FIRMCY Insights

The policy before the score

Practice notes · all insights
The policy before the score

Ask a firm where its client acceptance policy lives and you usually get a form: the questionnaire a new client fills in on day one. ICPAC's Directive uses those words for something written earlier and higher up: by senior management, before any client is scored. The policy comes first, and the score answers to it.

The order is in the text, in one of the few places the Directive puts a hard verb on a list of steps. Paragraph 4.1.5: in the implementation of a RBA, for assessing the most cost effective and proportionate way to manage the money laundering and terrorist financing risks posed by clients, a firm must follow the below steps. Step (a) is determining the risk appetite of the firm, to be decided at senior management level and which should be reflected in the Client Acceptance Policy. Step (b), which comes after it, is identifying and assessing the money laundering and terrorist financing risks emanating from particular clients, services, geographical areas of operation of the firm and its clients and service delivery channels.

Plainly: the list opens with deciding how much risk the firm wants, and only then turns to the clients. The Directive does not say in so many words that the steps run in that order. It calls them steps, says they must be followed, and puts this one first. And read the two modals in the same line. The steps must be followed. The appetite should be reflected in the policy. Following the steps is the hard part; where the appetite gets written down is put in the softer voice.

Risk appetite is a defined term, and the definition is not a size. The amount and type of risk that an organisation is willing to take in order to meet its strategic objectives. Firms may have different risk appetites depending on the services they provide, their resources, culture and objectives. Risk appetite may change over time. Yours, and it moves.

Now who decides. The Directive keeps two terms apart and uses both in this chapter. Senior Management is defined by authority: board members for companies, partners for partnerships, sole traders and other position in a different type of entity or legal arrangement, with top decision-making authority. A Senior Management Official is defined by what he knows and how far he can reach instead, and the definition says so expressly, irrespective of whether the said person is a member of the Board of Directors of the obliged entity. Step (a) puts the appetite at senior management level. The paragraph that fills the policy in addresses senior management officials. The Directive writes both phrases in lower case here and does not say whether the difference is deliberate. In a small practice those are the same people. In a larger one they need not be.

That paragraph sits under a heading the Directive calls Tone at the top. Each firm's senior management officials should establish the acceptable risk profiles of its clients. These should be documented in a Client Acceptance Policy (CAP), which will also outline the characteristics of a potential client, that the firm should potentially decline the application for establishment of a business relationship. The instance given is business relationships with PEPs from high risk countries, depending on the risk appetite of the firm. An example, offered as one, and it hangs on your own appetite rather than on a list of forbidden clients handed to you.

Then the sentence that makes the policy load-bearing instead of decorative. In the Client Acceptance Policy, senior management officials should outline the client acceptance criteria on which the RBA implementation and Economic profile of a client will be based on. The criteria are not a summary of what the firm already does. They are what the risk-based approach and the client's economic profile are built on.

Which is why the scorecard answers to the policy and not the other way round. Paragraph 4.7.1: the qualitative risk assessment methodology or scorecard should reflect the provisions of the Client Acceptance Policy mentioned in section 4.2 above and must be one of the first steps of the client due diligence process. Should reflect, must be one of the first steps. Two modals in one sentence, and the harder one is on the timing.

Then 4.9.1 turns the policy into the thing your framework is checked against. Firms must be able to demonstrate to the Institute how they evaluate and mitigate money laundering and terrorist financing risks, and the risk based approach framework adopted must be clearly documented, in line with the Client Acceptance Policy and made available to the Institute upon request. Must, must, and in line with.

After that the CAP keeps surfacing as the place an answer is supposed to already exist. Each firm should clearly outline in its AML manual or CAP the categories of clients for which it will be performing EDD, for clarity purposes. The rationale behind applying simplified due diligence should be clearly documented in the AML manual or CAP. In the case of an unregulated EU fund, firms should also consider whether there are any restrictions in their CAP for establishing such a business relationship. And where a live relationship changes significantly and the revised risk is not in line with the Client Acceptance Policy of the firm, then consideration should be made to terminate the business relationship. Consideration.

A document carrying that much weight is not meant to go stale. Senior management officials should also ensure that the CAP and corresponding risk management is refreshed regularly by periodic reviews, reflecting any significant changes that may take place in the business environment or the legal framework. The AML manual, which must be approved by senior management officials, gets the same treatment from the other direction: arrangements should also be made to update the manual in accordance with the latest provisions of the Law and the risk appetite of the management. The law moves and the manual follows. The appetite moves and the manual follows that too.

None of which makes appetite a licence, and the Directive marks the limit where it hands over discretion. Twice, on the documents a firm will accept for verification, it says each firm may define the documents to be accepted for verification depending on its operations and risk appetite, without jeopardising a violation of the provisions of the Law. The qualifier travels with the freedom. Resources are framed the same way: the compliance department should have enough resources in human capital, trainings and technology, always proportional to the risk appetite, complexity and broadness of tasks to be undertaken. Proportional to what you said you wanted.

And that wiring was not there at the start. The Directive's own table of amendments records, against 20 November 2019, the inclusion of risk appetite in the terms, mandatory steps to follow in the RBA at 4.1.5, and reflection of risk appetite in CAP. The definition, the mandatory steps and the link between appetite and policy are all logged against one amendment.

Two things this card is not saying. The Directive states that it is issued under articles 59(1)(d) and 59(4) of the Law and that the Law requires that all firms apply adequate and appropriate policies, controls and procedures; the paragraphs on the Client Acceptance Policy quoted here cite no section of the Law for it, and nothing in this card is a reading of the statute. And this is ICPAC's text, binding on its members. A firm supervised by someone else should be reading its own supervisor's directive.

So: open the policy and look for the sentence that would have stopped the last client you nearly turned away. If what you find only describes the clients you already have, it is a record of the book, not a criterion for it.

Appetite, then policy, then scorecard, then client. In that order the score means something, because there is a sentence above it that it could have failed. Backwards, it is a number you gave yourself.

Not legal advice. Verify against the primary source before acting.

Sources

Published 18 September 2026 · Practice notes
Drafted with AI assistance. Reviewed, edited and approved before publication by a named person at Ioannou & Sharpe LLC, who takes editorial responsibility for its content. Approved by Harris Sharpe, 20 September 2026.

Screen against the current lists in seconds

FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.

Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗
© 2026 Ioannou & Sharpe LLC · VAT CY60007091D · Griva Digeni, Limassol Center, Block B, 3rd Floor, Office 304, 3095 Limassol, Cyprus · [email protected]
Not legal advice. FIRMCY publishes this analysis for general informational purposes; verify against the primary sources before acting.