Introduction: The Rulebook of Compliance

Welcome! In this chapter, we are looking at the "brain" and the "voice" of an Anti-Financial Crime (AFC) program. If the compliance program was a ship, the Policies and Procedures would be the manual on how to sail, the Governance Committees would be the officers making the big decisions, and Training would be the drills ensuring every crew member knows exactly what to do when they spot a storm.

For the CAMS exam, it is vital to understand that a program isn't just a list of rules; it is a living system that must adapt to new threats. We will break down how these documents are built, who oversees them, and how to make sure every employee is ready to fight financial crime.

1. Policies, Standards, and Procedures: The Hierarchy

It’s easy to get these three terms mixed up, but they serve very different purposes. Think of them as a pyramid, starting with broad ideas at the top and getting more specific as you move down.

Policies (The "What" and "Why")

Policies are high-level documents approved by senior management or the Board. They set the tone for the organization and state the overall goals. Example: "Our institution has a zero-tolerance policy for bribery and corruption (ABC)."

Standards (The "Requirements")

Standards sit between policies and procedures. They provide the specific requirements or "yardsticks" that must be met to satisfy the policy. Example: "All customers from high-risk jurisdictions must undergo Enhanced Due Diligence (EDD) every 12 months."

Procedures (The "How-To")

Procedures are the "instruction manuals" for staff. they provide step-by-step directions on how to perform a task. Procedures are much more detailed than policies. Example: "To perform a liveness check, click the 'Verify' button, ask the customer to smile, and document the result in the KYC portal."

Quick Review:
Policy: High-level goals.
Standard: Specific rules/benchmarks.
Procedure: Step-by-step instructions.

2. Drafting Effective AFC Policies

Creating a policy isn't a "one and done" task. It requires looking at the world outside the bank and the rules set by regulators. To pass the CAMS exam, remember these three key inputs for policy drafting:

1. Regulatory Guidance: You must incorporate rules from bodies like FATF or local regulators (like FinCEN in the US or EU directives). These tell you the minimum legal requirements.
2. Industry Best Practice: This involves looking at what other leading institutions are doing to stay safe, even if it's not strictly required by law.
3. Horizon Scanning: This is a fancy term for "looking into the future." It means keeping an eye on emerging risks, such as new types of crypto-asset fraud or changes in sanctions, so you can update your policies before a problem hits.

Common Mistake to Avoid:

Don't assume policies should be static. If a new regulation is released (like EU Regulation 2024/1624), the policy must be updated immediately. This is part of the Risk-Based Approach (RBA).

3. Governing Committees: The Decision Makers

Compliance is too big for one person to handle alone. Governing Committees provide oversight and make sure the AFC program is actually working.

Structure and Terms of Reference (ToR)

Every committee needs a Terms of Reference (ToR). This is a document that acts like a charter, explaining:
• Who the members are (e.g., the MLRO, Head of Risk, Senior Management).
• How often they meet.
• What they are allowed to decide (their "decision-making role").

The Role of the Committee

These committees don't just sit around and talk; they review Management Information (MI). They look at Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) to see if the institution is staying within its Risk Appetite Statement (RAS). If the committee sees that SAR filings are dropping while unusual activity is rising, they are responsible for investigating why.

Did you know?
The committee is often the place where escalations happen. If a high-risk customer needs to be offboarded but the relationship manager disagrees, the committee usually has the final say.

4. Raising Awareness and Staff Training

You can have the best policies in the world, but if your staff doesn't know about them, the program will fail. Training is the "human firewall" of the AFC program.

Who Needs Training?

Training shouldn't be the same for everyone. It must be tailored to the specific role:
The Board and Senior Management: They need to understand high-level risks, legal liabilities, and the importance of a compliance culture.
The Front Office (Customer-Facing Staff): They need to know how to spot red flags and how to handle Requests for Information (RFIs) without tipping off the customer.
The AFC Compliance Team: They need deep, technical training on investigative tools and changing regulations.

What Should Training Cover?

According to the AFC blueprint, training must include:
FC Risk: Explaining what money laundering, terrorist financing, and fraud actually look like in their specific sector.
Internal Processes: How to report a suspicious transaction and who the MLRO is.
Consequences: The legal and reputational impact of failing to follow AFC rules.

A Note on "Awareness":

Awareness is different from formal training. It includes ongoing reminders like posters, internal newsletters, or "compliance minutes" in team meetings. It keeps the "culture of compliance" alive every day.

5. Key Takeaways for the Exam

• Hierarchy: Know the difference between a high-level Policy and a step-by-step Procedure.
• Maintenance: Policies must be updated through horizon scanning and regulatory guidance.
• Governance: Committees must have clear Terms of Reference and use KPIs/KRIs to make decisions.
• Training: Must be tailored to the audience (Board vs. Front Office) and include how to spot red flags without tipping off.
• Scope: Remember that "AFC" now covers a broad range: AML, CFT, Sanctions, Fraud, ABC (Bribery), and Tax Evasion.

Don't worry if the distinction between these documents seems subtle at first. Just remember: Policy = The Goal; Procedure = The Action. If you keep that in mind, you'll be well on your way to mastering Domain C!