Recommendation 17 (Reliance on Third Parties): countries may permit financial institutions to RELY on third parties to perform elements of CDD (R.10 + R.11 elements (a) (b) (c)) provided that: the institution relying on the third party immediately obtains the necessary CDD information; takes adequate steps to satisfy itself that the third party will provide CDD records on request; the third party is regulated + supervised + monitored for + has measures in place for compliance with FATF Recommendations 10-11. THE ULTIMATE RESPONSIBILITY REMAINS WITH THE FINANCIAL INSTITUTION RELYING ON THE THIRD PARTY. Recommendation 18 (Internal Controls + Foreign Branches and Subsidiaries): financial institutions should implement AML/CFT internal controls including (a) compliance management arrangements; (b) screening procedures for personnel hiring; (c) ongoing employee training; (d) independent audit function. Foreign branches + majority-owned subsidiaries should apply AML/CFT measures consistent with home-country requirements. Recommendation 19 (Higher-Risk Countries): financial institutions should be required to apply ENHANCED DUE DILIGENCE proportionate to the risk to business relationships + transactions with natural and legal persons + financial institutions from countries for which this is called for by the FATF (the FATF Grey List + Black List).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.