2025-sandbox.tex (13318B)
1 \documentclass[aspectratio=169,t]{beamer} 2 \input taler-macros 3 \usepackage{eurosym} 4 \usepackage[normalem]{ulem} 5 \newcommand{\TITLE}{NEXT \\ GENERATION \\ INTERNET} 6 \newcommand{\SUB}{The FINMA Sandbox Exception} 7 \newcommand{\AUTHOR}{Christian Grothoff} 8 \newcommand{\SPEAKER}{Christian Grothoff} 9 \newcommand{\INST}{Bern University of Applied Sciences} 10 \newcommand{\DATE}{Rethinking Money Symposium} 11 \usepackage{amsmath} 12 \usepackage{multimedia} 13 \usepackage[percent]{overpic} 14 \usepackage{framed,color,ragged2e} 15 \usepackage[absolute,overlay]{textpos} 16 \definecolor{shadecolor}{rgb}{0.8,0.8,0.8} 17 \usetheme{boxes} 18 \setbeamertemplate{navigation symbols}{} 19 \usepackage{colortbl} 20 \usepackage{booktabs} 21 \usepackage{url} 22 \usepackage{pifont} 23 \newcommand{\cmark}{\ding{51}}% 24 \newcommand{\xmark}{\ding{55}}% 25 \usepackage{array, adjustbox,url} 26 \usepackage{pifont} % wasysym 27 \usepackage{rotating,subfig} 28 \usepackage{xspace} 29 \ifpdf\usepackage{tikz}\fi 30 \usepackage{xcolor} 31 \usetikzlibrary{shapes,arrows} 32 \usetikzlibrary{positioning} 33 \usetikzlibrary{calc} 34 35 \usepackage{FiraMono} 36 \usepackage{fontawesome} 37 \usepackage[absolute,overlay]{textpos} 38 39 \usepackage{array, adjustbox,url} 40 41 \setlength{\TPHorizModule}{1mm} 42 \setlength{\TPVertModule}{1mm} 43 \usepackage[labelformat=empty, font=small]{caption} 44 \captionsetup[figure]{font=small} 45 46 47 \definecolor{tumblue}{RGB}{0,101,189} 48 \definecolor{shadecolor}{rgb}{0.8,0.8,0.8} 49 \definecolor{MidnightBlue}{rgb}{0.1, 0.1, 0.44} 50 \definecolor{CornflowerBlue}{rgb}{0.39, 0.58, 0.93} 51 \definecolor{Black}{rgb}{0, 0, 0} 52 53 54 % Do not edit this part 55 \title{\TITLE} 56 \subtitle{\SUB} 57 \date{\DATE} 58 \author[\SPEAKER]{\AUTHOR} 59 \institute{\INST} 60 61 % 15 minutes 62 \begin{document} 63 64 \begin{frame}[plain] 65 \maketitle 66 \end{frame} 67 68 69 \section{Introduction} 70 71 72 \begin{frame}{FINMA Licenses} 73 74 ``An activity pursuant to Art. 1b Banking Act may only be carried out 75 after FINMA has granted a license.'' 76 \vfill 77 \begin{itemize} 78 \item Full banking license (10M capital, major paperwork) 79 \item FinTech license (1M capital, no loans) 80 \item {\bf Sandbox exception} 81 \end{itemize} 82 \vfill 83 \begin{center} 84 \tiny 85 \url{https://www.finma.ch/en/documentation/dossier/dossier-fintech/entwicklungen-im-bereich-fintech/} 86 \end{center} 87 \end{frame} 88 89 90 \begin{frame}{The BankV Art. 6} 91 \vspace{-0.2cm} 92 {\small 93 \begin{enumerate} 94 \item Gewerbsmässig im Sinne des BankG handelt, wer: 95 \begin{enumerate} 96 \item[a.] dauernd mehr als 20 Publikumseinlagen oder sammelverwahrte kryptobasierte Vermögenswerte entgegennimmt; oder 97 \item[b.] sich öffentlich zur Entgegennahme von Publikumseinlagen oder sammelverwahrten kryptobasierten Vermögenswerten empfiehlt (...) 98 \end{enumerate} 99 \item Nicht gewerbsmässig im Sinne des BankG handelt, wer dauernd mehr als 20 Publikumseinlagen oder sammelverwahrte kryptobasierte Vermögenswerte entgegennimmt (...), wenn er: 100 \begin{enumerate} 101 \item[a.] Publikumseinlagen oder sammelverwahrte kryptobasierte Vermögenswerte von gesamthaft höchstens 1M CHF entgegennimmt; 102 \item[b.] kein Zinsdifferenzgeschäft betreibt; und 103 \item[c.] die Einlegerinnen und Einleger, bevor sie die Einlage tätigen, schriftlich oder in einer anderen Form, die den Nachweis durch Text ermöglicht, darüber informiert, dass: 104 (1) er von der FINMA nicht beaufsichtigt wird, und (2) die Einlage nicht von der Einlagensicherung erfasst wird. 105 \end{enumerate} 106 \end{enumerate} 107 } 108 \end{frame} 109 110 111 \begin{frame}{The GwG Art. 2} 112 Finanzintermedi\"are sind: 113 \begin{enumerate} 114 \item[3] Finanzintermediäre sind auch Personen, die berufsmässig fremde Vermögenswerte annehmen oder aufbewahren oder helfen, sie anzulegen oder zu übertragen; insbesondere Personen, die: 115 \begin{enumerate} 116 \item[b.] {\bf Dienstleistungen für den Zahlungsverkehr} erbringen, namentlich für Dritte elektronische Überweisungen vornehmen oder {\bf Zahlungsmittel} wie Kreditkarten und Reiseschecks {\bf ausgeben oder verwalten}; 117 \item[c.] für eigene oder fremde Rechnung mit Banknoten und Münzen, Geldmarktinstrumenten, Devisen, Edelmetallen, Rohwaren und Effekten (Wertpapiere und Wertrechte) sowie deren Derivaten handeln; 118 \end{enumerate} 119 \end{enumerate} 120 \end{frame} 121 122 123 \begin{frame}{The GwG Art. 14} 124 \begin{enumerate} 125 \item Finanzintermediäre nach Artikel 2 Absatz 3 müssen sich einer Selbstregulierungsorganisation anschliessen. 126 \end{enumerate} 127 \end{frame} 128 129 130 \begin{frame}{Supervision via SROs (example: VQF)} 131 \begin{center} 132 \includegraphics[width=0.70\textwidth]{supervision.png} 133 134 (from VQF training materials) 135 \end{center} 136 \end{frame} 137 138 139 \begin{frame}{Compliance processes} 140 \begin{itemize} 141 \item Customer identification (know-your-customer (KYC) and know-your-business (KYB)), including 142 risk classification 143 \item Transaction monitoring, plausibilization and reporting of suspicious activities 144 \item Enforcement of financial sanctions 145 \end{itemize} 146 \end{frame} 147 148 149 \begin{frame}{Know-Your-Customer} 150 \framesubtitle{Identification process of the economic beneficiary} 151 \begin{center} 152 \includegraphics[width=0.8\textwidth]{cascade.png} 153 154 (from VQF training materials) 155 \end{center} 156 \end{frame} 157 158 159 \begin{frame}{Who is a customer?} 160 A high-level approach is to restrict the business model 161 to minimize customer identification. For example, do not accept: 162 \begin{itemize} 163 \item Customers from outside of Switzerland 164 \item Customers without Swiss bank accounts, phone numbers or addresses 165 \item Customers to withdraw significant amounts 166 \item Customers to receive significant P2P transfers 167 \item Large transactions 168 \end{itemize} 169 \end{frame} 170 171 172 \begin{frame}{What are ``large'' transactions?} 173 \begin{center} 174 \begin{tabular}{l|r|l} 175 {\bf Operation} & {\bf Amount} & {\bf Period} \\ \hline \hline 176 Withdraw & $\le$ 2.500 CHF & per month \\ \hline 177 Withdraw & $\le$ 15.000 CHF & per year \\ \hline 178 P2P receive & $\le$ 2.500 CHF & per month \\ \hline 179 P2P receive & $\le$ 15.000 CHF & per year \\ \hline 180 Deposit & $\le$ 2.500 CHF & per month \\ \hline 181 Deposit & $\le$ 15.000 CHF & per year \\ \hline 182 Transact & $\le$ 1.000 CHF & per transaction \\ 183 \end{tabular} 184 \end{center} 185 \end{frame} 186 187 188 \begin{frame}[fragile]{VQF KYB process} 189 \begin{center} 190 \begin{tikzpicture}[scale=0.33, transform shape] 191 \tikzstyle{def} = [node distance=2.5em and 0.5em, inner sep=1em, outer sep=.3em]; 192 \node (zero) [def,draw] at (0,0){Deposit limit: zero}; 193 \node (dummy4) [left=of zero] {}; 194 \node (dummy5) [left=of dummy4] {}; 195 \node (origin) [left=of dummy5] {$\circ$}; 196 \node (tos) [def,below=of zero,draw]{Limited relationship}; 197 \node (vqf1) [def, draw, below=of tos] {\shortstack{VQF 902.1\\(Identification)}}; 198 \node (dummy0) [below=of vqf1]{}; 199 \node (vqf12) [def, draw, below=of dummy0] {VQF 902.12}; 200 \node (vqf13) [def, draw, left=of vqf12] {VQF 902.13}; 201 \node (addr) [def, draw, left=of vqf13] {\shortstack{Address\\validation}}; 202 \node (vqf15) [def, draw, right=of vqf12] {VQF 902.15}; 203 \node (vqf11) [def, draw, right=of vqf15] {\shortstack{VQF 902.11\\(Controlling\\person)}}; 204 \node (vqf9) [def, draw, below=of vqf11] {\shortstack{VQF 902.9\\(Beneficial\\owner)}}; 205 \node (dummy1) [below=of vqf12]{}; 206 \node (man) [def, draw, below=of dummy1]{Investigation}; 207 \node (complete) [def, draw, below=of man]{\shortstack{VQF 902.4\\(Risk Profile)}}; 208 \node (risk) [def, draw, below=of complete]{KYC complete}; 209 \node (dummy2) [right=of risk]{}; 210 \node (dummy3) [right=of dummy2]{}; 211 \node (good) [def, draw, right=of dummy3]{Regular account}; 212 % \node (customer) [def, draw, below left=of origin] {Customer}; 213 % \node (customer) [def, draw, below left=of origin] {Customer}; 214 % \node (merchant) [def, draw, below right=of origin] {Merchant}; 215 % \node (auditor) [def, draw, above right=of origin]{Auditor}; 216 % \node (regulator) [def, draw, above=of auditor]{CSSF}; 217 218 \tikzstyle{C} = [color=black, line width=1pt] 219 \tikzstyle{D} = [color=black, line width=1pt, dotted] 220 \draw [<-, C] (zero) -- (origin) node [midway, below] (TextNode) {KYC auth}; 221 \draw [<-, C] (tos) -- (zero) node [midway, right] (TextNode) {Accept Terms of Service}; 222 \draw [<-, C] (vqf1) -- (tos) node [midway, right] (TextNode) {Cross limits?}; 223 \draw [<-, C] (addr) -- (vqf1) node [midway, above, sloped] (TextNode) {Natural person?}; 224 \draw [<-, C] (vqf9) -- (vqf11) node [midway, right] (TextNode) {\shortstack{3rd party \\ control?}}; 225 \draw [<-, C] (vqf12) -- (vqf1) node [midway, above, sloped] (TextNode) {Foundation?}; 226 \draw [<-, C] (vqf13) -- (vqf1) node [midway, above, sloped] (TextNode) {Trust?}; 227 \draw [<-, C] (vqf15) -- (vqf1) node [midway, above, sloped] (TextNode) {Life insurance?}; 228 \draw [<-, C] (vqf11) -- (vqf1) node [midway, above, sloped] (TextNode) {Operational entity?}; 229 % \draw [<-, C] (vqf9) -- (vqf1) node [midway, above, sloped] (TextNode) {Other}; 230 \draw [->, D, bend left=20] (man) -| (addr) node [midway, below] (TextNode) {as needed}; 231 \draw [<-, C, bend right=20] (man) -- (addr) node [midway, below] (TextNode) {}; 232 \draw [<-, C] (man) -- (vqf12) node [midway, above, sloped] (TextNode) {}; 233 \draw [<-, C] (man) -- (vqf13) node [midway, above, sloped] (TextNode) {}; 234 \draw [<-, C] (man) -- (vqf15) node [midway, above, sloped] (TextNode) {}; 235 \draw [<-, C] (man) -- (vqf11) node [midway, above, sloped] (TextNode) {}; 236 \draw [<-, C] (man) -- (vqf9) node [midway, above, sloped] (TextNode) {}; 237 \draw [<-, C] (complete) -- (man) node [midway, right] (TextNode) {Document check}; 238 \draw [<-, C] (risk) -- (complete) node [midway, right] (TextNode) {Risk assessment}; 239 \draw [<-, C] (good) -- (risk) node [midway, below] (TextNode) {No sanctions?}; 240 \end{tikzpicture} 241 \end{center} 242 \end{frame} 243 244 245 \begin{frame}{Information to be collected} 246 \begin{itemize} 247 \item Business register excerpt; 248 \item Contact person identity; 249 \item List of beneficial owners with names and IDs; 250 \item Proof of ownership / authorization to act on behalf of the 251 business 252 \end{itemize} 253 Based on this, you need to make a risk-assessment of each customer: 254 \begin{itemize} 255 \item Establish if customer is a PEP 256 \item Establish additional risk factors (business domain, country risk, etc.) 257 \end{itemize} 258 There is no official list of PEPs, only rules for establishing if someone 259 is a PEP! $\Rightarrow$ Consult {\url https://opensanctions.org/datasets/peps/} 260 \end{frame} 261 262 263 \begin{frame}{Digital records: OK!} 264 \begin{center} 265 \includegraphics[width=0.75\textwidth]{vqf902.1.png} 266 \end{center}\pause 267 But: you still must have either seen the originals or received 268 certified copies on paper! 269 \end{frame} 270 271 272 \begin{frame}{Address validation: required!} 273 \begin{center} 274 \includegraphics[width=0.75\textwidth]{challenger.png} 275 \end{center} 276 \end{frame} 277 278 279 \begin{frame}{Transaction monitoring} 280 \begin{itemize} 281 \item You {\bf must} monitor for ``suspicious'' transactions 282 \item There is no legal definition of what is ``suspicious'' 283 \item You {\bf must} write your own risk-based rules! 284 \end{itemize} 285 286 \begin{center} 287 \includegraphics[width=0.5\textwidth]{newrules.png} 288 \end{center} 289 \vfill 290 Incident? $\Rightarrow$ Report to MROS! 291 \end{frame} 292 293 294 \begin{frame}{Sanction list enforcement} 295 \begin{itemize} 296 \item There is an official sanctions list you can download 297 \item The list is machine readable, but contains sometimes only approximate information 298 \item[$\Rightarrow$] Manual checks required in some cases 299 \end{itemize} 300 \end{frame} 301 302 303 \begin{frame}{VQF requirements} 304 \begin{itemize} 305 \item GwG trained staff 306 \item Independent audits (GwG + finances) 307 \item Statistical reports 308 \end{itemize} 309 \begin{center} 310 \includegraphics[width=0.66\textwidth]{vqfstats.png} 311 \end{center} 312 \end{frame} 313 314 315 \begin{frame}{Onboarding: Terms of Service} 316 \begin{center} 317 \includegraphics[width=0.3\textwidth]{tos.png} 318 \end{center} 319 \end{frame} 320 321 322 \begin{frame}{Hosting} 323 \begin{itemize} 324 \item In Switzerland 325 \end{itemize} 326 \end{frame} 327 328 329 \begin{frame}{Compliance cost} 330 \begin{itemize} 331 \item VQF membership + training: $\approx$ 2000 CHF/year 332 \item GwG paperwork: $\approx$ 4000 CHF/year 333 \item External audit: $\approx$ 5000 CHF/year 334 \end{itemize} 335 Note that these are minimal costs for a tiny operation, they 336 increase with customer and transaction volume! 337 \end{frame} 338 339 340 \begin{frame}{Final Remarks} 341 \begin{itemize} 342 \item This is not legal advice. 343 \item I am not a laywer. 344 \end{itemize} 345 \end{frame} 346 347 348 % This should be last... 349 \begin{frame}{Acknowledgements} 350 351 \begin{minipage}{0.45\textwidth} \ \\ 352 {\tiny Funded by the European Union (Project 101135475).} 353 354 \begin{center} 355 \includegraphics[width=0.5\textwidth]{../bandera.jpg} 356 \end{center} 357 \end{minipage} 358 \hfill 359 \begin{minipage}{0.45\textwidth} 360 {\tiny Funded by SERI (HEU-Projekt 101135475-TALER).} 361 362 \begin{center} 363 \includegraphics[width=0.65\textwidth]{../sbfi.jpg} 364 \end{center} 365 \end{minipage} 366 367 \vfill 368 369 {\tiny 370 371 Views and opinions expressed are however those of the author(s) only 372 and do not necessarily reflect those of the European Union. Neither the 373 European Union nor the granting authority can be held responsible for 374 them. 375 376 } 377 \end{frame} 378 379 \end{document}