자금세탁방지 효율성 제고를 위한 고위험고객 관리방안 연구 = A Study on high-risk customer management for enhanced Anti-Money Laundering effectiveness
저자
발행사항
서울 : 동국대학교 국제정보보호대학원, 2024
학위논문사항
학위논문(석사) -- 동국대학교 국제정보보호대학원 , 사이버포렌식학과 금융정보조사전공 , 2024. 8
발행연도
2024
작성언어
한국어
주제어
DDC
005.8 판사항(22)
발행국(도시)
서울
형태사항
v, 88 p. : 삽도 ; 26 cm.
일반주기명
동국대학교 논문은 저작권법에 의해 보호받습니다
지도교수: 황석진
서지적 각주와 참고문헌(p. 83-85) 수록
UCI식별코드
I804:11020-000000089070
DOI식별코드
소장기관
본 논문은 금융회사 등이 자금세탁방지(AML) 및 테러자금조달 위험을 예방하고 관리하는 과정에서 고위험 고객의 위험관리 효과성 제고를 위하여 제도적 측면과 운영적 차원에서의 보완 사항을 검토한 것이다.
제도적 측면에서는 특정금융거래정보법, 개인정보보호법, 금융실명법 등이 정보공유를 제한하는 부분에 대한 해석을 법 제도의 입법취지를 훼손하지 않는 범위 내에서 확대하여 고위험 고객과 관련된 최소한의 정보를 자금세탁방지 목적에서 공유할 수 있도록 허용하는 방안이 필요하다. 이를 통해 동일한 자금세탁방지 통제프레임 내에 있는 금융회사들이 일관된 기준으로 리스크 관리를 할 수 있도록 지원하며, 자금세탁 리스크가 높아 고객 수용이 어려운 경우 거래거절 요건을 법제화하여 금융회사들이 체계적으로 위험고객 관리를 할 수 있도록 한다.
고객확인업무(CDD) 과정에서 실소유자 파악의 어려움과 각 금융회사별 절차의 상이함에 따른 악용을 방지하고자 FinCEN의 BOI 등록 및 활용 사례를 참조하여 개선 방안을 모색하였고, 관련한 법제도적 정비가 의심거래보고서의 품질향상 및 금융회사등의 자금세탁방지 업무 인력의 효과성에도 기여할 수 있음을 검토하였다.
또한, 현재 명시적 요구사항이 없는 AML 전제범죄 영역의 언론보도 확인을 CDD 기본요건으로 포함시켜 자금세탁 관련 범죄 연관인들을 점검하고 필요한 경감 조치를 할 수 있도록 제안하였다.
운영적 측면에서는 규제당국과 법집행기관 간 정보 공유 시 누설 금지를 포함한 법제 위반 위험이 경감되는 시기에 해당 데이터를 규제당국 차원에서 관리하여 금융회사들이 자금세탁방지 업무의 제한적인 목적으로 활용하도록 하여 국가적 차원의 자금세탁 리스크를 경감하는 방법을 제안하였다.
끝으로 금융회사들이 변화하는 금융환경과 규제요건에 신속히 대응하기 위해 각 업권별 자율규제기구를 활용하여 위험고객 관리기준을 마련하고 규제당국의 검토를 받는 방식으로 객관성을 담보하며 자체적으로 내부통제 기준을 강화할 필요성을 제기하였다.
각 업권의 자율규제기구 중심의 선제적 조치들을 제도적 관리와 병행하면 이를 통해 국가 전체의 자금세탁방지 업무의 효율성과 효과성을 제고할 수 있을 것이다.
다만, 고위험고객 정보공유 및 규제당국 차원의 관리방안 등은 개인정보보호법을 포함한 타 법제와의 충돌 가능성 및 국민적 합의가 필요한 영역이므로 이후 추가적인 연구를 통해 개선방안을 연구할 것이다.
This paper focuses on the institutional and operational proceduresthat need to be improved in order to enhance the effectiveness of riskmanagement of high-risk customers in the process of preventing andmanaging anti-money laundering and terrorist financing risks. The areas in need of institutional overhaul reviewed in this paperinclude expanding the interpretation of the restrictions on informationsharing in the Specified Financial Transaction Information Act, thePersonal Information Protection Act, and the Financial Disclosure Act tothe extent that it does not undermine the legislative intent of the legalsystem, allowing the sharing of minimal information related to high-riskcustomers for anti-money laundering purposes, so that financialcompanies (including affiliates and subsidiaries) in the same anti-moneylaundering control framework can conduct risk management on aconsistent basis, Legislative support is needed to enable financialinstitutions to systematically manage risky customers by includingrequirements for refusal of transactions where there is a high risk ofmoney laundering and difficulty in accepting the customer. If the regulatory authorities have shared information with law enforcement agencies, consideration should be given to managing it atthe regulatory level at a time when the risk of violating the law,including prohibitions on disclosure, is reduced so that financialinstitutions can use it in their anti-money laundering efforts. Referringto the case of overseas countries that have designated high-risk targetsas sanctioned persons at the national level (Country list), such anapproach may be helpful in mitigating the risk of money laundering atthe national level. The identification of beneficial owners in the process of customerverification of financial companies requires additional efforts due to thelimited use of reliable information collected under other legal systems,and it is difficult to ensure the reliability of shareholder lists collectedfrom customers, etc. Since the beneficial ownership information obtained during thecustomer verification process of financial companies is also used as thebasis for suspicious transaction reporting, if the legal framework isimproved as above, it will lead to a positive effect on the accuracy ofthe report contents of financial companies from the perspective ofregulators using suspicious transaction reporting. In this regard, if the legal requirements for customer verificationinclude a basic requirement to check media reports in the AMLpredicate offence area, which is currently not explicitly required, it willbe possible to basically check and take necessary mitigation measuresfor those involved in money laundering-related crimes that have notbeen the subject of attention because they do not use financialinstitutions or their transactions are insignificant and therefore notextracted from suspicious transaction monitoring scenarios. If financial firms and other front-line companies can accuratelyidentify customers and related persons, take necessary mitigationmeasures and faithfully report suspicious transactions, they will be able to maximise the complementarity of AML work with regulators. In order to quickly respond to the changing financial environmentand regulatory requirements, financial companies need to strengthentheir own internal control standards, such as establishing detailedstandards for managing risky customers using self-regulatoryorganisations in each industry and ensuring objectivity by having themreviewed by regulators. As regulation cannot precede the status quo, and the legal systemhas many considerations such as interconnectedness with other lawsand public consensus, and the timing is limited to accommodate andmanage all changes in the financial environment, each industryself-regulatory organisation should take responsible and proactivemeasures to protect its business and manage regulatory risks. Based onthis, it is believed that if each industry sector establishes and managesstandards consistently, the ballooning effect of national anti-moneylaundering efforts will be prevented. However, in the process of studying the regulatory requirements andways to improve the operation of each business sector, we will furtherstudy the areas where there is a conflict with other laws, such as therequirements of the Fair Trade Act, including the Personal InformationProtection Act, the regulatory requirements of the Korea Fair TradeCommission, which regulates the abuse of dominant market positions,the requirements of laws related to financial consumer protection, andthe restrictions of the Terms and Conditions Regulation Act, and theareas where there is a possibility of conflict with the legislative intentof these laws, and areas where public consensus should be reached.
더보기서지정보 내보내기(Export)
닫기소장기관 정보
닫기권호소장정보
닫기오류접수
닫기오류 접수 확인
닫기음성서비스 신청
닫기음성서비스 신청 확인
닫기이용약관
닫기학술연구정보서비스 이용약관 (2017년 1월 1일 ~ 현재 적용)
| 주요 개정내역 | 변경 사유 |
|---|---|
| · 개인정보 처리 목적, 항목 및 법적 근거 수정 · 본인대상정보전송요구권 행사 방법 안내 · 개인정보 보호수준 평가 결과 추가 |
|
한국교육학술정보원은 정보주체의 자유와 권리 보호를 위해 「개인정보 보호법」 및 관계 법령이 정한 바를 준수하여, 적법하게 개인정보를 처리하고 안전하게 관리하고 있습니다. 이에 「개인정보 보호법」 제30조에 따라 정보주체에게 개인정보 처리에 관한 절차 및 기준을 안내하고, 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 하기 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다.
목 차
제1조(개인정보의 처리 목적)
제2조(개인정보의 처리 및 보유 기간)
제3조(처리하는 개인정보의 항목)
제4조(개인정보파일 등록 현황)
제5조(개인정보의 제3자 제공)
제6조(개인정보 처리업무의 위탁)
제7조(개인정보의 파기 절차 및 방법)
제8조(정보주체와 법정대리인의 권리·의무 및 그 행사 방법)
제9조(개인정보의 안전성 확보조치)
제10조(개인정보 자동 수집 장치의 설치·운영 및 거부)
제11조(개인정보 보호책임자)
제12조(개인정보의 열람청구를 접수·처리하는 부서)
제13조(정보주체의 권익침해에 대한 구제방법)
제14조(추가적 이용·제공 판단기준)
제15조(개인정보 보호수준 평가 결과)
제16조(개인정보 처리방침의 변경)
제1조(개인정보의 처리 목적)
제2조(개인정보의 처리 및 보유 기간)
5년
(「전자상거래 등에서의 소비자보호에 관한3년
(「전자상거래 등에서의 소비자보호에 관한
제3조(처리하는 개인정보의 항목)
제4조(개인정보파일 등록 현황)
개인정보파일 검색(privacy.go.kr)| 개인정보파일의 명칭 | 수집·이용 근거 | 수집·이용 목적 | 수집·이용 항목 | 보유·이용기간 |
|---|---|---|---|---|
| [학술연구정보 서비스 이용자 가입정보] |
「개인정보 보호법」 제15조 제1항 제4호(계약 이행) |
회원 서비스 운영 |
ID, 비밀번호, 이름, 생년월일, 신분(직업구분), 이메일, 소속분야, 보호자 성명(어린이회원), 보호자 이메일(어린이회원) |
회원탈퇴시 까지 |
| 「전자상거래 등에서의 소비자보호에 관한 법률」 제6조 및 같은 법 시행령 제6조 |
주문 및 결제 처리 |
ID, 비밀번호, 이름, 주소 |
5년 |
제5조(개인정보의 제3자 제공)
제6조(개인정보 처리업무의 위탁)
제7조(개인정보의 파기 절차 및 방법)
제8조(정보주체와 법정대리인의 권리·의무 및 그 행사 방법)
제9조(개인정보의 안전성 확보조치)
제10조(개인정보 자동 수집 장치의 설치·운영 및 거부)
제11조(개인정보 보호책임자)
| 구분 | 담당자 | 연락처 |
|---|---|---|
| KERIS 개인정보 보호책임자 | 정보보호본부 안재호 |
- 이메일 : jinuk@keris.or.kr - 전화번호 : 053-714-0158 - 팩스번호 : 053-714-0195 |
| KERIS 개인정보 보호담당자 | 개인정보보호부 송진욱 | |
| RISS 개인정보 보호책임자 | 교육학술데이터본부 정광훈 |
- 이메일 : giltizen@keris.or.kr - 전화번호 : 053-714-0149 - 팩스번호 : 053-714-0194 |
| RISS 개인정보 보호담당자 | 학술진흥부 길원진 |
제12조(개인정보의 열람청구를 접수·처리하는 부서)
제13조(정보주체의 권익침해에 대한 구제방법)
제14조(추가적인 이용ㆍ제공 판단기준)
제15조(개인정보 보호수준 평가 결과)
제16조(개인정보 처리방침의 변경)
자동로그아웃 안내
닫기인증오류 안내
닫기귀하께서는 휴면계정 전환 후 1년동안 회원정보 수집 및 이용에 대한
재동의를 하지 않으신 관계로 개인정보가 삭제되었습니다.
(참조 : RISS 이용약관 및 개인정보처리방침)
신규회원으로 가입하여 이용 부탁 드리며, 추가 문의는 고객센터로 연락 바랍니다.
- 기존 아이디 재사용 불가
휴면계정 안내
RISS는 [표준개인정보 보호지침]에 따라 2년을 주기로 개인정보 수집·이용에 관하여 (재)동의를 받고 있으며, (재)동의를 하지 않을 경우, 휴면계정으로 전환됩니다.
(※ 휴면계정은 원문이용 및 복사/대출 서비스를 이용할 수 없습니다.)
휴면계정으로 전환된 후 1년간 회원정보 수집·이용에 대한 재동의를 하지 않을 경우, RISS에서 자동탈퇴 및 개인정보가 삭제처리 됩니다.
고객센터 1599-3122
ARS번호+1번(회원가입 및 정보수정)