## 1. Post-Brexit AML/CFT Legal Framework

## Source details

**Canonical URL:** [1. Post-Brexit AML/CFT Legal Framework](https://www.imf.org/-/media/files/publications/cr/2022/english/1gbrea2022009.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2022/english/1gbrea2022009.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2022/english/1gbrea2022009.pdf.json)

---

### Executive summary — key findings
- The United Kingdom faces significant money laundering (ML) threats from foreign criminal proceeds owing to its status as a global financial center; authorities have a strong understanding of these risks.
- Authorities estimated the realistic possibility of "hundreds of billions of pounds" of illicit proceeds being laundered in their jurisdiction each year.
- ML/TF risks include illicit proceeds from transnational organized crime, overseas corruption, and tax crimes.
- High-risk sectors: financial services, trust and company service providers (TCSPs), accountancy and legal sectors; significant emerging risks from cryptoassets.
- Some Crown Dependencies (CDs) and British Overseas Territories (BOTs) have featured in U.K. money laundering investigations.
- Brexit and the COVID pandemic have impacted ML/TF risks.
- Authorities have deep experience in assessing ML/TF risks; leveraging big data and machine learning for cross-border payments analysis could add further insight.
- TN focus areas: risk-based AML/CFT supervision, entity transparency, and international cooperation.

### AML/CFT supervision — findings, capacity, and gaps
- Supervisory landscape and population:
  - AML/CFT supervisory authority divided among FCA, HMRC, Gambling Commission and 22 professional body supervisors (PBSs); OPBAS oversees PBSs.
  - As of end-2020, more than 97,000 entities supervised for AML/CFT compliance.
  - The FCA oversees more than 22,000 credit and financial institutions under the MLRs; of these 22,000 entities, 90 percent are identified as either high or medium risk; 23 percent are assessed as high risks, and 73 percent are deemed medium risks.
- FCA supervisory approach and activity:
  - Historic tiered approach: systematic, proactive, risk-assurance reviews, reactive.
  - Inspections activity (TOTAL ENTITIES INSPECTED): 2017/18 = 136; 2018/19 = 111; 2019/20 = 177.
  - Desk-Based Reviews totals: 2017/18 = 38; 2018/19 = 47*; 2019/20 = 147.
  - Onsite Inspections totals: 2017/18 = 98; 2018/19 = 64; 2019/20 = 30.
  - Onsite inspections ceased on March 16, 2020, due to COVID pandemic restrictions.
  - Concern: annual number of desk-based and onsite inspections (less than 200) appears not commensurate with assessed risks of supervised entities.
- Cryptoassets:
  - FCA is designated AML/CFT supervisor for cryptoasset businesses; registration and approval required.
  - As of end-December 2021, the FCA has approved registration for 22 entities, with more than 40 other entities subject of a temporary registration.
  - Recommendation: pursue amendments to legal framework to implement the FATF travel rule (obtain, hold and transmit identifying information of all parties to cryptoasset transactions).
- Resourcing and levy:
  - Proposed Economic Crime Levy: AML-regulated entities with annual U.K. revenue over £10.2m will be levied.
  - Levy bands: entities will pay either £10,000, £36,000 or £250,000 depending on U.K. revenue size band.
  - The levy aims to generate £100m per annum to fund AML capabilities.
- Enforcement:
  - Since 2018, more than £665 million of fines imposed by the FCA.
  - October 2021: FCA secured first criminal prosecution under the 2007 MLR when a major bank pleaded guilty and was sentenced to pay fines of over £264 million.
  - October 2021 global resolution (US$475 million) with US and Swiss authorities: FCA fined a major bank £147 million.
  - December 2021: a large international bank fined over £63 million for deficient transaction monitoring controls.
  - Recommendation: full resort to enforcement tools, including criminal penalties and reforms to corporate criminal liability.
- Supervision of TCSP, legal, and accountancy sectors:
  - Overlap in TCSP supervision (FCA, HMRC, PBSs); 13 PBSs for accountancy sector and 9 PBSs for legal sector covered in MLRs Schedule.
  - OPBAS reports: two thirds of PBSs did not demonstrate an effective enforcement framework; variance in effectiveness of implementation across PBSs.
  - Recommendation: consider empowering OPBAS to directly conduct AML/CFT supervision of legal and accountancy sectors where PBS has low capacity or high risks (would require legal amendments and additional resources).
- Data and analytics to enhance supervision:
  - More than 2,500 of the 22,000 entities were obliged to annually submit financial crime data returns; number required to file has almost tripled from 2,500 to 7,000 entities.
  - Recommendation: require periodic AML/CFT returns from all supervised entities disclosing key risk factors (PEP exposure, sanctions screening, jurisdictional risks, suspicious transaction reporting, resources).
  - Use advanced technological tools (big data, machine learning) and Skilled Persons mechanism to analyze large volumes and prioritize inspections.

### Entity transparency — PSC Register, trusts, real property
- People with Significant Control (PSC) Register:
  - Established in 2016; provides full and free public access to beneficial ownership information of U.K. legal entities (including Scottish limited partnerships as of 2017).
  - Legal entities required to submit annual statements confirming beneficial ownership and notify Companies House of changes within 28 days.
  - Discrepancy reporting:
    - Since January 2020 discrepancy reporting implemented.
    - More than 42,000 discrepancy reports filed with Companies House since implementation.
    - Footnote: As of November 2021, total discrepancy reports received by Companies House is 58,147.
    - Financial institutions are originators of more than 93 percent of submissions; less than 5 percent come from TCSPs, accountancy, legal and real estate sectors.
  - Recommendations to improve accuracy:
    - Introduce compulsory identity verification.
    - Expand powers of Companies House to verify information, access other government databases, and unilaterally remove inaccurate PSC Register entries.
    - Encourage increased monitoring and discrepancy reporting by TCSPs, accountants and lawyers.
- Trust Registration System (TRS):
  - TRS collects beneficial ownership information of more than 170,000 U.K. express trusts (with and without U.K. tax liabilities).
  - Majority of trusts required to report changes within 90 days; all relevant U.K. express trusts required to register by September 1, 2022.
  - Recommendation: ensure foreign counterparties have timely access to TRS information where links to foreign jurisdictions exist.
- Overseas Entities Bill:
  - Priority to pursue proposed Overseas Entities Bill to require public disclosure of beneficial ownership information of foreign entities owning U.K. real properties.
  - Complementary measures: identity verification, discrepancy reporting, enforcement mechanisms for non-submission or false information.
- Real property ML risks:
  - Example abuse: shell companies and trusts used to purchase “super prime” properties, obscuring true owners and sources of funds.

### International cooperation, asset recovery, and information sharing
- The United Kingdom provides timely and constructive international cooperation on economic crimes; was rated substantially effective for international cooperation (IO2) in 2018 MER.
- Tools and networks:
  - U.K. overseas criminal justice network covering over 160 jurisdictions.
  - Multi-agency National Economic Crime Centre (NECC) established in 2018 leads domestic and foreign economic crime response.
  - Public-private partnerships: Economic Crime Strategic Board (January 2019) and Joint Money Laundering Intelligence Taskforce (JMLIT).
- Confiscation and sanctions:
  - Robust frameworks include Unexplained Wealth Orders (UWOs) and Global Anti-Corruption Sanctions Regulations (2021).
- CDs and BOTs:
  - U.K. bilateral Exchange of Notes (2016) require beneficial ownership information be provided within 24 hours, or within one hour if urgent.
  - Recommendation: continue supporting BOTs and engage CDs to ensure robust, calibrated and publicly available beneficial ownership registers; Secretary of State to assist BOTs under Sanctions and AML Act of 2018 (Section 51).
- Information sharing:
  - Recommendation: strengthen cooperative mechanisms with foreign counterparties for timely sharing of financial intelligence in complex cross-border cases; continue to engage with CDs and support BOTs.

### Risk profile, national risk assessments, and cross-border financial flows
- National risk assessments (NRAs):
  - Three NRAs published, latest in 2020.
  - In September 2021, the first national assessment of proliferation financing risks published.
- High-risk sectors and enablers:
  - Financial services (retail banking, wholesale banking, wealth management and private banking) remain among highest ML risks.
  - TCSPs, accountancy and legal sectors high risk; professional enablers (e.g., family offices) facilitate opacity.
  - Art market participants and letting agencies became subject to the MLRs as of January 1, 2020.
- Geographic vulnerabilities:
  - Some CDs and BOTs (e.g., British Virgin Islands cited in 2020 NRA) exploited to establish corporate structures facilitating ML.
  - February 2021: Cayman Islands included in FATF list of jurisdictions with serious AML/CFT deficiencies; U.K. added Cayman Islands to its own list of high risk jurisdictions.
  - Regulated businesses required to apply enhanced CDD and monitoring for business relationships with persons established in high-risk jurisdictions.
- COVID-19 effects and trends:
  - Increased use of cryptoassets, mobile banking and electronic payments during the pandemic.
  - Risk of money mule accounts and abuse of distressed businesses to absorb illicit funds; investigations into potential large scale fraud related to government loan schemes (example: £47 billion loan value of Bounce Back Loan Scheme).
- Cross-border financial flows (IMF staff analysis):
  - Analysis uses SWIFT customer payment data July 2016 to October 2021; flows covered until October 2021.
  - Since the last FSAP, direction of flows changed with a "quarter increase" in share of flows with offshore financial centers (OFCs).
  - Inflows from and outflows to OFCs increased, particularly in 2021.
  - Payments to each of the five high risk countries identified in the 2020 NRA (China, Hong Kong, Pakistan, Russia, United Arab Emirates) have increased since 2016, including more than doubling of inflows from two countries and of outflows to three countries in 2021 as compared to 2016.
  - Supervised entities’ FCA financial crime survey shows increased inflows from high-risk jurisdictions and increased average value of transaction-inflow; average value of transaction-outflow stayed stable.
- Recommendation: leverage big data and machine learning to analyze cross-border flows, compare with economic fundamentals (trade, investments), and identify outliers and entities for prioritized supervision.

### Data, analytics, and the IMF outlier detection approach
- Big data and ML can be supplemented with trade, portfolio, direct investments, balance of payments and international investment position data to identify unusual payments unexplained by economic activity.
- IMF outlier detection machine learning algorithm:
  - Uses global cross-border payments since 2013 and indicators including bilateral trade, portfolio and direct investments, average transaction value, new payment corridors, AML/CFT regime strength, financial secrecy, tax practices, corruption perceptions.
  - Payment amounts normalized on the ordering country level.
  - Based on this analysis, the United Kingdom attracts the most inflow payments-outliers globally while not generating many outflows-outliers; inflows-outliers to the United Kingdom are persistent and well-diversified.

### Policy priorities and main recommendations (selected)
- Recommendation 1. Credit and Financial Institutions. Enhance breadth and depth of risk-based AML/CFT supervision via enhanced data collection, big data and machine learning, robust enforcement actions, and use of Skilled Persons. Responsible Agency: FCA. Timeline: NT.
- Recommendation 2. Cryptoasset Entities. Amend legal framework to obtain, hold and transmit identifying information of all parties to cryptoasset transactions (travel rule). Responsible Agency: HMT. Timeline: NT.
- Recommendation 3. TCSP, Legal and Accountancy Sectors. Intensify consistency of supervisory approaches and consider expanding OPBAS mandate/powers. Responsible Agency: HMRC, FCA, PBS/OPBAS. Timeline: MT.
- Recommendation 4. Augment Assessment of Threats. Leverage data to enhance understanding of aggregate financial flows and high-risk jurisdictions. Responsible Agency: HMT, FCA. Timeline: MT.
- Recommendation 5. Increased Resources. Move ahead with proposed Economic Crime Levy to generate resources for AML/CFT reforms. Responsible Agency: HMT. Timeline: MT.
- Recommendation 6. Accuracy of Beneficial Ownership Information. Amend legal framework and enhance Companies House powers, require verification and access to government databases. Responsible Agency: BEIS/Companies House. Timeline: NT.
- Recommendation 7. Beneficial Ownership of Real Properties. Pursue Overseas Entities Bill for public disclosure of beneficial owners of foreign entities owning U.K. properties. Responsible Agency: BEIS. Timeline: MT.
- Recommendation 8. Information Sharing. Strengthen cooperative mechanisms with foreign counterparties for timely sharing of financial intelligence. Responsible Agency: NCA. Timeline: NT.
- Recommendation 9. Support to BOTs and Engagement with CDs. Continue support to BOTs and engage CDs for accurate and publicly accessible beneficial ownership information. Responsible Agency: FCDO. Timeline: MT.
- Note: NT = Near Term (now to one year); MT = Medium Term (within 1 to 3 years).

### Cybersecurity and operational resilience — scope, findings, and recommendations
- Importance and transmission channels:
  - Cyber incidents at systemically important banks, insurers and FMIs can cause cross-border spillovers; third-party service provider incidents can create systemic events.
  - Decreasing technological diversity and concentration in Cloud Service Providers increases supply-chain risk.
- Regulatory and supervisory framework:
  - Principles-based and outcome-focused regime drawing on FSMA 2000 and Banking Act 2009.
  - PRA and FCA jointly supervise cyber risk for systemically important banks and insurers; BOE has a financial stability role and can regulate specified service providers where HMT brings them into remit.
  - Review limited to 29 systemically important institutions (15 banks, 10 FMIs and four insurers); PRA supervises around 1,500 institutions and FCA about 49,000.
- Testing and tools:
  - CBEST penetration testing program cornerstone; CBEST is intelligence-led, resource-intensive and typically on a three-year cycle.
  - Pilot STAR-FS introduced as lighter-weight penetration testing for a wider set of institutions.
  - Cyber stress tests mandated by FPC to assess systemic resilience (first pilot 2019; tests planned for 2020–2021 postponed; planning for a stress test in 2022).
  - Current cyber stress tests do not include capital and liquidity impact calculations; recommendation to research inclusion of liquidity and capital impacts.
- Supervisory practices and gaps:
  - Recommendation: complement desk-based analyses and CBEST with on-site examinations to verify operational effectiveness and encourage candor from senior management.
  - Recommendation: formalize and align reporting requirements, processes and tools to reduce inconsistencies and underreporting of incidents.
  - Recommendation: strengthen penetration testing program via guidance, accreditation, grey box testing, purple teaming, and leveraging firms’ internal threat intelligence where accredited.
  - CQUEST self-assessment:
    - CQUEST is a 48-question NIST-based questionnaire; current design relies on self-assessment with limited evidence requirements.
    - Recommendation: require firms to provide evidence supporting self-assessments for answers implying higher maturity.
  - Resource and capability recommendations:
    - Strengthen operational and cyber resilience supervisory teams; upskill generalist supervisors while recognizing limits.
    - Seek additional statutory powers to assess resilience of critical services provided by third-party service providers, narrowly scoped to relevant services.
- Third-party outsourcing and concentration:
  - Market concentration: three large cloud service providers combined global market share increased from 49.5 percent in Q1 2018 to 58 percent in Q1 2021.
  - PRA policy PS7/21: from March 2022, PRA-supervised institutions must ensure material outsourcing contracts meet regulatory requirements (access, audit, data security, sub-outsourcing management, business continuity and exit strategies).
  - Limitations: authorities currently lack legal powers to directly supervise cyber resilience of critical third-party service providers except where brought into regulatory perimeter.
- Governance, accountability and SM&CR:
  - Operational Resilience Framework (ORF) (PRA PS6/21 and FCA PS21/3, March 2021) requires firms to identify important business services, set impact tolerances, map resources supporting services, and take action to remain within impact tolerances.
  - Senior Managers and Certification Regime (SM&CR) assigns accountability; SMF24 covers operations and technology responsibilities.
  - Recommendation: extend SM&CR to BOE supervised FMIs (HMT consultation ongoing).
- Incident response and coordination:
  - Authorities’ Response Framework (ARF) and Sector Response Framework (SRF) coordinate responses; NCSC provides technical advice when invoked.
  - Recommendation: improve clarity on lead authority roles and streamline SRF architecture to support response agility.
- Testing and exercises:
  - Sector Crisis Exercise and other simulations (CMORG, SEG) rehearse collective response and decision-making; CBEST and cyber stress testing complement these efforts.
- International engagement:
  - U.K. authorities participate in G7 Cyber Expert Group outputs and collaborate internationally on penetration testing recognition and CBEST alignment.

*Source: IMF — Technical Note: Post-Brexit AML/CFT Legal Framework (chapter content provided).*

### 1. Post-Brexit AML/CFT Legal Framework ______________________________________________________________ 15

### 1. Post-Brexit AML/CFT Legal Framework

### Executive Summary — Key Findings
- The United Kingdom faces significant money laundering (ML) threats from foreign criminal proceeds owing to its status as a global financial center, and the authorities have a strong understanding of these risks.
- The authorities estimated the realistic possibility of hundreds of billions of pounds of illicit proceeds being laundered in their jurisdiction.
- ML/TF risks include illicit proceeds from foreign crimes such as transnational organized crime, overseas corruption, and tax crimes.
- High-risk sectors for money laundering: financial services, trust and company service providers (TCSPs), accountancy and legal sectors; significant emerging risks from cryptoassets.
- Some Crown Dependencies (CDs) and British Overseas Territories (BOTs) have featured in U.K. money laundering investigations.
- Brexit and the COVID pandemic have an impact upon money laundering risks in the United Kingdom.
- The authorities demonstrated deep and robust experience in assessing and understanding their ML/TF risks.
- Leveraging technology tools such as big data and machine learning to analyze cross-border payments may add further dimension to risk assessments.
- The TN focuses on: risk-based AML/CFT supervision, entity transparency, and international cooperation.

### AML/CFT Supervision — Findings and Gaps
- Priority should be given to enhancing the breadth and depth of risk-based supervision of key sectors, especially given the large supervisory population in the United Kingdom.
- The FCA’s tiered supervisory approach (systematic, proactive, and reactive) is risk-based.
- Desk-based and on-site inspections conducted (less than 200 per year) do not appear commensurate to the risks of the 22,000 supervised entities (almost all assessed as either high or medium risks).
- Broad access to data from supervised entities, robust technological analytical tools, and leveraging skilled persons will contribute to addressing challenges of effective risk-based supervision.
- On cryptoassets:
  - Continued assessment of ML/TF risks of cryptoasset businesses is required.
  - A robust approach to registration will help ensure FCA’s AML/CFT supervisory approach is effective.
  - This would need to be supported by obligations to have adequate information of parties to a cryptoasset transaction (travel rule).
- Robust enforcement actions (including effective, dissuasive, and proportionate penalties) over supervised entities will contribute to a strong AML/CFT compliance culture.
- OPBAS continues to intensify AML/CFT oversight of the legal and accountancy sectors, with scope to improve effectiveness of supervision by professional body supervisors (PBSs).
- Consider empowering OPBAS to directly conduct AML/CFT supervision of legal and accountancy sectors where the PBS has low capacity or high risks.

### Entity Transparency — Findings and Needed Actions
- The People with Significant Control (PSC) Register provides full, free, and public access to beneficial ownership information of U.K. legal entities and positions the United Kingdom as a global leader in promoting entity transparency.
- To support accuracy of the PSC Register, supervised entities are required to report discrepancies between information obtained through customer due diligence and PSC Register information.
- Efforts to further improve accuracy of beneficial ownership information should advance, including:
  - Requirement on compulsory identity verification.
  - Expanding the powers of Companies House over the information.
- The Trust Registration System (TRS) collects beneficial ownership information over U.K. express trusts (with or without U.K. tax liabilities); mechanisms for foreign counterparties to timely access such information should continue to be available.
- Priority should be given to legislative proposals to create the Overseas Entities Bill to give public access to beneficial ownership information of foreign entities owning U.K. properties.

### International Cooperation and Asset Recovery — Findings
- The United Kingdom provides a range of timely and constructive international cooperation on economic crimes.
- The U.K. overseas criminal justice network and strong domestic public-private partnerships are positive features for exchanging financial intelligence and information.
- Leveraging robust confiscation, asset recovery and targeted financial sanctions frameworks (including unexplained wealth orders and Global Anti-Corruption Sanctions Regime) is critical to address laundering of foreign proceeds of crime.
- Strong and timely information-sharing mechanisms between the United Kingdom, CDs and BOTs facilitate complex and cross-border criminal investigations.
- The U.K. authorities should continue to engage CDs and support BOTs in having robust, effectively calibrated and publicly available beneficial ownership registers to facilitate foreign criminal investigations.

### Introduction — Context and Assessment Basis
- This Technical Note (TN) provides a targeted review of the U.K. AML/CFT regime in the context of the 2021 Financial Sector Assessment Program (FSAP) and builds upon the 2016 AML/CFT TN from the previous U.K. FSAP.
- The review is based on a range of materials including the 2018 Mutual Evaluation Report (MER) by the Financial Action Task Force (FATF), information provided by authorities, and publicly available materials.
- Staff discussions occurred virtually from November 1–12, 2021 with key agencies including HMT, FCA, HMRC, PRA, OPBAS, OFSI, Companies House, FCDO, SFO, Home Office, and NECC.
- In the 2018 MER, 8 of the 11 Immediate Outcomes (IOs) were rated as satisfactory, with almost half being highly effective: IO1, IO9, IO10, and IO11.
- FATF recommended further improvements in IO3 (AML/CFT supervision), IO4 (preventive measures), and IO6 (financial intelligence).
- Key priority actions from the MER included:
  - Ensure appropriate intensity of AML/CFT supervision.
  - Improve the quality of beneficial ownership information in relation to legal persons.
  - Continue to work with international partners on information-sharing gateways.

### Policy Priorities and Main Recommendations
- The 2019–22 Economic Crime Plan (ECP) sets 52 action items with time-bound targets grouped into 8 key priority areas; as of February 2021 more than 40 percent of action items had been completed, and by November 2021 authorities reported completing 50 percent of the ECP.
- Focus areas for staff review: (a) AML/CFT supervision; (b) entity transparency; (c) international cooperation.

Main Recommendations (as presented)
- Recommendation 1. Credit and Financial Institutions. Further improve breadth and depth of risk-based AML/CFT supervision through enhanced data collection, leveraging technology analytical tools (e.g., big data and machine learning), robust and proportionate enforcement actions, and use of skilled persons.
  - Responsible Agency: FCA
  - Timeline: NT

- Recommendation 2. Cryptoasset Entities. Pursue amendments to legal framework for obtaining, holding and transmission of identifying information of all parties to all cryptoasset transactions (travel rule).
  - Responsible Agency: HMT
  - Timeline: NT

- Recommendation 3. TCSP, Legal and Accountancy Sectors. Intensify efforts to ensure consistency of supervisory approaches over TCSPs, accountancy and legal sectors, including considering the expansion of the supervisory mandate and powers of OPBAS.
  - Responsible Agency: HMRC, FCA, PBS/OPBAS
  - Timeline: MT

- Recommendation 4. Augment Assessment of Threats. Leverage data to enhance the understanding of threats, including in relation to aggregate financial flows and high-risk jurisdictions.
  - Responsible Agency: HMT, FCA
  - Timeline: MT

- Recommendation 5. Increased Resources. Move ahead with the proposed Economic Crime Levy to generate critical resources to support AML/CFT reforms (e.g., staffing and technology tools).
  - Responsible Agency: HMT
  - Timeline: MT

- Recommendation 6. Accuracy of Beneficial Ownership Information. Amend the legal framework and enhance the powers of Companies House to improve the accuracy of beneficial ownership information in the People with Significant Control Register, including requiring verification of beneficial ownership information and enabling Companies House to access other government databases.
  - Responsible Agency: BEIS/Companies House
  - Timeline: NT

- Recommendation 7. Beneficial Ownership of Real Properties. Pursue proposed Overseas Entities Bill that would require public disclosure of beneficial ownership information of foreign entities owning U.K. real properties.
  - Responsible Agency: BEIS
  - Timeline: MT

- Recommendation 8. Information Sharing. Continue to strengthen cooperative mechanisms with foreign counterparties for timely sharing of financial intelligence, especially in complex and cross-border economic crime cases.
  - Responsible Agency: NCA
  - Timeline: NT

- Recommendation 9. Support to BOTs and Engagement with CDs. Continue to ensure effective and calibrated support to relevant BOTs and to engage with CDs in accurate and publicly accessible beneficial ownership information of entities created in such jurisdictions.
  - Responsible Agency: FCDO
  - Timeline: MT

(Note: NT = Near Term (now to one year); MT = Medium Term (within 1 to 3 years).)

### Risk Profile — Key Statistic
- The authorities estimate that there is a realistic possibility that every year hundreds of billions of pounds of illicit proceeds are being laundered in the United Kingdom.

*Source: IMF — Technical Note: Post-Brexit AML/CFT Legal Framework (chapter content provided).*

### 10.      The authorities demonstrated a deep and robust experience  in assessing national

### 1gbrea2022009 - 10.      The authorities demonstrated a deep and robust experience  in assessing national

### National risk assessments and headline ML/TF risk findings
- Three national risk assessments (NRA) have been published, the latest one in 2020.
- In September 2021, the first national assessment of proliferation financing risks was made publicly available.
- Aside from cash and money service businesses, the financial services sector remains one of the highest risks for ML in the United Kingdom (i.e., retail banking, wholesale banking, wealth management and private banking).
- Risks from cryptoassets have risen since the 2017 NRA, recognizing they can be abused to move value and obfuscate the source of illicit proceeds.
- Art market participants and letting agencies became subject to the MLRs as of January 1, 2020.

### High-risk sectors, professional enablers, and examples of abuse
- Trust and company service providers (TCSPs), accountancy and legal sectors are high risk for ML.
- Professional enablers (e.g., family offices) provide services that can add privacy and layers of legitimacy, facilitating use of corporate structures, trusts, and shell companies to obscure beneficial ownership.
- Example: Complex systems of shell companies and trusts registered abroad are abused to purchase “super prime” properties in the United Kingdom, obscuring true owners and sources of funds.
- Family offices identified as increasingly present in ML investigations; they provide wealth and property management, legal, accountancy and other services to high-net-worth individuals and coordinate management of companies holding investment portfolios.

### Geographic vulnerabilities and high-risk jurisdictions
- Some Crown Dependencies (CDs) and British Overseas Territories (BOTs) feature prominently in U.K. ML investigations and reporting.
- Vulnerabilities in one BOT were exploited to establish corporate structures used to facilitate money laundering (British Virgin Islands cited in the 2020 NRA).
- In February 2021, the Cayman Islands was included in the FATF’s list of jurisdictions with serious AML/CFT deficiencies; this prompted U.K. authorities to add the Cayman Islands to its own list of high risk jurisdictions.
- Regulated businesses in the UK are required to apply enhanced customer due diligence measures and enhanced ongoing monitoring in any business relationship with a person established in a high-risk jurisdiction or where either party is established in a high-risk jurisdiction.

### COVID-19 and evolving illicit finance methods
- Despite COVID-related restrictions limiting physical cash movement, criminals increased use of cryptoassets, mobile banking, and electronic payments during the pandemic.
- Vulnerable individuals (e.g., unemployed) could be coerced to open money mule accounts; distressed businesses were at risk of being targeted to absorb illicit funds as capital.
- Investigations are being pursued against organized criminal groups potentially committing large scale fraud to obtain funds from government loan schemes, e.g., £47 billion loan value of Bounce Back Loan Scheme.
- Authorities warned supervised entities not to change risk appetites during COVID operational challenges and to remain vigilant to new fraud types.

### Brexit implications for ML/TF risks and legal framework adjustments
- Brexit may have medium- and long-term implications to ML/TF risks: U.K. entities may consider more trade opportunities in non-EEA jurisdictions, potentially raising corruption risks in high-risk industries.
- Creation of freeports and inland clearance hubs may be abused to disguise type and origin of goods and final destination of shipments; freeports will be subject to the same AML/CFT regulatory regime as the rest of the United Kingdom.
- Post-Brexit changes aimed to recognize EEA countries as third-country jurisdictions for the United Kingdom, including required information for payers/payees of U.K.-EEA cross-border payments and enhanced due diligence for U.K.-EEA correspondent banking relationships.
- The United Kingdom issues its own list of high-risk jurisdictions, including EEA jurisdictions (e.g., Malta), triggering enhanced due diligence requirements.
- Under the Trade and Cooperation Agreement, both parties committed to cooperating in preventing use of their financial systems to launder criminal proceeds and exchange relevant information.

### Cross-border financial flows: trends and risks
- Since the last FSAP, the direction of financial flows in the United Kingdom has changed with a quarter increase in share of the flows with offshore financial centers (OFCs).
- IMF staff analysis used aggregate monthly country-level SWIFT customer payment data from July 2016 to October 2021; the financial flows analysis covers data until October 2021.
- Share of cross-border payments with other G7 countries remained stable; share with the rest of European countries, except Eastern Europe, decreased.
- Both inflows from and outflows to OFCs increased, particularly in 2021.
- The share of Middle Eastern, Commonwealth of Independent States, Southern and Western African countries have also increased.
- Payments to each of the five high risk countries identified in the 2020 NRA (China, Hong Kong, Pakistan, Russia, United Arab Emirates) have increased since 2016, including more than doubling of inflows from two countries and of outflows to three countries in 2021 as compared to 2016.
- Supervised entities’ reports (FCA financial crime survey) show increased inflows from high-risk jurisdictions and increased average value of transaction-inflow, while average value of transaction-outflow stayed stable.

### Data, analytics, and supervisory recommendations
- Leveraging big data and advanced data analytics of cross-border flows can deepen understanding of ML/TF risks and complement qualitative and law enforcement typologies.
- Authorities should consider analysis of consistency between payment levels/trends with individual countries and economic fundamentals (e.g., bilateral trade, investments), and the extent flows are explained by provision of financial services.
- AML/CFT supervisors of key financial institutions and supervised entities (i.e., FCA, HMRC) should consider incorporating additional cross-border payments data in data collection and analysis to support risk understanding and risk rating of individual entities.
- Developing supervisory technology could help analyze and cover the entire AML/CFT supervisory population and guide prioritization and selection of entities for inspection (e.g., entities with small balance sheets but processing significant numbers of cross-border payments).

### Box: Big data, machine learning, and an IMF outlier detection insight
- Big data and advanced data analytics of cross-border flows can be supplemented with trade, portfolio, direct investments, financial instruments operations, balance of payments, and international investment position data to identify unusual payments unexplained by economic activity.
- Machine learning can efficiently identify supervised entities exposed to significant cross-border ML/TF risks and unusual payments patterns and provide early warnings on evolving risks.
- IMF staff’s outlier detection machine learning algorithm uses global cross-border payments since 2013 and incorporates indicators such as bilateral trade, portfolio and direct investments, average transaction value, appearance of new payment corridors, strength of AML/CFT regime, financial secrecy, harmful tax practices, corruption perceptions; payment amounts are normalized on the ordering country level.
- Based on analysis from this outlier detection algorithm, the United Kingdom attracts the most inflow payments-outliers globally, while not generating many outflows-outliers; inflows-outliers to the United Kingdom are persistent and well-diversified—the outlier activity is detected with most of the world’s countries.

*Source: IMF Staff analysis (extracted from the provided content).*

### 19.      The authorities’ ongoing work to understand the scale of economic crime is welcome.

### 19.      The authorities’ ongoing work to understand the scale of economic crime is welcome.

### Risk-Based AML/CFT Supervision: institutional structure and scope
- AML/CFT supervisory authority is divided among three statutory supervisors (FCA, HMRC, and the Gambling Commission) and 22 professional body supervisors (PBS) for the legal and accountancy sectors.
- Credit and financial institutions as well as cryptoasset businesses are supervised by the FCA for AML/CFT purposes.
- HMRC supervises art market participants, estate and letting agents, and high value dealers as well as other accountants (unless supervised by PBS), money service businesses (unless supervised by FCA), and TCSPs (unless supervised by the FCA or PBS).
- There are 13 PBSs for the accountancy sector and 9 PBSs for the legal sector that are covered in the MLRs Schedule; all PBSs are subject to oversight by OPBAS (established in 2018 within the FCA).
- The Gambling Commission is the AML/CFT supervisory authority for land based and remote casinos.
- All AML/CFT supervisors as well as OPBAS are part of the AML Supervisors Forum to discuss common supervisory issues and share best practices.

### Size and risk profile of the supervisory population
- As of end-2020, there are more than 97,000 entities being supervised for AML/CFT compliance.
- The FCA oversees more than 22,000 credit and financial institutions under the MLRs.
  - Of these 22,000 entities, 90 percent are identified as either high or medium risk (as referenced for credit and financial institutions).
  - Out of the 22,000 entities, 23 percent are assessed as high risks, and 73 percent are deemed medium risks.
- Operational challenge: the sheer number of entities poses challenges to achieving effective risk-based supervision in breadth and depth.

### AML/CFT Supervision of Credit and Financial Institutions and Cryptoassets: FCA approach and resourcing
- FCA historic tiered supervisory approach included: systematic AML program, proactive AML program, risk-assurance reviews, and reactive approaches.
  - The 14 largest financial institutions were subject to a systematic AML program involving an intensive 4–6-month inspection involving 4–5 staff conducted every four years.
  - Other high risk entities were subject to a proactive AML program where 2–3 staff inspect the entity within 2–4 days every four years.
  - Risk assurance reviews were undertaken yearly across a broader range of selected supervised entities.
- FCA adjustments to proactive supervision include:
  - Modular Assessment Proactive Programme — reviews highest risk areas of largest and most systematically important entities more frequently.
  - Proactive AML Programme — targets outliers, hotspots and emerging themes identified via data/intelligence.
  - Focused Supervisory Interventions Programme — increases breadth by engaging entities on specific issues or risk indicators.
- Inspections activity (FCA Results of On-Site and Desk Based Inspections):
  - TOTAL ENTITIES INSPECTED: 2017/18 = 136; 2018/19 = 111; 2019/20 = 177.
  - Desk-Based Reviews totals: 2017/18 = 38; 2018/19 = 47*; 2019/20 = 147.
  - Onsite Inspections totals: 2017/18 = 98; 2018/19 = 64; 2019/20 = 30.
  - Note: Onsite inspections ceased on March 16, 2020, due to COVID pandemic restrictions.
- Concern: annual number of desk-based and onsite inspections (less than 200) in the past three years appears not commensurate with assessed risks of supervised entities.
- FCA financial crime department has 47 financial crime specialists, who lead on complex AML/CFT issues.
- Cryptoassets:
  - FCA designated AML/CFT supervisor for cryptoasset businesses; registration and approval required for cryptoasset activities.
  - As of end-December 2021, the FCA has approved registration for 22 entities, with more than 40 other entities subject of a temporary registration.
  - Registered cryptoasset entities must identify beneficial owners, detail AML/CFT controls and risk assessment, submit to fit and proper assessment, conduct customer due diligence, and report suspicious transactions consistent with the MLR.
  - Authorities note increased ML risks from cryptoasset exchanges, cryptoassets automated teller machines and peer-to-peer exchange platforms.
  - HMT efforts to incorporate the FATF’s travel rule with respect to cryptoassets are welcomed (will require registered entities to obtain, hold and transmit identifying information of both parties in any cryptoasset transaction).

### Data, analytics, and supervisory reach
- FCA is developing data-driven analytical tools to identify outliers and test effectiveness of AML/CFT controls (e.g., fuzziness tests over names of designated or sanctioned individuals).
- More than 2,500 of the 22,000 entities are obliged to annually submit financial crime data returns, providing information on exposure to politically exposed persons, sanctions screening controls, jurisdictional risks, suspicious transaction reports, and resources to fight financial crime.
- The number of entities required to file annual financial crime data returns has almost tripled from 2,500 to 7,000 entities.
- Recommendation / finding:
  - Material data on supervised entities should be accessible and periodically submitted to the FCA as inputs to its risk-based supervisory plans.
  - All supervised entities should be obliged to periodically submit AML/CFT returns disclosing key risk factors including risk classifications of customer bases (including PEPs), products or services offered, and geographical risks.
  - Advanced technological tools (big data and machine learning) should be used to analyze large volumes, ensure data quality controls, and flag indicators to inform FCA supervision (example: monitoring cross-border payments to identify unusual transaction flows).
- Use of third parties:
  - FCA may appoint “Skilled Persons” to fact-find, obtain expert analysis, or recommend remedial action; skilled person mechanism could be further leveraged to support supervisory activities, particularly for lower risk entities, subject to targeted guidance and criteria.

### Funding, levy, and investments in capabilities
- Proposed Economic Crime Levy:
  - AML-regulated entities with annual U.K. revenue over £10.2m will be levied.
  - Levy bands: entities will pay either £10,000, £36,000 or £250,000 depending on U.K. revenue size band.
  - The levy aims to generate £100m per annum to help fund new and uplifted AML capabilities, including reform measures under the 2019 ECP.
- Additional resources recommended for AML/CFT supervisory activities should include investments in technological and analytical tools to aid risk identification and oversight.

### Enforcement: actions, fines, and legal framework
- FCA enforcement toolkit includes remedial actions and sanctions (action plans, attestations by firms, early interventions, restricting or suspending business or license; banning individuals, fines and disgorgements, public censures).
- Since 2018, there have been more than £665 million of fines imposed by the FCA, including against more than seven large financial institutions.
- October 2021: FCA secured its first criminal prosecution under the 2007 MLR when a major bank pleaded guilty and was sentenced to pay fines of over £264 million.
- Global resolutions and cross-border enforcement:
  - As part of a global resolution agreement (US$475 million) with US and Swiss authorities, the FCA fined a major bank in October 2021 for £147 million for failure to properly manage the risks of bribery related to loans for a foreign government-sponsored project.
  - In December 2021, a large international bank was fined over £63 million owing to deficient transaction monitoring controls and is undertaking remediation supervised by the FCA.
- Recommendation / finding:
  - Continued enforcement actions will help create deterrent impact and strengthen compliance.
  - Full resort should be made to the broad range of enforcement tools, particularly criminal penalties against corporations and senior managing officials, commensurate to the scale of AML/CFT violations.
  - Corporate criminal liability: the current identification principle presents a high bar for prosecuting corporate criminal liability; enhancing the legal framework on corporate criminal liability can help hold senior management accountable.
  - The Law Commission is studying options for corporate criminal liability, including for serious violations of AML/CFT obligations by supervised entities.

### AML/CFT supervision of TCSP, legal, and accountancy sectors; OPBAS oversight
- Overlap: TCSPs can be supervised by the FCA, HMRC, or PBSs.
- PBS coverage:
  - 9 PBSs supervise most of the accountancy sector, though HMRC also supervises other accountants (often sole practitioners); more than 95 percent of these HMRC-supervised accountants are classified as low risk.
  - 13 PBSs supervise the legal sector, with nearly two-thirds under the Law Society/Solicitors Regulation Authority.
  - Supervised entities can be multi-service businesses offering TCSP, accountancy and legal services as ancillary to main business lines (e.g., family offices).
- OPBAS impact:
  - Since establishment in 2018, OPBAS has published three reports (March 2019, March 2020, September 2021) assessing PBS supervisory practices.
  - PBSs generally assessed by OPBAS to be in technical compliance with the AML/CFT legal framework, but OPBAS observed variance in effectiveness of implementation.
  - Two thirds of PBSs did not demonstrate an effective enforcement framework.
  - Recommendation / finding: OPBAS should continue to guide PBSs to ensure consistency of supervisory approaches and prevent regulatory arbitrage; robust oversight by PBSs (including effective, dissuasive, and proportional sanctions) should promote strong compliance culture among TCSPs, accountants and lawyers.

*International Monetary Fund — United Kingdom Financial Sector Assessment: Risk-Based AML/CFT Supervision (sections 19–31).*

### 33.      Efforts by OPBAS to inform and raise awareness of key ML/TF risks in the accountancy

### 33.      Efforts by OPBAS to inform and raise awareness of key ML/TF risks in the accountancy and legal sector

### OPBAS and ISEWGs: information sharing and risk awareness
- OPBAS, in conjunction with the NECC, established two Intelligence Sharing Expert Working Groups (ISEWGs), each for the accountancy and legal sectors.
- ISEWGs aim to facilitate increased information sharing between the PBS, LEAs, AML/CFT supervisors and other relevant agencies.
- Types of information sharing facilitated:
  - Strategic intelligence sharing: developing common understanding of emerging or existing ML/TF threats.
  - Tactical intelligence sharing: developing high quality live intelligence sharing with LEAs.
- ISEWGs provided support and inputs to the 2020 NRA exercise, which helped identify additional key factors contributing to the high ML/TF risks in the accountancy and legal sectors.
- Outputs and benefits:
  - Typology reports, alerts, and anonymized case studies create a virtuous feedback loop, ensure consistency, and build trust between public and private stakeholders.
  - Supervisors and LEAs can gain operational perspective on transactions and flows; supervised entities are informed of trends to better calibrate their AML/CFT controls.
- Recommendation:
  - Such information sharing platforms should continue and help foster deeper understanding and awareness of risks in these two high risk sectors.

### Consideration of expanded OPBAS supervisory role
- Given the high risk of the TCSP, accountancy and legal sectors, the U.K. authorities should further explore mechanisms that ensure consistency of AML/CFT supervisory approaches.
- Proposal:
  - For low capacity or high-risk PBSs, OPBAS could be given discretionary power to directly conduct AML/CFT supervision to maximize efficiencies and better harmonize supervisory approaches.
- Rationale:
  - Some PBSs can manage and effectively perform their AML/CFT supervisory responsibilities, while others may lack resources or capacities; direct supervision by OPBAS could be an alternative for those PBSs.
- Constraints and requirements:
  - Such an expansion of OPBAS’s powers would require legal amendments and entail additional resources.
  - Extending OPBAS’s remit and powers is one of the questions in the HMT’s call for evidence on the AML/CFT regulatory and supervisory regime, including whether to seek a degree of consolidation of the supervisory regime towards a model with fewer, very few, or even a single supervisor.

### Entity Transparency — overview and PSC Register
- The United Kingdom remains a global leader in promoting entity transparency.
- The 2018 MER recognized that the United Kingdom’s system for entity transparency goes beyond the FATF technical standards in some respects (particularly open and public access to beneficial ownership information).
- Authorities recognized identifying the person who owns and ultimately controls a corporate entity is vital to exposing wrongdoing and disrupting economic crimes; improving transparency was a strategic priority under the ECP.
- The People with Significant Control (PSC) Register:
  - Established in 2016.
  - Allows full and free public access to beneficial ownership information of U.K. legal entities (including Scottish limited partnership as of 2017).
  - Legal entities are required to submit annual statements confirming beneficial ownership information and notify Companies House of any changes to beneficial ownership information within 28 days.
  - Legislative proposals on public procurement are being developed to mandatorily exclude bidders from competing for public contracts if they do not disclose their beneficial owner/s.

### Discrepancy reporting and PSC register accuracy
- Discrepancy reporting obligations introduced in line with the ECP (Action Item No. 43).
- Definition:
  - A discrepancy exists when the supervised entity has information that clearly indicates that the PSC information recorded by Companies House is inaccurate (i.e., clear factual errors, not typing mistakes).
- Since implementation of discrepancy reporting in January 2020:
  - There have been more than 42,000 discrepancy reports filed with Companies House.
  - Footnote: As of November 2021, the total number of discrepancy reports received by Companies House is at 58,147.
- Originators of discrepancy reports:
  - Financial institutions make up almost all originators (more than 93 percent of all submissions).
  - Less than 5 percent come from TCSPs, accountancy, legal and real estate sectors.
- Nature of most discrepancy reports:
  - Either the beneficial owner is missing or further information on the beneficial owner is lacking (e.g., date of birth).
- Recommendation:
  - Increased efforts by supervised entities (particularly TCSPs, accountants and lawyers) to monitor and report discrepancies should be encouraged.

### Strengthening Companies House and verification powers
- Current limitation:
  - Companies House generally cannot verify the accuracy of what it receives and has limitations in querying information presented to them.
- Recommendations:
  - Companies House should be able to verify the beneficial ownership information submitted to it (including the individuals filing the information).
  - Companies House should be able to unilaterally remove information from the PSC Register if it is found to be inaccurate.
  - Access to other databases would allow cross-referencing relevant data to verify accuracy.
  - Enhanced resources and analytical capabilities should strengthen Companies House’s capacity to identify red flags and facilitate information sharing with AML/CFT supervisors, LEAs, and other competent authorities.
- Additional legislative measure under consideration:
  - Legislation is being proposed to introduce compulsory identity verification for all directors and beneficial owners of U.K. registered companies and require compulsory identity verification for those that file beneficial ownership information in the PSC register.

### Trusts, real property, and overseas entities
- Trusts:
  - Beneficial ownership information of trusts is being collected and made accessible to competent authorities under HMRC through the Trust Registration System (TRS).
  - TRS covers and makes available to competent authorities the beneficial ownership information of more than 170,000 U.K. express trusts (with and without U.K. tax liabilities).
  - Majority of trusts on the register, including all trusts required to register for the purpose of combatting ML/TF, are required to report any changes to their beneficial ownership information within 90 days.
  - All relevant U.K. express trusts are currently required to register by September 1, 2022, and thereafter new trusts are required to register within 90 days of their formation.
  - Recommendation:
    - Authorities should ensure mechanisms are available to foreign counterparties to timely access such information, especially where the registered trust has a link to the foreign jurisdiction.
- Real property and Overseas Entities Bill:
  - ML risks from the real property sector identified in the 2017 and 2020 U.K. NRAs; property purchases by corporate structures or trusts from high risk or secrecy jurisdictions used to launder large amounts of illicit funds.
  - The proposed Overseas Entities Bill would ensure public access to beneficial ownership information of foreign entities owning U.K. properties.
  - Complementary measures:
    - Existing legal requirements for real estate agents and lawyers to conduct customer due diligence on property transactions.
    - Need to incorporate mechanisms to verify accuracy of information (e.g., identity verification, discrepancy reporting, enforcement mechanisms for non-submission or false information).

### International Cooperation: strengths and areas for continued focus
- 2018 MER findings:
  - United Kingdom received a substantial effectiveness rating for international cooperation (IO2).
  - Three central authorities for mutual legal assistance: U.K. Central Authority in the Home Office (England, Northern Ireland, Wales); International Mutual Assistance Team in HMRC (tax matters); International Co-operation Unit of the Scottish Crown Office and Procurator Fiscal Service (Scotland).
  - The United Kingdom was assessed to provide high-quality, constructive and timely mutual legal assistance and a wide range of assistance.
- Tools and networks:
  - Extensive overseas criminal justice network of U.K. law enforcement officers covering over 160 jurisdictions.
  - Established in 2018, the multi-agency National Economic Crime Centre (NECC) leads the U.K.’s response to domestic and foreign economic crimes.
- Public-private partnerships:
  - Economic Crime Strategic Board (created January 2019) sets priorities and includes Home Secretary, Chancellor and senior private financial sector representatives.
  - Joint Money Laundering Intelligence Taskforce (JMLIT) is a public-private partnership implementing a “whole of system” approach to exchanging analysis and information on economic crime threats and risks.
  - Through the NCA, foreign counterparts can submit cases to the JMLIT to generate financial intelligence using information and data from supervised entities and LEAs.
- Post-Brexit cooperation:
  - Authorities noted little difference in post-Brexit cooperation and financial intelligence sharing with EEA authorities.
  - In 2018–2021, most of the United Kingdom’s international cooperation activities (incoming exchange of information and mutual legal assistance requests) was with EEA countries.
  - Recommendation:
    - Sustained efforts in keeping the existing strong channels for information sharing are encouraged.
- Confiscation, asset recovery and sanctions:
  - Robust frameworks provide valuable tools, including Unexplained Wealth Orders (UWOs) (a civil power placing burden on respondent to justify sources of funds used to purchase U.K. assets).
  - 2021: Global Anti-Corruption Sanctions Regulations established to allow designation of persons involved in serious corruption and freezing of their U.K. assets.
- Cooperation with Crown Dependencies (CDs) and BOTs:
  - U.K. bilateral agreements (Exchange of Notes) from 2016 allow timely sharing of beneficial ownership information for legal entities and legal arrangements registered in CDs and BOTs.
  - Requested beneficial ownership information is to be provided within 24 hours, or within one hour if urgent.
  - Recommendation:
    - Maintain strong information sharing mechanisms with CDs and BOTs and continue efforts to ensure their registers are complete and information accuracy effectively verified.
  - U.K. support under Sanctions and AML Act of 2018 (Section 51):
    - Secretary of State tasked to provide all reasonable assistance to BOTs to enable establishment of publicly accessible registers of beneficial ownership.
    - FCDO’s draft Order in Council outlines expected key features, including public accessibility and relevant beneficial owner information.
    - Recommendation:
      - U.K. authorities are encouraged to provide technical, legal, financial, and other relevant support to high-risk or low-capacity BOTs and engage CDs on PSC Register experience and good practices.

### Strengthening the oversight of risks of cyber threat — Executive Summary
- Cyber risk is a top financial stability concern for U.K. authorities and has an important bearing on the findings of the FSAP.
- In June 2017, the Financial Policy Committee (FPC) set out a regulatory strategy aimed at strengthening the U.K. financial system’s ability to withstand, and recover from, cyber incidents.
- The strategy is supported by:
  - A fast developing institutional and regulatory framework.
  - Innovative supervisory approaches.
  - Extensive testing practices.
  - Communication policy.

*Source: 1gbrea2022009 - 33.      Efforts by OPBAS to inform and raise awareness of key ML/TF risks in the accountancy and legal sector (excerpt).*

### 48.      This focus is vital for the United Kingdom. Materialization of cyber risks at systemically

### 1gbrea2022009 - 48.      This focus is vital for the United Kingdom. Materialization of cyber risks at systemically

### Systemic cyber risk and transmission channels
- Materialization of cyber risks at systemically important banks, insurers and financial market infrastructures carries important ramifications for the wider financial system and its potential cross border spillovers.
- A cyber incident at a critical third-party service provider could impact a series of financial institutions and result in a systemic event.
- Single-firm incidents (disruption or integrity compromise of a critical service) can have an adverse impact if the firm’s size, non-substitutability, and interconnectedness exceed certain thresholds.
- Because of the global importance of the U.K. financial system, cyber shocks could be transmitted well beyond its national borders through interconnectedness and financial contagion.
- Compromising widely adopted technology solutions or the supply chain could impact a series of financial institutions simultaneously; technological diversity between institutions is decreasing as institutions adopt common software, similar hardware, and migrate to a select set of global Cloud Service Providers (CSPs).

### U.K. regulatory and supervisory framework (scope and roles)
- The U.K. authorities have been developing a principles-based and outcome-focused regulatory framework to address cyber risk, building on international good practices, guidelines, and cross-sectoral cybersecurity standards.
- General risk management expectations are implicit in:
  - PRA threshold conditions;
  - FCA principles of business;
  - An operational resilience framework and specific policies covering cyber resilience, business continuity and contingency planning, governance, and third-party risk management.
- The BOE, PRA and FCA roles:
  - PRA and FCA jointly supervise cyber risk for systemically important banks and insurers (PRA focuses on safety and soundness; FCA focuses on consumer detriment and market integrity).
  - BOE plays an important role in mitigating cyber risks that could affect financial stability and regulates firms that provide critical services to recognized payment systems where HMT brings them into BOE remit.
- Legal/statutory basis:
  - Authorities’ statutory powers are defined in the Financial Services and Markets Act of 2000 (FSMA 2000) and the Banking Act of 2009 and are fully applicable in cyber risk and resilience matters.
  - The FSMA 2000 provides the PRA and FCA with the power to request “skilled person reports” (Section 166), used sparingly: in the last three years the supervisor authorities, together, commissioned six skilled person reports in Technology and Information Management (Lot J).
  - Banking Act 2009 (Section 206A) allows HMT to bring specified service providers within BOE regulatory remit; so far there is only one such firm in the United Kingdom.
- Review scope limitations:
  - The review is limited to systemically important banks, insurers, and financial market infrastructures; supervisory practices for non-systemic institutions were out of scope.
  - The PRA supervises around 1,500 institutions and the FCA supervises about 49,000, while the number of systemically important institutions is 29 (i.e., 15 banks, 10 FMIs and four insurers).

### Supervisory practices, testing, and information sharing
- Macro-prudential and micro-prudential oversight complemented by sector coordination.
- CBEST penetration testing program is the cornerstone of testing strategy; it realistically assesses effectiveness of cyber defenses with simulated attacks.
- Supervisory dialogue is used to gain deeper insight into regulated firms’ cyber resilience strategies and capabilities (non-regulated financial firms not yet covered).
- Severe but plausible scenarios are played out in simulation exercises in public-private partnerships (e.g., under Cross Market Operational Resilience Group (CMORG)).
- Industry information sharing and response coordination: Finance Sector Cyber Collaboration Centre (FSCCC) and Finance Emergency Call Cyber (FinECC).
- Recommended enhancements to testing:
  - Leverage internal threat intelligence and testing capabilities of firms (subject to CBEST accreditation criteria) to stimulate adoption of tests like STAR-FS.
  - Create additional learning opportunities via grey box testing and purple teaming.
  - A generic threat intelligence report for smaller firms could broaden access to cyber threat intelligence–led testing.

### Implementation gaps and supervisory recommendations (nuts and bolts)
- Key issues requiring focus to strengthen cyber risk management:
  a. Timely and consistent communication of changes to the operational resilience framework. Regulated firms began implementing the operational resilience framework and outsourcing and third-party risk management requirements in 2021, with the first industry results expected in 2022. The principle-based and outcome-focused approach allows multiple interpretations that could lead to diverging implementations; supervisors should clearly communicate expectations and provide guidance on implementation challenges.
  b. Complement existing supervisory practices with on-site activities to verify operational effectiveness of firms’ cybersecurity controls. On-site examinations would:
     - Provide higher assurance over operational effectiveness of controls;
     - Encourage candor by senior management;
     - Develop deeper understanding of firms’ organization, operation, and corporate culture.
  c. Formalize and align reporting requirements, processes and tools. General notification requirements do not provide specific guidance and criteria for cyber incident reporting, risking inconsistencies and underreporting.
  d. Improve the penetration testing program: implement guidelines, templates, and reporting guidelines; consider leveraging firms’ internal testing capabilities (subject to CBEST accreditation); expand grey box testing and purple teaming.

### Strategic recommendations (summary and Table 2 highlights)
- Institutional and regulatory framework recommendations (timing: ST where indicated):
  - Regulators should continue reviewing cyber risk and technology risk management expectations to publish more specific guidance and/or industry best practice. (ST)
  - The Bank/PRA and FCA should seek additional statutory powers to assess the resilience (including cyber resilience) of any critical services that third party service providers provide to regulated financial institutions, as suggested by the Bank of England Financial Policy Committee (FPC). (ST)
  - The Senior Managers and Certification Regime should be extended to BOE supervised FMIs as currently being consulted on by HMT. (ST)
  - Cyber risk reporting processes, including for cyber incidents and material outsourcing arrangements, should be aligned across regulators based on specific criteria and templates. (ST)
- Supervisory practices recommendations:
  - Supervisors should conduct additional cybersecurity control verification activities to complement desk-based analytical work and CBEST testing. (ST)
  - Regulators should strengthen operational and cyber resilience supervisory teams. (ST)
  - The CQUEST cybersecurity questionnaire could be augmented by requiring firms to provide evidence supporting self-assessments. (ST)
  - Prioritize developing a cyber resilience maturity assessment framework as part of the core assurance framework to communicate supervisory expectations by defined maturity levels. (ST)
  - Regulators should consider additional opportunities to strengthen the penetration testing framework. (MT)
  - Improve cyber stress testing by quantifying impacts on liquidity and capital buffers; assess impact of severe but plausible cyber incidents on liquidity and capital buffers. (MT) — Note: "The PRA has started incorporating cyber scenarios in their financial resilience testing."
  - Leverage broad international representation in standard-setting bodies to promote better-aligned supervisory expectations and tools. (MT)
- Additional encouragements to U.K. authorities:
  - Seek additional statutory powers to directly assess resilience (including cyber resilience) of critical services provided by third-party service providers; BOE, PRA, FCA and HMT, under impulse of the FPC, should specify resilience standards for these providers and consider their inclusion in resilience testing — recognizing limits of financial regulators alone without cross-sectoral regulatory framework and cross-border cooperation.
  - Continue meeting regulatory and supervisory demands for internal cyber expertise, which is expected to further increase.
  - Increase supervisory attention on thousands of other U.K. regulated financial services firms facing important cyber risks; incidents at non-systemic firms may not be systemic but can impact customer protection and other objectives.

### Evolving threat landscape and operational resilience
- Constantly evolving threats require vigilance; malicious actors continue to innovate tactics, techniques, and procedures (TTPs).
- The first half of 2021 was characterized by exploitation of critical zero-day vulnerabilities (e.g., in F5 Big-IP, MS Exchange, and Pulse Secure), supply chain attacks, and distributed denial-of-service attacks.
- Non-malicious incidents (accidental data disclosures, configuration, implementation or processing errors) remain an important source of cyber risk.
- COVID-19 related shifts in operating practices increased vulnerability: business continuity and home working arrangements were successfully leveraged, but the attack surface grew due to increased use of potentially vulnerable services and personal devices; certain cybersecurity controls needed to be relaxed while pandemic response measures often impacted institutions’ ability to respond to additional operational stress.
- Continuous enhancement of operational and cyber resilience is becoming the norm; most financial institutions report having faced cyber incidents over the last year. Strong capabilities to detect anomalies and compromises, respond, and recover are critical.

*Italic: Source — IMF country report chapter content provided in the input.*

### 67.      The cybersecurity  framework  for the financial sector is principles-based and outcome-

### 67.      The cybersecurity  framework  for the financial sector is principles-based and outcome-

### Framework overview
- The cybersecurity regulatory framework is principles-based and outcome-focused, providing high-level expectations grounded in current internationally recognized best practices.
- A principles-based approach benefits advanced financial systems with mature risk management practices by allowing proportionality and risk-based supervision.
- Potential challenges: variance in interpretation, inconsistency across firms, and potentially debatable findings; strong regulatory engagement and soft power are needed to address these challenges.

### Roles of HMT and NCSC
- HMT focuses on mitigating cyber risks with the potential to cause economic or societal harm or harms to public finances.
- The National Cyber Security Centre (NCSC), as the United Kingdom’s National Technical Authority for cyber security, provides technical cyber security advice to both regulators and financial institutions.
- Note: Firm specific guidance offered by the NCSC to critical national infrastructure was out of scope for this review.

### Regulators’ governance structure
- Cyber risk is integrated into PRA and FCA risk and policy committees and the holistic risk view for the financial sector.
- Five key Bank of England/PRA committees dealing with cyber risk and resilience:
  - (i) the Financial Policy Committee (FPC) — considers financial stability and systemic aspects of cybersecurity and resilience;
  - (ii) the Prudential Regulation Committee (PRC) — highest decision-making committee for the PRA with responsibility for key micro-prudential decisions, including issuing new rules;
  - (iii) the PRA’s Supervision, Risk, and Policy Committee (SRPC) — oversees the risk portfolio, discusses thematic findings, reviews cyber risk supervisory tools and processes, and approves updates;
  - (iv) the FMI Board — highest decision-making committee of the BOE in its capacity as supervisor of FMIs and critical service providers to recognized payment system operators within the BOE’s regulatory remit;
  - (v) the Executive Committee — involved and consulted on the PRA cyber macro and microprudential strategy, cyber threat landscape, and the FPC cyber agenda.
- FCA committees involved in cyber risk matters:
  - (i) the Executive Committee — issues general guidance as defined by law and oversees crisis management arrangements including operational continuity;
  - (ii) the Executive Regulation and Policy Committee (ERPC) — oversees regulatory issues and is responsible for executive decision making.
- Center-of-excellence model adopted by supervisory authorities:
  - Within the Bank: the Operational Risk and Resilience Division (ORRD) within the Supervisory Risk Specialists (SRS) directorate provides deep technical cyber risk expertise supporting PRA supervision and FMID supervision.
  - Each PRA supervision directorate has operational resilience hubs focused on market segments (U.K. deposit takers, international banks, insurance companies) combining business understanding and cyber expertise.
  - FCA’s Technology, Resilience and Cyber (TRC) department provides technical expertise to supervisors and firms.

### Macroprudential framework
- The Financial Policy Committee (FPC) is the key governance body for macro-prudential cyber risk mitigation and resilience.
- Timeline and actions:
  - FPC formally recognized cyber threat as a risk to financial stability in 2013 and recommended a work program to improve and test cyber resilience.
  - In 2014, regulators launched the CBEST penetration testing program, globally the first of its kind.
  - The FPC evolved its recommendation to make CBEST a component for regular testing of the U.K. financial system.
  - In 2017 the FPC set out a framework with four key elements:
    - (i) clear and proportional baseline resilience expectations;
    - (ii) regular resilience testing by both firms and supervisors;
    - (iii) identification of important firms outside of the regulatory perimeter; and
    - (iv) clear and tested cyber incident response arrangements.
- FPC monitoring of cloud reliance: since 2018 the FPC has tracked cloud use; in 2021 it noted increased plans to scale up reliance on cloud service providers and risk from reliance on a small number of CSPs and other critical third parties (CTPs).

### Microprudential expectations and guidance
- Cyber risk management expectations are implicitly included in threshold conditions and fundamental rules (PRA Fundamental Rules and FCA Principles for Business) covering identification and management of cyber risks, outsourcing risks, business continuity and contingency planning; no technology- or cyber-specific provisions in these general rules.
- Supervisory statements and guidance provide further detail; regulatory framework informed by international good practice (e.g., NIST Cyber Security Framework) and cross-sectoral cybersecurity standards.
- FMIs supervised against CPMI-IOSCO Principles for Financial Market Infrastructures (PFMI) and Guidance on Cyber Resilience for Financial Market Infrastructures:
  - Principles cover governance, identification, protection, detection, response, recovery (including a two-hour recovery time objective), testing, situational awareness, and learning and evolving.
  - Guidance remains principle-based and mostly non-prescriptive, allowing flexibility.

### Operational Resilience Framework (ORF)
- ORF provides a holistic strategic framework covering operational (including cyber) incidents: operational risk management, business continuity and contingency planning, data security, outsourcing and third-party risk management.
- ORF leverages regulators’ requirements on corporate governance and individual accountability, including the Senior Managers and Certification Regime (SM&CR).
- March 2021 ORF requirements (PRA PS6/21 and FCA PS21/3) require supervised financial institutions to:
  - identify their important business services that if disrupted could cause harm to consumers or market integrity, threaten the viability of firms or cause instability in the financial system;
  - set impact tolerances for each important business service, which quantify the maximum acceptable level of disruption they would tolerate;
  - identify and document the people, processes, technology, facilities, and information that support their important business services; and
  - take action to remain within their impact tolerances through a range of severe but plausible disruption scenarios.

### SM&CR and individual accountability
- Senior Managers and Certification Regime (SM&CR) establishes individual accountability and responsibility for senior managers along several Senior Manager Functions (SMFs).
- For operations and technology, including cybersecurity, SMF24 function holders are accountable and responsible to a financial institution’s board and the regulators (PRA and FCA) for that firm’s operations and technology.
- SMF rules:
  - SMFs can be shared but not split, with the single exception of SMF24, which could be split (e.g., between COO and CIO).
  - A hierarchical dependency between SMF holders is prohibited (e.g., a CISO subordinated to the CIO cannot be an SMF24 holder).
- SM&CR together with the ORF promote convergence of business and technology resilience, expected to enhance cyber risk management practices.
- SM&CR does not extend to BOE supervised FMIs; a non-objection process with interviews and capability reviews is in place for appointment of key senior managers and board members.
- HMT is consulting on legislation to formally extend SM&CR to FMIs.

### Outsourcing and third-party risk
- Outsourcing and third-party risk are on macroprudential and microprudential agendas due to growth of outsourcing, especially to the cloud.
- PRA and FCA coordinated, principles-based, technology-agnostic expectations on outsourcing and third-party risk management, aligned with EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02) and complementing operational resilience framework.
- FPC concerns and planned measures (planned for 2022):
  - (i) an appropriate framework for designating certain third party service providers as ‘critical’;
  - (ii) resilience standards for CTPs in respect of any critical services they provided to U.K. firms, building on the operational resilience framework; and
  - (iii) resilience testing of CTPs building on existing testing frameworks and sector exercises (e.g., CBEST and SIMEX), potentially in collaboration with overseas regulators and other U.K. authorities.
- Industry data point: According to EY’s Banking Public Cloud Adoption Index survey, 27 percent of banks plan to migrate 50 percent or more of their business to the cloud in the next two years.
- PRA policy statement on outsourcing and third-party risk management (PS7/21):
  - From March 2022 onward, PRA-supervised financial institutions must ensure material outsourcing contracts meet regulatory requirements on access, audit, and information rights; data security; management of sub-outsourcing risk; and business continuity, contingency planning and exit strategies.
  - Financial institutions remain ultimately accountable for activities they outsource.
- FCA guidance FG16/5 sets largely similar expectations; firms should comply with Principle 3 and SYSC 1.2.1 and other relevant SYSC provisions and regulations.
- Notification and approval requirements:
  - Banks and insurance firms must notify PRA and FCA when entering or significantly changing a material outsourcing arrangement.
  - FMIs must seek BOE approval to outsource critical activities; EMIR requires CCPs to apply to BOE for permission to outsource critical risk management activities; CSDR requires CSDs to apply to BOE for permission to outsource core services. Both EMIR and CSDR have been retained in U.K. law after the Brexit transition period.
- Limitations on supervisory powers over third-party providers:
  - U.K. authorities currently have no legal powers to directly supervise cyber resilience of critical third-party services, except for critical service providers to recognized payment systems brought into the regulatory perimeter.
  - Section165A of FSMA 2000 provides the PRA with information gathering powers regarding third-party service providers, but this is not supervisory power and is subject to safeguards and criteria tied to the financial stability mandate.
  - FCA and PRA have information gathering powers over service providers to insurers and, in the FCA’s case, FCA-regulated investment firms under Section 165 of FSMA; these powers do not cover all critical ICT third-party service providers (e.g., global cloud service providers) and only apply to service providers to a subset of regulated firms.

*International Monetary Fund — United Kingdom chapter excerpt*

### 86.      The authorities have focused on firm-specific and thematic reviews of existing

### 1gbrea2022009 - 86.      The authorities have focused on firm-specific and thematic reviews of existing

### Third-party outsourcing, RegTech, and concentration risk
- The authorities have focused on firm-specific and thematic reviews of existing outsourcing arrangements, as well as related risk management and assurance processes.
- Plans to implement a RegTech solution to collect and analyze data on outsourcing and other third-party service agreements have the potential to enhance the ability of the authorities to identify, monitor and manage third-party concentration risks.
- Market concentration note: Three large cloud service providers dominate the market, and their combined global market share has increased from 49.5 percent in Q1 2018 to 58 percent in Q1 2021.

### Third-party cyber risk and CBEST testing
- Third-party cyber risks increasingly impact the scope and threat scenarios of CBEST testing:
  - Third-party service providers critical for the business services in scope of a CBEST assessment are expected to be involved by the assessed firm. Soft power is used by the U.K. authorities, in absence of hard legal powers, to incentivize firms to involve these third-party service providers.
  - Increased focus on supply-chain cyberattack scenarios as part of a CBEST assessment. The CBEST Implementation Guide states that “Malicious Insider and Supply Chain Scenarios are a feature of the threat landscape for many firms [and] should always be analyzed and discussed during CBEST”.
- CBEST testing specifics:
  - CBEST is an intelligence-led penetration testing exercise that aims to assess firms’ preventive cybersecurity controls and their ability to detect and respond to a range of external and internal attackers.
  - CBEST includes a threat intelligence capability assessment and tests are conducted against live production systems covering end-to-end processes in scope.
  - CBEST provides: a threat intelligence assessment, description of relevant threat scenarios, the penetration testing report, a capabilities assessment, and a remediation plan.
  - Typical testing cycle: a three-year cycle is the norm for CBEST testing; a retest could be required to verify remediation or assess new threats.
  - CBEST testing is resource-intensive: “breadth, complexity, length, and cost make it unsuitable for all but the largest firms and FMIs.”
  - Testing boundaries for critical scenarios (e.g., denial of service attacks and ransomware) are defined case by case to avoid actions that could impact live services.
  - The availability and quality of threat intelligence and penetration testing services are crucial; the PRA accreditation scheme and independent certification underpins CBEST quality.
  - CBEST testers and threat intelligence providers must be accredited by the PRA, including CREST membership and accreditation, meeting minimum experience levels, and references from institutions.

### Regulatory expectations, powers, and recommendations on third-party resilience
- Regulatory changes and timing:
  - The authorities’ cyber risk management expectations have gone through a major review and are now much more specific in critical areas such as operational resilience and third-party risk.
  - The strengthened regulatory framework for third-party risk supervision is still in early stages and insights on implementation by supervised financial institutions will only become available in 2022, after the expectations become effective.
  - The Bank/PRA and FCA, working with HMT, are planning to develop additional measures to manage the risks stemming from CTPs, including: an appropriate framework to designate certain third-party service providers as critical; resilience standards; and resilience testing. A joint Discussion Paper with detail on these proposals is planned for 2022.
- Limitations of current statutory powers:
  - The PRA does not have express statutory authority to directly review or examine any critical services that cloud and other third-party service providers provide to regulated firms, unless contracts authorize such regulatory access. The PRA and FCA require firms to include clauses granting regulatory access in their contracts with cloud providers and other ‘material’ third party service providers.
  - Supervisors can find it difficult or impossible to delve deeper into certain areas of concern at third parties without explicit statutory power.
- Recommendations regarding statutory powers and scope:
  - The Bank/PRA and FCA should seek additional statutory powers to assess the resilience (including cyber resilience) of any critical services that third party service providers provide to regulated financial institutions, as recently suggested by the Bank of England Financial Policy Committee (FPC).
  - Statutory powers should be limited to the services relevant to the Bank/PRA’s and FCA’s statutory objectives to avoid supervisory overreach.
  - The authorities are preliminarily contemplating measures to extend further powers and frameworks related to critical third-party providers.

### Governance and accountability recommendations
- Senior Managers and Certification Regime:
  - The Senior Managers and Certification Regime should be extended to BOE supervised FMIs as currently being consulted on by HMT to strengthen accountability for operational and cyber resilience, governance, and culture at FMIs and better align regimes across BOE, PRA and FCA supervised entities.
- Macro-level expectations:
  - Consider macro-level expectations regarding operational and cyber resilience to support financial stability and guide individual institutions.
  - Progress could include moving beyond expecting firms to set impact tolerances toward imposing upper limits in case of extreme but plausible scenarios affecting important services, and specific requirements for recovery testing.
  - Proportionality could be implemented based on the existing firm categorization system.
  - More specific supervisory expectations would assist firms in contract negotiations with critical technology service providers and support BOE’s Future of Finance project goal of a safe and controlled cloud migration.

### Supervisory practices: approach, engagement, and tools
- Supervisory principles and classification:
  - U.K. regulators have mature, risk-based, and proportional supervisory processes guided by: (i) judgement as critical in decision making; (ii) being forward looking to assess plausible future risks; and (iii) focusing on issues most likely to threaten supervisory objectives.
  - Firms are classified in importance categories to reflect potential impact and allow proportionality.
- Cyber risk supervisory focus:
  - Three key areas: (i) proactive supervisory interventions to mitigate firm-specific cyber risk; (ii) systemic cyber risk assessment and mitigation through sector level assessments and exercises; and (iii) industry collaboration to develop and disseminate good cybersecurity practices.
- Assessment models and review:
  - Holistic and formalized risk assessment models use cyber risk as an input, consider systemic impact, and emphasize qualitative assessment and expert judgment over mechanistic scoring.
  - Assessments are peer reviewed and undergo several levels of management review before finalization.
- Three lines of defense:
  - Regulators ensure firms develop capabilities within the three lines of defense: review of senior managers’ functioning and reporting, appropriateness of challenge by the risk function, and strength of internal audit assurance and remediation follow-up. External auditors’ work may be considered.
- Supervisory engagement and meeting frequency:
  - Supervisors meet bilaterally with SMF24 function holders of systemically important firms twice a year to discuss operational and cyber resilience, business continuity, contingency plans, and information security strategies, review remediation progress, and convey supervisory expectations.
  - The Periodic Summary Meeting (PSM) sets the supervisory agenda and work program for the coming year, including cyber risk matters; PSMs are annual reviews and could be complemented with Mid-Point Reviews (MPR).
- Communication of findings:
  - Firm-specific findings and recommendations are communicated via formal letters and CBEST final remediation plan documents.
  - A PSM feedback letter communicates PRA key messages and expected corrective measures; the FCA uses letters with an accompanying risk mitigation plan describing findings, mitigation steps, and timelines. Risk mitigation plans do not include risk rankings.
  - Sector-wide thematic findings are shared with supervisees or via a regulatory digest communication.
- Follow-up and enforcement:
  - Findings and recommendations are followed-up as part of continuous assessment. In exceptional cases (repeat findings or unsatisfactory remediation), a skilled person report could be required and/or a formal investigation launched, potentially leading to enforcement action.

### Thematic reviews, self-assessment, and testing programs
- Thematic reviews:
  - Used to assess emerging risks and identify prevailing industry practices (e.g., COVID-19 impacts). IBD and FMID have conducted thematic reviews on COVID-19 impact including working from home arrangements.
  - Collaboration with the NCSC is sought for expertise and best practice identification.
  - Cyber themes from CBEST and CQUEST assessments are periodically shared with all PRA and FCA regulated firms and FMID regulated FMIs; due to sensitivity, these documents are not published. The FCA published two cyber insights documents that do not contain sensitive information.
  - The thematic review process is being redesigned to increase completeness, coordination, and timeliness of reporting with a goal of annual regular and standardized thematic reporting, increasing data points, aligning PRA and FCA methodologies, and standardizing production and communication.
- Self-assessment (CQUEST):
  - A cyber resilience self-assessment questionnaire (CQUEST) collects information on firms’ practices and maturity levels to support cross-sectoral and temporal analyses and supervisory engagement steering.
  - CQUEST is based on the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework (CSF) and consists of 48 multiple-choice questions structured along NIST CSF functions: Identify, Protect, Detect, Respond, and Recover.
  - CQUEST incorporates an additional domain on Governance/Leadership and expectations of Board/Senior Execs.
  - CQUEST is a “light-touch” supervisory tool because there is no requirement to substantiate the self-assessment with evidence unless supervisors detect inconsistencies, over-confidence, or discrepancies later.
  - Maintenance cycle: the questionnaire is subject to an 18-months review cycle (24-months for FMIs) so it can keep pace with the changing threat landscape; the PRA and FCA coordinate assessments and share reports for dually supervised firms.
- Testing regime:
  - The authorities have implemented a comprehensive testing regime comprising the CBEST testing program, cyber stress tests, and industry crisis exercises.
  - CBEST is identified as the most effective supervisory tool for assessing and strengthening cyber resilience but is costly and complex, limiting applicability to the largest firms and FMIs.
  - Risks in CBEST (e.g., information leaks) are actively managed; the PRA accreditation scheme and independent certification underpin program quality but integrity risks remain if information leaks occur.
  - Non-intrusive alternatives, such as security configuration reviews, remain unexplored in CBEST.

*Source: 1gbrea2022009 - excerpt provided*

### 117.      The PRA works to further improve an already effective penetration testing regime. In

### 1gbrea2022009 - 117.      The PRA works to further improve an already effective penetration testing regime. In

### Penetration testing: CBEST and STAR-FS
- 2020: a new CBEST implementation guide was published addressing cross-jurisdictional assessments, risk management and planning, and enhanced execution requirements.
- PRA reviewed CBEST templates and improved reporting guidelines.
- Increased attention on malicious insider and supply chain attack scenarios.
- Pilot of STAR-FS initiated: a lighter weight threat-intelligence led penetration test intended for a wider set of financial institutions and maintains the same level of regulatory assurance and technical rigor as CBEST.
- STAR-FS suitability:
  - Intended to increase frequency of penetration testing at firms already subjected to CBEST.
  - Supervisory involvement in STAR-FS is going to be scaled back, but the scope, findings, and remediation plans will be reviewed.
- International focus: developing CBEST has centered on cross-jurisdictional assessments.

### Cyber Stress Testing
- Cyber stress tests are the macroprudential counterpart of CBEST, mandated by the FPC to determine firms’ ability to withstand cyber incidents of a magnitude that can cause material economic harm (severe but plausible cyberattacks with potential systemic impact).
- Target population: intended for the largest firms; so far only a subset of systemically important institutions have participated.
- 2019: first round of tests done as a pilot with voluntary participation.
- Tests planned for 2020–2021 were postponed due to the COVID-19 pandemic.
- At the time of the review planning work was underway for a stress test in 2022.
- Key scenario: disruption of payments.
  - FPC expectation: financial system to honor critical payment obligations by the end of the value date.
  - CPMI-IOSCO requirement: complete settlement by the end of the day the disruption occurred; separate CPMI-IOSCO requirement of a two-hour recovery time (stricter).
  - Rationale: end of value date limit argued to be preferable in some instances (e.g., insufficient threat elimination or difficult to detect data integrity attacks) as premature resumption can worsen financial stability outcomes.
- Current limitations:
  - Cyber stress tests do not include impact calculations on capital and liquidity buffers.
  - Financial stress tests do not include cyber incident-based scenarios.
  - Stresses caused by cyber incidents are difficult to model and quantify; scarcity of data reduces reliability.
  - There are early examples of cyber stress tests that include capital impact calculations; this is a research area worth considering.

### Sector Crisis Exercise
- Objective: rehearse collective response of the financial sector to major operational disruption; focus on collective response capacity rather than firm-level resilience.
- Exercise aims:
  - (i) test effectiveness of decision-making and crisis communication arrangements;
  - (ii) validate collective contingencies;
  - (ii) enable participants to practice their response protocols;
  - (iv) improve sector-level response coordination with other jurisdictions.
- Governance and delivery:
  - Responsibility of the Sector Exercising Group (SEG), a substructure of the Cross Market Operational Resilience Group (CMORG).
  - SEG represents FMIs, investment firms, retail firms, and authorities.
  - CMORG Project Management Office provides operational support.
  - An online simulation platform supports the exercise with secure communication facilities and simulated traditional and social media feeds.
- Participation: collaborative, voluntary, and no pass/fail assessment; growing interest. 2018 exercise tested sector’s response ahead of the G7 cross-border cyber incident coordination exercise.

### Incident Reporting
- Current guidance leaves firms to decide when to notify authorities, resulting in reporting inconsistencies.
- Systemic banks and insurance firms are expected to report cyber incidents under the PRA’s and FCA’s general notification requirements as soon as practically possible.
- No published specific framework, rule, or guidance on reporting cyber incidents; firms develop internal processes and reporting strategies.
- Observed inconsistencies led to reclassifications of reported incidents.
- Implicit expectations of the FCA appear to be stronger, resulting in broader reporting.
- United Kingdom DT’s cyber trend reporting is heavily based on professional judgement, making information flow dependent on experience and capabilities of a limited set of individuals.
- Information on cyber incidents is not collated and fed into risk summary and trend reports but shared with ORRD as deemed necessary (i.e., based on professional judgement).
- FCA practices:
  - TRC team maintains a structured process for managing and recording cyber incidents informed by an FCA-wide harm taxonomy to measure severity and impact (harm to the firm itself, to its customers and to the stability of the market).
  - Process includes collecting post incident reports to record root causes and various details including compromised third parties and data breach details.
  - Information is fed into several internal dashboards.
- The U.K. Financial Services Cyber Incident Response Framework provides guidance on incident reporting and expected response across government, regulators, and law enforcement, elaborates on NCSC incident thresholds and classification structure, and provides best practices on information sharing and coordination.

### Response Frameworks
- Authorities’ Response Framework (ARF):
  - Single mechanism to coordinate authorities’ response to cyber threats and incidents.
  - Invocation by consensus among all financial authorities, although any one authority can organize a call to discuss invocation.
  - Wider government may be included depending on severity.
  - Defined incident severity categorization system in place.
  - Once invoked, an agreed Lead Financial Authority assumes responsibility for information sharing and coordination.
  - For significant cyber incidents the NCSC provide technical advice.
  - Lack of formally documented rules on which authority leads in which type of incident does not seem to hinder agreement; agreed principles for decision-making exist (e.g., consumer detriment (FCA), safety and soundness or financial stability (Bank), economic or societal harm or a risk to public finances (HMT)).
  - ARF is owned by HMT but jointly maintained by all financial authorities based on an annual performance review in which the NCSC also participates.
- Sector Response Framework (SRF):
  - Sets out coordination and information sharing protocols between financial institutions, FMIs, industry groups and authorities to support collaborative engagement in case of critical incidents.
  - Criteria for classifying an incident are set out in the Industry Incident Lexicon within the SRF.
  - SRF architecture is complex due to large number of participating entities and their interrelationships, which may adversely impact response agility.
  - Over ten organizations or cooperation mechanisms are involved in the SRF map (not counting international organizations and individual firms).
  - Key groups: sub-sector information sharing groups (retail and wholesale), Finance Sector Cyber Collaboration Centre (FSCCC), CMBCG, U.K. Finance’s Incident Communication Group (ICG), NCSC, and ARF members.
  - CMBCG is pivotal as a strategic coordination and decision-making group; ICG plays a strategic role coordinating external communications with the CMBCG.

### Resources and Supervisory Capacity
- PRA and FCA work on upskilling generalist supervisors in cyber risk to reduce pressure on cyber risk specialists and pull cyber knowledge into generalist supervision teams for systemic banks and insurance firms.
- Skilled person reports are a tool to externally acquire highly specialized cyber expertise; a skilled person review can be commissioned to identify, measure and address risks; monitor development of identified risks; limit or reduce impact or likelihood of identified risks; and define and implement adequate responses for materialized risks.
  - 2020: three Lot J—Technology and Information Management reports were completed across banking and insurance, suggesting limited use of the tool.
- FMID resourcing:
  - Bank of England has established a team of more than  50 supervisors for 10 FMIs and a critical service provider, composed of supervisors with a general risk expert profile and cyber/IT experts.
  - Access to subject matter experts at the PRA has been formalized and used for periodic supervisory assessments and CBEST exercises.

### Coordination, Cooperation, and International Engagement
- Coordination procedures between the PRA and the FCA are detailed in a Memorandum of Understanding.
- Supervised institutions tend to actively collaborate with supervisory authorities on technology and cybersecurity risk.
- Authorities participate in international cyber resilience guidance development:
  - 2016: G7 formed a Cyber Expert Group (CEG) co-chaired by the U.S. Department of the Treasury and the Bank of England; HMT and the FCA are members.
  - CEG developed several public documents including Fundamental Elements for Cybersecurity; Fundamental Elements for Effective Assessment of Cybersecurity in the Financial Sector; Fundamental Elements for Third Party Risk Management; Fundamental Elements for Threat Led Penetration Testing; and a Cyber Incident Response Protocol (CIRP).
  - Bank of England supervisory and policy teams participate in committees and working groups hosted by FSB and BIS, including CPMI and BCBS.
- Collaboration on CBEST:
  - PRA and FCA have collaborated with the ECB to ensure alignment between CBEST and TIBER-EU frameworks; first pilots completed in 2020 for collaboration with other European authorities.
  - Supervisory authorities of the United States and several Asian jurisdictions have acted as observers in CBEST exercises.
  - Recognition of other threat intelligence-led penetration testing regimes is possible if minimum requirements have been met; international collaboration and recognition reduce burden for firms and supervisors.
- BOE international approach for FMIs systemically important for more than one jurisdiction:
  - Concluded Memorandums of Understanding with a wide range of authorities, organizes colleges for each of its CCPs, and participates in international oversight forums.
  - A context of participation and mutual recognition of supervisory threat-intelligence led cyber testing has been established.

### Enforcement
- FSMA 2000 provides PRA and FCA with powers to take enforcement, criminal or civil action against regulated and non-regulated firms and individuals failing to meet standards.
- Examples of enforcement actions include:
  - (i) prohibiting an individual from performing functions in relation to regulated activities and withdrawing approvals;
  - (ii) suspending a firm for up to 12 months from undertaking specific regulated activities;
  - (iii) suspending an individual for up to two years from undertaking specific controlled functions;
  - (iv) censuring firms and individuals through public statements;
  - (v) imposing financial penalties on firms and individuals.
- Past three years: the PRA has not imposed penalties related to non-compliance with cyber risk related regulations while the FCA has fined one firm.

### Recommendations
- Supervisors should conduct additional cybersecurity control effectiveness verification activities (on-site examination) to complement desk-based analytical work, supervisory engagement, and CBEST testing. Value areas:
  - independent verification of information provided during supervisory engagements;
  - encouraging candor in providing accurate cyber risk related information;
  - developing in-depth knowledge on how supervised firms are organized and operated (including corporate culture).
- U.K. authorities should further strengthen operational and cyber resilience supervisory teams due to strain on specialized cyber expertise and expected increase in regulatory and supervisory work; upskilling non-specialist supervisors is useful but limited.
- Consider additional opportunities to strengthen the penetration testing framework:
  - (i) Leverage internal threat intelligence and/or testing capabilities of firms (subject to meeting CBEST accreditation criteria) to reduce costs and stimulate adoption of testing regimes like STAR-FS.
  - (ii) Use grey box testing and purple teaming to bring additional learning opportunities for CBEST participants. Grey box testing provides more comprehensive testing within time limits though it less closely mimics a real cyber-attack. Purple teaming provides faster feedback cycles and deeper insights for detection and response teams.
  - (iii) Provide a generic threat intelligence report for smaller firms to broaden participation in threat intelligence led testing, supporting inclusion of a wider set of financial institutions while maintaining regulatory assurance and technical rigor.
  - (iv) Conduct security reviews of key protections against vulnerabilities that cannot be included in penetration testing of live production systems (examples: denial of service attacks, ransomware attacks, data integrity attacks). Configuration reviews (network perimeter defenses, traffic scrubbing, anti-malware systems, data integrity protection systems) would add assurance and facilitate purple teaming.
  - (v) Allow red teams greater freedom to develop a cyberattack that has not yet been observed and set out in a scenario.

*Source: Content unit 1gbrea2022009 (excerpt).*

### 144.      The CQUEST  cybersecurity questionnaire could be usefully augmented with requiring

### 1gbrea2022009 - 144.      The CQUEST  cybersecurity questionnaire could be usefully augmented with requiring

### Cybersecurity self-assessment and CQUEST
- Paragraph 144 finding:
  - The CQUEST cybersecurity questionnaire currently relies on firms’ self-assessments with only some internal consistency checks and, "by design", no further steps to ascertain accuracy.
  - Recommendation: Require firms to provide evidence to support the self-assessment by attaching supportive documentation to answers implying higher maturity, to convey stronger assurance over CQUEST results.

### Cyber resilience maturity assessment framework
- Paragraph 145 findings and recommendation:
  - Prioritize developing the proposed cyber resilience maturity assessment framework as part of the core assurance framework to gain better insight into the cyber resilience posture of supervised FMIs and to communicate supervisory expectations according to defined maturity levels.
  - When fully developed, the proposed maturity assessment framework—aligned with international standards—will:
    - Provide a convenient structure.
    - Define maturity levels.
    - Link indicators to support better insights obtained from supervisory engagement, inspections, and operational control effectiveness assessments.
  - The maturity assessment could clarify supervisory expectations regarding operationalization of the CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures and provide a meaningful basis for further improvements.

### Cyber stress testing: liquidity and capital impacts
- Paragraph 146 findings and recommendation:
  - Risk transmission from systemic cyber events primarily occurs via liquidity shortfalls (short term) and deterioration of capital positions (longer term).
  - Recommendation: Research ways of including liquidity and capital impact calculations in cyber stress tests to quantify impacts on liquidity and capital buffers.
  - Alternative: Perform such calculations in the financial stress test based on severe but plausible cyber incident scenarios.

### International coordination and standard setting
- Paragraph 147 findings and implications:
  - Broad international representation and key functions in standard-setting bodies should be leveraged to promote better-aligned supervisory expectations and tools across jurisdictions.
  - Misaligned or incoherent cybersecurity guidance across jurisdictions could:
    - Negatively impact U.K. regulators’ objectives.
    - Create conflicting, redundant, or confusing approaches (including questionnaires and intelligence-led testing).
    - Result in unnecessary duplication of effort, draining resources from supervised firms away from actual cybersecurity-enhancing activities.
  - Industry observation: Recurring attack vectors (e.g., phishing) appear across different tests; more resourceful attackers do not necessarily follow threat-intel-provider scenarios.

### Financial Services Future Regulatory Framework (FRF) Review — overview and key implications
- Paragraphs 148–158 findings and recommendations:
  - Background:
    - The U.K. government launched in 2020 a Financial Services Future Regulatory Review (FRF review) proposing redesign of the regulatory framework within which financial services regulators operate.
    - The aim is to move to a model where rules are made by regulators rather than a mix of legislation and rules, addressing the transitional onshoring of EU law after EU exit.
  - Benefits and proposed changes:
    - Delegating technical rulemaking to regulators provides flexibility to update standards to respond to emerging risks.
    - Key proposals (paragraph 154) include:
      - Division of responsibilities: U.K. government and Parliament set the overall framework; regulators design and implement direct requirements currently set out in retained EU law. The Financial Services Act of 2021 delegates Basel 3 implementation rulemaking to the PRA within a policy framework set out in law.
      - New regulatory objectives: HMT’s second consultation proposes new statutory secondary objectives for the FCA and PRA to facilitate long-term growth and international competitiveness, subject to alignment with international standards.
      - Principles, “have regards”, and obligations: Proposed amendments to clarify growth consistent with the government’s commitment to achieve a net zero economy by 2050; HMT may apply additional "have regards" considerations and place obligations on regulators to make rules in specific areas.
      - Accountability to Parliament and HMT: Existing informal engagement mechanisms would be formalized; regulators would be required to respond to HMT recommendation letters and review rules under unspecified public-interest circumstances.
      - Production of Cost-Benefit Analysis: Regulators would be required to publish a framework for conducting CBA, and establish a new independent statutory panel to support CBA development.
      - Other aspects: Granting the BOE rulemaking power for CCPs and CSDs and introducing a new Designated Activities Regime (DAR).
  - Views and risks:
    - Responses to consultations show varied views: private sector respondents seek more scrutiny and accountability; regulators welcome delegated rulemaking but express caution about proliferation of regulatory objectives and enhanced accountability mechanisms.
    - The House of Commons Treasury Committee report emphasized preserving regulators’ independence and cautioned against excessive proliferation of objectives and "have regards" that could force frequent prioritization by regulators.
  - Implementation considerations:
    - Many proposed measures codify existing practices, but several would substantially change relationships between regulators, HMT, and Parliament.
    - The process of repealing retained EU law and replacing it with regulators’ new rules is intended to maintain continuity and avoid a regulatory "gap"; this repealing-and-replacing process will take place over several years.
    - Authorities note in the consultative document that regulators may, in many cases, ensure continuity with current retained EU provisions, but may also tailor rules to U.K. market specifics and make targeted improvements aligned with regulators’ objectives.
- Policy priority guidance (Table 3 excerpt):
  - Recommendation 1: Preserve the primacy of PRA and FCA’s objectives of safety and soundness and market integrity in principle and in practice over any secondary objectives and ad hoc policy priorities — Priority: High — Timeline: NT
  - Recommendation 2: Ensure that the final accountability and transparency mechanisms adopted under the FRF review safeguard regulatory independence and pose no constraints for operational and oversight effectiveness — Priority: High — Timeline: NT
  - Note: NT = Near Term (now to one year); MT = Medium Term (within 1 to 3 years)

*Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1gbrea2022009.pdf*

### 159.      Several other proposals move in the right direction. Granting the BOE a general

### 159.      Several other proposals move in the right direction. Granting the BOE a general 

### Strengthening BOE rulemaking and the Designated Activities Regime (DAR)
- Granting the BOE a general rulemaking power in relation to CCPs and CSDs would help ensure that the BOE has adequate powers to regulate and supervise these FMIs.
- The introduction of a new Designated Activities Regime (DAR) would enable regulators to make rules for certain activities outside the current financial service’s regulatory perimeter in FSMA and other relevant legislation.
- HMT would specify the scope of designated activities through secondary legislation. Regulators would make rules about how the designated activity would be carried out and firms would be required to follow those rules.

### Risks from proliferating wider policy objectives (competitiveness vs stability)
- A proliferation of wider policy priorities, objectives and “have-regards” could divert focus from safety and soundness and financial stability.
- Historical context: In the run up to the GFC several jurisdictions, including in the United Kingdom, encountered a potential conflict between financial stability objectives and competitiveness considerations.
- The FSA was obliged to meet its main objectives in ways consistent with the "principles of good regulation" prescribed by FSMA, which included the desirability of maintaining the competitive position of the United Kingdom when making and enforcing regulations. Competitiveness considerations were eliminated after the GFC.
- The PRA’s existing secondary objective to facilitate effective competition in financial services (for example by facilitating entry and promoting competition between participants) is distinct from an objective to support the international competitiveness of the United Kingdom’s financial sector when making and enforcing regulations.
- Recent and proposed changes that increase focus on competitiveness:
  - “Competitiveness” has been listed as an aspect of Government economic policy to which the regulators should have regard in Recommendations Letters issued by the Chancellor since 2015.
  - The Financial Services Act of 2021 (which grants the PRA rulemaking authority to implement Basel III standards) added additional considerations that the PRA must have regard to when making rules implementing the outstanding Basel III standards, including “the likely effect of the rules on the relative standing of the United Kingdom as a place for internationally active credit institutions and investment firms to be based or to carry on activities”.
  - The second consultation document further proposes (i) elevating facilitating the long-term growth and international competitiveness of the U.K. economy as new statutory secondary objectives for the FCA and PRA, and (ii) introducing more have regard to considerations.
- Key risk: While these new objectives and have-regard considerations may not formally affect primacy of “primary” objectives, they could increase weight assigned to non-prudential considerations and potentially delay, dilute, or divert focus from safety and soundness and financial stability.
- Recommendation/assertion: The primacy of PRA and FCA’s objectives of safety and soundness and market integrity should be maintained in principle and in practice, as required by international standards.

### Accountability, engagement, and transparency
- Accountability and engagement mechanisms are essential and already well established in the United Kingdom:
  - Regulatory independence includes mechanisms for holding financial regulators accountable while allowing them to remain free of interference in their operations.
  - As required by the BCPs and ICPs, supervisors must be accountable through a transparent framework for discharge of duties.
  - Meaningful engagement in a transparent manner with all stakeholders supports policy-making and calibration of requirements.
- In the United Kingdom:
  - Financial regulators are accountable to Parliament, which plays a key role in objective setting and high-level policy making through primary legislation.
  - Engagement mechanisms exist between HMT and the regulators; existing legislation provides a large number of formal accountability mechanisms between regulators and HMT in specific circumstances.
  - Stakeholder engagement during the policy-making process is well established; U.K. financial regulators are described as extremely transparent in their approach to regulating firms.
  - Key transparency processes include regular communications on supervisory approach and expectations, a structured consultation process, and regular evaluations conducted in a transparent manner.

### Concerns about enhanced accountability measures, rule reviews, and CBA requirements
- The FRF Review 2021 Consultation is seeking comment on whether HMT should have power to require regulators to review their rules where the government considers it is in the public interest, including appointment of an independent person to conduct the review.
- The consultation also considers whether cost benefit analyses (CBA) for proposed regulations should be improved, proposing creation of new statutory panel(s) to support development of regulators’ CBAs.
- HMT would be empowered to require regulators to conduct a rule review and regulators would have to respond to recommendation letters.
- Potential negative effects of additional accountability measures:
  - Potential impact on operational independence: introducing new avenues for challenging regulators’ rulemaking (e.g., requiring another look or independent review) may undermine operational independence in practice and place regulators in a delicate situation when responding to HMT Recommendation Letters.
  - Resource implications: some proposals would be resource intensive and could divert attention from core supervisory activities; authorities will need to weigh benefits against resource burdens to ensure adequate resources are devoted to core activities (i.e., supervising regulated firms).
  - Regulators’ agility: while some proposals make rulemaking more agile (enabling rules in areas covered by retained EU law), other proposals could delay introduction of new or updated rules in response to emerging risks or changing circumstances.
  - CBA limitations: CBA can be resource intensive, time consuming, and may have difficulty capturing long-term benefits to financial stability; concerns about whether scope of CBA would be extended to supervisory guidance and whether inadequate CBA analyses could be subject to judicial review.
- Guidance for calibration:
  - Introduce new requirements in a proportionate manner, focusing primarily on major rules.
  - Ensure inputs provided by existing statutory panel, or any revised panel, do not excessively emphasize short-term costs and are provided on a regular basis (at a specified frequency) rather than on a case-by-case basis.

### Preserving primacy of regulators’ objectives
- Preserving the primacy of U.K. financial regulators’ general objectives (safety, soundness, market integrity) in principle and in practice is paramount.
- Accountability and scrutiny mechanisms should preserve day-to-day independence of financial regulators and not reduce operational and regulatory effectiveness.
- Maintaining robust and high-quality regulatory standards that naturally encourage investment and growth is the best way to preserve the United Kingdom’s role as a major financial centre.

### Appendix I. Using Financial Payments Data and Machine Learning for Financial Integrity Surveillance

A. Data Points Used
- SWIFT data:
  - Uses SWIFT message types 103, 103+, 103R representing payments between customers of financial institutions.
  - Aggregated at the level of a financial institution and anonymized by replacing the name of the financial institution with the corresponding country name.
  - Includes countries of financial institutions that originated and received payments, and countries of correspondent financial institutions that facilitated the payment.
  - Monthly series going back to January 2013.
  - Data fields include currency, number and value of transactions that passed through each payment corridor (originator-correspondents-beneficiary). Example row: Nov-13 MT103+ Single Customer Credit Transfer Country X Country Y United Kingdom USD 85 5326336
- Compliance with AML Standards:
  - Based on assessments by the Financial Action Task Force and regional bodies.
  - The AML compliance index is based on assessment ratings of effectiveness of a country’s AML/CFT regime; where not available the index is based on technical compliance.
  - The AML compliance index is a time series that takes into account new and follow-up assessments.
- Portfolio and direct investments: Investment data from the Coordinated Portfolio and Direct Investment surveys.
- Foreign trade: Export data from IMF’s Direction of Trade data.
- Corruption: Control of corruption indicator from the World Governance Indicators.
- Financial Secrecy and Tax Haven Indexes: Financial Secrecy Score and Tax Haven Score from the Tax Justice Network.
- Gross Domestic Product: Data on current prices GDP from the World Economic Outlook Database.

B. Methodological Approach
- Cross-Border Payments Only: only cross-border payments are used (drop payments originating and received in same country).
- Normalization of Outflows from Ordering Countries:
  - The (i) value of transactions and (ii) the average transaction sent through a given payment corridor are normalized using z-scores and the means and standard deviations for the outflows from the ordering country to avoid bias toward advanced economies and established financial centers.
- Normalization of Flows from Payment Corridor:
  - The (i) value of transactions and (ii) average transaction of a given payment corridor are normalized using z-scores and means and standard deviations for flows via that particular payment corridor (unique originator-correspondents-beneficiary chain) to detect new corridors or corridors with unusually high values or high average transaction values.
- AML Index Factor:
  - The AML index (ranges from 0 to 1, 0 being the lowest level of compliance with the AML/CFT Standards) for the ordering country is multiplied by normalized (i) value of transactions and (ii) average transaction, increasing likelihood that a payment corridor is identified as an outlier.
- Economic Activity Factor:
  - A ratio of the value of transactions between two countries and the portfolio/direct investment between those two countries is introduced; lower investment between the two countries results in a higher ratio and higher likelihood of being an outlier.
  - Portfolio and direct investment have semiannual and annual frequency respectively; flows between two countries are summed over 6 or 12 months correspondingly and added to all payments between the two countries over respective periods.
- Trade Activity:
  - A ratio of the value of transactions between two countries and the foreign trade activity (imports and exports) between those two countries is introduced; lower trade leads to higher ratio and higher likelihood of being an outlier.
- Tax and Financial Secrecy Indexes:
  - Multiplication of financial secrecy and tax haven indexes with (i) value of transactions normalized by ordering country and by payment corridor and (ii) average transaction normalized by ordering country and by payment corridor; higher indexes increase weighting and likelihood of being an outlier.
- Corruption Risks:
  - Multiplying the control of corruption indicator by (i) value of transactions normalized by ordering country and by payment corridor and (ii) average transaction normalized by ordering country and by payment corridor increases likelihood of being an outlier for higher perceived corruption.
- Trade and Investment Data Lag and Extrapolation:
  - Trade and investment data have longer lags than SWIFT data; to run model when SWIFT data is available, trade and investment data are extrapolated using the average of previous periods, adjusted for projected GDP growth and seasonality of monthly trade data.
- Macro-Criticality and GDP:
  - A ratio of the value of transactions (nominal values, not normalized) to the GDP of the ordering country is added to focus on outflows large enough to potentially destabilize external or domestic stability of the ordering country.
- Algorithm output drivers:
  - Based on Shapley values analysis, variables with highest contribution to the output are (i) foreign direct investment, (ii) foreign portfolio investment, and (iii) foreign trade — i.e., whether high financial flows correspond to high trade or portfolio/direct investment flows is the most important determinant of whether payments are identified as unusual or outliers.
- Outlier threshold:
  - The threshold for outlier payments is set at the 0.0001 percent of all payment corridors.

*International Monetary Fund.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1gbrea2022009.pdf_
