Recommendation 10 (Customer Due Diligence / CDD): financial institutions should be required to undertake CDD measures: (a) identifying the customer + verifying that customer's identity using reliable + independent source documents + data + information; (b) identifying the beneficial owner + taking reasonable measures to verify the beneficial owner's identity; (c) understanding + obtaining information on the purpose + intended nature of the business relationship; (d) conducting ongoing due diligence on the business relationship + scrutiny of transactions throughout the course of that relationship to ensure that the transactions being conducted are consistent with the institution's knowledge of the customer + the customer's business + risk profile. CDD applies to new + existing customers + occasional transactions above the designated threshold + wire transfers + suspicions of ML/TF + doubts about the veracity / adequacy of previously obtained identification data. Recommendation 11 (Record Keeping): financial institutions should be required to maintain, for at least 5 YEARS, all necessary records on transactions + customer identification data including: account files + business correspondence + the results of any analysis + risk-assessment + reports to the FIU.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.