Compliance Essentials #22 – The key stages of KYC

Phoenix Compliance Essentials #22 Today’s focus: the key stages of KYC You are onboarding a new customer. Do you know exactly what needs to be verified? KYC enables institutions to identify and verify customers, understand their activities and assess their level of risk in order to prevent ML/FT-P-C risks. 1️⃣ Identify the customer Identification must … Read more

Data Protection Essentials #4 – Data breaches: do you know how to respond when an incident occurs?

Phoenix Data Protection Essentials #4 Today’s focus: data breaches – do you know how to respond when an incident occurs? No organisation is entirely immune to a personal data breach. When an incident occurs, responding quickly is essential.But having the right methodology is just as important. Identify, assess, document, notify, inform and remediate: these are … Read more

Compliance Essentials #21 – Rebound accounts: understanding a money laundering scheme

Phoenix Compliance Essentials #21 Today’s focus: rebound accounts, understanding a circumvention scheme used in money laundering networks. ➡️ Definition A rebound account (also referred to as a transit account) is a bank or payment account used as an intermediary to conceal the origin of funds or circumvent certain control measures and international sanctions. In practice, … Read more

Data Protection Essentials #3 – When is the appointment of a Data Protection Officer mandatory in Monaco?

Phoenix Data Protection Essentials #3 Today’s focus: when is the appointment of a Data Protection Officer mandatory in Monaco? In Monaco, the appointment of a Data Protection Officer (DPO) is mandatory in certain cases provided for under Law No. 1.565 of 3 December 2024. The appointment of a DPO is required where the organisation: ➡️ … Read more

Compliance Essentials #20 – Risk assessment: a cornerstone or a weakness of your AML/CFT-P-C framework?

Phoenix Compliance Essentials #20 Today’s focus: risk assessment, a cornerstone or a weakness of your AML/CFT-P-C framework? In the field of AML/CFT-P-C, the risk-based approach is more than a regulatory requirement: it is a structured methodology at the heart of every effective compliance framework. At the core of this approach lies the enterprise-wide risk assessment. … Read more

Compliance Essentials #19 – Lines of defence within the AML/CFT-P-C framework

Phoenix Compliance Essentials #19 Today’s focus: lines of defence within the AML/CFT-P-C framework Compliance is not only about having procedures in place, but also about how they are implemented. The lines of defence provide the structure for that implementation. ➡️ What are the lines of defence? A line of defence represents a level of responsibility … Read more

Data Protection Essentials #2 – The risks and penalties for non-compliance with Law No. 1.565

Phoenix Data Protection Essentials #2   Today’s focus: the risks and penalties for non-compliance with Law No. 1.565   Non-compliance with personal data protection requirements goes far beyond the issue of regulatory penalties.   It represents a cross-cutting risk that may affect the organisation as a whole.   1️⃣ The risks   👉 Reputational risk … Read more

Compliance Essentials #18 – KYC and Artificial Intelligence

Phoenix Compliance Essentials #18 Today’s focus: KYC and Artificial Intelligence AI is reshaping operational practices across many sectors.AML/CFT-P-C frameworks are no exception.This transformation is two-sided: AI enhances KYC processes but also makes them easier to circumvent.Deepfakes and forged documents are becoming tools for gaining access to business relationships. ➡️ How do deepfakes threaten KYC frameworks? … Read more

Compliance Essentials #17 – The STRIX questionnaire

Phoenix Compliance Essentials #17 Today’s focus: the STRIX questionnaire ➡️ A key annual regulatory requirement The STRIX questionnaire is a mandatory requirement for entities subject to Articles 1 and 2 of amended Law No. 1.362. It takes the form of a detailed online questionnaire to be completed as part of the sectoral campaigns organised by … Read more

Data Protection Essentials #1 – GDPR and Law No. 1.565 – common inspiration, distinct approaches

Phoenix Data Protection Essentials #1 Today’s focus: GDPR and Law No. 1.565 – common inspiration, distinct approaches Monaco’s law on personal data protection is often presented as a “local GDPR”. In practice, however, certain differences must be taken into account by Monaco-based businesses. 1️⃣ Purpose of the frameworks 👉 GDPR: to harmonise the rules and enable … Read more