Knowledge Base
Mitigate fraud risks, including cybercrime
Which client due diligence procedure is required by Articles L.561-1 et seq. of the Code monétaire et financier to mitigate external fraud risk?
The required client due diligence procedure is KYC (Know Your Customer), which constitutes the first line of defense against external fraud. Enhanced due diligence also applies to atypical transactions in accordance with Article R.561-10.
What measure is mandatory upon detection of a significant anomaly according to due diligence procedures?
Filing a suspicious transaction report with TRACFIN is mandatory as soon as a significant anomaly is detected. This is part of enhanced due diligence measures to combat fraud.
What is the main purpose of regularly checking the AMF and ACPR blacklists?
Regularly checking the blacklists helps identify unauthorized entities, which is crucial for avoiding interactions with fraudulent counterparties. These lists have included nearly 5,000 unauthorized entities since 2022.
The DORA Regulation imposes a harmonized framework for ICT risk management, including regular penetration testing.
The DORA (Digital Operational Resilience Act) Regulation does indeed impose a harmonized framework that includes a regular program of operational resilience testing, including penetration testing. This regulation has been applicable since January 17, 2025.
The AMF SPOT Cybersecurity reports identify inadequate management of IT service providers as a best practice.
The AMF SPOT Cybersecurity reports identify inadequate management of IT service providers as a frequently sanctioned deficiency, not a best practice. Best practices include appointing a cybersecurity officer and formalizing a documented strategy.
DICT criteria for sensitive data:
Click to see answer
The DICT criteria are Availability, Integrity, Confidentiality, and Traceability. These criteria are applied to ensure the security of sensitive data within internal control frameworks.
Categorize items by dragging them to the appropriate zones
Items to categorize:
Cybersecurity best practices
Frequently sanctioned deficiencies
Cybersecurity best practices include appointing a dedicated officer, formalizing a strategy, and raising staff awareness. Deficiencies often involve gaps in these areas.
According to AMF Guide DOC-2014-06, what constitutes the first level of control for mitigating fraud risk?
The first level of control is performed by operational staff themselves and their direct management. It includes dual validation of significant transactions, implementation of auditable and tamper-proof audit trails, and application of access restrictions to sensitive data based on DICT criteria (Availability, Integrity, Confidentiality, Traceability).