This section complements guidance in FCG 2.2.4G, FCG 6.2.2G and FCG 6.2.4G and FCTR 9.3.2G and FCTR 9.3.3G
Business-wide risk assessments
Intermediaries should identify and assess the bribery and corruption risk across all aspects of their business.
Examples of factors which intermediaries should consider when assessing risk across their business.
• Risks associated with the jurisdictions the intermediary does business in, the sectors they do business with and how they generate business.
• Risks associated with insurance distribution chains, in particular where these are long. This includes taking steps to understand the risk associated with parties that are not immediate relationships, where these can be identified. Parties that are not immediate relationships may include, in addition to the insured and the insurer, entities such as introducers, sub-brokers, co-brokers, producing brokers, consultants, coverholders and agents.
• Risks arising from non-trading elements of the business, including staff recruitment and remuneration, corporate hospitality and charitable donations.
Risk assessments and due diligence for individual relationships
The risk-rating process for individual third-party introducer and client relationships, for example the producing broker, should build on the intermediary’s business-wide risk assessment.
Examples of factors intermediaries may consider when assessing bribery and corruption risk associated with individual relationships include:
• the role that the party performs in the distribution chain
• the territory in which it is based or in which it does business
• how much and how the party is remunerated for this work
• the risk associated with the industry sector or class of business, and
• the governance and ownership of the third party, including any political or governmental connections.
Intermediaries should decide on the level of due diligence, and which party to apply due diligence to, based on their assessment of risk associated with the relationship. This may include other parties in the insurance chain and not just their immediate contact. Where it is not possible or feasible to conduct due diligence on other parties, intermediaries should consider alternative approaches, such as adjustments to the level of monitoring to identify unusual or suspicious payments.
Examples of the type of information which intermediaries may obtain as part of the due diligence process include:
• other intermediaries’ terms of business and identification documentation, including information about their anti-corruption controls
• checks, as risk dictates, on company directors, controllers and ultimate beneficial owners, considering any individuals or companies linked to the client, PEP screening and status, links to a PEP or national government, sanctions screening, adverse media screening and action taken in relation to any screening hits, and
• for third-party introducers, details of the business rationale.