exists for nominee directors to disclose on whose behalf they act.

### Implementation issues — FMA powers and DNFBPs/TCSPs
- The DDA power of the FMA to obtain information or request documents from FIs/TCSPs outside supervisory functions has never been tested; assessors have reservations it could be exercised.
- For obtaining information from FIs, the FMA uses powers envisaged by the banking and securities law.
- Authorities demonstrated ability to use DDA power to compel information from DNFBPs, particularly TCSPs, in the context of supervisory functions, even for information covered by secrecy.
- Firms interviewed had mixed views:
  - Majority view: powers apply only during onsite inspections, not to requests outside that process.
  - Some would not allow auditors carrying inspections on behalf of the FMA to obtain the information.
  - Very few were uncertain; many would argue confidentiality or privilege as defense.
- Concerns raised about timeliness and adequacy/accuracy of information given:
  - Reliance on foreign introducers.
  - Uneven implementation of CDD by DNFBPs; trustee business identified as one of the weakest links.

### Prevention of Misuse of Bearer Shares (c. 33.3)
- Under Liechtenstein law, bearer shares or instruments (Inhaberaktien, Inhaberpapiere, Treuhandzertifikate) can be issued by joint stock companies, limited liability companies (Art. 323 PGR), cooperatives (Art. 447 PGR), Versicherungsvereinen auf Gegenseitigkeit und Hilfskassen (Art. 508 PGR), foundations (Art. 567.4 PGR in connection with Arts. 928.1 and 3 PGR), limited partnership with share capitals and trust enterprises. Trusts can also issue bearer paper (certificates embedding beneficiary’s rights).
- Law no. 67/2013 (entered into force March 1, 2013) requires immobilization of bearer shares through deposit with a custodian, who must maintain a register containing certain information.
- Immobilization is not required for bearer shares of entities for joint investments in securities, investment funds and investment companies.
- The new regime does not necessarily ensure identification of the real beneficial owner in all instances.

### Custodian (requirements)
- The custodian is appointed by the company (or the court), must be entered in the CR with reference to functions, and must be either:
  - Subjected to the DDA or a regulation and supervision abroad equivalent to Directive 2005/60/EC (Art. 326.b.2.1 PGR); or
  - If not subject to regulation under point 1, have registered office or residence in Liechtenstein and have an account in Liechtenstein or another EEA member state in the name of the shareholder (Art. 326.b.2.2 PGR); or
  - In the case of legal persons under Art. 180a, para. 3, need not be subject to the DDA or equivalent regulation or have a registered office or residence in Liechtenstein; a bank account in Liechtenstein or another EEA member state in the name of the shareholder shall suffice (Art. 326.b.2.3 PGR).
- Custodians are not always professional intermediaries subject to DDA requirements and thus may not be required to identify and verify the beneficial owner.

### Information required to be registered
- The share register must be kept at the registered office of the company, which must be in Liechtenstein (Arts. 113 and 232 PGR).
- For each bearer share the register must contain: the shareholder’s name, birth date, nationality, and residence or legal business name and place of business, the date of deposit and, as the case may be, an account in Liechtenstein or another EEA member state in the name of the shareholder.

### Transitional regime for bearer shares
- Bearer shares issued prior to March 1, 2013 must be deposited with a depository for registration by March 1, 2014.
- After expiry of that period, bearer shares may be registered only if the affected shareholder presents a decision of the Court of Justice stating the shareholder is the rightful owner.
- After March 2024, all bearer shares not yet registered are to be declared null and void by the company and no more rights shall result from such shares.
- Bearer securities of other entities connected to a membership or purchase right shall be destroyed or converted to registered securities by March 1, 2014; after expiry, no more rights may be claimed on basis of such shares.
- The law provides that a register of certificates be established and maintained by the trustee “similar to the share register.” It is unclear whether trust certificates envisaged by Art. 928 PGR that grant beneficiary creditor rights (not “connected to a membership or purchase rights”) are covered.
- Authorities consider new bearer shares would follow the same regime, but the law is silent on issuance of new shares after March 1, 2013.
- The transitional duration (10 years) before completely phasing out bearer shares is considered too long.

### Voting rights and transfer of bearer shares
- Shareholders’ rights arising from a bearer share may only be claimed if the share has been deposited and all information on the bearer shareholder is registered (Art. 326f).
- The custodian is entitled to exercise voting rights, with or without instructions (instructions can be given by the shareholder or the board of directors).
- Transfer by the shareholder is subject to notification to the custodian, must include last name and first name, date of birth, citizenship, and residence or business name and registered office of the acquirer. Transfer becomes effective upon entry of acquirer in the register (Art. 326h).
- If custodian exercises voting rights, he shall request instructions prior to every general meeting; if instructions cannot be obtained in time, custodian shall exercise voting rights in accordance with a general instruction by the bearer shareholder; only if no instruction exists shall the custodian follow proposals of the board of directors (Art. 326g PGR).
- Custodian may surrender bearer shares only upon termination of custodian's function to successor custodian; upon conversion into registered shares to the company; or upon redemption, retraction, or amortization to the company (Art. 326e PGR).

### Sanctions for noncompliance (custodian duties)
- Compliance verified as part of annual audit or review and confirmed by the person conducting the audit or review (Art. 326i PGR).
- If deficits are discovered, the person conducting the audit/review must immediately transmit a report to the OJ. The OJ shall set a deadline and require custodian to remedy deficits. If not remedied, the Court of Justice shall file a criminal complaint.
- Other instances require immediate filing of a criminal complaint by the OJ.
- There are sanctions for noncompliance concerning custodian requirements, but not for noncompliance with the obligation to deposit the shares and to appoint the custodian.
- On information from the Office of Justice:
  - The Court of Justice may in line with § 66d SchlTPGR in noncontentious proceedings impose an administrative fine of up to 10,000 francs on anyone who as a custodian:
    - fails to keep the share register properly in accordance with Art. 326c Abs. 1 PGR; or
    - issued a confirmation about deposit of bearer shares in accordance with Art. 326c Abs. 6 PGR; or
    - surrenders bearer shares contrary to Art. 326e PGR; or who as the person who conducted the audit or the review, provides an incorrect confirmation pursuant to Art. 326i PGR or fails to transmit the report pursuant to Art. 326i, Abs. 2 PGR.
  - This administrative fine may be repeatedly imposed until lawful status is produced.
  - If the perpetrator acts negligently, the administrative fine shall be up to 5,000 francs.

### Legal and implementation issues (bearer shares)
- Immobilization and registration system is positive, but challenges remain:
  - Immobilization and registration may not always result in identification of beneficial owners because nominal share problems persist (nominee shareholders, legal entities holding nominal shares).
  - Custodians are not always subject to the DDA (Art. 326(b)(2)(2) grants persons not within DDA scope to act as custodians under certain situations), so they would not have to identify and verify BO.
  - New requirements do not explicitly prohibit issuance of new shares; deposit requirement concerns only bearer shares issued prior to March 1, 2013.
  - Authorities state for companies founded prior to March 1, 2013 the new provisions apply at the latest after end of transitional period (March 1, 2014).
  - Other mitigating factors: requiring all payments by the company to the shareholder to be made to the registered account in circumstances under Art. 326b, para. 2(2) and (3).
  - Duration of transitional regime (10 years) before phasing out bearer shares is considered too long.

### Additional Element — Access to Information on Beneficial Owners of Legal Persons by Financial Institutions (c. 33.4)
- Financial Institutions only have access to information that is publicly available in the CR or deposited with the OJ (for the latter, they must demonstrate a legitimate interest).
- Apart from CDD process (with limitations described under R.5), financial institutions have no other access to beneficial ownership information.

### Effective Implementation and entity counts (as of December 31, 2012)
- Liechtenstein has a liberal regime for creating legal entities, professionals specializing in creation of complex legal structures, and a favorable tax regime, making it attractive for incorporation and registration.
- Total number of registered/deposited entities as of 12/31/2012 (also showing figures for 2011 and new entries/deletions):
  - Sole trader: By 12/31/2011 614 | New entries 30 | Deletions 100 | By 12/31/2012 544
  - Collective partnership (Kollektivgesellschaft): 19 | 1 | 0 | 20
  - Joint Stock Company (AG): 6,573 | 266 | 583 | 6,256
  - Limited liability company (GmbH): 114 | 24 | 11 | 127
  - Cooperative: 19 | 1 | 2 | 18
  - Commercial or noncommercial association: 232 | 26 | 4 | 254
  - Registered foundation (Stiftung): 1,806 | 110 | 107 | 1,809
  - Limited partnership (Kommanditgesellschaft): 18 | 3 | 0 | 21
  - Limited partnership with share capital (KomAG): 0 | 0 | 0 | 0
  - Registered trust (eingetragene Treuhänderschaft): 2,764 | 212 | 310 | 2,666
  - Establishment (Anstalt): 11,486 | 222 | 1,125 | 10,583
  - European joint-stock company (SE): 5 | 0 | 0 | 5
  - European economic interest association (EWIV): 0 | 1 | 0 | 1
  - Trust Enterprise (Trust reg.): 2,018 | 15 | 222 | 1,811
  - European Cooperative: 1 | 0 | 0 | 1
  - Subsidiary of an enterprise with domicile within EEA: 5 | 4 | 0 | 9
  - Subsidiary of an enterprise with domicile outside of EEA: 95 | 3 | 3 | 95
  - New deposited foundations (nonregistered foundations pursuant to Art. 552, para 19 PGR): 32,425 | 534 | 4,144 | 28,815
  - Deposited trust: 197 | 3 | 29 | 171
  - Total all legal entities: 58,391 | 1,455 | 6,640 | 53,206

*Source: cr18257 - 906. An additional challenge is that, in this scenario in which foreign trustees, lawyers or other*

### 931. The number of registered or otherwise deposited entities is quite high, although there has

### cr18257 - 931. The number of registered or otherwise deposited entities is quite high, although there has

### Assessment of beneficial ownership transparency and overall findings
- The number of registered or otherwise deposited entities is quite high, although there has been a decrease, since 2011.  
- Authorities attribute the decrease mainly to Liechtenstein’s signing of several agreements concerning the exchange of information on tax matters with the U.S. and the EU and on its greater transparency.  
- Significant improvements since the previous assessment have been made, including with regard to R.33, but significant challenges to effective implementation remain.  
- Creation of complex legal structures is identified as posing a risk (authorities and assessors concur).  
- There is an inherent risk that beneficial ownership information is not always accurate, adequate, or accessible to authorities on a timely basis; legal and implementation issues affect the effectiveness of measures to prevent unlawful use of legal persons by money launderers.

### Implementation of CDD requirements and TCSP capacity
- The system to prevent unlawful use of legal persons relies mainly on the CDD obligations to which TCSPs are subject, complemented by powers of competent authorities to access or compel information.  
- The real capacity of TCSPs to effectively implement CDD requirements and to obtain, verify, and retain accurate and adequate beneficial ownership information is of paramount importance.  
- Analysis of R.12 reveals an uneven and at times unsatisfactory level of implementation of CDD-related requirements, with TCSPs relying heavily on introducers.  
- Reliance on declarations from foreign introducers (other trustees or lawyers) may lead to mistaken or inaccurate beneficial owner information held by Liechtenstein trustees.  
- TCSPs are subject to inspection every three years (unless reason to impose a more frequent cycle), which may not enable supervisory authorities to properly check effective implementation of CDD requirements.  
- Assessors consider the whole sector of TCSPs to be among the riskiest in Liechtenstein.

### Access to beneficial ownership information by authorities
- Authorities indicate the DDA information powers give them the power to access beneficial ownership information, and they have used those powers, but such power has not been exercised outside supervisory functions of the FMA.  
- Authorities believe the DDA permits passing beneficial ownership information to other domestic authorities, but contradictions in the law may challenge this; the issue has not been tested in court.  
- Current legal system limitations for prosecutors and law enforcement reduce effectiveness of access to beneficial owner information: Art. 98a restricts access to documents held by trustees, and the broad definition of privilege extends beyond proceedings to auditors.

### Risks arising from types of legal institutions and structures
- Deposited foundations and anstalten can be used as placeholders for more complex structures; their regime has elements challenging the identification of beneficial owners or beneficiaries (use of agents to establish these entities; identification of beneficial owner and beneficiaries in bylaws that are not subject to registration or deposit with the OJ and may not always be maintained by TCSPs, especially with foreign introducers).  
- The regime reliance on DNFBPs and FMA creates inherent vulnerabilities where deposited/registered information does not often contain beneficial ownership or beneficiary details.

### Recommendations and supervisory measures (section 6.1.2)
Authorities should:
- Reconsider the actual system of access to beneficial owner information (which relies on DNFBPs and FMA); in particular amend the law so that it clarifies that supervisory powers are not restricted to the fulfilment of FMA’s supervisory function;  
- Subject “deposited” foundations to the same registration requirements as “registered” foundations;  
- Require nominee shareholders and directors to disclose the identity of their nominator to the company;  
- Require the custodian of bearer shares, in all instances, to be a licensed professional, resident in Liechtenstein and always subject to the DDA;  
- Increase amount of sanctions for noncompliance with registration/notification requirements; and  
- Increase the number of inspections by OJ to check compliance of registration/notification requirements.

### Compliance with Recommendation 33 (6.1.3) — Summary and factors underlying rating
- R.33 rated: PC  
- Summary of factors underlying rating:
  - The system in place does not ensure adequate transparency on beneficial ownership of legal persons.  
  - The system in place does not always allow access in a timely fashion to adequate, accurate and current information on the beneficial ownership of legal persons.  
  - Powers of FMA to access information restricted to supervisory functions.  
  - Measures in place for bearer shares are not adequate and commensurate to risk of ML.  
- Issues of effectiveness:
  - Inadequate implementation of CDD requirements of DNFBPs and ineffective supervision; sanctions for non compliance with registration/notification requirements are not dissuasive and not applied in practice; low number of inspections by the OJ.

### Legal arrangements — trusts, definitions, and registration (6.2.1 and following)
- Factors from 2007 MER leading to PC: beneficial owner definition did not extend to beneficiary with no economic right to trust assets; absence of obligation on intermediaries to verify beneficial ownership; absence of legal obligation on private trustees to obtain, verify and record beneficial ownership information.  
- DDA and DDO changes since 2008 MER:
  - Definition of beneficial owner now extends to those with control over a trust (Art. 3 of the DDO);  
  - Obligation to obtain (Art. 7, para. 1 DDA), verify (Art. 7, para 2 DDA) and maintain (Art. 20 DDA) information on the natural person that ultimately exercises effective control over a legal arrangement;  
  - Intermediaries are required by law to verify beneficial ownership information (Art. 7, para. DDA);  
  - Obligation on intermediaries to obtain, verify and record the individual who exercises ultimate control over a trust (Art. 3, DDO);  
  - No changes with respect to private trustees.
- Legal framework cited:
  - Law on Persons and Companies 1926 (PGR) Arts. 897–932a;  
  - Law on Professional Trustees (PTA);  
  - Due Diligence Act (DDA);  
  - Due Diligence Ordnance (DDO).
- Registration/central registry rules for trusts:
  - Trusts under Liechtenstein law (Arts. 900–902 PGR) must be recorded in the Public Register if: at least one trustee is resident or domiciled in Liechtenstein; and the trust is created for more than 12 months; unless property/trust is registered in another public register or the trust deed (or certified copy) has been deposited with the Office of the Public Register within 12 months of formation.  
  - If trust deed is deposited, amendments must also be deposited (Art. 902 PGR).  
  - Where trust deed is not deposited, registration must include name of trust, date of formation, duration, and name of the trustee (Art. 900 PGR). There is no requirement that beneficiaries be recorded unless they are in the trust deed.  
  - Information in the register is publicly available; deposited documents are not public (except depositor and universal successors); Office of the Registry will confirm existence of a trust if asked. Files of registered trusts are accessible only upon proof of a legitimate interest. Disclosure of representative/person authorized to accept service may be made to domestic criminal prosecution authorities, the FIU and the FMA (Art. 955a PGR).  
  - Noncompliance with duty to enter in the Commercial Registry triggers a 14-day call to apply for necessary entry with threat of an administrative penalty (Art. 967, Abs. 1 PGR); court may not accept jurisdiction in disputes if trust not registered or deposited.
- Use and numbers (end of 2012):
  - Registered trust 2,666  
  - Deposited trust 171
- Trusts under foreign law:
  - Recognized by Liechtenstein law; may be subject to Liechtenstein law under Art. 931 PGR; a trust pursuant to foreign law may be created in Liechtenstein, but if neither registered nor deposited in Liechtenstein nor has a Liechtenstein trustee, it is not a Liechtenstein trust.
- Professional Trustees Act (PTA) and licensing:
  - Practicing trustee profession requires license by the FMA (Art. 1b, para. 1 PTA); the concept of acting on a professional basis is broad.  
  - Professional trustees and trust companies licensed by the FMA under the PTA are subject to the DDA (Art. 3, para. 1, lett. k).  
  - Trustees not licensed as professionals are not subject to due diligence requirements.
- Definitions and limitations concerning beneficial owner of trusts (DDA/DDO):
  - Professional trust providers required to identify, verify and maintain records of the beneficial owner (DDA, Art. 7, paras. 1–3; DDO, Art. 3, para. 1, lett. b). Beneficial owner in trusts covers:
    - Those named beneficiaries who are the beneficiaries of 25 percent or more of the assets of the trust;  
    - Where there are not named beneficiaries, those natural persons, or group of persons in whose interests a trust was mainly established;  
    - Those natural persons who ultimately exercise direct or indirect control over the assets of the trust; and  
    - Those with the power to dispose of the assets of the trust and to amend the beneficiaries (which would include the trustees).  
  - DDO Art. 3, para. 2 further covers those able to dispose of the assets of the trust or amend the list of beneficiaries (including trustees) and those able to influence the exercise of the control powers.  
  - The definition does not include the settlor unless the settlor is able to influence the exercise of control powers (Art. 3, para. 1, lett. b DDO). In practice settlors may not have explicit powers and thus may not be treated as controllers.  
  - The definition may not catch beneficiaries with a right to income rather than assets, beneficiaries with less than 25 percent of assets, beneficiaries not named in the trust deed but receiving discretionary payments, or discretionary trusts where trustee discretion prevents any single beneficiary qualifying as a beneficial owner. Private sector representatives noted it would be normal to identify beneficiaries who owned 20 percent of a trust, indicating potential vulnerabilities for trusts with many beneficiaries.

*Source: cr18257 - 931. The number of registered or otherwise deposited entities is quite high, although there has*

### 962. It is recognized that the authorities have followed the approach in the third EU ML Directive,

### cr18257 - 962. It is recognized that the authorities have followed the approach in the third EU ML Directive,

### Beneficial ownership and trusts (issues and analysis)
- The assessors note deficiencies in the definition of beneficial owner in the DDO and suggest amending it to:
  - include the settlor; and
  - require due diligence to be conducted on any person who receives a payment as a beneficiary (subject to a small de minimis exception if necessary).
- Professional trustees and trust companies (but not private trustees) are subject to DDA and DDO requirements for due diligence, monitoring, record keeping, control, training, and reporting.
- There is no obligation on private trustees to identify or verify beneficial ownership information; authorities consider there are no private trustees but acknowledge a theoretical risk of exploitation.
- Art. 928 PGR allows trusts to issue transferable certificates demonstrating a beneficial interest; these certificates:
  - the trustee must keep a register unless the trust deed provides to the contrary;
  - can be issued in bearer form;
  - can grant creditor’s rights to trust property (right to participate in the income and the liquidation surplus), which are not “connected to a membership or purchase rights.”
- Liechtenstein introduced reform of bearer shares and other titles issued in bearer form:
  - bearer securities of other entities shall be destroyed or converted to registered securities by March 1, 2014; after that date no more rights may be claimed on the basis of such shares.
  - authorities stated that trust certificates envisaged by Art. 928 PGR are covered by these provisions, although assessors note ambiguity because some trust-certificate rights are not “connected to a membership or purchase rights.”
- Professional trustees are obligated to obtain beneficial ownership information, but beneficiaries or settlors are not obligated to provide it; professional trustees would be required to refuse payments without such due diligence, while private or foreign trustees might possibly make payments without it.
- The Office of Justice considers there are virtually no private trustees and stated it would inform the FMA; assessors recommend a monitoring policy so any private trustees seeking registration would be known to the FMA and Office of Justice.

### Access to information on beneficial owners of legal arrangements (c. 34.2)
- The FMA supervises AML/CFT obligations of professional trustees and trust companies (FMAA Art. 3, para. 1, 269 and L). The DDA gives the FMA powers to obtain information from those it supervises:
  - DDA Art. 28, para. 4: FMA can demand from persons subject to due diligence any information and records required for supervisory activities.
  - DDA Art. 28, para. 1, letts. b and c: FMA can carry out inspections and extraordinary inspections to verify information availability and completeness.
- The FMA’s information powers are restricted to supervisory functions. The Supreme Administrative Court has ruled the DDA prevails over absolute confidentiality under Art. 11 PTA in the supervisory context.
- Assessors express reservations whether the DDA could be used to access information outside supervisory functions; no cases exist of use outside supervision.
- EEA rules required removal of the requirement that a foreign trustee must have a resident co-trustee in Liechtenstein; licensing rules still apply for foreign trustees conducting business professionally.
- Foreign trustees are not subject to Art. 28(5) DDO obligation to store due diligence files within Liechtenstein; authorities state that requesting official confirmation from the Commercial Register would, in practice, lead to application of Art. 239 PGR requiring appointment of a permanent domestic resident (EEA citizen) representative, who would be subject to the DDA (Art. 3(1)(r) DDA) and Art. 28(5) DDO storage requirement.
- Art. 923, Abs. 1 PGR requires trustees (including foreign trustees) to draw up an inventory of trust assets in accordance with Art. 1045, para. 3 PGR and to revise it annually; trustee must ensure all records are available without delay at the registered office in Liechtenstein.

### Access to information on beneficial owners by financial institutions (c. 34.3)
- Financial institutions only have access to the Commercial Registry and any information included on the Registry itself.
- The Office of Justice would confirm the existence of a deposited trust.
- Financial institutions have no access to beneficial ownership information contained only in a trust deed.

### Effective implementation (observations and risks)
- Liechtenstein’s system relies on CDD obligations for TCSPs and powers to compel information; Liechtenstein also permits registration or deposit of trusts.
- Significant challenges:
  - Deposited/registered information does not very often contain beneficial ownership or beneficiary information.
  - Professional trustees are obligated to obtain beneficial ownership; financial institutions routinely request it when opening accounts for trusts.
  - Definition of beneficial owner and beneficiary in the DDA does not always capture all beneficial owners (such as the settlor) or the beneficiaries in all instances.
  - Trustees rely heavily on introducers, especially problematic when domestic trustees deal with foreign introducers (other trustees or lawyers) and rely on potentially inaccurate declarations.
  - No prudential regulation of trust companies: a trust company is only obliged to have a single licensed professional trustee; other executive board members are not required to be subject to a fit and proper test.
  - Trust companies are subject to inspection only every three years (unless reason for more frequent inspection).
  - Assessors consider the TCSP and trustee sector among the riskiest in Liechtenstein.
- Authorities believe DDA information powers permit access to beneficial ownership information and its disclosure to domestic and foreign authorities, but legal contradictions may challenge this power; the issue has not been tested in court.
- Confidentiality and privilege issues for prosecutors and law enforcement may hamper access to or compulsion of beneficial ownership information.
- Assessors conclude an inherent risk that beneficial ownership information may not always be accurate, adequate, or accessible on a timely basis; exact quantification of this risk is not possible.

### Recommendations (6.2.2)
- The FMA and Public Registry should introduce a policy designed to ensure that any private trustee seeking to register a trust would be notified to the FMA, so that they can confirm that the person is not acting as a professional;
- Consider amending the definition of a beneficial owner in the context of a trust so as to include the settler and any beneficiary who receives a payment (even if that due diligence cannot be undertaken until a payment is about to be made);
- Amend the law so that it clarifies that supervisory powers can be used to obtain information for the purposes of enforcing the law and for disclosure to other authorities, both domestic and foreign;
- Clarify that the reform of bearer shares extends to Art. 928 bearer certificates in all instances; and
- Introduce a full prudential regulatory regime for trust companies that would impose a fit and proper test on all executives and owners of trust companies (as is currently the authorities’ intention).

### Compliance with Recommendation 34
- Rating: R.34          LC
- Summary of factors underlying rating:
  - Restrictive legal framework concerning the FMA’s access to beneficial ownership information.
- Effectiveness issues:
  - Issues noted under Recommendation 12 and the three year inspection cycle affect effectiveness; in particular, beneficial ownership information may not be adequate or accurate.

### Nonprofit organizations (NPOs) — overview and supervision (sections 6.3 onward)
- 2007 MER: SR.VIII—rated PC in the 2007 MER; prior concerns included absence of a review of laws/regulations for NPOs and insufficient outreach on FT risks.
- Legal framework governing NPOs primarily provided under PGR with updates dated June 26, 2008 (entered into force April 1, 2009). Additional relevant instruments:
  - Foundation Law Ordinance, StRV, LGBI. 2009 No. 114 (FLO);
  - Tax Act, LGBI. 2010, No. 340 (TA);
  - Tax Ordinance, LGBI 2010 No. 437 (TO).
- NPO forms: foundations and associations set up for a common-benefit purpose; common-benefit entities may not conduct commercial activities except non-commercial purpose activities.
- Definition of ‘common-benefit’ purpose: Art. 107, para. 4, lett. a) PGR — includes charitable, religious, humanitarian, scientific, cultural, moral, sporting or ecological purposes benefiting the general public, even if only a specific category benefits.
- Any legal entity governed by the PGR may be set up for common-benefit purpose; all non-commercial legal entities must appoint at least one director who is a citizen of the EEA and holds a professional trustee license or is an employee of a trustee with a special qualification certificate; such directors are required to conduct CDD on founders and beneficial owners in line with DDA.
- Foundation Supervision Authority (FSA):
  - Set up in April 2009 within the Office of Land and Public Registration (Office of Justice);
  - Responsibilities and competences set out under the FLO;
  - Comprises a head of division, two legal officers, and an administrative officer;
  - As of December 31, 2012, there were 1,169 common-benefit foundations under FSA supervision.
- Associations are not subject to supervision; foundations and establishments are supervised by the FSA (no establishments have been set up for common-benefit purpose to date).
- Review of adequacy: laws were revised June 2008 to strengthen founder responsibility, preservation and governance of foundations, and re-organize regulation/supervision; the revision process involved private sector and courts, with academic drafting and consultation including the FMA and FIU; amendments were not preceded by a review to determine NPO activities, size, or features at risk of misuse for FT.
- Authorities (FSA, law enforcement, FIU) have never identified a case where an NPO was linked to FT; Liechtenstein NPOs have never operated in certain high FT risk geographical locations; no specific reviews to assess new vulnerabilities have been undertaken.
- Outreach: In April 2013, an information leaflet “Risks of Terrorist Abuse” was distributed to the NPO sector by the FMA and is available on the FSA and FIU websites.
- Training: various training seminars were organized in 2012 by the FSA with the Association of Auditors on audit procedures for common-benefit foundations, but FT issues were not covered.
- Presentation to NPO association in November 2012 promoted transparency/accountability but did not reference FT issues.
- Supervision/monitoring (c. VIII.3):
  - All common-benefit foundations are subject to FSA supervision; common-benefit associations are not.
  - FSA ensures assets are managed/utilized according to foundation purpose; both regularity and effectiveness audits are carried out.
  - An audit firm is appointed for every common-benefit foundation in special noncontentious civil proceedings to conduct inspections; FSA relies largely on court-appointed audit firms for full-scope annual inspections, with inspection reports submitted to the FSA.
  - Audit firm must be independent; must notify court and FSA of any independence-impeding reasons; FSA may demand evidence to assess independence.
  - Persons excluded from appointment by the court include:
    - members of another executive body of the foundation;
    - persons with an employment relationship with the foundation;
    - persons with close family connections with members of executive bodies of the foundation; or
    - persons who are beneficiaries of the foundation.

*cr18257 - 962. It is recognized that the authorities have followed the approach in the third EU ML Directive,*

### 998. The Liechtenstein Association of Auditors has issued binding directives on the independence

### The Liechtenstein Association of Auditors has issued binding directives on the independence

### Auditor directives, scope and reporting obligations
- The Liechtenstein Association of Auditors issued binding directives on the independence and the performance of statutory audits in accordance with Art. 9b, para. 6 of the Auditors and Auditing Companies Act (WPRG) which entered into force in June 2011.
- As an executive body of the foundation, the audit firm is under an obligation to verify once a year whether the foundation assets are being managed and utilized in accordance with the purpose of the foundation.
- Auditor responsibilities include:
  - ensuring that the bookkeeping obligations of the foundation are being complied with;
  - ensuring that the business behavior of the administrators is in line with the stated activities of the foundation.
- Notwithstanding the extensive checks carried out by the auditors, none relate to FT issues.
- Reporting obligations:
  - A report on the outcome of the audit must be submitted to the foundation council and the FSA.
  - If no issues are identified by the auditors (“objections”), it is sufficient to provide confirmation that the foundation assets have been managed and utilized in accordance with the purpose of the foundation and in conformity with the provisions of the law and the foundation documents.
  - Where the audit firm ascertains circumstances which may jeopardize the existence of the foundation, it must report to the FSA.
  - The FSA may demand from the audit firm disclosure of all facts of which it has become aware during the course of its audit.
  - The audit firm also informs the FSA of any particular findings which it deems necessary to bring to the attention of the FSA (“remarks”).

### FSA supervisory powers, exemptions and use of inspection powers
- The FSA may, on request, dispense with the appointment of an audit firm, if the foundation only manages minor value assets or if this appears to be expedient for other reasons. The prerequisites for exemption from the obligation to appoint an audit firm are set out in the Foundation Law Ordinance.
- As of the end of 2012:
  - 207 of the 1,169 common-benefit foundations subject to supervision were exempt from the obligation to appoint an audit firm.
- In exempt cases, the FSA as a rule exercises the right of inspection itself and may:
  - obtain information from other administrative authorities and the courts;
  - through special non-contentious civil proceedings apply to the judge for the required orders, such as the control and dismissal of the executive bodies of the foundation, carrying out of special audits or cancellation of resolutions of executive bodies of the foundation.
- Upon receipt of objections, the FSA makes recommendations to the foundation to address the issues identified by the auditors.
- The FSA does not have the power to sanction foundations directly; sanctions may only be imposed through a judicial procedure. The FSA reported having instituted two judicial cases against two foundations for not implementing the recommendations made by the FSA.

### Audit findings and auditor communications (statistics and main issues)
- Auditor statistics provided by the FSA:
  - Year 2009: Objection 41, Remarks 21
  - Year 2010: Objection 39, Remarks 24
  - Year 2011: Objection 25, Remarks 18
- Main findings of the auditors:
  - failure to take action in particular circumstances against the deed of foundation;
  - absence of board meetings;
  - risky allocation of assets;
  - outstanding loans.
- Main remarks:
  - situations where no assets were available to the foundation;
  - no assets were spent by the foundation;
  - pending court proceedings.

### Information maintained by NPOs, public availability and registration requirements
- Common-benefit foundations are required to maintain information on the purpose and objectives of their stated activities. The foundation deed must provide, inter alia, the intention of the founder to form the foundation and the purpose of the foundation, including the designation of beneficiaries.
- Information publicly available on the commercial register website includes: founder or his representative, members of the foundation council, the audit authority and the representative (Art. 552, §19, para 3 PGR).
- Registration process requires submission of a founding deed containing:
  - the intention of the founder to form the foundation;
  - the purpose of the foundation, including the designation of tangible beneficiaries, or beneficiaries identifiable on the basis of objective criteria, or of the category of beneficiaries (unless exceptions apply);
  - regulations on the appointment, dismissal, terms of office, and nature of the management and power of representation of the foundation council;
  - the name and place of residence, or corporate name and domicile, of the founder or representative and express mention of the activity as indirect representative where applicable;
  - notes on the supplementary formation deed, regulations or creation of executive bodies;
  - the reservation of the right of revocation of the foundation or amendment of the foundation documents by the founder;
  - the reservation of a right to amend the foundation deed or supplementary foundation deed by the foundation council or by another executive body;
  - the founder may draw up a supplementary foundation deed if such right is reserved.
- Legal personality and registry entry details:
  - Common-benefit foundations acquire the right of legal personality upon registration.
  - The entry in the Commercial Registry must contain information including:
    - the organization and representation, stating the last name, first name, date of birth; nationality, and place of residence or registered office, or the corporate name and domicile of the members of the foundation council as well as the form of the signatory’s power;
    - the last name, first name, date of birth, nationality, and place of residence or registered office of the legal attorney, or the corporate name and domicile of the audit authority;
    - the last name, first name, date of birth, nationality, and place of residence or registered office of the legal attorney, or corporate name and domicile of the representative.
  - The information maintained by the Commercial Registry is available on its website and may be accessed by all competent authorities.

### Record keeping by foundations
- The general rules for accounting apply only to those foundations that, in addition to charitable activities, undertake commercial or business activities (Art. 26 of the Law on Foundations).
- For other foundations, the foundation council is required to:
  - maintain appropriate records of the financial circumstances of the foundation and keep documentary evidence presenting a comprehensive account of the conduct of business and the movement of the foundation assets;
  - maintain a schedule of assets indicating the asset position and the asset investments.
- Retention requirements (Art. 1059 of the PGR):
  - foundations are required to retain business records, account records, and business correspondence for a period of ten years.
  - The annual financial statements and the annual report are to be retained in writing and signed; other records may be maintained and retained in writing, electronically, or in a comparable manner provided conformity with underlying business transactions is ensured and records can be made legible at any time.

### Investigative powers, information sharing and case example on NPOs and FT
- Coordination and cooperation mechanisms under Recommendation 31 are available to exchange information on potential terrorist financing concerns related to NPOs.
- Law enforcement authorities may avail themselves of all information on the administration and management of a particular NPO in the course of an investigation.
- The coordination and cooperation mechanisms referred to under Recommendation 31 are available to ensure prompt sharing of information among all relevant competent authorities to take preventive or investigative action when there are suspicions that a particular NPO is being exploited for FT purposes.
- Case example:
  - The FIU received a SAR from a bank involving a foreign NPO wishing to open a bank account in Liechtenstein. The bank did not initiate the business relationship since media reports indicated that the NPO had been promoting terrorist ideologies in the country where it was set up. Nevertheless, the bank reported to the FIU. The FIU and the Office of the Public Prosecutor cooperated; no charges were eventually brought against the NPO.
- International requests regarding NPOs would be processed through the Mutual Legal Assistance framework.

### Effectiveness assessment, deficiencies and recommended measures
- Assessment summary:
  - Since the Third Round Evaluation, the authorities in Liechtenstein have taken measures: FSA set up to supervise foundations with a common-benefit purpose and a system of annual inspections by independent auditors instituted.
  - Supervisory oversight does not yet extend to the FT threat; only foundations with a common-benefit purpose are subject to FSA supervision.
  - No formal review has been carried out to understand the activities, size and other relevant features of the sector.
  - The FSA leaflet on the misuse of NPOs for FT purposes should be supplemented by other outreach activities to increase sector awareness.
- Recommendations and comments (as listed):
  - The authorities should conduct a review to understand the activities, size, and other relevant features of NPOs in Liechtenstein in order to determine the features and types of organizations that are at risk of being misused for FT;
  - The authorities should conduct periodic re-assessments by reviewing new information on the sector’s potential vulnerabilities to terrorist activities;
  - More outreach programs to the NPO sector should be considered with a view to protecting the sector from terrorist financing;
  - Associations with a common-benefit purpose that account for (i) a significant portion of the financial resources under control of the sector and (ii) a substantial share of the sector’s international activities should be subject to FSA supervision;
  - Supervision of foundations by the FSA should also focus on FT issues;
  - Measures should be in place to sanction violations of oversight measures or rules by NPOs or persons acting on their behalf.
- Compliance with Special Recommendation VIII:
  - Rating: SR.VIII PC
  - Factors underlying the rating:
    - No review to understand the activities, size and other relevant features of NPOs in Liechtenstein in order to determine the features and types of organizations that are at risk of being misused for FT.
    - No periodic re-assessments by reviewing new information on the sector’s potential vulnerabilities to terrorist activities.
    - Not all common-benefit entities are subject to supervision.
    - No measures in place to sanction violations of oversight measures or rules by NPOs or persons acting on their behalf.
  - Effectiveness issue: Supervision of foundations does not cover FT issues.

### National cooperation and coordination (PROTEGE) — structure, responsibilities and effectiveness
- Creation:
  - AML/CFT Working Group “PROTEGE” created by government decision in January 2013, replacing former coordination bodies.
- Legal framework references:
  - Government decision of January 15, 2013;
  - Art. 25 LVG;
  - Art. 36 DDA;
  - Art. 9 FIU Act;
  - Art. 10 and 53 CPC.
- PROTEGE membership (participants):
  - The Director of the FIU (Chairman);
  - The Financial Market Authority Liechtenstein;
  - The Office for Foreign Affairs;
  - The Office of Justice;
  - The National Police;
  - The Court of Justice;
  - The Office of the Public Prosecutor;
  - The Financial Intelligence Unit;
  - The Office for International Financial Affairs;
  - The Fiscal Authority.
- Responsibilities of PROTEGE include:
  - preparing strategy for combating ML, FT, and nonproliferation, based on an analysis of the risks and threats (No formal strategy has been adopted, this exercise has just started and is ongoing);
  - coordination of the implementation of that strategy;
  - coordination of the implementation of the relevant international standards (FATF, MONEYVAL, EU Money Laundering Directives);
  - preparation and organization of the country assessments by MONEYVAL/IMF;
  - coordination of the drafting of the relevant legal texts;
  - coordination of specific cases involving several authorities and administrative offices;
  - coordination of the implementation of international sanctions;
  - internal and external communication within its scope of activities.
- Additional coordination practices:
  - Informal quarterly meetings among Prosecutor General, a Court Judge, the Director of FIU, the CEO of the FMA, the Head of the Criminal Police, and Directors of the Foreign Office, the Tax Administration, and the Office for International Financial Affairs (ERFAG-Group).
- Information exchange and effectiveness:
  - Operational cooperation is regulated in various Acts (Art. 25 LVG, Art. 36 DDA, Art. 6 and 9 FIU Act, Art. 10 and 53 CPC), allowing for exchange according to due process.
  - The exchange of strategic information between the FIU and the FMA in a systematic way has only started recently, with the FIU sharing information about SARs and the FMA sharing the list of banks that it is planning to inspect.
  - A draft report on the main vulnerabilities has been prepared and is currently under review for preparation of the National Risk Assessment.
  - Effective implementation observations:
    - Due to size and structure, Liechtenstein benefits from close relations and flexible cooperative culture among authorities.
    - Domestic operational cooperation is flexible though not unlimited because each authority has confidentiality rules that may limit information exchange.
    - Issues under Recommendation 4 regarding financial secrecy may affect domestic exchange of information.
    - Cooperation and exchange of information between the FMA and the FIU should be enhanced.

*Source: cr18257 - 998. The Liechtenstein Association of Auditors has issued binding directives on the independence*

### 1033. The creation of the PROTEGE working group is an important step consolidating the ongoing

### cr18257 - 1033. The creation of the PROTEGE working group is an important step consolidating the ongoing

### 7.1.3–7.1.4: PROTEGE working group; Recommendations; Compliance R.31 and R.32
- Purpose of PROTEGE: consolidating the ongoing work of organizing a coordinated AML/CFT regime, addressing operational cooperation issues and preparing for the implementation of the new standards, including the national risk assessment.
- Recommendations:
  - Clarify the legal framework concerning financial secrecy provisions, as noted under Recommendation 4.
  - Enhance cooperation between the FMA and the FIU, particularly:
    - exchange of information that can be used for the FMA to develop a fully fledged risk-based approach; and
    - information for the FIU to have a better understanding of the level of compliance with AML requirements by the entities subject to supervision from the FMA.
- Compliance ratings and factors:
  - R.31 — LC
    - Issues of financial secrecy (noted under R.4) affect the effectiveness of domestic exchange of information.
    - Cooperation FMA/FIU needs enhancement.
  - R.32 — C (criterion 32.1 only)

### 7.2: The Conventions and UN Special Resolutions (R.35 and SR.I)
- Background and progress since the 2007 MER:
  - Third round assessors criticized nonratification of the Palermo Convention and recommended ensuring full implementation of the Palermo and Vienna Conventions and the United Nations International Convention for the Suppression of Financing of Terrorism.
  - Needed refinements: expressly cover assets under indirect control or ownership of terrorists, and fully criminalize terrorism financing.
- Ratifications and key dates:
  - Liechtenstein acceded to the Vienna Convention on March 9, 2007 (with reservations).
  - Liechtenstein ratified the Palermo Convention on February 20, 2008 without reservations.
  - Liechtenstein has ratified the UN Convention Against Corruption on July 8, 2010.
  - Liechtenstein ratified the Council of Europe Convention on Laundering, Search, Seizure, and Confiscation of the Proceeds of Crime on November 9, 2000.
  - Liechtenstein ratified the Protocol amending the European Convention on the Suppression of Terrorism on February 8, 2005.
- Implementation findings:
  - Vienna Convention: acceded; implemented all relevant provisions bar Art. 26 TOC.
  - FT Convention: all relevant provisions implemented and the terrorism financing offense fully criminalized.
  - Procedural implementation of UNSCR 1267 and 1373 improved.
- Legal transpositions (selected examples listed as in source):
  - Vienna Convention (Arts. 3–11, 15, 17, and 19):
    - Art. 3 — Offenses and Sanctions: Article 165 PC (Criminal Code)
    - Art. 4 — Jurisdiction: Article 62–65 PC
    - Art. 5 — Confiscation: Article 20, 20b, 26 PC; article 96, 97a, 249, 253 ff, 353ff CPC; Art. 64 bis 67 MLA
    - Art. 6 — Extradition: Art. 10–49, 60–70 MLA; Art. 59–66 SIA
    - Art. 7 — Mutual Legal Assistance: Art. 50–59, 71–73 MLA; Art. 48–53 SIA
    - Art. 11 — Controlled Delivery: Art. 23b Law on Police
  - CFT Convention (Arts. 2–18):
    - Art. 2 — Offenses: Art. 5 (1), 12, 15, 278d PC
    - Art. 4 — Criminalization: Art. 278b, 278c, 278d PC
    - Art. 5 — Liability of legal persons: Art. 74a–74g PC, Art. 124 and 986 PGR
    - Art. 8 — Measures for identification, detection, freezing, and seizure of funds: Arts. 20, 20b, 278b, 278c, 278d PC; Arts. 96, 97a, 249, 253 ff, 353ff CPC
    - Art. 18 — Measures to prohibit persons from encouraging, organising the commission of offenses and STRs, record keeping and CDD measures by FIs and other institutions carrying out financial transactions: Art. 287d PC, Art, 2, 4, 5, 9, 10 DDA
  - Palermo Convention (selected):
    - Art. 5 — Criminalization of participation in an organized criminal group: Art. 278, 278a PC
    - Art. 6 — Criminalization of laundering of the Proceeds of Crime: Art. 165 PC
    - Art. 7 — Measures to combat money laundering: Due Diligence Act, Due Diligence Ordinance, Art. 24e National Police Act
    - Art. 12 — Confiscation and Seizure: Art. 20, 20b, 26 PC; Art. 96, 97a, 353ff CPC
    - Art. 20 — Special Investigative Techniques: Art. 103–104c CPC
- Additional implementation notes:
  - All relevant provisions of the Conventions are transposed in national law or otherwise covered.
  - Deficiencies in implementation of Rec. 1, 3, 5, SR.II, and SR.IX cascade into evaluation of Rec. 35 and SR.I, including effectiveness issues.
  - Adoption of the ISA significantly improved and completed legal framework for implementation of UNSCR 1272 and especially UNSCR 1373; areas still need refining and specific procedures to be defined (see section 2.4 SR.III).
- Recommendations and comments:
  - Address deficiencies noted on seizure and confiscation measures, CDD, and the freezing regime of terrorist assets (see respective sections of the MER).
- Compliance ratings and factors underlying ratings:
  - R.35 — LC
    - Implementation of Vienna/Palermo Convention: Art. 98a CPC does not cover information gathering with some relevant categories, such as payment system providers, e-money institutions, insurance mediators, and DNFBPs.
    - Implementation of UN International Convention for the Suppression of the Financing of Terrorism: R.5-related issues (Art. 18.1.b of the Convention).
  - SR.I — LC
    - Implementation of UN International Convention for the Suppression of the Financing of Terrorism: R5-related issues (Art. 18.1.b of the Convention).
    - Implementation of UNSCRs:
      - Scope of application of ISA 2008 restricted in relation to UN Res. 1373.
      - No procedures in place for domestic designations.

### 7.3: Mutual Legal Assistance (R.36, SR.V)
- Background and prior MER findings:
  - Third round MER found excessive delays possible by extensive means of appeal and absence of a legal basis for Liechtenstein to give MLA in matters of serious and organized fiscal fraud.
  - Legal deficiencies in ML and FT offenses could obstruct MLA compliance with dual criminality rule requests.
- Progress since last MER:
  - Removal of one appellate instance (Supreme Court) on confirmation of the initial decision countered procedural delaying tactics.
  - VAT fraud is explicitly included in the MLA regime.
  - ML and FT deficiencies have been addressed.
- Legal framework governing MLA (as listed):
  - Mutual Legal Assistance Act of September 15, 2000 (MLA), as amended;
  - European Convention on Mutual Assistance in Criminal Matters (ECMA, ETS 30);
  - CoE Convention on Laundering, Search, Seizure and Confiscation of the Proceeds from Crime (MLC, ETS 141);
  - Schengen Implementation Agreement December 19, 2011.
- Widest possible range of mutual assistance (c. 36.1):
  - MLA governs international cooperation; based on ECMA, ETS 30, and MLC, ETS 141.
  - Assistance available on reciprocity under Arts. 1 and 3, paras. 1 and 50 MLA, and CPC generally applicable (Art. 9.1 MLA).
  - Measures include (as provided in source):
    - production, search, and seizure of information, documents, or evidence (including financial records) from financial institutions, or other natural or legal persons (Art. 92, 96, and 98a CPC);
    - taking of evidence or statements (Art. 105 CPC);
    - providing originals or copies of relevant documents and records (Art. 52 MLA);
    - servicing judicial documents (Art. 51, para. 3 and Art. 53 MLA);
    - facilitating voluntary repatriation of assets and documents; voluntary appearance of persons (no formal legal basis required);
    - identification, freezing, seizure, or confiscation of assets laundered or intended to be laundered, proceeds of ML and assets used for or intended to be used for FT, instrumentalities, and assets of corresponding value (Art. 92, 96, 97a, 98a CPC; Arts. 64–67 MLA).
  - Ad hoc assistance possible on basis of reciprocity, subject to consultation of the Ministry of Justice (Art. 3, para 3 MLA).
- Provision of assistance in a timely, constructive and effective manner (c. 36.1.1):
  - Incoming requests processed through Ministry of Justice or directly to court, particularly since Schengen Agreement entry into force for Liechtenstein on December 19, 2011.
  - Only requests not governed by ECMA/Schengen or special bilateral treaties go through diplomatic channels.
  - 2009 revision of MLA (LGBl. 2009 No. 36) streamlined procedure; key procedural changes include:
    - Decisions of the Court of Justice generally appealable only at end of MLA proceedings (new Art. 58c MLA), limiting appeals during proceedings; exception for rulings with immediate and irreparable effect (e.g., Art. 97a CPC).
    - Legal position and right of appeal of entitled parties defined (new Art. 58d MLA); limits on further appeals to Supreme Court in certain circumstances (Arts. 238.3 and 240.1.4 CPC); Constitutional Court appeals still possible on fundamental right grounds.
    - Service of court decisions on entitled parties residing abroad restricted (Art. 58b MLA).
    - Service of documents on deleted legal persons effected on last governing body or representative (Art. 58b, para. 2 MLA).
    - Art. 54a MLA enables spontaneous transmission of information to foreign authorities (implementation of Art. 10 ML Convention).
    - MLA Act applies to civil forfeiture proceedings (Art. 50, para. 1a MLA).
    - Simplified procedure for sending objects and documents under Art. 52, para. 5 MLA.
    - Liechtenstein subject convicted abroad no longer has right to grant consent to transfer of enforcement of a sentence (Art. 64, para. 2 MLA).
    - No legal remedies permissible against Liechtenstein requests for MLA transmitted to a foreign state (Art. 77, para. 3 MLA).
  - Impact on timeliness:
    - Statistics show a reduction of the average duration of the MLA proceedings from 91 days in 2009 to 49 days in 2012 (verified by random checks).
- No unreasonable or unduly restrictive conditions on mutual assistance (c. 36.2):
  - MLA process subordinated to reciprocity (Art. 3 MLA).
  - Specific and mandatory refusal grounds (Art. 51 MLA) include:
    - dual criminality condition not met;
    - request relates to criminal offense of political, military, or fiscal nature (Arts. 14 and 15 MLA) (fiscal exception valid only when exclusive);
    - proceedings do not meet basic principles of Arts. 3 and 6 ECHR;
    - sentence or enforcement of preventive measures contravenes basic human rights (Art. 5 ECHR);
    - specific CPC conditions for confiscation or special investigative techniques not met;
    - secrecy obligations that cannot be lifted (e.g., medical secret, lawyer’s and auditor’s legal privilege). Banking and other financial secrecy do not fall under this category.
  - Assessment: These refusal grounds are generally recognized as acceptable and not exceptional compared with other jurisdictions; Art. 51 MLA is mandatory but allows some flexibility and interpretation. The political alibi cannot stop requested assistance for particularly serious offenses such as financing of terrorism.
- Additional practical notes:
  - Many incoming MLA requests originate from jurisdictions in Africa, Middle East, and Asia when not governed by ECMA/Schengen or special bilateral treaties.
  - Footnoted operational facts in source:
    - There are no airports in Liechtenstein.
    - Liechtenstein is doubly landlocked.
    - All mail goes first via Switzerland who is in charge of control as a result of the Customs Union.

*IMF Country Report content as provided.*

### 1055. Any foreign legal assistance request usually follows the same procedure:

### cr18257 - 1055. Any foreign legal assistance request usually follows the same procedure:

### Procedure for MLA requests
- The MLA request is addressed to the Office of Justice in the Ministry of Justice (as “Central Authority” according to the 1990 Strasbourg Convention), or directly to the judicial authorities.
- The request is passed to a judge (investigating magistrate) at the Court of Justice who, after a summary examination, decides whether or not the assistance should be granted.
- All MLA requests are copied to the Office of the Public Prosecutor for possible comments.
- Requests related to money laundering, predicate offenses, or FT are copied to the FIU (Art. 7.1 FIU Act).
- The ECMA and Art. 1 MLA allow for direct transmission of legal assistance requests in the cases provided in Art. 15.2 and 4 ECMA (urgency). Judicial authorities have accepted direct MLA requests even when involving coercive measures; direct transmission also takes place between members of the Schengen Implementation Agreement.

### Admissibility, scope of court examination, and execution
- The court examines requests predominantly for admissibility: whether basic legal conditions are met and no grounds for refusal exist (such as the dual criminality requirement for coercive actions and the fiscal exception—Art. 51 MLA).
- The court’s examination is marginal and does not review the substance (evidentiary value) but assesses whether the request contains enough information to comply meaningfully.
- Any refusal of the request can be subject to an appeal by the Office of the Public Prosecutor.
- If the court deems the request admissible it executes it by:
  - questioning witnesses (Art. 105 CPC),
  - obtaining documents and bank records (also with coercive measures, if necessary—Arts. 96 and 98a CPC),
  - issuing a search warrant (Art. 92 CPC).
- Searches are conducted by the National Police Authority.
- Banking or professional secrecy (except in legal privilege circumstances) does not apply and all documents and items must be handed over to comply with the order.
- Once proceedings are concluded, materials to be surrendered are transferred to the Ministry of Justice, which forwards them to the requesting foreign authority, directly or through diplomatic channels (mainly via the Liechtenstein Embassy in Berne). In direct transmission cases, answers and attachments may be sent directly.

### Timeframes and execution complexity
- The time to comply depends on request complexity.
- Overview of MLA requests received between 2009 and 2012: in most cases it takes between one and four months to execute.
- Some (high profile) cases may take longer due to procedural complications and the high standard of proof required by the Liechtenstein Courts on the link between the assets and the predicate offense in seizure and confiscation related domestic procedures triggered by a MLA request.

### Provision of assistance regardless of fiscal matters (exceptions to fiscal prohibition)
- General prohibition in fiscal criminal matters remains (Art. 15.2 and 51 MLA). Four exceptions where MLA is granted notwithstanding exclusively fiscal nature:
  - MLAT with the U.S. of July 8, 2002, LGBl. 2003 No. 149: Art. 1, para. 4 permits mutual legal assistance including compulsory measures in cases of tax fraud. Tax fraud is defined as tax evasion committed by means of the intentional use of false, falsified, or incorrect business records or other documents. The tax due, either as an absolute amount or in relation to an annual amount due, must be substantial.
  - Art. 10 of the Savings Tax Agreement between Liechtenstein and the European Community: Liechtenstein undertakes to exchange information on conduct constituting tax fraud “or the like” under Liechtenstein law. Implementing law (Savings Tax Act, ZBStG, LGBl. 2005 No. 112), Art. 20 specifies the Court of Justice handles requests under Art. 10 and that the provisions of the MLA Act apply to the proceedings.
  - Implementation of the Third EU Money Laundering Directive (LGBl. 2007 No. 189) inserted Art. 51 para. 1a into the MLA Act: Vis-à-vis EU states and in the case of VAT fraud and certain customs violations, mutual legal assistance is permissible if the offense is connected with damage to the budget of the European Communities, and the evaded tax, reduced customs duties, or other unlawful advantage exceeds CHF 75,000 (threshold clause).
  - Schengen association entry into force on December 19, 2011: Liechtenstein undertakes to provide mutual legal assistance in fiscal criminal matters to all Schengen states. In the case of indirect taxes, compulsory measures are permissible if the offense is tax fraud according to Art. 88 or qualified tax evasion according to Art. 89 of the VAT Act. VAT tax evasion is deemed qualified if committed under aggravating circumstances (enlisting one or more persons for VAT evasion; VAT evasion on a professional basis). Dealing in goods subject to import duty is included per Art. 90 VAT Act if the underlying offense is tax fraud or qualified tax evasion. For indirect taxes relating to customs duty fraud and qualified tax evasion offenses, Swiss law is applicable in Liechtenstein (mineral oil tax, automobile tax, and customs duties) and MLA including compulsory measures is allowed. For direct taxes, mutual legal assistance relating to search and seizure is generally limited to facts that constitute tax fraud under Liechtenstein tax law.

### Mixed offenses and specialties
- For MLA requests concerning mixed offenses (fiscal and others), legal assistance is given for the common criminal offense.
- Legal assistance results may be returned to the requesting authority subject to a “reservation of specialty” that limits their use to the sole prosecution of the common offense.

### Secrecy, confidentiality laws, and legal privilege
- Banking secrecy cannot be opposed to an MLA request; firm jurisprudence established that banking secrecy can be waived in domestic and legal assistance criminal proceedings for common offenses.
- Banking secrecy is otherwise lifted by court order (Art. 98a, para. 1a CPC).
- The exception in Art. 51, para. 1, no 1 MLA (legal impediment on fiscal and political grounds) cannot be interpreted to allow refusal of legal assistance on the grounds of banking secrecy.
- Arts. 96, 97, 97a, 98, and 98a CPC regulating seizure apply.
- Art. 98a CPC disclosure obligations in ML and FT matters require divulging all relevant data and documents on:
  - identity and address of a business relation,
  - nature of the business relationship,
  - beneficial ownership,
  - related transactions or operations.
- Art. 98a CPC does not apply to certain categories under the preventive AML/CFT system (payment system providers, e-money institutions, insurance mediators, and DNFBPs); in those cases the judge applies seizure provisions of Art. 96 CPC.
- Legal privilege can be an obstacle: CPC provides broad definition of legal privilege. Art. 108 CPC states “Defense counsel, attorneys at law, legal agents, auditors, and patent attorneys“ are entitled to refuse to give evidence with regard to what has become known to them in this capacity.
- Authorities counter potential privilege abuse by presuming the DNFB is acting in capacity of financial intermediary or other professional subject to the DDA; the DNFB must show that requested information or documents fall under privilege.
- Lawyers, trustees, and auditors are conspicuously exempted from Art. 98a CPC; judicial authorities can still call them as witnesses under Art. 105 CPC or use search and seize powers of Arts. 92 and 96 CPC. However:
  - The broad legal privilege definition could hamper identification and tracing of property subject to confiscation or suspected proceeds of crime.
  - Lawyers acting as trustees may allow inappropriate use of legal privilege to impede tracing.
  - Extension of privilege to auditors is considered unfounded in the R.3 analysis.

### Availability of powers of competent authorities (R.28)
- All powers granted to relevant authorities in domestic cases are available in response to MLA requests.
- Art. 9, para. 1 of the MLA stipulates CPC provisions apply to mutual legal assistance proceedings unless specified otherwise.
- Powers concerning production of documents, search of persons and premises, seizing and obtaining documents, and instrumentalities are available; issues noted under R.3 and criterion 36.5 apply accordingly.

### Avoiding conflicts of jurisdiction and coordination
- Domestic coordination: related legal assistance proceedings and domestic criminal proceedings are allocated to the same judge responsible for communicating and coordinating with foreign requesting jurisdiction(s).
- Experience shows proceedings conclude more quickly if competence for active and passive MLA is assigned to the competent investigating judge and the same prosecutor handles legal assistance and domestic criminal proceedings.
- Transfer of prosecution or of enforcement (seizure and confiscation) to foreign judicial authorities to coordinate proceedings is regular practice.
- Liechtenstein forwards information on criminal proceeds on the basis of new Art. 54a MLA (spontaneous transmission of information). The Public Prosecutor estimates having supplied spontaneous information in some 10 cases since 2010.
- Art. 59 MLA (amended 2010) allows foreign judicial and law enforcement authorities to consult court files and participate in execution of the MLA request on Liechtenstein territory.

### Police-to-police cooperation and investigative powers
- Investigative powers under R.28 are available for direct requests from foreign judicial or law enforcement authorities (Art. 9, para. 1 MLA).
- Police-to-police requests through Interpol normally allow communication of information or intelligence, not coercive measures.
- With consent of the involved or targeted person, some noncoercive investigative acts (such as taking a statement) are not excluded.

### Applicability to FT and SR V
- All comments and conclusions regarding MLA related to the ML offense apply in the FT context.
- Art. 98a CPC explicitly applies to FT-related situations for FIs and management entities to supply relevant information and render documents for law enforcement purposes.
- All MLA comments for money laundering also apply in the financing of terrorism context.

### Statistics (R.32) — MLA requests addressed to Liechtenstein (2009–2012)
- 2009: Number of MLA requests addressed to Liechtenstein 339; Average duration of execution 91 days; Refused requests 4 (no factual information given 1, recall 3)
- 2010: Number of MLA requests addressed to Liechtenstein 368; Average duration of execution 93 days; Refused requests 39 (no factual information given 18, request was recalled by requestor 5, fiscal affairs 3, no link to LIE 5, fishing exhibition 1, others 6)
- 2011: Number of MLA requests addressed to Liechtenstein 385; Average duration of execution 69 days; Refused requests 26 (no factual information given 12, military affairs 1, no link to LIE 4, others 4)
- 2012: Number of MLA requests addressed to Liechtenstein 333; Average duration of execution 59 days; Refused requests 23 (no factual information given 14, fiscal affairs 3, no link to LIE 3, lack of dual criminality 2, others 1)
- Note: Many requests refused for lacking information were later sent again in a complete form and were then executed.

### Statistics — Confiscation and freezing/seizure implemented (2009–2012)
- Requests for confiscation implemented:
  - 2009: Number 2; Amount in EUR 2,120,000
  - 2010: Number 3; Amount in EUR 5,068,000
  - 2011: Number 2; Amount in EUR 2,751,400
  - 2012: Number 3; Amount in EUR 900,000
- Foreign requests for freezing/seizure (implemented) — only available for 2012:
  - 2012: 18 requests; 63.500.000 EUR

### Statistics — Liechtenstein mutual legal assistance requests (outgoing)
- 2012: 347
- 2011: 416
- 2010: 320
- 2009: 328

### Statistics — Mutual legal assistance requests listed by requesting state (2009–2012)
- Switzerland: 2012 114; 2011 104; 2010 115; 2009 147
- Austria: 2012 99; 2011 157; 2010 136; 2009 86
- Germany: 2012 45; 2011 51; 2010 63; 2009 48
- Slovenia: 2012 11; 2011 6; 2010 2; 2009 1
- Spain: 2012 7; 2011 3; 2010 3; 2009 4
- Czech Republic: 2012 7; 2011 9; 2010 2; 2009 4
- Hungary: 2012 7; 2011 2; 2010 3; 2009 3
- France: 2012 6; 2011 9; 2010 2; 2009 3
- Italy: 2012 6; 2011 8; 2010 10; 2009 8
- Netherlands: 2012 6; 2011 5; 2010 4; 2009 8
- UK: 2012 2; 2011 8; 2010 8; 2009 6
- USA: 2012 1; 2011 6; 2010 4; 2009 4
- Brazil: 2012 2; 2011 - ; 2010 3; 2009 1
- Poland: 2012 2; 2011 5; 2010 3; 2009 6
- Finland: 2012 4; 2011 1; 2010 - ; 2009 6
- Latvia: 2012 3; 2011 1; 2010 2; 2009 4

### Statistics — Offenses for incoming MLA requests (2009–2012)
- Fraud: 2012 124; 2011 111; 2010 108; 2009 95
- Money laundering: 2012 70; 2011 60; 2010 70; 2009 68
- Violation of Road Traffic Act: 2012 68; 2011 122; 2010 100; 2009 80
- Embezzlement: 2012 40; 2011 42; 2010 43; 2009 38
- Criminal breach of trust: 2012 38; 2011 38; 2010 62; 2009 37
- Offense involving documents: 2012 38; 2011 23; 2010 33; 2009 36
- Theft: 2012 21; 2011 21; 2010 - ; 2009 25
- Various bankruptcy offenses: 2012 16; 2011 18; 2010 17; 2009 21
- Bribery: 2012 15; 2011 19; 2010 26; 2009 32
- Criminal group/organisation: 2012 10; 2011 - ; 2010 - ; 2009 -
- Violation of the Narcotics Act: 2012 - ; 2011 16; 2010 19; 2009 21

*Source: cr18257 - 1055. Any foreign legal assistance request usually follows the same procedure:*

### 1076. As the tables show, the MLA traffic is quite intense in both directions. The figures indicate a

### cr18257 - 1076. As the tables show, the MLA traffic is quite intense in both directions. The figures indicate a

### Mutual Legal Assistance (MLA) — Findings on responsiveness and outcomes
- The figures indicate a generally responsive approach by Liechtenstein.
- The number of incoming ML-related requests that meet with a positive response is to be noted.
- The statistics in the area of seizure and confiscation are encouraging.
- The number of refusals or nonexecutions is not disproportionate, and the reasons appear founded.
- In many cases the request could not be complied with in the absence of any element being present in Liechtenstein.
- Refusals on the fiscal exception ground were said to be justified by the exclusive fiscal character of the request.
- Other refusals related to requests for administrative assistance or emanating from nonjudicial authorities.
- Authorities have taken steps reducing delaying procedural tactics: appeals against conservatory measures no longer automatically suspend the MLA procedure; procedural incidents are brought together with the final ruling on implementation of the MLA request.
- The possibility to appeal to the Supreme Court as an intermediary step delaying the procedure is no longer open to the defendant.
- Result: significant shortening of the average implementation duration from 91 to 59 days.

### Legal and normative changes affecting MLA
- Third round recommendation implementation:
  - Serious and organized fiscal fraud excluded from the fiscal exemption list has been implemented insofar as it relates to serious VAT fraud affecting the budget of the European Union by the introduction of a specific provision in the MLA (Art. 51.1a) and as a result of the Schengen Agreement.
  - Mutual legal assistance is also allowed for violation of Customs prohibitions.
- Remaining impediment: effective provision of MLA when the offense has a fiscal character remains; issue to be addressed by an extension to all serious tax crimes with transposition to the new FATF standards.

### Vulnerabilities in MLA and evidence-gathering
- A vulnerability remains in the restriction of Art. 98a CPC: it does not cover information gathering with some relevant categories, such as payment system providers, e-money institutions, insurance mediators, and DNFBPs.
- The possibility of seizing documents according Art. 96 CPC does not cover that lacuna.
- Particular risk that substantial information may not be captured in seizable documents for:
  - lawyers (acting as financial intermediaries or in other nonlitigation or legal advices circumstances),
  - auditors,
  - trustees.
- Not clear how an abuse of the legal privilege can be countered.
- The approach of assuming that lawyers with a dual capacity act as trustees in case of doubt is practical, but not beyond legal challenge.
- Feedback indicates that obtaining bank records can be challenging in the presence of dilatory tactics and in light of information given to affected person(s), which is perceived as hampering ongoing investigations in the requesting country.
- Authorities stated that necessary conservatory actions are taken first to avoid evidence being destroyed or assets dissipated.

### Recommendations and Comments (MLA)
- The margin for effectiveness of the MLA, although improved in terms of expeditiousness, should be further improved by the following:
  - The incomplete coverage of Art. 98a CPC needs to be addressed to include all persons and entities subject to the DDA, more in particular lawyers, auditors, and trustees;
  - The authorities should consider criminalizing serious tax offenses, include them as predicate offense to ML and extend the MLA to all these serious tax crimes by transposing the present relevant international standards shortly; and
  - The authorities should consider measures to mitigate the risk of hampering ongoing investigations in requesting countries that might stem by informing the parties affected by requests of MLA.

### Compliance with Recommendations 36 and Special Recommendation V — Ratings and factors
- R.36: LC
  - Not all DDA subjects are under the obligation to supply relevant information as provided by Art. 98a CPC.
  - Effectiveness: Issues of legal privilege and confidentiality in dual capacity situations.
  - Effectiveness: Particularly with regard to obtaining bank record, the effectiveness of the legal procedures could be challenging in the presence of dilatory tactics.
- SR.V: LC
  - Not all DDA subjects are under the obligation to supply relevant information as provided by Art. 98a CPC.
  - Effectiveness: Issues of legal privilege and confidentiality in dual capacity situations.
  - Effectiveness: Particularly with regard to obtaining bank record, the effectiveness of the legal procedures could be challenging in the presence of dilatory tactics.

### Extradition — Description and analysis (R.37, 39, SR. V)
- Third MER (2007) advice recap:
  - Find a solution for possible excessive delays caused by delaying tactics before the Constitutional Court.
  - Serious and organized fiscal fraud should no longer be excluded as ground for extradition.
  - Deficiencies in the ML and FT offenses needed addressing so as not to pose a potential obstacle for extradition in the light of the dual criminality principle.
- Recent figures: the average duration of an extradition procedure is not excessive.
- Serious VAT fraud can be a basis for extradition under the Schengen regime.
- Deficiencies in the ML and TF criminalization have been addressed and meet the dual criminality test.

### Extradition legal framework and scope
- Legal instruments:
  - Mutual Legal Assistance Act of September 15, 2000 (MLA), as amended;
  - Schengen Implementation Agreement (SIA) December 19, 2011;
  - European Convention on Extradition (ECE).
- Extradition can be granted for prosecution of willfully committed acts punishable under requesting state by deprivation of liberty of more than one year or a preventive measure of the same duration, and that are subject to a deprivation of liberty of more than one year under Liechtenstein law.
- Extraditable offenses include ML (Art. 165 PC), participation in or support of a terrorist group (Art. 278b PC), terrorist activities (Art. 278c PC), and FT (Art. 278d).
- Exceptions to extradition include (selection of listed grounds):
  - person is a Liechtenstein national (Art. 12, para. 1 MLA);
  - political offenses (Art. 14, para. 1) and offenses of an exclusive military and fiscal nature (Art. 15);
  - other grounds including Art. 16, Art. 17, Art. 18, Art. 19 paras 1–3, Art. 20, Art. 21, Art. 22 MLA as listed in the source.
- Art. 15, no. 2 MLA: request for extradition is inadmissible for acts that constitute violation of stipulations relating to taxes, monopolies or customs duties, or foreign exchange regulations, or stipulations relating to control of or foreign trade in goods — consequence: as a rule, extradition cannot be granted when the underlying offense is a violation of customs duties or serious or organized fiscal fraud (except in SIA circumstances).

### Schengen implications for extradition
- Accession to Schengen: Art. 63 of the Convention implementing the Schengen Agreement requires extradition for punishable acts referred to in Art. 50, para. 1, or for executing a sentence or measure imposed because of such an act.
- Art. 59 SIA refers to Art. 2 of the European Convention on Extradition.
- Since Liechtenstein’s accession to Schengen, a punishable act qualified as tax fraud under Liechtenstein law in accordance with Art. 88 of VAT Act—with a penalty of imprisonment of up to one year—is extraditable under the European Convention on Extradition.

### Extradition of nationals and cooperation for prosecution
- Extradition of Liechtenstein nationals is not admissible pursuant to Art. 12, para. 1 MLA, except if the person has given his/her express consent after being informed of the consequences.
- European Arrest Warrant regime does not apply to Liechtenstein.
- If extradition for ML is denied on ground of nationality, Liechtenstein can take jurisdiction pursuant to Art. 65, para. 1, no. 1 PC (direct jurisdiction over acts committed by Liechtenstein nationals abroad) on condition of double criminality.
- Liechtenstein courts have explicit jurisdiction over terrorist acts and terrorist financing, wherever committed, when the perpetrator is a Liechtenstein citizen (Art. 64, para. ,1 nos. 10 and 11 PC).
- Art. 60 MLA gives the Ministry of Justice role to liaise with foreign authorities to collate facts and ensure the case can be effectively pursued in Liechtenstein.
- The Office of the Public Prosecutor uses its own channels of communication with foreign counterparts.
- The possibility of waiving jurisdiction and taking over prosecutions is frequently used in Liechtenstein.

### Efficiency of extradition process and procedures
- In practice, almost all requests are transmitted between the Ministry of Justice, not through diplomatic channels.
- Simplified extradition procedures under Art. 32 MLA (consent of the extraditable person) take just a matter of days.
- Ordinary procedures take more time; full use of appeals is not uncommon (provisional arrest to Constitutional Court).
- Appeals against provisional arrest do not suspend or delay extradition proceedings.
- Typical subsequent steps may take about four to six months, although latest statistics show a shorter duration of approximately three months.
- Final decision of the government (Minister of Justice) is not open to legal challenge (Art. 77, para 1 MLA).
- Simplified procedure may apply when the crime is ML or FT.

### Extradition statistics (submitted by authorities)
- Statistics Table 7. Extradition requests and duration of execution.
  - Year 2009: Number of extradition requests addressed to Liechtenstien: 6 (2 recalled); Average duration of execution: 19.5 days
  - Year 2010: Number of extradition requests addressed to Liechtenstien: 1 (pending) 78 — Average duration of execution: -
  - Year 2011: Number of extradition requests addressed to Liechtenstien: 2 — Average duration of execution: 92 days
  - Year 2012: Number of extradition requests addressed to Liechtenstien: 4 (1 recalled, 1 refused due to lack of reason for request) — Average duration of execution: 92 days
- Prosecutions transferred to a foreign jurisdiction:
  - 2009: 18
  - 2010: 22
  - 2011: 31
  - 2012: 14
- Requests to Liechtenstein of foreign jurisdictions to take over criminal proceedings; Number of criminal proceedings taken over from foreign jurisdictions:
  - 2009: Requests 20 — Taken over 17
  - 2010: Requests 18 — Taken over 13
  - 2011: Requests 13 — Taken over 12
  - 2012: Requests 13 — Taken over 12
- Grounds for refusal for taking over foreign proceedings: statute of limitation, unknown perpetrators, no residence of the perpetrators, and violation of public order.

### Effective implementation — observations and remaining issues
- Duration of extradition proceedings has been substantially reduced in practice to a maximum average of around three months.
- Dilatory procedural tactics before the Constitutional Court have been met by the court giving priority to extradition matters; effectiveness will be enhanced if courts maintain this approach.
- Third round criticism on exclusion of extradition for serious and organized fiscal offenses has not received a satisfactory response: still a general ground for refusal and only legally permissible for serious VAT fraud with Schengen countries since SIA came into force on December 19, 2011.
- Recent revision of FATF standards gives specific emphasis to countering serious tax crimes — noted as relevant but not yet fully transposed.
- There remain deficiencies in criminalization of ML and FT that can create obstacles as a result of the dual criminality rule.
- Between 2009 and 2012, Liechtenstein received 64 requests to take over proceedings, 54 accepted.
- Between 2009 and 2012, Liechtenstein waived jurisdiction and transferred prosecution to foreign judicial authorities in 85 cases.
- These figures reflect cooperative willingness but may raise questions in respect of the autonomy of the ML offense.

*Source: cr18257 - 1076. As the tables show, the MLA traffic is quite intense in both directions. The figures indicate a — cr18257 PDF content provided above.*

### 1099. It is recommended that the authorities:

### cr18257 - 1099. It is recommended that the authorities:

### Key recommendations (from paragraph 1099)
- Adopt legislation introducing serious tax crimes as extradition ground.  
- At a minimum expand the possibility to extradite for serious VAT fraud beyond the Schengen jurisdictions.

### Ratings (compliance snapshot)
- R.39: C  
- SR.V: C

### Summary of earlier MER findings relevant to international cooperation (R.40 and SR.V)
- The 2007 MER rating for Recommendation 40 was PC.  
- The MER noted reliance on case law to override legislation with explicit secrecy provisions restricting information exchange.  
- The appeals procedure had the potential to undermine the effectiveness of information exchange.  
- The 2008 MER noted that the law does not expressly provide for the FIU to have direct or indirect access to all relevant information held by all entities subject to the DDA. This shortcoming has not yet been addressed by the authorities.

### Legal framework (listed statutes cited in the assessment)
- Financial Market Authority Act 2004 (FMAA)  
- Due Diligence Act 2008 (DDA) Art. 37  
- Banking Act 1992 (BA), Art. 30f et seq  
- Insurance Supervision Act 1995 (ISA), Art. 61et seq  
- Investment Undertakings Act 2005 (IUA) Art. 102 et seq  
- Asset Management Act 2005 (AM) Art. 53 et seq  
- Public Enterprise Act, Arts. 3 and 23  
- Data Protection Act  
- Arts. 35, 35a, and 35b National Police Act (NPA)  
- FIU Act

### National and international cooperation — major findings
- Supervisors’ exchanges of confidential customer data are normally for verifying regulated institutions’ compliance, not to investigate customers per se; exception exists for securities market abuse supervision.  
- Powers of cooperation and information exchange must enable the FMA to assist foreign supervisors on AML/CFT obligations, including assessing fitness and properness of persons seeking licenses or positions subject to AML/CFT obligations.  
- In Liechtenstein, practical experience of information exchange is mainly in securities markets and prudential banking supervision; virtually no experience exchanging information specifically on AML/CFT matters.  
- To cooperate effectively with foreign supervisors, the FMA needs:
  - The ability to share, with foreign authorities, confidential information that the authority holds on request and spontaneously (R.40.1–40.3).  
  - A power to collect information from regulated institutions on behalf of other authorities, without requiring a domestic reason beyond the foreign request (R.40.4).  
  - No obligation to impose unreasonable conditions on exchange or be constrained by domestic secrecy provisions (R.40.6, 40.7, and 40.8).  
  - The ability to protect information received from a foreign supervisor (R.40.9).

### FMA-specific findings
- DDA Art. 37 obliges the FMA to provide information to a foreign financial market supervisory authority where needed to fulfill that authority’s responsibilities, subject to certain conditions. The FMA is under an obligation to cooperate on AML/CFT matters, not merely discretion.  
- Information-exchange provisions in the DDA apply only to the extent cooperation with foreign authorities is not regulated by “special legislation.” Numerous statutes (Banking Act, Insurance Act, FMAA, AMA, UCITSA) contain overlapping provisions; Art. 27a et seq of the FMAA takes precedence over other administrative assistance provisions in securities supervision, but legislation does not clearly define which provisions override others, creating uncertainty about applicability.  
- For banks, insurance, and securities, either the DDA or sectoral legislation explicitly gives the FMA power to pass confidential information to foreign supervisory authorities to enable those supervisors to fulfill their responsibilities. In the case of the FMAA, there is, in principle, a requirement for approval of the administrative court (the FMA confirmed this has not been a practical barrier).  
- For DNFBPs (trust and company service providers and attorneys), strict confidentiality in the Professional Trustees Act and the Lawyers Act exists, but the FMA’s interpretation (confirmed by the Supreme Administrative Court in 1999) is that DDA powers override those constraints; assessors accept the DDA would apply for DNFBPs as well.  
- Conditions for protection of information by the recipient authority differ across statutes; DDA provisions are more restrictive than those in the Banking, Insurance, and FMA Acts, and the latter may require administrative court approval. Despite differences, the FMA has wide powers to exchange customer confidential information for banks, insurance, and securities, and—by court precedent—access for DNFBPs for passing to foreign authorities.

### FIU-specific findings
- The FIU may request information from foreign FIUs where required under the FIU Act and may provide official, nonpublicly available information to foreign counterparts on a reciprocal basis, subject to conditions in the FIU Law.  
- Generally, the FIU exchanges available information with foreign counterparts in a timely, constructive and effective manner; statistics provided show information was provided within a few days.  
- Limitations that may impact effectiveness: (i) the FIU can obtain information from a reporting entity only if a SAR has been submitted; and (ii) the power to obtain information is subject to secrecy provisions and the FMA’s limitations to share confidential information indirectly.  
- The Director of the FIU may, after consultation with the Minister of Finance and government approval, conclude MoUs with other FIUs; an MoU is not a prerequisite for exchange. The FIU has signed MoUs with multiple countries (Belgium, Monaco, Slovakia, Croatia, Lithuania, Poland, San Marino, Georgia, Switzerland, Russia, Romania, Chile, France, Ukraine, Canada, South Africa, Japan) and is negotiating with others (Australia, Serbia, Singapore, Republic of Moldova, Bosnia and Herzegovina).  
- The FIU is not subject to any compliance procedure in Egmont and can share financial and other information with other Egmont FIUs; as an EEA member it attends European FIU Platform meetings.  
- Information is exchanged via the Egmont Secure Web (ESW); ESW checked twice daily and incoming requests are immediately assigned to an analyst. Average response times for incoming requests of the top five countries (in terms of quantity of incoming requests) are:
  - FIU of country A: 1.8 days  
  - FIU of country B: 1.0 days  
  - FIU of country C: 7.0 days  
  - FIU of country D: 7.3 days  
  - FIU of country E: 8.6 days

### Police cooperation findings
- The National Police Act gives police broad capacity to cooperate with foreign counterparts on condition of reciprocity, allowing a broad range of administrative assistance and information exchange without court order or MLA, including covert investigations, interviews in presence of foreign officers, and sharing of various databases (police database including criminal records; commercial register data; vehicle owners data; hotel registration data; telephone number data; traffic data; IP addresses data; Individual citizens register (ZPR) data).  
- Police-to-police cooperation is informal and flexible; no incidents obstructing adequate and timely responses to counterpart requests were reported.  
- Liechtenstein’s accession to the Schengen system enhances police cooperation with Schengen countries through SIRENE and the Schengen Information System; liaison officer networks are commonly used and effective.  
- Police may spontaneously provide information on all offenses including ML and FT (Art. 35.2.b NPA).

### Spontaneous exchange and scope of exchanged information
- FMA statutes (DDA, FMAA, Banking Act) refer to exchange with a “requesting” authority; the FMAA is explicit that exchange should only occur in response to a request, implying no explicit right to spontaneous exchange. The FMA reports spontaneous exchanges have occurred in practice (e.g., at international meetings), and assessors consider absence of explicit statutory spontaneous-exchange provisions would not be an insuperable barrier in practice.  
- The FMA can exchange information on market abuse as a predicate offense because it has responsibility to investigate such offenses, but supervisors should generally not exchange information on underlying offenses beyond their direct responsibility.  
- The FIU can exchange information both spontaneously and upon request and is empowered to exchange information in relation to ML, FT, and predicate offenses.  
- The police have the ability to spontaneously provide information to counterparts on all offenses and related issues, including ML and FT.

### Making inquiries on behalf of foreign counterparts (FMA powers to obtain information)
- Art. 28(4) DDA: FMA may demand from any person subject to the Act all information and records required to fulfill supervisory activities for purposes of the DDA, including cooperation with foreign authorities pursuant to Art. 37.  
- Art. 28(1)(c) DDA: extraordinary inspection may be undertaken if circumstances appear to endanger the reputation of the financial center or if a request indicates a financial institution failed to conduct due diligence properly; Art. 37 allows passing this information to a foreign supervisor.  
- Art. 26(1) FMAA: FMA may invoke fact finding where circumstances may put the reputation of the finance sector at risk; allows demanding information from licensed persons and unlicensed persons carrying out licensable activity (Art. 2,6 para. 2). Art. 27 et seq FMAA would allow passing information to foreign securities supervisors, subject in principle to administrative court approval.  
- Art. 30i Banking Act: permits the FMA to respond to a foreign authority request to cooperate in monitoring, onsite inspections, or investigations by carrying out the work, permitting foreign supervisor to do it, or allowing independent auditor/expert; limited to “matters concerning the law of supervision.”  
- Similar powers exist in Art. 27 EIA, Art. 28 PSA, Art. 27h FMAA, and Arts. 133 and 136 UCITSG for sharing information with foreign supervisors within supervision framework. For insurance, IUA contains similar powers with respect to reinsurance businesses only. It is not explicit whether this covers compliance with DDA requirements, but assessors accept it is probable.

*Italic: Content based on cr18257 - 1099. It is recommended that the authorities:*

### 1131. As noted above, the assessors accept that, under the sector specific Acts: Banking and FMA

### cr18257 - 1131. As noted above, the assessors accept that, under the sector specific Acts: Banking and FMA

### Access and transmission powers (sections 1131–1132)
- The FMA has powers under the sector specific Acts: Banking and FMA Acts (the latter for securities), and the DDA to make enquiries to obtain information for the purpose of passing it to foreign supervisory authorities (1131).
- For obtaining information it makes little difference whether the Banking, Insurance, or DDA laws apply; however, Art. 27h in the FMAA appears stricter though FMAA stated this has not proved a barrier in practice (1131).
- For insurance businesses other than reinsurance companies, Art. 28(4) of the DDA remains applicable despite the absence of sector-specific provisions (1131).
- Professional trustees and lawyers: relevant laws do not envisage exceptions to strict confidentiality; the FMA may rely on DDA powers to obtain information. The Supreme Administrative Court confirmed that under the DDA the FMA can access information otherwise covered by professional secrecy from lawyers and trustees; assessors accept it is reasonable to assume these powers can be used to pass information to foreign authorities though this has not been tested (1132).

### FIU authorized inquiries and limitations (sections 1134–1136, 1152–1153)
- The FIU may search its own databases, including information related to SARs, and may search or request information in other (government and commercial) databases to which it has direct and indirect access (1134).
- The FIU Act gives a general competence to “obtain information necessary to detect ML, predicate offense to ML, organized crime, and terrorist financing” but this power is subject to legal provisions relating to the protection of secrecy (1134).
- Information that needs to be requested from the FMA may not be shareable with (or obtainable for) the FIU due to issues noted under Recommendations 4 and 26 (1134).
- In certain cases where requested information requires gathering information subject to secrecy from a reporting entity, the FIU holds a meeting with the reporting entity to bring potential suspicious activity to its attention, which may trigger the submission of a SAR by the reporting entity; the FIU then forwards information to the foreign FIU. This indirect method has been tested and shown to work in practice (1135).
- Assessors retain reservations: information from requesting foreign FIU should be substantiated enough to trigger a SAR by the relevant reporting entity in Liechtenstein (1135).
- Given Liechtenstein’s specificity and importance of international cooperation, the framework does not allow for “the widest range of international cooperation” with foreign FIUs as required by Recommendation 40 (1136).
- Art. 7, para. 2, lett. a) of the FIU Act: the information requested must be in accordance with the FIU Act and must not violate public order and other essential national interests (1152).
- Before exchanging information the Liechtenstein FIU must ensure: the requesting FIU would grant a similar request from Liechtenstein; guarantee information will only be used to combat ML, predicate offenses of ML, organized crime, and FT; information will only be forwarded after consultation with the Liechtenstein FIU; and the requesting FIU is subject to official and professional secrecy. Requests may be acceded to only where the Law on International MLA in Criminal Matters does not apply (1153).
- Assessors view these FIU conditions as not unreasonable or unduly restrictive except for some reservations regarding the reference to official and professional secrecy (1154).

### Feedback on FIU exchanges and assessors’ reservations (sections 1137–1138)
- Feedback from eighteen countries: thirteen reported exchange of information is very good, good, standard, or without particular problems; one country noted high quality where used; however four countries were critical of quality (1137).
- Critical feedback examples: until mid-2012 Liechtenstein provided information only via letters rogatory; nowadays FIU shares banking information only if in its database; financial information was not provided in review period; difficulty obtaining identity or beneficial owner information; “limited access of the FIU to financial data”; and number/content of FIU requests did not reflect expected ML cases (1137).
- FIU emphasized it has never refused to provide information; assessors nevertheless retain reservations (1138).

### Police cooperation and conducting investigations on behalf of foreign counterparts (sections 1133, 1139–1141, 1143–1144)
- The police can render assistance in the form of inquiries on behalf of foreign law enforcement authorities as described in 40.1 and 40.5 (1133).
- Police-to-police requests through Interpol normally allow communication of information or intelligence, not incisive investigation; with consent of the involved person some noncoercive investigative acts (e.g., taking a statement) are possible; otherwise MLA procedure applies (1139).
- Treaty between Liechtenstein, Switzerland, and Austria provides broader cooperative measures; national police can at request:
  - determine the domicile or sojourn of a person during a certain time;
  - determine the holder of telephone numbers;
  - establish the identity of a person;
  - establish information concerning the origin of things (history of property in goods like cars, weapons etc.);
  - coordinate and initiate search measures;
  - conduct and take over cross-border observations and deliveries;
  - establish the willingness of persons to stand as a witness;
  - conduct police interrogations;
  - clarify traces for evidence (1140).
- Swiss customs cooperation capacities (whose radius of action includes Liechtenstein) are available insofar as Liechtenstein is concerned (1141).
- Art. 37, para. 2 of the DDA stipulates conditions for exchange of confidential information (see “Conditions applicable under DDA” below) (1143–1144).

### Conditions and restrictions on exchange of information — FMA (sections 1142–1151)
- Uncertainty exists whether DDA or sector-specific laws apply for information exchange involving banks, securities, and insurance; these laws apply different conditions, notably regarding the nature of confidentiality in the requesting state and restrictions on use (1142).
- DDA, Art. 37, para. 2 conditions for exchange of confidential information:
  - Sovereignty, security, public order, or other essential interests of the state are not violated;
  - The recipient and persons mandated by the competent authority are subject to a confidentiality requirement equivalent to Art. 23 of the Public Enterprise Act;
  - It is guaranteed that transmitted information is used to verify compliance with due diligence requirements as referred to in the DDA;
  - Where requested information had been received from a foreign authority, the express permission of the transmitting authority must be given and information must only be used for the purpose for which those authorities have consented (1143).
- Art. 23 of the Public Enterprise Act creates a “triple lock”: secrecy must be observed if information was gained in course of public company activity and if it is in the interest of the public company or the state or predominantly in the private interest for information to be withheld; no provision to override private interest if state or FMA wish to disclose; Art. 23 provides no exceptions (1144–1145).
- If Art. 23 interpreted strictly it could result in severe restrictions; Art. 23 is unusual and highly unlikely foreign authorities would have equivalent restriction (1145).
- Information exchange articles in Banking and Insurance Acts require confidentiality provisions equivalent to those in those acts; these are less restrictive and would not amount to undue constraint (1146).
- FMAA has no “equivalence” provision but requires information should not be disclosed by requesting authority except with prior written consent of the FMA; DDA insists on a guarantee information only used to verify compliance with due diligence; Banking and Insurance Acts require use only for supervisory purposes (1147).
- DDA gives FMA authority to pass information received from foreign authorities to other domestic authorities (Art. 37, para. 4); Liechtenstein legislation allows FMA to pass information domestically but prevents foreign authorities from similar onward use of information provided by the FMA (1148).
- FMAA provisions require judicial review and Administrative Court approval before FMA authorized to obtain requested information from holder of information; FMA informs assessors this has not proved a barrier in their experience (1148).
- Given experience and limited demand for AML/CFT information exchange from regulated securities businesses, assessors do not consider FMAA provisions constitute unreasonable barrier to information exchange for securities supervision; nevertheless assessors recommend harmonizing requirements across statutes (1148).
- Jurisprudence suggests “best efforts” of recipient institution to protect information received from FMA might be sufficient to satisfy legal requirements against onward disclosure but this was not in AML/CFT context and could be open to challenge, especially under FMAA which requires written permission and allows FMA to cease cooperation after violation until remedial measures (1149).
- If sector-specific laws apply, FMA could pass confidential information to a foreign authority as that authority likely can meet confidentiality conditions; if DDA overrides sector-specific laws, FMA would have to satisfy that the foreign authority had a “triple lock” equivalent to Art. 23 — an unreasonable barrier (1150).
- For lawyers and TCSPs, DDA is the only statute that could permit exchange of confidential information to a foreign regulatory authority; Professional Trustees Act and Lawyers Act do not provide for exchange. Restriction created by DDA requirement that recipient authority have confidentiality provisions equivalent to Art. 23 constitutes an unreasonable or unduly restrictive condition (1151).

### Conditions and restrictions on exchange of information — FIU and police fiscal exception (sections 1155–1159)
- Mutual police assistance is not permitted on traditional refusal grounds: violation of public order, essential national interests, tax matters, nonrespect of human rights and political, military, religious, or racist purposes. These restrictions are within internationally accepted standards (1155).
- Art. 7, para. 2, lett. a) of the FIU Act provides that information requested must not violate matters subject to fiscal interests (1156).
- Authorities stated this fiscal-related provision was introduced to safeguard against requests by a foreign FIU on behalf of a law enforcement or tax authority for purposes extraneous to ML/FT; FIU may not exchange information with foreign FIU in such cases. Authorities clarified the condition prohibits disclosure concerning fiscal interests of the state and is not intended to protect fiscal interests concerning the person who is the subject of the request (1157).
- Assessors believe this provision should be amended to clarify the extent of application of the condition relating to fiscal matters (1158).
- Fiscal exception rule applies to whole Liechtenstein law enforcement system, including police and intelligence; exceptions could be made for VAT-carousel related matters. The DDA provisions that previously restricted information exchange for secrecy or fiscal interests (2007 MER) have been removed; general restriction relating to matters of essential interest to the State retained (1159).

### Specific statutory secrecy provisions (section 1160)
- Confidentiality/secrecy provisions for financial sector and professions set out as follows (1160):
  - FIs: Art. 14 of the BA, Art. 44 of the ISA, Art. 21 of the AMA, Art. 25 of the UCITSG, Art. 18 of the EIA, Art. 5 of the PSL, Art. 4a of the IMA, and Art. 15 of the IUA.
  - Lawyers, trustees, and auditors: Art. 15 of the Law on Lawyers, Art. 10 of the Law on Auditors, and Art. 11 of the Law on Trustees.

### Assessors’ conclusions and policy recommendations (derived from text)
- The framework allows information exchange in many cases but does not permit “the widest range of international cooperation” with foreign FIUs as required by Recommendation 40 (1136).
- The assessors retain reservations about FIU indirect methods of obtaining information through triggering SARs—requests from foreign FIUs must be substantiated sufficiently to induce SAR filing by reporting entities (1135, 1138).
- The “triple lock” confidentiality requirement in Art. 23 of the Public Enterprise Act, as applied via DDA Art. 37, para. 2, risks creating an unreasonable barrier to information exchange if DDA is held to override sector-specific laws (1144–1151).
- The assessors recommend harmonizing the requirements for information exchange across the different statutes to avoid uncertainty and potential unreasonable restrictions (1148).
- The assessors recommend amending Art. 7, para. 2, lett. a) of the FIU Act to clarify the scope of the fiscal matters condition (1158).

*Source: Extracted content from the provided IMF assessment text (paragraphs 1131–1160).*

### 1161. For FIs, the secrecy provisions under the relevant sector-specific laws are identical and

### cr18257 - 1161. For FIs, the secrecy provisions under the relevant sector-specific laws are identical and 

### Secrecy provisions for FIs and DNFBPs
- FIs: Secrecy provisions under sector-specific laws require members of governing bodies and employees of FIs to keep secret all facts entrusted or made accessible to them through business relations with clients. Failure to comply may result in criminal responsibility.
- Exception for FIs: Obligation of confidentiality does not apply to legal provisions regulating provision of information to criminal courts, supervisory authorities, or provisions regulating cooperation with other supervisors.
- DNFBPs: Relevant provisions impose an obligation of secrecy on matters entrusted to the lawyer, auditor, or trustee and on facts learned in the course of professional capacity that are confidential in the interest of the client.
- Limitation for DNFBPs: The right to such secrecy is subject to applicable rules of procedure in court proceedings and other proceedings before government authorities.

### Financial Market Authority (FMA) powers and limitations
- Art. 28(4) of the DDA grants the FMA access to any information held by persons subject to the law needed to carry out its supervisory functions under the DDA.
- FMA supervisory functions include passing confidential information to foreign supervisors pursuant to Art. 37 of the DDA.
- Non-provision of requested information by persons subject to the law may result in the imposition of an administrative fine by the FMA.
- For DNFBPs, Art. 28(4) of the DDA is not limited to nonconfidential information: the FMA can compel production of confidential information held by DNFBPs and may share such information with foreign supervisory authorities.
- Outside the supervisory context the FMA’s power to access confidential information remains unclear.
- Restrictions on use of exchanged information by the FMA (Art. 37, para. 4 of the DDA): information received from foreign authorities may be used only to:
  - verify compliance with due diligence requirements;
  - impose sanctions;
  - in the framework of administrative proceedings concerning the appeal of decisions of a responsible authority; or
  - in the framework of judicial proceedings.
- The FMA is subject to confidentiality obligations of Art. 23 of the Public Enterprise Act; those are overridden by Art. 3 of that Act concerning passing information to other authorities. Provisions requiring equivalent confidentiality protections in foreign supervisory authorities, however, refer to Art. 23 and do not refer to the override in Art. 3.
- No scope for the FMA to exchange information with foreign authorities that are not counterparts. DDA Art. 37, para. 2 permits information exchange only to foreign financial market supervisory authorities/competent authorities (term not defined).
- There are no statutory provisions requiring the FMA to disclose the purpose of a request for information or the person on whose behalf it is made, although FMA practice is to do so.
- Statistics: No statistics on information requests can be supplied since there have been no instances of information exchange by the FMA on AML/CFT matters.

### Financial Intelligence Unit (FIU) powers and limitations
- Art. 7, para. 2, let. a) of the FIU Act requires that information requested must not violate matters subject to secrecy. Authorities clarified this intends to restrict disclosure of state secrets to other FIUs, not to protect financial secrecy of the person in regard to whom the request is made.
- Assessors view the scope of the condition in Art. 7, para. 2, let. a) as not entirely clear and potentially challengeable.
- FIU obtaining of information is also restricted by the FIU Act provision subjecting obtaining of information to secrecy provisions.
- The FIU may only request information required for purposes of the FIU Act.
- Information received from a foreign FIU may only be used by the FIU for purposes as defined in the request.
- FIU officers are bound to keep confidential information received in the performance of functions pursuant to Art. 38 of the Secrecy Act.
- The FIU Act does not provide for the power of the FIU to exchange information with non-counterparts.
- The FIU may obtain information from other competent authorities pursuant to a request from a foreign FIU.
- FIU statistics (incoming foreign requests / requests to foreign FIUs):
  - Year 2009: Incoming foreign requests to the FIU 231 ; Requests to foreign FIUs 235
  - Year 2010: Incoming foreign requests to the FIU 261 ; Requests to foreign FIUs 248
  - Year 2011: Incoming foreign requests to the FIU 153 ; Requests to foreign FIUs 175
  - Year 2012: Incoming foreign requests to the FIU 304 ; Requests to foreign FIUs 332
  - Year 2013 (Q1): Incoming foreign requests to the FIU 87 ; Requests to foreign FIUs 88

### Police access and cooperation
- The police have no direct access to confidential or privileged information; any criminal investigation request to that end falls under the MLA regime.
- Mutual administrative assistance is purpose bound: shared data can only be used for the same purposes they were provided unless prior consent is given by the National Police (Art. 35.4 NPA).
- International police assistance principle: only relate to requests emanating from an authority having police qualifications and powers.
- Police statistics on incoming counterpart requests related to economic and financial crime (fraud, embezzlement, money laundering, corruption) 2009–2012:
  - 2009: 128
  - 2010: 104
  - 2011: 87
  - 2012: 74
  - Total: 393

### Safeguards in use of exchanged information
- FMA: constrained by Art. 37, para. 4 of the DDA to use information from foreign authorities only for specified purposes (see FMA section above).
- FIU: may only request information required under the FIU Act; information from foreign FIUs may only be used for purposes defined in the request; officers bound by Art. 38 Secrecy Act.
- Police: shared data purpose-bound under Art. 35.4 NPA and general confidentiality rules govern operational communications.

### Exchange with non-counterparts and international cooperation
- FMA: no legal scope to exchange information with non-counterparts; exchanges are restricted to equivalent authorities.
- FIU: FIU Act does not permit exchange with non-counterparts; FIU may not exchange information on FT with non-counterparts.
- International cooperation for ML applies equally to terrorist financing under SR V (provisions described for ML also apply to TF).
- The FIU may obtain information from other competent authorities pursuant to a request from a foreign FIU.

### Effective implementation and assessment findings
- FMA: exchange of information on AML/CFT matters by supervisors is rare; legal provisions are theoretical in practice though FMA has exchanged information with foreign counterparts on other matters.
- There is uncertainty about which laws apply for information exchange on AML/CFT matters. If the DDA applies, it permits information exchange subject to severe constraints imposed by the need for Art. 23 COPE equivalence. If sector-specific laws apply, information exchange would be less restrictive for banks, insurance, and securities business.
- Authorities consider the DDA takes precedence; DDA is the only statute providing for exchange of confidential information for DNFBPs.
- The DDA obliges the FMA to check that a receiving authority has a triple lock confidentiality provision equivalent to Art. 23 of the Public Enterprise Act; strict application would be a severe restriction.
- FIU effectiveness hampered by restricted secrecy provisions and inability to obtain information unless a SAR has been submitted; FIU’s ability to obtain beneficial ownership information in response to foreign FIU requests is limited.
- Feedback from foreign FIUs was uneven: several FIUs provided positive or neutral feedback while some jurisdictions raised issues concerning the information received.
- Police-to-police cooperation is frequent within economic/financial matters; assistance by Liechtenstein police appears constructive and flexible though informal cooperation limits investigative incisiveness. Formal refusal grounds are not uncommon and unreasonable.

### Recommendations and comments (as presented)
- Harmonize provisions regulating exchange of information by the FMA with foreign authorities to clarify confidentiality obligations and specify other conditions for exchange. Remove reference under Art. 37 of the DDA requiring the foreign supervisor to be subject to the same secrecy provisions as contained in Art. 23 of the COPE.
- Remove the reference in Art. 4 para.3 of the FIU Act restricting the power of the FIU to obtain only information not subject to legal provisions relating to protection of secrecy. Consider a provision stating that information provided by reporting entities to the FIU for any purpose shall not be subject to legal provisions on secrecy.
- Consider introducing an express provision in the FIU Act empowering the FIU to obtain additional information from reporting entities following a request from a foreign FIU, irrespective of whether a SAR has been submitted; provision should indicate information requested is to be provided without delay.
- Remove conflicting provisions regarding the FMA’s ability to exchange information with the FIU to ensure proper FIU access to such information in international cooperation.
- Amend Art. 7, para. 2, lett. b) of the FIU Act to clarify the extent of application of the condition relating to secrecy and fiscal matters.
- FIU should consider introducing a provision in the FIU Act to permit exchange of information with non-counterparts.

### Compliance ratings and issues (summary)
- R.40: PC
  - Issues concerning the FMA:
    - Art. 37 of the DDA requiring foreign supervisor to be subject to same secrecy provisions as contained in Art. 23 of the COPE is unduly restrictive.
  - Issues concerning the FIU:
    - FIU’s access to information could be restricted by secrecy provisions (Art. 4(3) of the FIU Act).
    - Ambiguity in the FIU Act (Art. 7) concerning secrecy and exchange of information.
    - Limitations regarding FMA’s access to information on behalf of domestic third parties and sharing of information limits FIU’s ability to make inquiries on behalf of foreign counterparts.
  - Effectiveness:
    - Concerns on quality of information exchanged by the FIU expressed by a number of jurisdictions.
    - FIU’s inability to request additional information (e.g. beneficial ownership information) from reporting entities pursuant to a request from a foreign FIU has a negative impact on effectiveness.
- SR.V: PC
  - Same core issues identified for both FMA and FIU as under R.40.
  - Effectiveness: FIU inability to request additional information (e.g. beneficial ownership information) from reporting entities pursuant to a request from a foreign FIU negatively impacts effectiveness.

### Resources and statistics (selected figures)
- FMA financing: state contribution 49 percent; remainder covered by supervisory levies, fees, and services.
- FMA staffing:
  - Total staff employed 72.5 full-time equivalents at end of 2012 (75.6 at time of evaluation).
  - At 2007 MER: 29 staff (plus eight trainees).
  - Approximately 50 staff work in four supervisory divisions split roughly equally between banks, insurance, securities, and other institutions (including TCSPs).
  - Total staff increased from 56.7 to 76.6 over 2008–period referenced.
- FMA assessment: resources are not sufficient to allow appropriate degree of AML/CFT supervision; DNFBP sector subject to less frequent inspection cycle than FIs due to resource constraints.
- FIU staffing and resources:
  - Total number of persons employed by the FIU is 10 (a forty percent increase since 2008).
  - FIU units: Strategic Analysis Unit (2 analysts), Operational Analysis Unit (4 analysts), International Affairs Unit (1 person), secretariat (1 administrative officer).
  - FIU access to commercial databases: LexisNexis, World-Check; developed ARIS with Basel Institute on Governance.
  - FIU staff backgrounds include lawyers, economists, police officers, international affairs experts, and private sector compliance experience.
- Public Prosecutor’s Office:
  - Seven prosecutor magistrates serve all instances of courts in all criminal matters.
  - Judiciary: 14 judges at the Court of Justice; four serve as investigating judges/magistrates and are specialized in mutual legal assistance.

*IMF country report content unit cr18257 (excerpts provided).*

### 1196. The police count 120 staff, with 7 investigators assigned to financial and economic affairs.

### 1196. The police count 120 staff, with 7 investigators assigned to financial and economic affairs.

### Staffing and operational capacity
- Police strength:
  - The police count 120 staff, with 7 investigators assigned to financial and economic affairs.
- Assessment of capability:
  - They appear sufficiently trained and capable.
  - There does not seem to be abnormal backlog of cases under investigation.

### Supervisory and analytical bodies — statistics and reporting
- FMA (Financial Market Authority):
  - Maintains statistics on onsite inspections undertaken and on sanctions applied to individual institutions.
  - Does not maintain regular statistics on requests for information on AML/CFT because such requests are so rare but it does maintain statistics on information requests more generally.
- FIU (Financial Intelligence Unit):
  - Maintains statistics on SARs received by the FIU, including a breakdown of the type of FI, DNFBP, or other business or person making the SAR and a breakdown of SARs analyzed and disseminated.
- Police/Public Prosecutor’s Office:
  - Authorities provided comprehensive and detailed statistics on ML/TF investigations, prosecutions and convictions, freezing and confiscation of criminal proceeds, property frozen under the UNSCR lists, and MLA and extradition traffic.

### Recommendations (selected)
- Recommendation 32 (FMA)
  - FMA should review the level of staffing according to the recommendations of this report. Staff should be allocated taking account of the AML/CFT risk of different sectors;
  - FMA should adopt a policy with regard to training on AML/CFT and monitor its implementation.
- Additional operational recommendation (from section 9.1.1):
  - FMA should review staffing allocation between divisions to address inadequate staffing in DNFBP supervision that affects the processing of onsite inspection reports on a risk-reflective cycle.

### Ratings and summary of factors underlying ratings (selected)
- R.30: LC
  - Staff allocation between divisions has left DNFBP supervision division with inadequate staff to process onsite inspection reports on a cycle that reflects the risk of the sector.
- R.32: C
- Institutional and system-wide notes:
  - The report contains extensive ratings and factors across the FATF 40+9 framework, including specific findings under Legal systems, Preventive measures, Institutional and other measures, International Cooperation, and Special Recommendations.
  - Examples of systemic concerns noted in the report:
    - Verification and CDD shortcomings (e.g., high threshold of CHF 25,000 for identification of existing anonymous or bearer passbooks, accounts, or custody accounts).
    - Restrictions on information access and secrecy provisions affecting FIU and FMA information exchange.
    - Over-reliance on audit firms for inspections with potential conflicts of interest.
    - Limited aggregate off-site analysis and absence of a fully risk-based allocation of inspection resources.
    - Low number of SARs from many DNFBPs (except TCSPs).
    - Administrative fines for institutions are not proportionate or dissuasive.
    - Issues in mutual legal assistance and delays in obtaining bank records due to dilatory tactics and legal privilege.

### Key statistics and precise figures (verbatim)
- Police staff: 120
- Investigators assigned to financial and economic affairs: 7
- Threshold for identification of existing anonymous or bearer passbooks, accounts, or custody accounts: CHF 25,000

### Noted effectiveness issues affecting AML/CFT outcomes (selected)
- Confiscation hampered by high burden of proof to establish link between illegal assets and specific predicate offenses.
- Inconsistent application of due diligence measures across FIs and DNFBPs.
- The automatic five-day freezing on filing a SAR may have an adverse effect on the reporting mechanism.
- The requirement to submit SARs to the Office of the Public Prosecutor (OPP) by the FIU hinders effectiveness and may expose reporting entities.
- FIU’s unclear authority to request additional information could have impacted its ability to obtain information from reporting entities during the period under review.
- Limitations on FMA’s ability to exchange confidential information domestically and with foreign supervisors restrict cooperation.

### Recommended Action Plan—priority themes (as reflected in report)
- Review and reallocate staffing at FMA to ensure DNFBP supervision can process onsite inspection reports on a cycle that reflects sector risk.
- Adopt and implement an AML/CFT training policy at FMA and monitor implementation.
- Address legal and regulatory gaps that limit FIU and FMA access to information, including secrecy provisions that impede information sharing.
- Strengthen CDD requirements and remove blanket exemptions (e.g., Art. 10 of the DDA) that are not FATF-compliant.
- Enhance supervisory practices: reduce over-reliance on external audit firms, adopt risk-based inspection allocation, and increase off-site aggregate analysis.
- Improve effectiveness of SAR mechanism by reassessing mandatory automatic freezing periods and streamlining SAR handling to avoid exposing reporting entities.

*Source: cr18257 - 1196. The police count 120 staff, with 7 investigators assigned to financial and economic affairs.*

### 1.      General

### 1.      General

### 2. Legal System and Related Institutional Measures

- 2.1 Criminalization of Money Laundering (R.1 and 2)
  - Pursue proactively money laundering as an autonomous offense, in order to create jurisprudence on the burden of proof to establish the predicate offense; and
  - Consider increasing the effectiveness of the repressive approach by attenuating the formal high level of proof by amending the list-based money laundering offense to an all-crimes offense.

- 2.2 Criminalization of Terrorist Financing (SR.II)
  - The penalties be increased to enhance their deterrent effect.

- 2.3 Confiscation, freezing, and seizing of proceeds of crime (R.3)
  - The incomplete coverage of Art. 98a CPC needs to be addressed to include all persons and entities subject to the DDA, more in particular lawyers, auditors and trustees;
  - The legislator examine effective countermeasures against abuse of the legal privilege protection in case of dual capacity;
  - As with the money laundering offense, develop autonomous procedures as a correction to the reliance on foreign factors;
  - The legislator considers extending the principle of the sharing or reversal of proof, now provided in Art. 20, para. 2 and 3 PC, to all serious offenses or crimes in all circumstances in the context of an in rem procedure;
  - Exclude the auditors, who have no legal representation function, from the scope of legal privilege regime envisaged by article 108 CPC Compliance with Recommendation 3.

- 2.4 Freezing of funds used for terrorist financing (SR.III)
  - The scope of application of the ISA 2008 is not restricted to certain countries by removing this general clause from the ISA;
  - Issue guidance on the procedures for de-listing from the Al-Qaeda and Taliban UN list.
  - Procedures to be followed for drafting domestic lists are elaborated.

- 2.5 The Financial Intelligence Unit and its functions (R.26)
  - The FIU should take measures to ensure that when SARs are submitted they always contain protective markings;
  - The provisions in the FIU Act which deal with the FIU’s access to information from other competent authorities should require that such information is provided on a timely basis;
  - The provisions (in sector-specific laws) restricting the exchange of information between the FMA and the FIU should be revised;
  - Art. 6 of the FIU Act should be amended to clearly state that competent authorities are required to provide information to the FIU when they are so requested;
  - The reference in Art. 4 para. 3 of the FIU Act which restricts the power of the FIU to obtain only information which is not subject to legal provisions relating to the protection of secrecy should be removed to avoid any ambiguity. The authorities should also consider introducing a provision in the law which states that any information that is provided by reporting entities to the FIU for any purpose shall not be subject to any legal provisions on secrecy;
  - The authorities should consider including specific sanctions in the DDO for failure to provide additional information when requested by the FIU;
  - The FIU should consider implementing a system whereby information provided by reporting entity is submitted electronically and integrated automatically into the IT system of the FIU;
  - The FIU should not be required to disseminate the SAR itself to the OPP as stated in Art. 5, para 1, let. b) of the FIU Act;
  - Authorities could consider to conduct a review to determine whether the low number of prosecutions and absence of convictions resulting from FIU notifications is related to the quality of the disseminated reports;
  - The FIU should regularly request feedback from foreign FIUs on the quality and usefulness of information provided;
  - Reference to secrecy and fiscal matters within the power of the FIU to exchange information with foreign FIUs should be clarified.

- 2.6 Law enforcement, prosecution and other competent authorities (R.27 and 28)
  - (No specific bulleted recommendations provided in the source for this subheading.)

- 2.7 Cross-Border Declaration and Disclosure (SR IX)
  - Apply the requirements to containerized cargo and to the mailing of currency;
  - Align the seizure requirements to fully comply with the power to stop or restrain the currency when there is a suspicion of ML/FT or when there is a false disclosure;
  - Introduce sanctions that are proportionate to the undeclared amount of funds (for example, by adding to the existing fixed sanction, a pecuniary sanction expressed in percentage to the undeclared amount) and establish sanctions in the case of legal persons;
  - Ensure effective implementation of the disclosure requirements at the border with Switzerland;
  - Establish training program and implement SRIX best practices.

### 3. Preventive Measures–Financial Institutions

- 3.1 Risk of money laundering or terrorist financing
  - (No specific bulleted recommendations provided in the source for this subheading.)

- 3.2 Customer due diligence, including enhanced or reduced measures (R.5–8)
  - The authorities should formulate more practical and broadly defined risk indicators (i) to ensure that even the slightest indication of risk results in a review of the categorization for a given customer, business relationship or service; (ii) to promote a better understanding amongst the industry as to what “risk” is; and (iii) to assist in applying more consistent approach by FIs to defining the various risk categories;
  - Revise Art. 5(2)(b) of the DDA to require the application of CDD measures also to occasional transactions that are not cash transactions;
  - For customers that are natural persons, introduce an express legal obligation for FIs to determine in all cases whether a customer is acting on behalf of another person, and to take reasonable steps to obtain sufficient identification data to verify the identity of that other person.
  - Verification measures for legal persons should be strengthened, and incorporate the methods suggested in the General Guide to Account Opening and Customer Identification;
  - Art. 11 of the DDO should be amended to require verification measures for beneficial owners to be based on relevant data and information obtained from reliable source;
  - Art. 8(2) of the DDA should be revised to impose an obligation on persons subject to the law to carry out reviews of existing records as part of their ongoing CDD;
  - The blanket exemption for CDD under Art. 10 of the DDA should be removed. Simplified CDD measures should be allowed only in cases of a proven low risk and at least some minimum level of CDD should be required to be carried out in all cases. For foreign customers, simplified CDD should be allowed only where Liechtenstein (as opposed to the FI) is satisfied that the country in which the customer is located complies with and effectively implements the FATF standard;
  - Art. 18(2) should allow only for verification but not identification measures to be delayed in certain circumstances. The possibility of delayed verification should be limited to situations where it can be assured that the delayed measures are carried out as soon as reasonably practicable, and all aspects of the ML risks are effectively managed. The legal framework under the DDA should set out an express requirement to apply CDD measures to all existing customers on at appropriate times, and on the basis of materiality;
  - The threshold of CHF 25,000 for identification of existing anonymous or bearer passbooks, accounts, or custody accounts should be eliminated;
  - For business relationships with PEPs or beneficial owners that are PEPs consider aligning the provisions of the DDA and the DDO to set out an express obligation for FIs to establish the source of wealth in all cases;
  - Art. 11(5) of the DDA and Art. 16 of the DDO should also extend to correspondent relationships with respondent institutions in other EEA member states;
  - Art. 11(5)(b) of the DDA should be amended to require FIs not only to assess the respondent institutions AML/CFT controls before entering into a cross-border banking relationship, but also to ensure that such controls are adequate and effective;
  - Art. 9 (2) of the DDA should set out an obligation for FIs to have in place policies or measures to prevent use of technological developments for ML/FT;
  - Put in place provisions to require FIs to implement policies and procedures to address the risks associated with non-face-to-face transactions (as opposed to business relationships) as part of the ongoing due diligence;
  - Consider whether the definition of beneficial owners under Art. 2 of the DDA and Art. 3 of the DDO should be revised to expressly cover the settlor of trusts, regardless of whether they maintain express control powers;
  - Commensurate with the high risk characteristics of business activities and customers in Liechtenstein, the FMA should compel Liechtenstein FIs to increase their due diligence focus towards the beneficial owner of the customer, including through verification measures;
  - Consider means of ensuring that FIs develop more thorough customer profiles based on reliable information and documentation, including by gaining a thorough understanding of how a legal entity customer fits into a structure and the relationship between the customer and the beneficial owner and other relevant parties;
  - Regarding information and documentation necessary to understand the relationship amongst legal entity customers, intermediaries, and beneficial owners, particularly in the case of foreign parties, consider clarifying what information and documentation is necessary to effectively undertake this task;
  - Consider means of ensuring that FIs are able to compel any relevant due diligence documentation, including documentation beyond the minimum requirement, from customers represented by intermediaries, or otherwise;
  - Consider requiring FIs to undertake periodic reviews of CDD information, based on risk, to augment industry practice of ad hoc review procedures;
  - Consider requiring the compliance function within an FI to take an active role in the customer on boarding and transaction monitoring and review processes, and to require compliance and management approval according to risk;
  - Consider requiring FIs applying simplified due diligence to obtain beneficial ownership information, information on the structure of the client, and other information necessary to understand the relationship, as well as to conduct periodic reviews of the customer;
  - Consider requiring FIs to undertake internal institution risk assessments of all customer relationships and transactions, and any other relevant factors, on a periodic basis, which should then inform internal policies and assist in managing customer risk;
  - Consider requiring FIs to proactively apply complete CDD on legacy customers.

- 3.3 Third parties and introduced business (R.9)
  - Liechtenstein should take a more independent approach to determining from which countries intermediaries may be for purposes of introduced business and reliance on the introducers CDD measures.
  - The authorities should conduct an assessment of the supervisory framework and of the CDD measures in place in the concerned countries where the third parties are located and limit the location of third parties to those countries that have a satisfactory supervisory framework and CDD measures.

- 3.4 Financial institution secrecy or confidentiality (R.4)
  - Undertake a review of all secrecy provisions and harmonize them with AML/CFT-related requirements and responsibilities, in order to avoid any conflict of provisions or ambiguities. Clarify that DDA overrides all secrecy provisions of sector-specific laws.
  - Eliminate any reference to secrecy as a condition for obtaining information (Art. 4) and for the exchange of information with foreign FIUs (Art. 7).
  - Clarify that the secrecy provision enshrined in sector specific laws do not inhibit FI’s ability to share confidential information with other FIs in cases where this is required under FATF Recommendations 7 or 9, for example where a Liechtenstein FI is a respondent institution or is relied upon by a foreign FI to carry out some of the CDD measures;
  - Expressly grant the FMA the legal power to share otherwise confidential information domestically for purposes of AML/CFT, either by amending sector specific laws or by clarifying in the DDA that the FMA’s powers under Art. 36 supersede any secrecy provisions in other laws.
  - Remove reference under Art. 37 of the DDA to the foreign supervisor having to be subject to the same secrecy provisions as contained in Art. 23 of the COPE.
  - Determine whether the lengthy appeals process for orders by the FMA to provide confidential information could constitute an obstacle to the effective implementation of the FATF Recommendations and if so, take measures to address this issue.

- 3.5 Record keeping and wire transfer rules (R.10 & SR.VII)
  - Revise the legal framework to also require the keeping of business correspondence ;
  - Consider revising the legal framework to include an express power by the FMA or another competent authority to extend the record retention period; and
  - Revise the legal framework to ensure that transaction records are detailed enough to permit the reconstruction of individual transactions in all cases.

- 3.6 Monitoring of transactions and relationships (R.11 and 21)
  - Recommendation 11:
    - Consider further clarifying what types of transactions might be considered “complex”;
    - Consider requiring a financial institution’s compliance function to approve transactions requiring investigation or clarification;
    - Consider requiring incoming transactions incongruent with the customer profile be frozen until investigated and cleared;
    - Consider requiring documenting all transactions and associated clarifications with the customer profile, or, if maintained in a separate system, referenced in the customer profile and immediately accessible.
  - Recommendation 21:
    - Art. 11(6) of the DDA should be further revised to require enhanced CDD not only with respect to persons in but also to persons from high risk countries;
    - Ensure that FIs understand the obligation to carry out enhanced CDD under Art. 11(6) of the DDA as mandatory;
    - Grant the government or any authority in Liechtenstein a broader power to issue and enforce countermeasures in relation to transactions or business relationships involving high risk countries.

- 3.7 Suspicious transaction reports and other reporting (R.13, 14, 19, 25, and SR.IV)
  - Recommendation 13 and Special Recommendation IV
    - The FIU should continue to undertake a thorough analysis of banks’ level of reporting to identify concretely which issues inhibit reporting and, where necessary, implement targeted measures to resolve these issues. The FIU should also continue organizing awareness-raising activities, which are already an integral part of the FIU’s activities, as a matter of priority to further enhance the reporting regime;
    - Banks’ reporting patterns should be subject to greater attention by the FIU to determine to what extent banks submit SARs only when information gathered from public sources indicates that a customer may have been involved in criminal activities. The assessors encourage the FIU to continue holding meetings with banks on an individual basis to discuss issues relating to reporting. Special emphasis should be made on the identification of suspicious activities or transactions that are not necessarily linked, either directly or indirectly, to a particular criminal activity;
    - The FIU should review the automatic freezing mechanism which applies upon the submission of a SAR. The review should include extensive consultation with all reporting entities. This review should inform the FIU on how the relevant legal provisions are to be amended;
    - The FIU should consider conducting a formal assessment to determine whether the reporting of FT suspicions should be higher;
    - The FIU should consider maintaining statistics on the number of reported SARs related to a suspicious transaction which is to be executed. This would enable the FIU to determine the extent to which Art. 18, para. 1 of the DDA is being complied with.
  - Recommendation 14
    - Art. 18, para. 3 of the DDA should be amended to extend the tipping off prohibition to person’s directors, officers and employees (permanent or temporary) of a reporting entity as required under c.14.2. Additionally, the prohibition should explicitly apply not only to the SAR but also to related information.

- 3.8 Internal controls, compliance, audit and foreign branches (R.15 and 22)
  - Provide guidance to FIs to clarify what additional measures could be taken in cases where a foreign branch or subsidiary is not in a position to comply with the DDA provisions.

- 3.9 Shell banks (R.18)
  - (No specific bulleted recommendations provided in the source for this subheading.)

- 3.10 The supervisory and oversight system—competent authorities and SROs Role, functions, duties and powers (including sanctions) (R.23, 29, 17, and 25)
  - Consider amending the DDA to clarify that the powers to undertake inspections and to obtain information for the purpose of administering the Act override any confidentiality obligations in other legislation (preferably also identifying and amending such provisions) (R29);
  - Consider providing further detail on the meaning of the term “inspection,” so as to clarify the rights and obligations of the FMA, and mandated audit firms as well as the subjects of inspections, when inspections are conducted (R29);
  - Amend the guidance to mandated audit firms to require such firms to adopt best practices with regard to the reviews of board papers and minutes, training materials, monitoring and IT systems, and internal control documents (R23);
  - Introduce a procedure further to mitigate the risk of regulatory capture of the audit firms by regulated persons, including a rotation requirement and more systematic oversight by the FMA, which would include regular reviews of their performance, rating, benchmarking of their findings, accompanying them from time to time and reviewing their working papers (R23);
  - Include the documents evidencing the source of funds and wealth in the list of required documents listed on the FMA web site and include in the FMA internal procedures manuals a specific and explicit requirement that the source of wealth and funds should normally be checked.
  - Consider extending the sector specific guidance to banks (R23);
  - Increase the number of inspections undertaken by FMA staff (R23);
  - Develop the risk-based approach by inviting the AML Committee to prepare a risk assessment on an annual basis for adoption by the board to inform an overall supervisory strategy for AML/CFT and thereafter as the basis for determining the scope and frequency of inspections on the basis of risk, the information required by a new more comprehensive off-site reporting regime, focusing on the key risk mitigation policies and procedures of regulated firms; the allocation of FMA resources to those divisions dealing with the institutions posing the highest risk and the detail given in guidance, so that it is focussed on products and services of higher risk and provides greater clarity as to the FMA’s expectations (R23);
  - Amend the definition of control in the sector based laws to make sure that any person exercising substantial influence on management, regardless of their shareholding or nominal title, should be subject to the prior approval of the FMA on the basis of integrity and competence (R23);
  - Review the upper limit on fines in the case of companies so as to ensure it is proportionate and dissuasive (R29);
  - Review the resources of the FMA in the light of the recommendations in this report with a review to allocating resources within the FMA on the basis of risk and taking account of any savings that may accrue to regulated firms, as well as the FMA as a result of a risk based approach to the frequency and scope of onsite inspections (R23).

*Source: cr18257 - 1.      General*

### 3.11  Money value transfer

### 3.11  Money value transfer services (SR.VI)

### 4. Preventive Measures – Nonfinancial Businesses and Professions

- Consider revising the definition of beneficial owners under Art. 2 of the DDA and Art. 3 of the DDO to expressly cover the settlor of trusts, regardless of whether they maintain express control powers.
- Art. 11 of the DDA should be amended to clearly require verification measures for beneficial owners to be based on reliable sources and not merely on the signature of the contracting party.
- Both for land-based and online casinos, the requirement to link certain transactions to the customer due diligence file should at a minimum apply to all transactions covered under Recommendation 12 that are equal to or in excess of 3,000 euros.
- Require both land-based and online casinos to identify and take reasonable measures to verify the identity of the beneficial owner as required under Recommendation 12.
- Art. 8(2) of the DDA should be revised to impose an obligation on persons subject to the law to carry out reviews of existing records as part of their ongoing CDD, in particular for higher risk categories of customers or business relationships.
- For customers that are natural persons, introduce an express legal obligation for DNFBPs to determine in all cases whether a customer is acting on behalf of another person and to take reasonable steps to obtain sufficient identification data to verify the identity of that other person.
- The blanket exemption for CDD under Art. 10 of the DDA should be removed. Simplified CDD measures should be allowed only in cases of proven low risk, and in all cases at least some minimum level of CDD should be carried out by the DNFBPs in Liechtenstein. Simplified CDD in relation to foreign customers should be allowed only in cases where Liechtenstein (as opposed to the DNFBP) is satisfied that the foreign country in which the foreign customer is located complies with and effectively implements the FATF standard.
- Art. 18 (2) should be amended to allow only for verification but not identification measures to be delayed in certain circumstances, and should limit the possibility to delay such verification measures to situations where it can be assured that the delayed measures are carried out as soon as reasonably practicable, and all aspects of the ML risks are effectively managed.
- The legal framework under the DDA should set out an express requirement to apply CDD measures to all existing customers on the basis of materiality.
- Art. 9(2) of the DDA should be rephrased to set out an obligation for persons subject to the law to have in place policies or measures to prevent use of technological developments for ML/FT.
- Consider the need for revising Art. 5(2)(b) of the DDA to require the application of CDD measures also to occasional transactions that are not cash transactions.
- For business relationships with PEPs or beneficial owners that are PEPs, consider aligning the provisions of the DDA and DDO to set out an express obligation for DNFBPs to establish the source of wealth in all cases.
- Consider revising the legal framework to include an express power by the FMA or another competent authority to extend the record retention period; to also require the keeping of business correspondence; and to ensure that transaction records are detailed enough to permit the reconstruction of individual transactions in all cases.
- Require land-based and online casinos to determine in all cases required under Recommendation 12 whether a customer or beneficial owner is a politically exposed person.
- Consider requiring DNPFBPs to increase their due diligence focus towards the beneficial owner of the customer.
- Consider means of ensuring DNPFBPs develop more thorough customer profiles based on reliable information, understanding and documenting how a legal entity customer fits into a broader structural framework and the relationship to the beneficial owner and other relevant parties.
- Regarding information and documentation necessary to understand the relationship amongst legal entity customers, intermediaries, and beneficial owners, particularly in the case of foreign parties, consider clarifying what information and documentation is necessary to effectively undertake this task.
- Consider requiring the compliance function within a DNPFBP to take an active role in the customer on boarding and transaction monitoring and review processes, and to require compliance and management approval according to risk.

### 4.2 Suspicious transaction reporting (R.16)

- Art. 11(6) of the DDA should be further revised to require enhanced CDD not only with respect to persons in but also to persons from high risk countries.
- Ensure that DNFBPs understand the obligation to carry out enhanced CDD under Art. 11(6) of the DDA as mandatory.
- There should be a specific obligation for the compliance officer to be at a management level.
- Grant the government or any authority in Liechtenstein the power to issue and enforce a wider range of countermeasures in relation to transactions or business relationships involving high risk countries.
- Art. 18, para. 3 of the DDA should be amended to extend the tipping off prohibition to person’s directors, officers and employees (permanent or temporary) of a reporting entity as required under c.14.2. Additionally, the prohibition should apply not only to the SAR but also to related information.
- Review the level and type of reporting by DNFBP sectors and institutions in order to identify any challenges related to reporting, and, where gaps are identified, take measures necessary to facilitate effective reporting.
- Consider means of facilitating and clarifying reporting with respect to suspicious activities or transactions not associated with any criminal activity.
- Consider removing the automatic asset freezing mechanism that accompanies reporting.
- Consider means of promoting the development of useful internal policies, accompanied by training, in all DNFBPs.
- The FIU should not be required to disseminate the SAR itself to the OPP as stated in Art. 5, para. 1, lett. b) of the FIU Act.

### 4.3 Regulation, supervision, monitoring, and sanctions (R.17, 24, and 25)

- (Content headings present in source; specific recommendations for these topics are included elsewhere in the report.)

### 4.4 Other designated non-financial businesses and professions (R.20)

- (Content headings present in source; specific recommendations for DNFBP sectors are provided in sections above.)

### 5. Legal Persons and Arrangements and Nonprofit Organizations

#### 5.1 Legal Persons–Access to beneficial ownership and control information (R.33)

- Reconsider the actual system of access to beneficial owner information (which relies on DNFBPs and FMA); in particular amend the law so that it clarifies that supervisory powers are not restricted to the fulfilment of FMA’s supervisory function.
- Subject “deposited” foundations to the same registration requirements as “registered” foundations.
- Require nominee shareholders and directors to disclose the identity of their nominator to the company.
- Require the custodian of bearer shares, in all instances, to be a licensed professional, resident in Liechtenstein and always subject to the DDA.
- Increase amount of sanctions for noncompliance with registration/notification requirements.
- Increase the number of inspections by OJ to check compliance of registration/notification requirements.

#### 5.2 Legal Arrangements–Access to beneficial ownership and control information (R.34)

- The FMA and Public Registry should introduce a policy designed to ensure that any private trustee seeking to register a trust would be notified to the FMA, so that they can confirm that the person is not acting as a professional.
- Consider amending the definition of a beneficial owner in the context of a trust, so as to include the settler and any beneficiary who receives a payment (even if that due diligence cannot be undertaken until a payment is about to be made).
- Amend the law so that it clarifies that supervisory powers can be used to obtain information for the purposes of enforcing the law and for disclosure to other authorities, both domestic and foreign.
- Clarify that the reform of bearer shares extends to Art. 928 bearer certificates in all instances.
- Introduce a full prudential regulatory regime for trust companies that would impose a fit and proper test on all executives and owners of trust companies (as is currently the authorities’ intention).

#### 5.3 Nonprofit organizations (SR.VIII)

- The authorities should conduct a review to understand the activities, size and other relevant features of NPOs in Liechtenstein in order to determine the features and types of organizations that are at risk of being misused for FT.
- The authorities should conduct periodic re-assessments by reviewing new information on the sector’s potential vulnerabilities to terrorist activities.
- More outreach programs to the NPO sector should be considered with a view to protecting the sector from terrorist financing.
- Associations with a common-benefit purpose that account for (i) a significant portion of the financial resources under control of the sector and (ii) a substantial share of the sector’s international activities should be subject to FSA supervision.
- Supervision of foundations by the FSA should also focus on FT issues.
- Measures should be in place to sanction violations of oversight measures or rules by NPOs or persons acting on their behalf.

### 6. National and International Cooperation

#### 6.1 National cooperation and coordination (R.31)

- Clarify the legal framework concerning financial secrecy provisions, as noted under Recommendation 4.
- Cooperation between the FMA and the FIU should be enhanced, particularly the exchange of information that can be used for the FMA to develop a fully fledged risk based approach, and for the FIU to have a better understanding of the level of compliance with AML requirements by the entities subject to supervision from the FMA.

#### 6.2 The Conventions and UN Special Resolutions (R.35 and SR.I)

- The deficiencies noted on the implementation of the recommendations concerning, seizure and confiscation measures, CDD, and the freezing regime of terrorist assets need to be addressed (see respective sections of the MER).

#### 6.3 Mutual Legal Assistance (R.36, 37, 38, and SR.V)

- The incomplete coverage of Art. 98a CPC needs to be addressed to include all persons and entities subject to the DDA, more in particular lawyers, auditors and trustees.
- The authorities should consider criminalizing serious tax offenses, include them as predicate offense to ML and extend the MLA to all these serious tax crimes by transposing the present relevant international standards shortly.
- The authorities should consider measures to mitigate the risk of hampering ongoing investigations in requesting countries that might stem by informing the parties affected by requests of MLA.

#### 6.4 Extradition (R. 39, 37, and SR.V)

- Adopt legislation introducing serious tax crimes as extradition ground.
- At a minimum expand the possibility to extradite for serious VAT fraud beyond the Schengen jurisdictions.

#### 6.5 Other Forms of Cooperation (R. 40 and SR.V)

- Harmonize the provisions regulating exchange of information by the FMA with foreign authorities to clarify confidentiality obligations applicable to the FMA and to specify any other conditions that need to be met for the exchange of information with foreign authorities. Remove reference under Art. 37 of the DDA to the foreign supervisor having to be subject to the same secrecy provisions as contained in Art. 23 of the COPE.
- The reference in Art. 4, para.3 of the FIU Act which restricts the power of the FIU to obtain only information which is not subject to legal provisions relating to the protection of secrecy should be removed. The authorities should also consider introducing a provision in the law which states that any information that is provided by reporting entities to the FIU for any purpose shall not be subject to any legal provisions on secrecy.
- Consider introducing an express provision in the FIU Act empowering the FIU to obtain additional information from reporting entities following a request for information from a foreign FIU, irrespective of whether a SAR has been submitted. The provision should indicate that information requested is to be provided without delay.
- The conflicting provisions regarding the FMA’s ability to exchange information with the FIU should be removed to ensure that the FIU has proper access to such information in the context of international cooperation.
- Art. 7, para. 2, lett. b) of the FIU Act should be amended to clarify the extent of the application of the condition relating to secrecy and fiscal matters.
- The FIU should consider introducing a provision in the FIU Act to permit the exchange of information with noncounterparts.

### 7. Other Issues

#### 7.1 Resources and statistics (R. 30 and 32)

- FMA should review the level of staffing according to the recommendations of this report. Staff should be allocated taking account of the AML/CFT risk of different sectors.
- FMA should adopt a policy with regard to training on AML/CFT and monitor its implementation.

#### 7.2 Other relevant AML/CFT measures or issues

- (Section present in source; specific items appear elsewhere in the report.)

#### 7.3 General framework—structural issues

- (Section present in source; specific items appear elsewhere in the report.)

*Source: cr18257 - 3.11  Money value transfer*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2018/cr18257.pdf_
