## EXECUTIVE SUMMARY

## Source details

**Canonical URL:** [EXECUTIVE SUMMARY](https://www.imf.org/-/media/files/publications/cr/2022/english/1irlea2022012.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2022/english/1irlea2022012.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2022/english/1irlea2022012.pdf.json)

---

### ML/TF RISK AND CONTEXT
- Ireland faces significant ML threats from foreign proceeds of crimes, including transnational organized crime, tax evasion, and overseas corruption.
- As a growing international financial center, Ireland is exposed to inherent transnational ML/TF risks including inflows for integration into the legitimate economy, pass-through funds, and outflows for ML layering.
- Key quantitative developments and indicators:
  - Total financial sector assets increased by 30.2 percent between 2017 and 2020 to EUR 6.57 trillion.
  - The value of cross-border payments in Ireland increased at a significantly higher rate—more than threefold from an already high base.
  - Financial flows to offshore financial centers have increased fivefold in value since 2017.
  - Since the 2017 Mutual Evaluation Report:
    - the number of e-money institutions increased from 1 to 18 firms;
    - the number of investment funds increased from approximately 7,000 to 9,650;
    - the number of umbrella funds with AML/CFT obligations decreased from 2,581 to 1,402.
  - In the last four years, the number of supervised entities increased significantly and the volume of financial flows more than tripled.
- Drivers increasing ML/TF risks:
  - Brexit and relocation of international banks to Dublin.
  - COVID-19 pandemic.
  - Increased use of single authorization principle (passporting) for activities across the Single Market.
  - Rapid growth of non-resident and cross-border activity and business models focused on non-residents.
- Assessment gaps and recommended diagnostic actions:
  - Authorities demonstrate deep understanding of domestic ML/TF risks but less-developed analysis of transnational aspects.
  - The 2016 NRA predates the rapid sector growth; while sectoral updates exist (gambling 2018, new technologies 2019, legal persons and legal arrangements 2020, TCSPs 2022), a thematic assessment on transnational ML/TF risks is recommended.
  - The thematic assessment should analyze business models and geographical reach of FIs, economic rationale for flows involving higher risk countries, exposure of sectors to cross-border and non-resident activity, and potential vulnerabilities to tax evasion.
  - The assessment should rely on quantitative indicators, crucially including cross-border payments statistics, and incorporate independent expert views.

### AML/CFT RISK-BASED SUPERVISION OF BANKS AND VASPS
- Central Bank of Ireland (Central Bank) supervisory approach:
  - Comprehensive and well-designed, with depth of engagement determined by an entity’s overall risk rating (inherent ML/TF risk and AML/CFT controls rating), informed by the 2016 NRA and more recent sectoral assessments.
  - Since 2017, the Central Bank has broadened access to data from supervised entities, but cross-border data and analytical tools remain insufficient.
  - Desk-based and on-site inspection frameworks may need reassessment to reflect increasing risks from rapidly growing supervised entities and related financial flows.
  - The Central Bank has a broad enforcement toolkit (directives to fines) and should continue vigorous enforcement aligned with compliance breaches and risk levels.
- Resourcing and tools:
  - Given considerable expansion of the financial sector, augmentation of resources and personnel is necessary to maintain current supervisory depth.
  - Broad access to data from supervised entities coupled with robust analytical tools, and improved resourcing and upskilling, will support effective risk-based supervision.
- VASPs:
  - Commencement of the registration process for VASPs is underway.
  - A few minor legal deficiencies remain regarding customer due diligence (CDD) thresholds and the travel rule as applicable to VASPs; these will be addressed in an upcoming regulation.
  - The Central Bank is processing a significant number of VASP registration applications and expects a high volume of transactions in the sector.
  - Recommendations for VASP supervision: develop supervisory tools, provide adequate training to supervisors, and increase resources (human, technical, budget) commensurate with risks.

### AML/CFT RISK-BASED SUPERVISION OF PROFESSIONAL GATEKEEPERS
- Professional gatekeepers (lawyers/solicitors, accountants, TCSPs):
  - Awareness and outreach efforts (guidance, training, feedback) by the Department of Justice’s Anti-Money Laundering Compliance Unit (AMLCU) and self-regulatory bodies (SRBs) are positive.
  - The 2022 TCSP risk assessment: TCSPs that are subsidiaries of financial institutions (approximately five percent of the total number of TCSPs) and supervised by the Central Bank and those supervised by the AMLCU are considered medium-low risk.
  - STR filings in the sector remain dismally low despite awareness programs.
  - Supervision shortcomings:
    - Inconsistencies across supervisors in resources, depth of supervision, and available sanctions undermine effectiveness.
    - Fragmentation of supervision (except solicitors and barristers, where one designated supervisor exists) leads to inconsistency and potential regulatory arbitrage.
    - Enforcement toolkits for gatekeeper supervisors differ from the financial sector and have limited options for imposing monetary penalties.
  - Recommendation: oversee efforts to ensure consistency of supervisory approaches across SRBs, consider establishing or determining mandate/powers of a regulatory body to ensure consistency, and empower supervisors to impose monetary penalties for AML/CFT contraventions.

### ENTITY TRANSPARENCY AND AVAILABILITY OF ACCURATE BENEFICIAL OWNERSHIP INFORMATION
- Beneficial ownership (BO) registers:
  - Ireland created three BO registries in 2019 and 2020 for companies, trusts, and certain financial vehicles (CFVs).
  - The Central Beneficial Ownership Register of Companies and Industrial & Provident Societies (created in 2019) is the focal register in this Note.
  - A sectoral risk assessment for legal persons and legal arrangements (published in 2020) identified significant ML risk for certain entities, particularly those with complex ownership structures.
  - The Pandora Papers highlighted potential misuse of limited partnerships and lack of transparency concerning third-country partners in certain jurisdictions.
- Data quality and verification:
  - Significant efforts have been made to collect BO information, but the Central Beneficial Ownership Register should ensure registration is complete and up to date.
  - Verification is regularly conducted, but the Register should enhance accuracy and access to information.
  - Professional gatekeepers could assist by promptly submitting and updating BO information and discrepancy reports.
  - Streamlining discrepancy reporting by supervised entities during their own CDD could enhance verification and timeliness.

### MAIN RECOMMENDATIONS (AS PRESENTED)
- Understanding of Risk and AML/CFT Priorities
  1. Understanding of ML/TF risks. Conduct and publish a thematic assessment on transnational aspects of ML/TF risks and communicate it domestically to enhance the understanding of related risks.
     - Responsible Agency: AMLSC
     - Timeline: ST
  2. Reprioritize AML/CFT policy. AML/CFT national policy and institutions should prioritize tackling ML/TF risks related to cross-border and non-resident activity.
     - Responsible Agency: AMLSC
     - Timeline: ST
- AML/CFT Supervision
  3. Banks and other FIs. Enhance risk-based supervision through broader data collection (particularly cross-border data), use of analytical tools, proportionate and dissuasive enforcement actions, and increased resourcing.
     - Responsible Agency: Central Bank
     - Timeline: ST
  4. VASPs. Commence risk-based supervision of the sector as a priority, with enhancements in resourcing and upskilling as appropriate.
     - Responsible Agency: Central Bank
     - Timeline: ST
  5. Assessment of Threats. Use broader data and analytical tools to enhance the understanding of threats facing individual FIs, including links to higher risk jurisdictions and non-resident exposure.
     - Responsible Agency: Central Bank
     - Timeline: ST
  6. Increased Resources. Recruit additional AML/CFT qualified supervisors and risk experts and provide them with the necessary tools (e.g., data, IT solutions) to effectively perform their functions.
     - Responsible Agency: Central Bank
     - Timeline: ST
  7. Lawyers, accountants, and TCSPs. Oversee efforts to ensure consistency of supervisory approaches over these sectors, including considering the determination of the mandate and powers of a regulatory body with the role of ensuring consistency in supervisory approaches among SRBs. Supervisors to have powers to impose monetary penalties for contraventions of AML/CFT obligations.
     - Responsible Agency: AMLSC with AMLCU and relevant SRBs
     - Timeline: ST
- Entity Transparency
  8. Beneficial ownership: Make the BO information of legal entities and arrangements more accurate and easily accessible.
     - Responsible Agency: Central BO Registers
     - Timeline: ST
- Timeline key: I = Immediate (now to one year); ST = Short Term (within one to three years)

### Box 1. Data Analytics for Monitoring Cross-Border Flows
- Data analytics opportunity and rationale:
  - High and increasing value and volume of cross-border payments in Ireland, rapidly growing supervised population, availability of large volumes of relevant data in an advanced economy, and sophistication of its financial sector create an opportunity to apply advanced data analytics to develop supervisory technology for efficient, effective, and timely detection and assessment of cross-border ML/TF risks.
  - Cross-border payments data from various payment infrastructures can be supplemented with:
    - foreign trade in goods and services,
    - portfolio and direct investments,
    - financial instruments operations,
    - balance of payments and international investment position data,
    - investment funds’ activity.
  - Such combined analytics can identify unusual payments potentially unexplained by economic rationale and incorporate indicators of increased ML/TF risk, including: authorities’ risk understanding, ML/TF red flags, trends, typologies, open-source data, and indicators related to foreign countries’ vulnerability to tax evasion.
  - Recommendation: establish a permanent national mechanism for monitoring cross-border financial flows on a higher frequency than the sectoral risk assessment.
- Unsupervised machine learning and outlier detection:
  - Authorities can leverage unsupervised machine learning algorithms to efficiently identify financial institutions exposed to significant cross-border ML/TF risks and unusual payments potentially related to illicit financial flows, providing early warnings about evolving payments patterns and changes in ML/TF risks.
  - The Fund’s outlier detection machine learning algorithm, based on global cross-border payments since 2013 and incorporating various indicators of lower and higher ML/TF risks, has flagged the recent increase in outflows as unusual, with significant number and value of outlier payments.
  - Footnotes (as described in source):
    - The Fund’s cross-border payments outlier detection algorithm is based on the isolation forest approach (Fei Tony Liu, Kai Ming Ting, and Zhi-Hua Zhou; 2008).
    - Indicators include bilateral trade, portfolio and direct investments, average transaction value, appearance of new payment corridors, strength of AML/CFT regime, financial secrecy, potential harmful tax practices, corruption perceptions. The payment amounts are normalized on the ordering country level.

### Central Bank supervisory capacity, scope, and recent activity
- The Central Bank is the designated AML/CFT supervisor for FIs and for TCSPs that are subsidiaries of credit or FIs. Per the Criminal Justice (Money Laundering and Terrorist Financing) Amendment Act of 2021 (CJ Amendment Act, 2021), the Central Bank is responsible for the regulation and supervision of VASPs.
- Financial sector composition includes banks, insurance companies, credit unions, investment and insurance intermediaries, mortgage intermediaries, e-money institutions, funds and funds administrators, investment firms, stockbrokers, money lenders, exchanges, and money transmitters.
- Supervisory workload and activity (2021):
  - 34 inspections,
  - 87 review meetings,
  - issuance of 630 Risk Evaluation Questionnaires (REQs) to firms,
  - participation in 31 AML/CFT supervisory colleges for firms with branches and subsidiaries established in Ireland,
  - hosting of 6 AML/CFT supervisory colleges.
- Since 2016 the number of FIs increased from approximately 9,500 institutions in 2016 to 12,536 institutions by end-2021 (with significant increases in high and medium-high risk firms). This growth, partly driven by Brexit-related relocation, strains Central Bank supervisory resources, which have seen no commensurate increase.
- Risk assessment, cross-border data gaps, and Suptech recommendations:
  - The Central Bank uses an independent risk assessment model that assigns entity risk categories: ultra-high risk, high risk, medium-high risk, medium-low and low risk; domestic retail banks and the largest money remittance firm occupy the ultra-high-risk category.
  - Gap: determination of higher risk jurisdictions is presently guided by the EC’s list and findings of international organizations without accounting for Ireland’s inherent ML/TF risks from cross-border business relationships, despite striking increases in inflow/outflow patterns since 2017.
  - Insufficient focus on cross-border payments data (mostly conducted by international banks) is a lacuna in the supervisory approach. The Central Bank should rely on broader sources of aggregated transactional data (notably, cross-border payments) for entity-level and sectoral risk determination.
  - Since 2020 the Central Bank requires annual returns in the form of REQs from all supervised entities regardless of risk level; however, the existing data analysis system is insufficient to process higher volumes of data.
  - Recommendations:
    - Update the data analytic toolkit to allow effective analysis of larger volumes of data (aggregate monitoring of ML/TF threat evolution and FI-level scrutiny).
    - Invest in Suptech solutions, including network analysis, machine learning, and big data.
    - Prioritize development of models for analyzing broad cross-border data within the Central Bank’s Anti-Money Laundering Division and the specialized Risk Team.
    - Leverage the development of the Central Bank’s bank-wide data strategy to consider more sophisticated data analysis tools for AML/CFT risk-based supervision.

### Thematic supervision, STRs, and cross-border threats
- The Central Bank’s thematic supervisory engagements robustly assess control frameworks and legal obligations, covering governance, CDD, transaction monitoring, STRs, BO, and politically exposed persons.
- Observations:
  - FIU and Revenue Administration Suspicious Transactions Unit noted improvements in quality and quantity of STRs from the financial sector, but STRs related to suspicious cross-border activities are fewer.
  - Threats from cross-border illicit financial flows related to foreign proceeds of crimes (e.g., tax evasion, transnational corruption) are increasing rapidly and could be channeled through the Irish banking system.
- Recommendation: ensure thematic inspections on CDD, transaction monitoring, and STRs with international banks focus on cross-border activities that could be related to foreign proceeds of crimes; a thematic assessment of cross-border risks would fine-tune controls assessment.

### VASP registration, supervision, and sector tools
- Commencement of the registration process for VASPs following the CJ Amendment Act, 2021 is welcomed; Ireland’s AML/CFT framework for the VASP sector is almost entirely aligned with FATF standards, with a few minor deficiencies remaining (CDD thresholds and the travel rule as applicable to VASPs) expected to be addressed in the recast EU 2015 Regulation once adopted.
- The Central Bank is processing a significant number of VASP registration applications and expects a high volume of transactions in the sector.
- Registration includes comprehensive assessment of applicants; post-registration entity-level risk ratings will determine ongoing supervisory engagement.
- Medium-long term recommendations:
  - Conduct a thematic risk assessment of the virtual asset sector.
  - Invest in supervisory tools (tailored data-collection tools and blockchain analysis solutions), upskilling, and increase resources (human, technical, budget) commensurate with risks.

### Enforcement framework and recommendations
- The Central Bank has a broad enforcement toolkit including reprimands, monetary penalties, restrictions, suspension or revocation of authorizations, and directions disqualifying/restricting persons from management positions.
- Since 2015, nine enforcement actions in respect of suspected contraventions of AML/CFT requirements have resulted in monetary penalties.
- Penalties depend on extent of AML/CFT control failures and scale of the concerned entity’s operations and range from approximately a few hundred thousand euros to upwards of €3 million.
- The Central Bank is enhancing its enforcement framework through the Individual Accountability Project to improve ability to take enforcement action against individuals; the proposed Individual Accountability Framework could improve sanctioning of individuals for compliance breaches.
- Recommendation: vigorously pursue enforcement actions proportionate to controls failures and ML/TF risk exposure, and make full use of enforcement tools (including criminal penalties against corporations and senior management officials) commensurate to the scale of AML/CFT violations.

### Professional gatekeepers, supervisory fragmentation, and enforcement limits
- Continued efforts to inform and raise awareness of ML/TF risks for lawyers (solicitors), accountants and TCSPs are positive; awareness programs could improve compliance, but STR filings in the sector remain dismally low.
- Supervision of professional gatekeepers is fragmented across multiple supervisors: AMLCU, Law Society of Ireland, Legal Services Regulatory Authority (LSRA), Property Services Regulatory Authority (PSRA), and six designated accountancy bodies (DABs). For TCSPs the Central Bank supervises TCSPs that are subsidiaries of regulated entities, DABs supervise their members providing TCSP services, and the AMLCU supervises those TCSPs not otherwise supervised.
- Since 2016 supervisory population of gatekeepers has increased (except solicitor firms); the AMLCU has broadened supervisory reach for TCSPs and accountants not otherwise supervised.
- Gap: supervision of TCSPs, accountants, and solicitors is not commensurate with sector risk levels; some supervisors focus on awareness rather than supervision and enforcement. The NRA classifies ML/TF risk within professional gatekeepers as medium high.
- Recent development: a risk-assessment of the TCSP sector was published in March 2022 with findings widely disseminated.
- Fragmentation consequences:
  - Inconsistency in supervisory approaches and potential for regulatory arbitrage due to variations in understanding of risks, depth of supervision, and available sanctions.
  - Recommendation: ensure consistency in supervision of higher risk professional gatekeepers—consider tasking a regulatory body with ensuring consistency among SRBs, setting risk-sensitive minimum supervisory standards, and/or assigning better-resourced bodies to supervise higher risk sectors and entities.
- Enforcement limitations:
  - AMLCU cannot issue administrative fines and is limited to legal directions or revoking authorizations or liaising with An Garda Siochána for criminal prosecution.
  - Most SRBs are limited to orders/reprimands/directives and withdrawal of licensing, though some accountancy bodies can impose fines.
  - Government decision: the AMLCU should be given powers to issue administrative fines for strict liability compliance breaches by supervised entities by end Q2-2023.
  - Recommendation: all supervisors, including SRBs, should have powers to impose monetary penalties, at minimum, for strict liability offences.

### Progress with BO registries and legal reforms
- Ireland created three BO registries in 2019 and 2020 for companies, trusts, and certain financial vehicles.
- A sectoral risk assessment for legal persons and legal arrangements was published in 2020 showing a significant risk of ML for certain entities, particularly those with complex ownership structures.
- The Pandora Papers highlighted potential misuse of limited partnerships and suggested that a lack of transparency in respect of the third-country partners based in certain jurisdictions meant some limited partnerships could not be easily subject to scrutiny.
- A review of the 1907 Limited Partnership Act was launched with a view to strengthening the legislation.
- The Companies (Corporate Enforcement Authority) Act 2021 contains a new requirement for company directors to use their personal public service number (PPSN) when incorporating a company, making an annual return or changing director’s details on the Register of Companies.
- The new PPSN requirement is expected to come into force in early 2023 and is intended to strengthen the accuracy and transparency of the register.
- The AMLCU will be afforded powers to impose sanctions for strict liability offences by mid-2023.

### Central Beneficial Ownership Register: coverage and statistics
- Ireland established a Central Register of Beneficial Ownership of Companies and Industrial and Provident Societies on June 22, 2019 under SI 110 of 2019.
- From that date, relevant entities have been obliged to file information regarding their beneficial owners with the Central Register and to update such information if there are any changes to it.
- Statistics related to progress in the registration of companies and societies are publicly available to the end of 2020.
- As of end-2020, it is reported that almost 189,000 (81 percent) of companies and 616 societies (64 percent) had filed beneficial ownership information with the register.
- The register is still in its early stages; it would be important to ensure the registration of companies is complete and up to date.
- The team was unable to find statistics on-line for the other two registries; the authorities are encouraged to regularly publish statistics on-line for the other two registries.

### Accuracy, verification, and access issues
- While verification is being regularly conducted, the Central Beneficial Ownership Register should ensure registration is complete and up to date.
- The 2020 Annual Report mentions that only two discrepancies notices were received from competent authorities, and none were received from designated persons and the general public, but mission feedback points to a larger number of discrepancies noticed, signaling accuracy concerns.
- It would be important for the register to look into the source of the discrepancies and explore additional verification mechanisms to ensure the accuracy of the beneficial ownership information collected.
- Inter-operability with other registers, such as the Central Register of Beneficial Ownership of Trusts and Beneficial Ownership Register for Certain Financial Vehicles (CFVs), as well as cross-checks with other public beneficial ownership registers, should be considered.
- For designated persons who form a business relationship with a relevant entity or are taking CDD measures in relation to a relevant entity, and for members of the public, there is a fee to access the register information, only payable by credit card.
- The register may want to consider facilitating access for designated persons so that there are alternative ways of access, allowing for a high-volume of simultaneous consultations, not limited by single transactions.
- Easier access to information could facilitate crowdsourcing of the accuracy of the information.
- The authorities shared that there was a significant increase in the number of submissions received by the RBO in 2021, as well as the number of Non-Compliance Notices (NCNs) and Discrepancy Notices (DNs) received in 2021, particularly from designated persons.

### Role of professional gatekeepers and CDD
- Designated persons (including the full range of FIs and DNFBPs) are obliged to collect BO information of legal entities or arrangements utilizing financial or professional services.
- Ireland now has an obligation for designated persons to identify and verify the person purporting to act on behalf of the customer, following up on the MER recommendations.
- The legislation incorporates Article 3 of the Fourth Money Laundering Directive of the EU requiring identification of senior managing officials if all means to identify the BO of a legal person are exhausted.
- Existing customers are now subject to CDD at any time, including when the relevant circumstances of a customer have changed and, where warranted, by the ML/TF risk.
- Ensuring consistent quality in the CDD procedures across financial institutions and DNFBPs, including for professional gatekeepers, is key given the increased use of complex structures.
- Streamlining the submission of discrepancies by supervised entities with AML/CFT obligations during their own CDD activities could enhance verification of the data and its timeliness.

*Source: EXECUTIVE SUMMARY (Ireland), IMF staff note for the 2022 Financial Sector Assessment Program.*

### EXECUTIVE SUMMARY __________________________________________________________________________ 4

### EXECUTIVE SUMMARY

### ML/TF RISK AND CONTEXT
- Ireland faces significant ML threats from foreign proceeds of crimes, including transnational organized crime, tax evasion, and overseas corruption.
- As a growing international financial center, Ireland is exposed to inherent transnational ML/TF risks including inflows for integration into the legitimate economy, pass-through funds, and outflows for ML layering.
- Key quantitative developments and indicators:
  - Total financial sector assets increased by 30.2 percent between 2017 and 2020 to EUR 6.57 trillion.
  - The value of cross-border payments in Ireland increased at a significantly higher rate—more than threefold from an already high base.
  - Financial flows to offshore financial centers have increased fivefold in value since 2017.
  - Since the 2017 Mutual Evaluation Report:
    - the number of e-money institutions increased from 1 to 18 firms;
    - the number of investment funds increased from approximately 7,000 to 9,650;
    - the number of umbrella funds with AML/CFT obligations decreased from 2,581 to 1,402.
  - In the last four years, the number of supervised entities increased significantly and the volume of financial flows more than tripled.
- Drivers increasing ML/TF risks:
  - Brexit and relocation of international banks to Dublin.
  - COVID-19 pandemic.
  - Increased use of single authorization principle (passporting) for activities across the Single Market.
  - Rapid growth of non-resident and cross-border activity and business models focused on non-residents.
- Assessment gaps and recommended diagnostic actions:
  - Authorities demonstrate deep understanding of domestic ML/TF risks but less-developed analysis of transnational aspects.
  - The 2016 NRA predates the rapid sector growth; while sectoral updates exist (gambling 2018, new technologies 2019, legal persons and legal arrangements 2020, TCSPs 2022), a thematic assessment on transnational ML/TF risks is recommended.
  - The thematic assessment should analyze business models and geographical reach of FIs, economic rationale for flows involving higher risk countries, exposure of sectors to cross-border and non-resident activity, and potential vulnerabilities to tax evasion.
  - The assessment should rely on quantitative indicators, crucially including cross-border payments statistics, and incorporate independent expert views.

### AML/CFT RISK-BASED SUPERVISION OF BANKS AND VASPS
- Central Bank of Ireland (Central Bank) supervisory approach:
  - Comprehensive and well-designed, with depth of engagement determined by an entity’s overall risk rating (inherent ML/TF risk and AML/CFT controls rating), informed by the 2016 NRA and more recent sectoral assessments.
  - Since 2017, the Central Bank has broadened access to data from supervised entities, but cross-border data and analytical tools remain insufficient.
  - Desk-based and on-site inspection frameworks may need reassessment to reflect increasing risks from rapidly growing supervised entities and related financial flows.
  - The Central Bank has a broad enforcement toolkit (directives to fines) and should continue vigorous enforcement aligned with compliance breaches and risk levels.
- Resourcing and tools:
  - Given considerable expansion of the financial sector, augmentation of resources and personnel is necessary to maintain current supervisory depth.
  - Broad access to data from supervised entities coupled with robust analytical tools, and improved resourcing and upskilling, will support effective risk-based supervision.
- VASPs:
  - Commencement of the registration process for VASPs is underway.
  - A few minor legal deficiencies remain regarding customer due diligence (CDD) thresholds and the travel rule as applicable to VASPs; these will be addressed in an upcoming regulation.
  - The Central Bank is processing a significant number of VASP registration applications and expects a high volume of transactions in the sector.
  - Recommendations for VASP supervision: develop supervisory tools, provide adequate training to supervisors, and increase resources (human, technical, budget) commensurate with risks.

### AML/CFT RISK-BASED SUPERVISION OF PROFESSIONAL GATEKEEPERS
- Professional gatekeepers (lawyers/solicitors, accountants, TCSPs):
  - Awareness and outreach efforts (guidance, training, feedback) by the Department of Justice’s Anti-Money Laundering Compliance Unit (AMLCU) and self-regulatory bodies (SRBs) are positive.
  - The 2022 TCSP risk assessment: TCSPs that are subsidiaries of financial institutions (approximately five percent of the total number of TCSPs) and supervised by the Central Bank and those supervised by the AMLCU are considered medium-low risk.
  - STR filings in the sector remain dismally low despite awareness programs.
  - Supervision shortcomings:
    - Inconsistencies across supervisors in resources, depth of supervision, and available sanctions undermine effectiveness.
    - Fragmentation of supervision (except solicitors and barristers, where one designated supervisor exists) leads to inconsistency and potential regulatory arbitrage.
    - Enforcement toolkits for gatekeeper supervisors differ from the financial sector and have limited options for imposing monetary penalties.
  - Recommendation: oversee efforts to ensure consistency of supervisory approaches across SRBs, consider establishing or determining mandate/powers of a regulatory body to ensure consistency, and empower supervisors to impose monetary penalties for AML/CFT contraventions.

### ENTITY TRANSPARENCY AND AVAILABILITY OF ACCURATE BENEFICIAL OWNERSHIP INFORMATION
- Beneficial ownership (BO) registers:
  - Ireland created three BO registries in 2019 and 2020 for companies, trusts, and certain financial vehicles (CFVs).
  - The Central Beneficial Ownership Register of Companies and Industrial & Provident Societies (created in 2019) is the focal register in this Note.
  - A sectoral risk assessment for legal persons and legal arrangements (published in 2020) identified significant ML risk for certain entities, particularly those with complex ownership structures.
  - The Pandora Papers highlighted potential misuse of limited partnerships and lack of transparency concerning third-country partners in certain jurisdictions.
- Data quality and verification:
  - Significant efforts have been made to collect BO information, but the Central Beneficial Ownership Register should ensure registration is complete and up to date.
  - Verification is regularly conducted, but the Register should enhance accuracy and access to information.
  - Professional gatekeepers could assist by promptly submitting and updating BO information and discrepancy reports.
  - Streamlining discrepancy reporting by supervised entities during their own CDD could enhance verification and timeliness.

### TABLE 1: MAIN RECOMMENDATIONS (AS PRESENTED)
- Understanding of Risk and AML/CFT Priorities
  1. Understanding of ML/TF risks. Conduct and publish a thematic assessment on transnational aspects of ML/TF risks and communicate it domestically to enhance the understanding of related risks.
     - Responsible Agency: AMLSC
     - Timeline: ST
  2. Reprioritize AML/CFT policy. AML/CFT national policy and institutions should prioritize tackling ML/TF risks related to cross-border and non-resident activity.
     - Responsible Agency: AMLSC
     - Timeline: ST
- AML/CFT Supervision
  3. Banks and other FIs. Enhance risk-based supervision through broader data collection (particularly cross-border data), use of analytical tools, proportionate and dissuasive enforcement actions, and increased resourcing.
     - Responsible Agency: Central Bank
     - Timeline: ST
  4. VASPs. Commence risk-based supervision of the sector as a priority, with enhancements in resourcing and upskilling as appropriate.
     - Responsible Agency: Central Bank
     - Timeline: ST
  5. Assessment of Threats. Use broader data and analytical tools to enhance the understanding of threats facing individual FIs, including links to higher risk jurisdictions and non-resident exposure.
     - Responsible Agency: Central Bank
     - Timeline: ST
  6. Increased Resources. Recruit additional AML/CFT qualified supervisors and risk experts and provide them with the necessary tools (e.g., data, IT solutions) to effectively perform their functions.
     - Responsible Agency: Central Bank
     - Timeline: ST
  7. Lawyers, accountants, and TCSPs. Oversee efforts to ensure consistency of supervisory approaches over these sectors, including considering the determination of the mandate and powers of a regulatory body with the role of ensuring consistency in supervisory approaches among SRBs. Supervisors to have powers to impose monetary penalties for contraventions of AML/CFT obligations.
     - Responsible Agency: AMLSC with AMLCU and relevant SRBs
     - Timeline: ST
- Entity Transparency
  8. Beneficial ownership: Make the BO information of legal entities and arrangements more accurate and easily accessible.
     - Responsible Agency: Central BO Registers
     - Timeline: ST
- Timeline key: I = Immediate (now to one year); ST = Short Term (within one to three years)

*Source: EXECUTIVE SUMMARY (Ireland), IMF staff note for the 2022 Financial Sector Assessment Program.*

### Box 1. Data Analytics for Monitoring Cross-Border Flows

### Box 1. Data Analytics for Monitoring Cross-Border Flows

### Data analytics opportunity and rationale
- High and increasing value and volume of cross-border payments in Ireland, rapidly growing supervised population, availability of large volumes of relevant data in an advanced economy, and sophistication of its financial sector create an opportunity to apply advanced data analytics to develop supervisory technology for efficient, effective, and timely detection and assessment of cross-border ML/TF risks.
- Cross-border payments data from various payment infrastructures can be supplemented with:
  - foreign trade in goods and services,
  - portfolio and direct investments,
  - financial instruments operations,
  - balance of payments and international investment position data,
  - investment funds’ activity.
- Such combined analytics can identify unusual payments potentially unexplained by economic rationale and incorporate indicators of increased ML/TF risk, including: authorities’ risk understanding, ML/TF red flags, trends, typologies, open-source data, and indicators related to foreign countries’ vulnerability to tax evasion.
- Recommendation: establish a permanent national mechanism for monitoring cross-border financial flows on a higher frequency than the sectoral risk assessment.

### Unsupervised machine learning and outlier detection
- Authorities can leverage unsupervised machine learning algorithms to efficiently identify financial institutions exposed to significant cross-border ML/TF risks and unusual payments potentially related to illicit financial flows, providing early warnings about evolving payments patterns and changes in ML/TF risks.
- The Fund’s outlier detection machine learning algorithm, based on global cross-border payments since 2013 and incorporating various indicators of lower and higher ML/TF risks, has flagged the recent increase in outflows as unusual, with significant number and value of outlier payments.
- Footnotes (as described in source):
  - The Fund’s cross-border payments outlier detection algorithm is based on the isolation forest approach (Fei Tony Liu, Kai Ming Ting, and Zhi-Hua Zhou; 2008).
  - Indicators include bilateral trade, portfolio and direct investments, average transaction value, appearance of new payment corridors, strength of AML/CFT regime, financial secrecy, potential harmful tax practices, corruption perceptions. The payment amounts are normalized on the ordering country level.

### Central Bank supervisory capacity, scope, and recent activity
- The Central Bank is the designated AML/CFT supervisor for FIs and for TCSPs that are subsidiaries of credit or FIs. Per the Criminal Justice (Money Laundering and Terrorist Financing) Amendment Act of 2021 (CJ Amendment Act, 2021), the Central Bank is responsible for the regulation and supervision of VASPs.
- Financial sector composition includes banks, insurance companies, credit unions, investment and insurance intermediaries, mortgage intermediaries, e-money institutions, funds and funds administrators, investment firms, stockbrokers, money lenders, exchanges, and money transmitters.
- Supervisory workload and activity (2021):
  - 34 inspections,
  - 87 review meetings,
  - issuance of 630 Risk Evaluation Questionnaires (REQs) to firms,
  - participation in 31 AML/CFT supervisory colleges for firms with branches and subsidiaries established in Ireland,
  - hosting of 6 AML/CFT supervisory colleges.
- Since 2016 the number of FIs increased from approximately 9,500 institutions in 2016 to 12,536 institutions by end-2021 (with significant increases in high and medium-high risk firms). This growth, partly driven by Brexit-related relocation, strains Central Bank supervisory resources, which have seen no commensurate increase.

### Risk assessment, cross-border data gaps, and Suptech recommendations
- The Central Bank uses an independent risk assessment model that assigns entity risk categories: ultra-high risk, high risk, medium-high risk, medium-low and low risk; domestic retail banks and the largest money remittance firm occupy the ultra-high-risk category.
- Gap: determination of higher risk jurisdictions is presently guided by the EC’s list and findings of international organizations without accounting for Ireland’s inherent ML/TF risks from cross-border business relationships, despite striking increases in inflow/outflow patterns since 2017.
- Insufficient focus on cross-border payments data (mostly conducted by international banks) is a lacuna in the supervisory approach. The Central Bank should rely on broader sources of aggregated transactional data (notably, cross-border payments) for entity-level and sectoral risk determination.
- Since 2020 the Central Bank requires annual returns in the form of REQs from all supervised entities regardless of risk level; however, the existing data analysis system is insufficient to process higher volumes of data.
- Recommendations:
  - Update the data analytic toolkit to allow effective analysis of larger volumes of data (aggregate monitoring of ML/TF threat evolution and FI-level scrutiny).
  - Invest in Suptech solutions, including network analysis, machine learning, and big data.
  - Prioritize development of models for analyzing broad cross-border data within the Central Bank’s Anti-Money Laundering Division and the specialized Risk Team.
  - Leverage the development of the Central Bank’s bank-wide data strategy to consider more sophisticated data analysis tools for AML/CFT risk-based supervision.

### Thematic supervision, STRs, and cross-border threats
- The Central Bank’s thematic supervisory engagements robustly assess control frameworks and legal obligations, covering governance, CDD, transaction monitoring, STRs, BO, and politically exposed persons.
- Observations:
  - FIU and Revenue Administration Suspicious Transactions Unit noted improvements in quality and quantity of STRs from the financial sector, but STRs related to suspicious cross-border activities are fewer.
  - Threats from cross-border illicit financial flows related to foreign proceeds of crimes (e.g., tax evasion, transnational corruption) are increasing rapidly and could be channeled through the Irish banking system.
- Recommendation: ensure thematic inspections on CDD, transaction monitoring, and STRs with international banks focus on cross-border activities that could be related to foreign proceeds of crimes; a thematic assessment of cross-border risks would fine-tune controls assessment.

### VASP registration, supervision, and sector tools
- Commencement of the registration process for VASPs following the CJ Amendment Act, 2021 is welcomed; Ireland’s AML/CFT framework for the VASP sector is almost entirely aligned with FATF standards, with a few minor deficiencies remaining (CDD thresholds and the travel rule as applicable to VASPs) expected to be addressed in the recast EU 2015 Regulation once adopted.
- The Central Bank is processing a significant number of VASP registration applications and expects a high volume of transactions in the sector.
- Registration includes comprehensive assessment of applicants; post-registration entity-level risk ratings will determine ongoing supervisory engagement.
- Medium-long term recommendations:
  - Conduct a thematic risk assessment of the virtual asset sector.
  - Invest in supervisory tools (tailored data-collection tools and blockchain analysis solutions), upskilling, and increase resources (human, technical, budget) commensurate with risks.

### Enforcement framework and recommendations
- The Central Bank has a broad enforcement toolkit including reprimands, monetary penalties, restrictions, suspension or revocation of authorizations, and directions disqualifying/restricting persons from management positions.
- Since 2015, nine enforcement actions in respect of suspected contraventions of AML/CFT requirements have resulted in monetary penalties.
- Penalties depend on extent of AML/CFT control failures and scale of the concerned entity’s operations and range from approximately a few hundred thousand euros to upwards of €3 million.
- The Central Bank is enhancing its enforcement framework through the Individual Accountability Project to improve ability to take enforcement action against individuals; the proposed Individual Accountability Framework could improve sanctioning of individuals for compliance breaches.
- Recommendation: vigorously pursue enforcement actions proportionate to controls failures and ML/TF risk exposure, and make full use of enforcement tools (including criminal penalties against corporations and senior management officials) commensurate to the scale of AML/CFT violations.

### Professional gatekeepers, supervisory fragmentation, and enforcement limits
- Continued efforts to inform and raise awareness of ML/TF risks for lawyers (solicitors), accountants and TCSPs are positive; awareness programs could improve compliance, but STR filings in the sector remain dismally low.
- Supervision of professional gatekeepers is fragmented across multiple supervisors: AMLCU, Law Society of Ireland, Legal Services Regulatory Authority (LSRA), Property Services Regulatory Authority (PSRA), and six designated accountancy bodies (DABs). For TCSPs the Central Bank supervises TCSPs that are subsidiaries of regulated entities, DABs supervise their members providing TCSP services, and the AMLCU supervises those TCSPs not otherwise supervised.
- Since 2016 supervisory population of gatekeepers has increased (except solicitor firms); the AMLCU has broadened supervisory reach for TCSPs and accountants not otherwise supervised.
- Gap: supervision of TCSPs, accountants, and solicitors is not commensurate with sector risk levels; some supervisors focus on awareness rather than supervision and enforcement. The NRA classifies ML/TF risk within professional gatekeepers as medium high.
- Recent development: a risk-assessment of the TCSP sector was published in March 2022 with findings widely disseminated.
- Fragmentation consequences:
  - Inconsistency in supervisory approaches and potential for regulatory arbitrage due to variations in understanding of risks, depth of supervision, and available sanctions.
  - Recommendation: ensure consistency in supervision of higher risk professional gatekeepers—consider tasking a regulatory body with ensuring consistency among SRBs, setting risk-sensitive minimum supervisory standards, and/or assigning better-resourced bodies to supervise higher risk sectors and entities.
- Enforcement limitations:
  - AMLCU cannot issue administrative fines and is limited to legal directions or revoking authorizations or liaising with An Garda Siochána for criminal prosecution.
  - Most SRBs are limited to orders/reprimands/directives and withdrawal of licensing, though some accountancy bodies can impose fines.
  - Government decision: the AMLCU should be given powers to issue administrative fines for strict liability compliance breaches by supervised entities by end Q2-2023.
  - Recommendation: all supervisors, including SRBs, should have powers to impose monetary penalties, at minimum, for strict liability offences.

_Excerpted from Box 1. Data Analytics for Monitoring Cross-Border Flows (Ireland IMF report content)._

### 19.     Ireland has taken an important step forward with the creation of three BO registries in

### 1irlea2022012 - 19.     Ireland has taken an important step forward with the creation of three BO registries in

### Progress with BO registries and legal reforms
- Ireland created three BO registries in 2019 and 2020 for companies, trusts, and certain financial vehicles.
- A sectoral risk assessment for legal persons and legal arrangements was published in 2020 showing a significant risk of ML for certain entities, particularly those with complex ownership structures.
- The Pandora Papers highlighted potential misuse of limited partnerships and suggested that a lack of transparency in respect of the third-country partners based in certain jurisdictions meant some limited partnerships could not be easily subject to scrutiny.
- A review of the 1907 Limited Partnership Act was launched with a view to strengthening the legislation.
- The Companies (Corporate Enforcement Authority) Act 2021 contains a new requirement for company directors to use their personal public service number (PPSN) when incorporating a company, making an annual return or changing director’s details on the Register of Companies.
- The new PPSN requirement is expected to come into force in early 2023 and is intended to strengthen the accuracy and transparency of the register.
- The AMLCU will be afforded powers to impose sanctions for strict liability offences by mid-2023.

### Central Beneficial Ownership Register: coverage and statistics
- Ireland established a Central Register of Beneficial Ownership of Companies and Industrial and Provident Societies on June 22, 2019 under SI 110 of 2019.
- From that date, relevant entities have been obliged to file information regarding their beneficial owners with the Central Register and to update such information if there are any changes to it.
- Statistics related to progress in the registration of companies and societies are publicly available to the end of 2020.
- As of end-2020, it is reported that almost 189,000 (81 percent) of companies and 616 societies (64 percent) had filed beneficial ownership information with the register.
- The register is still in its early stages; it would be important to ensure the registration of companies is complete and up to date.
- The team was unable to find statistics on-line for the other two registries; the authorities are encouraged to regularly publish statistics on-line for the other two registries.

### Accuracy, verification, and access issues
- While verification is being regularly conducted, the Central Beneficial Ownership Register should ensure registration is complete and up to date.
- The 2020 Annual Report mentions that only two discrepancies notices were received from competent authorities, and none were received from designated persons and the general public, but mission feedback points to a larger number of discrepancies noticed, signaling accuracy concerns.
- It would be important for the register to look into the source of the discrepancies and explore additional verification mechanisms to ensure the accuracy of the beneficial ownership information collected.
- Inter-operability with other registers, such as the Central Register of Beneficial Ownership of Trusts and Beneficial Ownership Register for Certain Financial Vehicles (CFVs), as well as cross-checks with other public beneficial ownership registers, should be considered.
- For designated persons who form a business relationship with a relevant entity or are taking CDD measures in relation to a relevant entity, and for members of the public, there is a fee to access the register information, only payable by credit card.
- The register may want to consider facilitating access for designated persons so that there are alternative ways of access, allowing for a high-volume of simultaneous consultations, not limited by single transactions.
- Easier access to information could facilitate crowdsourcing of the accuracy of the information.
- The authorities shared that there was a significant increase in the number of submissions received by the RBO in 2021, as well as the number of Non-Compliance Notices (NCNs) and Discrepancy Notices (DNs) received in 2021, particularly from designated persons.

### Role of professional gatekeepers and CDD
- Designated persons (including the full range of FIs and DNFBPs) are obliged to collect BO information of legal entities or arrangements utilizing financial or professional services.
- Ireland now has an obligation for designated persons to identify and verify the person purporting to act on behalf of the customer, following up on the MER recommendations.
- The legislation incorporates Article 3 of the Fourth Money Laundering Directive of the EU requiring identification of senior managing officials if all means to identify the BO of a legal person are exhausted.
- Existing customers are now subject to CDD at any time, including when the relevant circumstances of a customer have changed and, where warranted, by the ML/TF risk.
- Ensuring consistent quality in the CDD procedures across financial institutions and DNFBPs, including for professional gatekeepers, is key given the increased use of complex structures.
- Streamlining the submission of discrepancies by supervised entities with AML/CFT obligations during their own CDD activities could enhance verification of the data and its timeliness.

*Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1irlea2022012.pdf*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1irlea2022012.pdf_
