← Study index · ← Cheat sheet (digest)RES5 โ Rules, Ethics and Skills for Financial Advisory Services โ Full Facts
Chapter 5 · every fact by topic · 89 source facts
Priority โ core important supporting
๐Scope Application
Para 1: legal basis (s27B MAS Act) and who FAA-N06 applies to, with the research-report carve-out.
- MAS Notice No: FAA-N06 is issued pursuant to Section 27B of the Monetary Authority of Singapore Act 1970 ("MAS Act"). โ Ch. 5, p. 3
⚠ FAA-N06 is issued under the MAS Act (s27B), not under the FAA itself.
- FAA-N06 applies to (a) licensed financial advisers under the FAA; (b) registered insurance brokers exempt under Section 23(1)(c) of the FAA from holding a financial adviser's licence; and (c) persons exempt under Section 23(1)(f) of the FAA read with Regulation 27(1)(d) of the FAR. โ Ch. 5, p. 3
- FAA-N06 does not apply to a person who only provides advice by issuing or promulgating research analyses or research reports (in electronic, print or other form) concerning any investment product. โ Ch. 5, p. 3
⚠ The only carve-out from FAA-N06 is research-report-only advice โ nothing to do with fees or investor class.
๐Definitions
Para 2: defined terms โ beneficial owner, business relations, customer, connected party, officer, STR/STRO/CDSA/TSOFA.
- A "beneficial owner", in relation to a customer, means the natural person who ultimately owns or controls the customer, or the natural person on whose behalf a transaction is conducted or business relations are established, and includes any person who exercises ultimate effective control over a legal person or legal arrangement. โ Ch. 5, p. 3
⚠ A beneficial owner is always a natural person with ultimate ownership/control โ not a corporate parent or the appointed agent.
- "Business relations" means the opening or maintenance of an account by the financial adviser in the name of a person, or the provision of financial advice by the financial adviser to a person (whether a natural person, legal person or legal arrangement). โ Ch. 5, p. 3
- A "customer" means a person with whom the financial adviser establishes or intends to establish business relations, and includes, where the financial adviser arranges a group life insurance policy, the owner of the master policy. โ Ch. 5, p. 4
⚠ For a group life policy, the 'customer' is the owner of the master policy.
- A "connected party" means, for a legal person other than a partnership, any director or natural person having executive authority; for a partnership, any partner or manager; and for a legal arrangement, any natural person having executive authority. โ Ch. 5, p. 3, 4
⚠ Connected party = director/executive/partner. Distinct from the beneficial owner (ultimate natural-person owner/controller).
- "STR" means suspicious transaction report; "STRO" means the Suspicious Transaction Reporting Office, Commercial Affairs Department of the Singapore Police Force; "CDSA" means the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992; and "TSOFA" means the Terrorism (Suppression of Financing) Act 2002. โ Ch. 5, p. 4
⚠ STRs go to STRO โ a Police (Commercial Affairs Department) office, not MAS. A copy goes to MAS for information.
- An "officer", for the purposes of FAA-N06, means any director or any member of the committee of management of the financial adviser. โ Ch. 5, p. 4
- "Reasonable measures" means appropriate measures which are commensurate with the level of money laundering or terrorism financing risks. โ Ch. 5, p. 4
- A "legal arrangement" means a trust or other similar arrangement. โ Ch. 5, p. 4
๐งญUnderlying Principles
Para 3: the three guiding principles โ due diligence, high ethical standards, cooperation with law enforcement.
๐กIn context
Three principles, one posture
Everything else in FAA-N06 is an application of the three principles in paragraph 3: due diligence towards customers and everyone around them, high ethical standards that keep the adviser out of ML/TF entanglement, and full cooperation with law enforcement. When a detailed requirement seems arbitrary, tracing it back to one of the three usually explains it.
๐งฎRisk Based Approach
Para 4: risk assessment (four dimensions) and risk mitigation approved by senior management.
๐กIn context
Risk-based, not checkbox
'Reasonable measures' in this Notice means measures commensurate with the ML/TF risk โ the same duty scales up or down with the customer, product and channel. That is why the Notice can demand risk assessment of new products and technologies before launch: the framework regulates the risk, not the paperwork.
๐งชNew Products Tech
Para 5: assess ML/TF risks of new products/practices/technologies before launch; special attention to anonymity.
๐Cdd General
Para 6.1-6.3: no anonymous accounts, pre-relations suspicion, and when CDD must be performed.
โDid you know?
The duty bites before the relationship exists
CDD is not only for existing customers: where an adviser already has reasonable grounds to suspect that a prospect's assets are criminal proceeds, the obligation applies before business relations are ever established. Suspicion at the door is handled the same way as suspicion inside.
๐ชชCustomer Identification
Para 6.4-6.7B: identify each customer, the minimum identification data, legal persons and connected parties.
โ
Identity Verification
Para 6.8-6.11: verify identity via reliable independent sources; appointed persons and due authority; Government-entity relief.
- A financial adviser shall verify the identity of the customer using reliable, independent source data, documents or information; where the customer is a legal person or legal arrangement, it shall also verify the legal form, proof of existence, constitution and powers using reliable, independent sources. โ Ch. 5, p. 9
⚠ Verification must draw on RELIABLE, INDEPENDENT sources โ not customer-supplied information alone.
- Where a customer appoints natural persons to act on its behalf (or the customer is not a natural person), the financial adviser shall identify each such person by obtaining at least full name (including aliases), unique identification number, residential address, date of birth and nationality, and shall verify their identity using reliable, independent sources. โ Ch. 5, p. 9
- A financial adviser shall verify the due authority of each natural person appointed to act on the customer's behalf by obtaining appropriate documentary evidence authorising the appointment and verifying that the person is so authorised, through methods including obtaining a specimen signature or electronic means of verification. โ Ch. 5, p. 9
- Where a financial adviser has assessed the customer's ML/TF risks as not high and, after taking reasonable measures, cannot obtain the residential address of the natural person appointed to act on the customer's behalf, it may obtain that person's business address in lieu, take reasonable measures to verify the business address using reliable independent sources, and must document the assessment and measures. โ Ch. 5, p. 9, 10
⚠ Appointed-person address fallback (risk not high) = business address in lieu of residential โ but still verify it.
- Where the customer is a Singapore Government entity, the financial adviser is only required to obtain such information as may be required to confirm that the customer is a Singapore Government entity as asserted. โ Ch. 5, p. 10
๐คBeneficial Owner
Para 6.12-6.17: identify/verify beneficial owners, the cascade, exemptions (App 5A), life-policy beneficiaries, purpose of relations.
- Subject to paragraph 6.15, a financial adviser shall inquire whether there exists any beneficial owner in relation to a customer. โ Ch. 5, p. 10
- Where one or more beneficial owners exist, the financial adviser shall identify them and take reasonable measures to verify their identities using reliable independent sources: for legal persons, identify the natural persons who ultimately own the legal person, failing which those who ultimately control it, failing which those having executive authority; for trusts, identify the settlors, trustees, protector (if any), beneficiaries, and any natural person exercising ultimate control. โ Ch. 5, p. 10, 11
⚠ Beneficial-owner cascade: ultimate OWNERS -> ultimate CONTROLLERS -> executives. BO identity is verified via 'reasonable measures'.
- A financial adviser is not required to inquire whether a beneficial owner exists where the customer is: an entity listed and traded on the Singapore Exchange; an entity listed on a foreign exchange subject to disclosure and beneficial-owner transparency requirements; a financial institution set out in Appendix 5A; a foreign financial institution supervised for AML/CFT consistent with FATF standards; or an investment vehicle managed by such financial institutions โ unless the adviser doubts the veracity of the CDD information or suspects ML/TF. โ Ch. 5, p. 11
⚠ BO-inquiry exemption references APPENDIX 5A (not 5B) and is LOST if the adviser has doubts or suspicion.
- Where the customer is not a natural person, the financial adviser shall understand the nature of the customer's business and its ownership and control structure. โ Ch. 5, p. 11
- Where a financial adviser distributes life policies on behalf of a direct life insurer licensed under section 8 of the Insurance Act 1966, it shall, as soon as a beneficiary is identified as a specifically named natural person, legal person or legal arrangement, obtain the full name (including aliases) of that beneficiary; where the beneficiary is designated by characteristics or class, obtain sufficient information for the insurer to establish the beneficiary's identity at payout. โ Ch. 5, p. 11, 12
⚠ Life-policy beneficiary: NAMED -> obtain full name; by CLASS -> enough info to identify at payout.
- A financial adviser shall, when processing the application to establish business relations, understand and, as appropriate, obtain from the customer information as to the purpose and intended nature of the business relations. โ Ch. 5, p. 11
- For the exemptions in paragraphs 6.15(f) and 6.15(g)(ii) (foreign FATF-supervised institutions), a financial adviser shall document the basis for its determination that the requirements have been met. โ Ch. 5, p. 11
๐Purpose Monitoring
Para 6.18-6.25: ongoing monitoring, unusual transactions and retaining a suspected customer.
๐Cdd Special Situations
Para 6.26-6.39: non-face-to-face, acquiring adviser, timing of verification, incomplete CDD, joint/existing customers, screening.
- Where there is no face-to-face contact, a financial adviser shall perform CDD measures that are at least as robust as those that would be required if there were face-to-face contact, and shall develop and implement policies to address the specific risks of non-face-to-face relations. โ Ch. 5, p. 13
⚠ No face-to-face = CDD 'at least as robust' as face-to-face โ not lighter, and not automatically 'enhanced'.
- Subject to paragraphs 6.31 and 6.32, a financial adviser shall complete verification of the identity of the customer, any appointed natural persons and any beneficial owners before it establishes business relations with the customer. โ Ch. 5, p. 13
⚠ Default = verify BEFORE establishing relations; delayed verification (6.31) is the exception, not the rule.
- A financial adviser may establish business relations before completing verification only if the deferral of completion is essential in order not to interrupt the normal conduct of business operations, and the ML/TF risks can be effectively managed; it must then develop internal policies on the conditions for such deferral and complete verification as soon as reasonably practicable. โ Ch. 5, p. 13, 14
⚠ Delayed verification needs BOTH: deferral essential to normal business AND risks effectively managed; then verify ASAP.
- Where a financial adviser is unable to complete the CDD measures required by paragraphs 6, 7 and 8, it shall not commence or continue business relations with, or undertake any transaction for, the customer, and shall consider whether the circumstances are suspicious so as to warrant filing an STR. โ Ch. 5, p. 14
⚠ Cannot complete CDD -> do not commence/continue relations, and CONSIDER filing an STR.
- When a financial adviser acquires (in whole or part) the business of another financial institution, it shall perform CDD on the acquired customers at the time of acquisition, except where it acquired at the same time all corresponding customer records (including CDD information) with no doubt about their veracity or adequacy, and conducted and documented due diligence enquiries that raised no doubt about the adequacy of the AML/CFT measures previously adopted. โ Ch. 5, p. 13
- In the case of a joint account, a financial adviser shall perform CDD measures on all of the joint account holders as if each of them were individually a customer of the financial adviser. โ Ch. 5, p. 14
- A financial adviser shall perform CDD measures on its existing customers based on its own assessment of materiality and risk, taking into account any previous measures applied, when they were last applied, and the adequacy of the data, documents or information obtained. โ Ch. 5, p. 14
- A financial adviser shall screen the customer, appointed natural persons, connected parties and beneficial owners against relevant ML/TF information sources and lists provided by the Authority or other relevant Singapore authorities; screening shall occur when (or as soon as practicable after) relations are established, periodically thereafter, and when there are changes to the lists or to the persons; results shall be documented. โ Ch. 5, p. 14, 15
โDid you know?
Can't finish CDD? Then don't start
An adviser unable to complete the required CDD measures must not commence โ or continue โ business relations or perform the transaction, and must consider whether the circumstances warrant an STR. Walking away and reporting are the two prescribed exits; pressing on is not one of them.
๐ขSimplified Cdd
Para 7: simplified CDD where risk is low, the prohibitions, and Appendix 5B institutions.
- A financial adviser may perform simplified CDD measures in relation to a customer, any appointed natural person and any beneficial owner (other than a beneficial owner it is exempt from inquiring about under 6.15) if it is satisfied that the risks of money laundering and terrorism financing are low. โ Ch. 5, p. 15
⚠ Simplified CDD is permitted only where ML/TF risk is assessed LOW (and supported by analysis).
- A financial adviser shall not perform simplified CDD where a customer or beneficial owner is from or in a country in relation to which the FATF has called for countermeasures; where a customer or beneficial owner is from or in a country known to have inadequate AML/CFT measures; or where the adviser suspects that money laundering or terrorism financing is involved. โ Ch. 5, p. 15
⚠ SDD barred by: FATF-countermeasure country, inadequate-AML country, or any ML/TF suspicion โ the mirror image of higher-risk triggers.
- The assessment of low risk that supports simplified CDD shall be supported by an adequate analysis of risks by the financial adviser, and the simplified measures shall be commensurate with the level of risk. โ Ch. 5, p. 15
- Subject to the low-risk analysis and the prohibitions in 7.4, a financial adviser may perform simplified CDD measures in relation to a customer that is a financial institution set out in Appendix 5B, and shall document the details of its risk assessment and the nature of the simplified measures. โ Ch. 5, p. 15
⚠ Simplified CDD for FI customers references APPENDIX 5B (not 5A).
๐๏ธEnhanced Cdd Pep
Para 8.1-8.4: politically exposed persons โ definitions, enhanced measures and the risk-based approach.
- Where a customer or beneficial owner is determined to be a PEP, or a family member or close associate of a PEP, the financial adviser shall, in addition to standard CDD, perform at least: obtain senior management approval to establish or continue business relations; establish (by reasonable means) the source of wealth and source of funds; and conduct enhanced monitoring of the business relations. โ Ch. 5, p. 16, 17
⚠ PEP triad: senior-management approval + source of WEALTH and FUNDS + enhanced monitoring.
- A financial adviser may adopt a risk-based approach in deciding whether, or to what extent, to apply enhanced CDD measures for domestic PEPs, international-organisation PEPs, and PEPs who have stepped down from prominent public functions (and their family members and close associates), except where their business relations or transactions present a higher risk of ML/TF. โ Ch. 5, p. 16
⚠ FOREIGN PEP -> always enhanced CDD. Domestic / international-org / stepped-down PEP -> risk-based (unless higher risk).
- A "politically exposed person" (PEP) is a domestic, foreign or international-organisation PEP โ a natural person who is or has been entrusted with prominent public functions; a "family member" of a PEP means a parent, step-parent, child, step-child, adopted child, spouse, sibling, step-sibling and adopted sibling; and a "close associate" is a natural person closely connected to a PEP, socially or professionally. โ Ch. 5, p. 16
⚠ PEP = domestic OR foreign OR international-organisation. 'Family member' is a closed list; cousins/in-laws are not included.
โDid you know?
PEPs are not blacklisted
A politically exposed person is not a prohibited customer โ the label triggers enhanced CDD: senior management approval, establishing source of wealth and source of funds, and enhanced ongoing monitoring. And the treatment is calibrated: for domestic and international-organisation PEPs, the adviser may take a risk-based approach to how much of that applies.
๐ดEnhanced Cdd Other
Para 8.5-8.8: other higher-risk categories and the duty to apply enhanced CDD.
๐คThird Party Reliance
Para 9: reliance on third parties โ who qualifies, the conditions, the ongoing-monitoring bar and continuing responsibility.
- A financial adviser may rely on a third party to perform CDD measures (paragraphs 6, 7 and 8) only if: it is satisfied the third party is subject to and supervised for AML/CFT consistent with FATF standards and has adequate measures; it takes steps to understand the ML/TF risks of the third party's jurisdictions; the third party is not one the Authority has precluded reliance upon; and the third party is able and willing to provide, without delay on request, the CDD data, documents or information. โ Ch. 5, p. 18, 19
⚠ Third-party reliance needs the four 9.2 conditions, including provision of CDD info WITHOUT DELAY on request.
- No financial adviser shall rely on a third party to conduct ongoing monitoring of business relations with customers. โ Ch. 5, p. 19
⚠ A third party may perform CDD (paras 6-8) but NEVER ongoing monitoring โ that stays with the adviser.
- Notwithstanding reliance on a third party, the financial adviser remains responsible for its AML/CFT obligations under the Notice. โ Ch. 5, p. 19
⚠ Reliance never shifts responsibility โ the adviser remains fully responsible for its AML/CFT obligations.
- For reliance purposes, a "third party" means a financial institution set out in Appendix 5B; a financial institution supervised by a foreign authority for AML/CFT consistent with FATF standards (other than a payment services licensee); and, for a Singapore-incorporated adviser, its branches, subsidiaries and related corporations (or, for a foreign-incorporated adviser, its head office, parent, and their branches, subsidiaries and related corporations). โ Ch. 5, p. 18
- Where a financial adviser relies on a third party, it shall document the basis for its satisfaction that the requirements in 9.2(a) and (b) are met (except where the third party is an Appendix 5B financial institution), and immediately obtain from the third party the CDD information the third party had obtained. โ Ch. 5, p. 19
๐๏ธRecord Keeping
Para 10: prepare/maintain/retain records, the 5-year retention periods and their anchors.
- For CDD information relating to the business relations โ as well as account files, business correspondence and results of any analysis โ a financial adviser shall retain records for a period of at least 5 years following the termination of the business relations.5 years โ Ch. 5, p. 20
⚠ CDD records: at least 5 years from TERMINATION of business relations (not from opening).
- For data, documents and information relating to a transaction โ including any information needed to explain and reconstruct the transaction โ a financial adviser shall retain records for a period of at least 5 years following the completion of the transaction.5 years โ Ch. 5, p. 20
⚠ Both periods are 5 years but differ by anchor: CDD -> from TERMINATION of relations; transactions -> from COMPLETION of the transaction.
- A financial adviser shall prepare, maintain and retain records of all data, documents and information that it is required to obtain or produce to meet the requirements under the Notice. โ Ch. 5, p. 19
- Records shall be kept such that all legal requirements are met; any individual transaction can be reconstructed (including the amount and type of currency) to provide evidence for prosecution; the Authority, other authorities and the adviser's internal and external auditors can review the business relations, transactions, records and CDD information; and the adviser can satisfy any enquiry or order within a reasonable time. โ Ch. 5, p. 19, 20
- A financial adviser shall retain records of data, documents and information on all business relations or transactions pertaining to a matter under investigation or that has been the subject of an STR, in accordance with any request or order from STRO or other relevant authorities. โ Ch. 5, p. 20
- A financial adviser may retain data, documents and information as originals or copies, in paper or electronic form or on microfilm, provided they are admissible as evidence in a Singapore court of law. โ Ch. 5, p. 20
๐ง Memory hook
Five years, two anchors
Both retention periods are five years โ the trick is the anchor. CDD records run five years from the end of the business relations; transaction records run five years from completion of the transaction. Records tied to an investigation or an STR are kept as the Authority directs, however long that is.
๐Personal Data
Para 11: the PDPA access/correction relief, the limited access right, and use/disclosure without consent.
- For the purpose of complying with the Notice, a financial adviser is not required to provide an individual with access to personal data held about them, information about how that data has been or may be used or disclosed, or a right to correct an error or omission in that data. โ Ch. 5, p. 20, 21
⚠ General rule (11.2): NO access/use-info/correction duty โ but 11.3 carves out access to 6 basic identity items on request.
- A financial adviser shall, as soon as reasonably practicable upon an individual's request, provide access to that individual's full name (including aliases), unique identification number, residential address, date of birth, nationality and other personal data the individual provided, and the right to correct errors or omissions in those items where there are reasonable grounds. โ Ch. 5, p. 21
⚠ Individuals CAN, on request, access their basic identity data (name, ID number, address, DOB, nationality, other data they provided) and correct errors.
- For the purpose of complying with the Notice, a financial adviser may, whether directly or through a third party, collect, use and disclose the personal data of an individual (customer, life-policy beneficiary, appointed person, connected party or beneficial owner) without the individual's consent. โ Ch. 5, p. 21
⚠ For AML/CFT compliance the adviser may collect, use AND disclose personal data WITHOUT the individual's consent.
๐จStr Reporting
Para 12: internal STR arrangements, prompt filing regardless of amount, and the tipping-off provision.
- A financial adviser shall promptly submit reports on suspicious transactions (including attempted transactions), regardless of the amount of the transaction, to STRO, and extend a copy to the Authority for information. โ Ch. 5, p. 22
⚠ STRs go to STRO (copy to MAS), promptly, for ANY amount, and cover ATTEMPTED transactions too.
- Where a financial adviser forms a suspicion of ML/TF and reasonably believes that performing CDD measures will tip off the customer, an appointed person, a connected party or a beneficial owner, it may stop performing those measures; it shall document the basis for its assessment and file an STR. โ Ch. 5, p. 22
⚠ Tipping-off risk: the adviser MAY stop CDD measures, but must still document the basis AND file an STR.
- A financial adviser shall implement internal policies, procedures and controls to meet its CDSA and TSOFA reporting obligations, including establishing a single reference point within the organisation to whom all employees, representatives and officers promptly refer transactions suspected of ML/TF for possible referral to STRO, and keeping records of all transactions referred to STRO together with internal findings and analysis. โ Ch. 5, p. 22
โDid you know?
No amount too small, and no warning given
Suspicious transactions โ including attempted ones โ are reported to the STRO promptly regardless of amount, with a copy to the Authority. And where performing the CDD measures themselves would tip the customer off, the adviser may stop the checks and file the STR instead: the one thing it must never do is alert the target.
๐Internal Policies
Para 13: internal and group policies, higher-standard rule, compliance officer, audit, hiring and training.
- Where the AML/CFT requirements in a host country differ from those in Singapore, the financial adviser shall require its overseas branch or subsidiary to apply the higher of the two standards, to the extent the host country's law permits; where local law conflicts so the higher standard cannot be fully observed, it shall apply additional appropriate measures, report to the Authority, and comply with any further directions. โ Ch. 5, p. 24
⚠ Overseas branches apply the HIGHER of Singapore vs host AML/CFT standards; if host law blocks it, add measures + report to MAS.
- A financial adviser shall develop appropriate compliance management arrangements, including at least the appointment of an AML/CFT compliance officer at the management level, who (with any assisting persons) must be suitably qualified and have adequate resources and timely access to all relevant records. โ Ch. 5, p. 23
⚠ AML/CFT compliance officer must be at MANAGEMENT level, suitably qualified, with timely access to records.
- A financial adviser shall maintain an audit function that is adequately resourced and independent, and that is able to regularly assess the effectiveness of the adviser's internal policies, procedures and controls, and its compliance with regulatory requirements. โ Ch. 5, p. 23
⚠ AML/CFT audit function must be INDEPENDENT and adequately resourced, assessing effectiveness regularly.
- A financial adviser shall develop and implement adequate internal policies, procedures and controls โ taking into account its ML/TF risks and the size of its business โ to help prevent ML/TF, communicate these to its employees, and ensure they meet all the requirements of the Notice. โ Ch. 5, p. 23
- A financial adviser incorporated in Singapore shall develop a group policy on AML/CFT meeting all the requirements of the Notice and extend it to all its branches and subsidiaries in its financial group; where a branch or subsidiary is in a FATF-countermeasure or inadequate-AML jurisdiction, it shall ensure the group policy is strictly observed there. โ Ch. 5, p. 23, 24
- A financial adviser shall have in place screening procedures to ensure high standards when hiring employees and appointing officers and representatives. โ Ch. 5, p. 25
- A financial adviser shall take all appropriate steps to ensure its employees, officers and representatives (in Singapore or elsewhere) are regularly and appropriately trained on AML/CFT laws and CDD measures and the detecting and reporting of suspicious transactions; prevailing techniques, methods and trends in ML/TF; and the adviser's internal AML/CFT policies and the roles and responsibilities of staff in combating ML/TF. โ Ch. 5, p. 25
๐กIn context
AML is an organisational sport
The Notice regulates the firm, not just the file: a Singapore-incorporated adviser must extend a group AML/CFT policy to its branches and subsidiaries, screen its own hires, train staff wherever they sit, and keep an independent audit function testing whether any of it works. Customer checks are only the front line.
๐Appendices
Appendices 5A and 5B โ the institution lists, their different uses, and the 5B-within-5A relationship.
- Appendix 5A covers financial institutions that are licensed, approved, registered or regulated by the Authority, but excludes persons exempted from licensing, approval or regulation by the Authority (other than specified s23(1)(f) FAA and s99(1)(h) SFA exempt persons). Appendix 5A is referenced by the beneficial-owner inquiry exemption in paragraph 6.15(e). โ Ch. 5, p. 26
⚠ Appendix 5A -> beneficial-owner inquiry exemption (6.15(e)). Appendix 5B -> simplified CDD (7.5) & third-party reliance (9.1).
- Appendix 5B is an enumerated list of financial institutions (e.g. banks and merchant banks licensed under the Banking Act, finance companies, licensed financial advisers, CMS licence holders, registered fund management companies, approved trustees, licensed trust companies, direct life insurers, and registered insurance brokers). It is referenced by the simplified-CDD provision (7.5) and the third-party definition (9.1), and every Appendix 5B institution falls within Appendix 5A. โ Ch. 5, p. 27
⚠ Every Appendix 5B institution falls WITHIN Appendix 5A (5B is the narrower list used for SDD & third-party reliance).