Category
Author
DATE
A “yes” in the Risk and Compliance Return is not evidence. It is a declaration.
The evidence is what sits behind it.
Directive 11 requires specified accountable institutions to submit a Risk and Compliance Return (RCR) to the Financial Intelligence Centre. The return asks institutions to answer questions about their money laundering, terrorist financing and proliferation financing risks, and the controls they have in place to manage those risks.
Training is one of those controls.
The return asks whether the institution provides ongoing training to employees to enable them to comply with the FIC Act and the institution’s Risk Management and Compliance Programme (RMCP). It also asks whether staff receive training on aspects of proliferation financing.
Directive 11 does not require institutions to upload a prescribed training report. But if an institution answers “yes” to training-related questions, it should be able to show what supports that answer.
It is easy to say: “Our employees receive FIC Act training.”
It is harder to show exactly what that means.
If training forms part of the institution’s control environment, it should not be treated as a vague activity that happened somewhere in the business. It should be visible, dated, capable of being checked, and clear enough for the institution to rely on when completing the return.
This is especially important where the reporting period stretches back over several years. The institution may need to know what happened during a specific period, not only what its current training plan says today.
One of the common weaknesses in training evidence is the gap between access and completion.
Many institutions run awareness webinars during the year, and staff may well join them. But a general statement that “staff attend awareness webinars” is not the same as a clear training record.
For the record to be useful, the institution should be able to show who attended, which employees were expected to attend, what was covered, when the training took place, and whether anyone relevant was missed.
Without that, a course or webinar may support the institution’s broader training effort, but it may not be strong enough on its own to support a training-related answer in the RCR.
On paper, the evidence requirement sounds simple: show who was trained, when they completed the training, and what the training covered.
In practice, those records are often harder to produce than expected.
The institution first needs to know who should have been included. That may mean checking staff lists, roles, departments, joiners, leavers, contractors, representatives or other groups who fall within the training population.
It then needs records that distinguish between people who were invited, people who attended part of a session, people who completed the training, and people who still need to be followed up.
If training happened through informal webinars, shared recordings, calendar invitations or ad hoc internal sessions, that evidence may be scattered or incomplete.
The reporting period also matters. A current training plan may show what the institution intends to do now, but the RCR may require the institution to support what happened during an earlier period.
This is why training evidence should not be treated as something to tidy up at the end of the process. The report is only useful if the training rollout was set up to produce reliable records in the first place.
Many organisations will look at the RCR process and realise that their training evidence is not as clean as it should be.
That is a fixable problem.
Compliance Online helps clients run FIC Act and related compliance training in a way that produces clearer records from the start.
Our training reports help show who was assigned the training, who completed it, when they completed it, what remains outstanding, and what course coverage sits behind the record.
Compliance training does not have to be complicated, but it does need to be done in a way that leaves the business with records it can use.
Related posts