Changes

Change #8

file_content

Executive Summary

The updated guidelines introduce mandatory oversight requirements for financial institutions utilizing third-party e-KYC service providers. Institutions must now perform formal due diligence before engagement and conduct annual reviews to ensure continued compliance.

Impact Assessment

high
Vendor Management / Compliance

New requirement to conduct and document formal due diligence on all third-party e-KYC providers, with an annual review mandate.

Affected: 3.3

Recommended Actions

Role Action
Head of Compliance Update vendor management policy to include annual e-KYC provider reviews
Audit existing third-party contracts for compliance with new due diligence requirements
Compliance Team Conduct initial due diligence assessments for all current third-party e-KYC providers

Timeline

Effective Date
1 April 2024
Notes
Immediate compliance expected as of the effective date.

Document Details

Field 1.0 1.1 Status
Version 1.0 1.1 CHANGED
Effective Date 1 January 2024 1 April 2024 CHANGED
Copyright 2024 Bank Negara Malaysia. All rights reserved. 2024 Bank Negara Malaysia. All rights reserved. Unchanged
Document Owner Bank Negara Malaysia Bank Negara Malaysia Unchanged
Total Pages 1 1 Unchanged

1. Document Metadata

Updates to versioning and effective dates

CHANGED
Effective Date

Updated effective date for version 1.1

Old: 1 January 2024
New: 1 April 2024
CHANGED
Version

Incremented version number

Old: 1.0
New: 1.1

2. Operational Requirements

New requirements for third-party management

ADDED
Clause 3.3 (3.3)

New requirement mandating due diligence and ongoing oversight of third-party e-KYC providers.

Where financial institutions engage third-party providers to deliver e-KYC functions, they remain fully responsible for compliance with these guidelines. A formal due diligence assessment of the third-party provider must be conducted prior to engagement and reviewed annually thereafter.

3. Revision History

Addition of formal revision tracking

ADDED
Revision History Table (6)

Formalized tracking of document changes.

Added table detailing version 1.0 and 1.1 changes.

Sections with No Changes

Section Clauses
Introduction Section 1 - Regulatory expectations for e-KYC
Risk-Based Approach Section 3 - General risk-based approach requirements
Data Protection Section 4 - PDPA compliance
Reporting Section 5 - Reporting frequency and deadlines

Summary of Changes

Category Count Detail
CHANGED 2 Updated document version and effective date.
ADDED 2 Added new clause 3.3 regarding third-party service providers and a formal revision history table.
Added Removed
Added Removed Changed No matching line