Control Definition
Control Objective: Restrict transaction activity to validated and approved business counterparties.
In-scope components:
- GUI
- messaging interface
- SWIFT and customer Connector
Note: GUI, connectors, and messaging interface are mentioned as the potential vector for Relationship Management Application (RMA) exchange and reporting.
Risk Drivers:
• business conducted with an unauthorised counterparty
Implementation Guidance
Control Statement:
Implement RMA controls to restrict transaction activity with effective business counterparties.
Control Context:
• Implementing business controls that restrict SWIFT transactions to the fullest extent possible reduces the opportunity for both the sending and receiving of fraudulent transactions. These restrictions are best determined through an analysis of effective business relationships where RMA is a mechanism to prevent unwanted traffic on a service by controlling who can send traffic and what type of messages can be exchanged through Relationship Management Application Plus (RMA+).
Implementation Guidelines:
The implementation guidelines are common methods to apply the relevant control. The guidelines are a helpful way to begin an assessment, but should never be considered as an "audit checklist" as each user’s implementation may vary. Therefore, in cases where some implementation guidelines elements are not present or partially covered, mitigations as well as particular environment specificities must be considered to properly assess the overall compliance adherence level (as per the suggested guidelines
or as per the alternatives).
- RMA
- Appropriate know-your-customer principles and due diligence is performed during the creation and maintenance of RMA relationships.
- RMA relationships are reviewed annually (at least) to make sure that obsolete (unused, dormant, or unwanted) relationships are analysed and removed or revoked in a timely manner.
Optional Enhancements:
- RMA+
- Restrict the valid RMA relationships to the specific message types that are agreed with the counterparty.