Guidance Note 7B: How extensively must RMCPs be updated?

Written by Justin Joannides
Posted on August 18, 2026

Table Of Contents

From CompliNEWS | Financial Services Intelligence Watch

Guidance Note 7B: How extensively must RMCPs be updated?

The short answer is that every accountable institution should conduct and document a GN 7B gap assessment, but not every RMCP requires a complete rewrite. GN 7B is a targeted strengthening of the existing framework. An RMCP that already properly addresses proliferation financing, technology and product-change risk, evidence-based simplified due diligence and enhanced due diligence following suspicious transaction reporting may need only limited amendments. An outdated RMCP that remains focused mainly on money laundering and terrorist financing, however, will require substantial revision. The FIC describes its guidance as authoritative: accountable institutions must take it into account or be able to demonstrate that their alternative arrangements achieve an equivalent level of compliance. Waiting for the next annual RMCP review would therefore be difficult to defend where a material gap has already been identified.

FIC Guidance Note 7B notice

Full Guidance Note 7B

What GN 7B actually changes

Although the document runs to 77 pages, most of it carries forward the existing guidance. The substantive additions are concentrated in four areas. First, proliferation financing is expressly integrated throughout the risk-based framework. RMCPs must therefore address PF across the risk assessment, controls, customer due diligence, monitoring and training, rather than mentioning it only in a sanctions paragraph.

Second, institutions must assess the ML, TF and PF risks associated with new products, services, business practices, delivery channels and technologies before implementation or launch, and again when material changes occur. Third, low-income or underserved clients may not automatically be classified as low risk; simplified due diligence must be supported by a documented, evidence-based risk assessment. Finally, where an institution files a section 29 report because it suspects ML, TF or PF, it must conduct enhanced due diligence on the relevant business relationship or single transaction without tipping off the client.

New products and technology

  • ML, TF and PF risks must be assessed before launch and when material changes occur
  • Introduce a documented AML/CFT/CPF risk-assessment gate into product, system and technology change processes. 

Financial inclusion and SDD

  • Low-income or underserved clients may not automatically be treated as low risk
  • Replace blanket low-risk classifications with documented, evidence-based criteria. 

Section 29 reports and EDD

  • Filing an STR/SAR for suspected ML, TF or PF must be followed by EDD
  • Update the investigation and reporting procedure to include post-report EDD without tipping off the client. 

1. Proliferation financing must be integrated properly

GN 7B inserts a definition of proliferation financing and systematically changes the Chapter 1 risk-based framework from an ML/TF framework into an ML/TF/PF framework. PF must therefore be considered when identifying inherent and residual risk; evaluating clients, products, services, jurisdictions and delivery channels; assigning risk ratings; applying simplified or enhanced measures; monitoring activity; and designing controls.

This does not mean that PF first became relevant on 3 August 2026. Revised GN 7A’s RMCP chapter already required accountable institutions to develop an AML/CFT/CPF programme and conduct an entity-wide ML, TF and PF risk assessment. The FIC has also previously issued specific proliferation-financing guidance in PCC 54. A properly updated RMCP should therefore already contain much of this material. FIC guidance on drafting RMCPs, PCC 54

The practical problem is that many RMCPs mention PF only in the title, definitions or targeted financial sanctions section. That will no longer be enough. An institution should be able to demonstrate:

  • How PF exposure is assessed separately from conventional ML and TF risk.
  • Which clients, sectors, jurisdictions, commodities, technologies and transaction types may increase PF risk.
  • How PF indicators influence client, product and institutional risk ratings.
  • How sanctions and targeted financial sanctions controls interact with the broader PF risk assessment.
  • What escalation, investigation, reporting and relationship-management measures apply where PF concerns arise.
  • How employees are trained to identify relevant PF risks. 

The FIC declined industry requests to expand paragraph 7A by expressly linking it to sections 26A and 26B and the wider targeted financial sanctions framework. Institutions should therefore retain the statutory definition used by GN 7B and address targeted financial sanctions separately and accurately rather than creating an overbroad internal definition.

2. New products, services and technology require a pre-launch risk assessment

Paragraph 37A is probably the most operationally significant change. Accountable institutions must identify and assess the ML, TF and PF risks associated with:

  • New products and services.
  • New business practices.
  • New delivery channels.
  • New or developing technologies used for new offerings.
  • New or developing technologies applied to existing products, services, practices or delivery channels. 

The assessment must take place before implementation or launch and must be reconsidered when material changes occur. It must also be reflected in the institution’s risk-assessment process and RMCP.

This is not simply an information-security or cybersecurity assessment. The question is whether the development could make the institution more vulnerable to money laundering, terrorist financing or proliferation financing. Relevant developments may include digital onboarding, biometric verification, automated screening, AI-assisted monitoring, client portals, application programming interfaces, outsourced KYC platforms, remote advice, new payment functionality, crypto services and non-face-to-face distribution models.

A compliant RMCP should set out:

  • What developments trigger an AML/CFT/CPF assessment.
  • Who is responsible for initiating and completing it.
  • Which risk factors must be considered.
  • How inherent and residual risk will be scored.
  • Which controls must be operational before launch.
  • Who may approve the residual risk.
  • What evidence must be retained.
  • When a material change or post-launch review is required. 

This requirement must be applied proportionately. A small FSP with limited products does not need a bank-sized product governance committee, but it still needs a workable process. A short assessment and approval form may be sufficient if it genuinely considers the risks. An institution cannot simply state that technology risk is ‘not applicable’ when it uses digital onboarding, outsourced systems or other developing technologies.

Importantly, GN 7B does not clearly require institutions to perform a retrospective assessment of every mature system that has not changed. It does, however, justify reviewing the present technology inventory to establish whether new or developing technology is being used in existing offerings without an appropriate ML/TF/PF assessment.

3. Low-income clients may not automatically be treated as low risk

GN 7B preserves the ability to apply simplified due diligence. The FIC rejected concerns that its draft wording might effectively eliminate SDD and removed the proposed requirement for a ‘comprehensive’ risk assessment. SDD therefore remains available where it is justified by the institution’s risk-based approach.

However, paragraph 40A makes it clear that underserved or low-income clients cannot automatically be classified as lower risk simply because they fall within those categories. Financial inclusion is important, but low income is not, by itself, evidence of low ML, TF or PF risk.

RMCPs should therefore be checked for statements such as:

  • Entry-level, low-income or financially underserved clients are automatically classified as low risk.
  • That approach should be replaced with an assessment that considers the complete relationship, including the product, expected activity, payment method, delivery channel, geography, occupation, source of funds, transaction limits and any other relevant indicators. 

This does not mean every low-income client must undergo standard or enhanced due diligence. It means that the decision to apply SDD must be supported by a recorded risk assessment. Institutions may still classify particular low-value products or defined client groups as lower risk where the evidence supports that conclusion.

4. A section 29 report must now be followed by EDD

Paragraph 58A defines SDD as a basic level of identification and verification used where a business relationship or single transaction presents a low ML, TF and PF risk. It then introduces a significant requirement: where an institution has a suspicion of ML, TF or PF and files a report under section 29 of FICA, it must conduct EDD on the relevant relationship or single transaction.

The FIC’s consultation feedback provides important clarification on the sequence.

Not every automated or internal alert requires a section 29 report or EDD. The institution must first investigate the alert. If there is a reasonable explanation consistent with the client’s profile, the alert may be closed with reasons. Once the institution concludes that the matter is reportable and files the report, however, EDD becomes necessary.

The RMCP should describe what post-report EDD entails. Depending on the circumstances, it may include:

  • Refreshing the client’s identification and beneficial ownership information.
  • Obtaining or corroborating source-of-funds or source-of-wealth information.
  • Reconsidering the purpose and intended nature of the relationship.
  • Examining the transaction and surrounding activity more closely.
  • Conducting additional adverse-media, PEP, sanctions or related-party screening.
  • Reassessing the client’s risk rating.
  • Increasing the frequency or intensity of monitoring.
  • Escalating the relationship for senior management consideration.
  • Deciding whether the relationship can continue, must be restricted or should be terminated. 

The process must be designed carefully to avoid tipping off the client. EDD does not invariably require immediately contacting the client and asking questions that reveal that a report has been filed. Institutions should first use information already held, reliable independent sources and ordinary review processes. Any client contact must be managed in accordance with the tipping-off prohibition.

GN 7B does not expressly require every historic STR or SAR to be reopened. A sensible response would be to review active relationships that were previously reported and determine whether appropriate EDD was completed. Closed historic relationships would generally require a documented risk-based decision rather than an indiscriminate back-book exercise.

So, must the entire RMCP be rewritten?

Not necessarily. The extent of the work depends on the present standard of the RMCP.

Limited update

A limited update may be sufficient where the RMCP already:

  • Covers ML, TF and PF throughout its risk-based framework.
  • Contains an adequate entity-wide AML/CFT/CPF risk assessment.
  • Requires financial-crime risk assessment before new products or technology are launched.
  • Applies SDD only after an evidence-based low-risk assessment.
  • Requires EDD after an STR or SAR is filed.
  • Contains properly referenced supporting procedures and annexures. 

In that case, the institution should still update references from GN 7A to GN 7B, confirm the paragraph 37A and 58A processes expressly, document its gap assessment and obtain approval for the revised controlled version.

Targeted substantive revision

Most institutions will probably fall into this category. The RMCP, BRA and supporting procedures should be updated in the four affected areas, but the remainder of the programme can remain intact.

This will ordinarily require changes to:

  • The institutional or business risk assessment.
  • Product and technology change procedures.
  • Client risk-rating methodology.
  • SDD criteria.
  • Transaction-monitoring and alert-investigation procedures.
  • Section 29 reporting procedures.
  • EDD and relationship-review procedures.
  • Training material and compliance monitoring plans. 

Full redevelopment

A full redevelopment is warranted where the RMCP:

  • Still refers primarily or exclusively to ML and TF.
  • Treats PF as no more than sanctions screening.
  • Uses fixed document checklists without a genuine risk-based approach.
  • Automatically classifies entire categories of clients as low risk.
  • Does not distinguish between an alert, a suspicion and a reportable matter.
  • Has no documented product or technology risk-assessment process.
  • Consists of a high-level outline and refers to unapproved or unreferenced procedures.
  • Has not been properly approved by the board or highest authority. 

Approval and version-control implications

Any GN 7B amendments must be properly approved. Paragraph 190 states that RMCP reviews and amendments must be documented and approved. The board, senior management or person with the highest authority—depending on the institution’s structure—must approve the RMCP. This responsibility cannot be delegated to a compliance committee or the compliance officer.

GN 7B specifically gives the example of an FSP implementing an updated RMCP that has not been approved by its board. The FIC says this may constitute non-compliance. Institutions should therefore avoid circulating or implementing a supposedly final GN 7B version before formal approval.

Where procedures, templates or risk assessments sit outside the main RMCP, they must be clearly referenced. GN 7B states that documentation not referenced in the RMCP is not considered part of the RMCP.

Recommended implementation approach

Every accountable institution should now complete the following:

  • Record that GN 7B took effect on 3 August 2026 and replaced the earlier guidance.
  • Complete a documented gap analysis against paragraphs 7A, 37A, 40A and 58A.
  • Review the BRA or entity-wide risk assessment for proper PF integration.
  • Review current and planned technologies, products and delivery channels.
  • Replace any automatic low-income or financial-inclusion risk classifications.
  • Add the section 29 report-to-EDD workflow.
  • Update related procedures, risk matrices and templates.
  • Conduct a focused review of active previously reported relationships.
  • Update relevant employee training.
  • Table the complete revised RMCP and supporting documents for proper approval.
  • Retain the gap assessment, change log, approval and implementation evidence. 

Overall conclusion

GN 7B does not justify automatically replacing every RMCP from the first page to the last. It does, however, require more than changing the document title or adding ‘PF’ next to ‘ML/TF’.

At a minimum, every institution needs a documented review and a properly approved GN 7B-aligned version. Where an existing RMCP was genuinely compliant with Revised GN 7A’s stronger Chapter 4 requirements, the amendments can be focused. Where the RMCP remains generic, checklist-driven or weak on PF, technology governance, SDD and post-report EDD, a substantial rewrite is necessary.

The most important new operational rule is straightforward: financial-crime risk must be considered before new products or technology are launched, and filing a section 29 report must now lead to documented EDD.

Categories:

Recent Comments

Comments are closed