• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Impact Professional Services

Impact Professional Services

Pragmatic compliance and risk solutions.

  • Home
  • Services
    • Financial Services
    • E-Gaming Services
    • Compliance and Risk Training
  • Resources
    • Useful Articles
    • In Conversation With…
  • About Us
  • Contact Us
  • IOM Compliance Newsletter

Summary of the IOM Financial Services Authority Business Risk Assessment Thematic Review Phase One

31 July 2023 by Impact Professional Services

Phase one of the Isle of Man Financial Services Authority’s Thematic Review was the issuing of a Business Risk Assessment (BRA) questionnaire to a selection of regulated Trust & Corporate Services Providers for completion.   

The Authority published a report in July 2023 which outlines the results from this first phase, as well as the Authority’s observations on the data and some subsequently identified best practice points.  

Phase two of the Thematic Review is currently underway, with the Authority conducting desk-based inspections. 

Below is a summary of the first phase. 

  • A BRA should clearly set out the risks a business faces in relation to customers and their activities and explains the basis of the assessment. Highlight how much, and what level of risk the business is prepared to take.  Additionally, what risk the firm is not prepared to take. 
  • There should be a documented Risk Appetite Statement or associated Policy. 
  • There should be a documented Anti-Money Laundering / Countering the Financing of Terrorism Policy in place. 
  • The BRA should by informed by other risk assessments required by the Anti-Money Laundering and Countering the Financing of Terrorism Code 2019 (the Code) as well as the Isle of Man National Risk Assessment. 
  • Detail the composition of the customer base and where the risks are. For example, how many high & standard risk clients, Politically Exposed Persons split by domestic & foreign and high & standard risk ratings. 
  • Incorporate the link to Customer Risk Assessments as a key source of information.   
  • There should be evidence of a BRA’s review and approval, for example extracts of Board minutes. 
  • The BRA should be communicated to the entire business. 
  • The BRA should have clearly documented reviews and approvals, using a version control. 
  • There should be a process in place to ensure the timely supply of information or documentation requested by the Authority. 
  • There should be a documented Risk Assessment Methodology / Risk Scoring Matrix in place:
    Assessment of the inherent risks relevant to the business
    Identify mitigating factors and controls to manage the impact of the risks
    Assessment of the risk impact
    Assessment of the effectiveness of the controls in place
    Assessment of whether the residual risk is within the documented risk appetite
    Assessment of likelihood / probability of the risksAssessment of the cumulative risks.
  • Consider the use of different information sources for a BRA.
  • If the business is part of a Group, the BRA should consider the specific risks relevant to the Isle of Man licenceholder.
  • The Code, paragraph 5(3) should be clearly documented in the BRA: 

5 Business risk assessment 

3) The business risk assessment must have regard to all relevant risk factors, including —  

(a) the nature, scale and complexity of the relevant person’s activities;  

(b) any relevant findings of the most recent National Risk Assessment relating to the Island;  

(c) the products and services provided by the relevant person;  

(d) the manner in which the products and services are provided, including whether the relevant person meets its customers;  

(e) the involvement of any third parties for elements of the customer due diligence process, including where reliance is placed on a third party;  

(f) customer risk assessments carried out under paragraph 6; and 

(g) any technology risk assessment carried out under paragraph 7. 

  • Any areas for development highlighted in the BRA should be reported to the Board / senior management. 
  • Identify whether there any barriers in place to prevent the operation of effective systems & controls. 
  • Record keeping requirements – keep previous versions for a minimum of 5 years. 
  • Document whether the BRA would be reviewed and updated at a trigger event. 

We’re currently supporting our clients in respect of IOMFSA findings and feedback on their Business Risk Assessments. 
 
If you’re looking for guidance, support or reassurance around your Business Risk Assessment please do contact us today through [email protected], on 01624 820601, or to save time, book directly into our calendar here.  

Filed Under: Useful Articles

Primary Sidebar

Blog Categories

  • Useful Articles (37)

Latest Blog Posts

Fatca & crs classification what isle of man tcsps need to know

FATCA & CRS Classification: What Isle of Man TCSPs Need to Know

2025 Manx State Of The Nation Highlights And Takeaways

2025 Manx State of the Nation: Highlights & Takeaways

Your Guide To Compliance Planning In 2025 Featured Image

Your Guide to Compliance Planning in 2025

Blog Archives

Footer

Impact hlogo v2

Connect on LinkedIn   Connect on Facebook

Copyright © 2025 · All Rights Reserved. Privacy Policy

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies. Read More
Cookie SettingsAccept
Manage cookie consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT