FINANCIAL MARKETS AUTHORITY v CLSA PREMIUM NZ LTD [2021] NZHC 2325
Court concluded KVB committed four civil liability acts (failure to conduct/enhanced CDD, failure to terminate when CDD could not be completed, failure to report suspicious activity on nine occasions including very late or missing reports, and failure to keep full records due in part to third-party retention)....
Source-derived case information.
- Citation
- [2021]NZCCLR 16
- Parties
- Plaintiff: Financial Markets Authority; Defendant: CLSA Premium New Zealand Ltd (formerly KVB Kunlun New Zealand Ltd)
- Court
- High Court
- Jurisdiction
- New Zealand
- Judgment Date
- 6 September 2021
- Procedural Posture
- Civil Enforcement for Breaches of the Anti Money Laundering and Countering Financing of Terrorism Act 2009 / Penalty Hearing and Judgment (penalty Determination)
- Outcome
- Judgment entered against defendant for four civil liability acts; pecuniary penalty of NZD 770000 imposed; costs awarded to plaintiff on scale 2B
- Legal Topics
- Customer Due Diligence, Suspicious Activity Reporting, Record Keeping, Termination of Business Relationships, Pecuniary Penalty Assessment
Source-derived case record
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
Financial Markets Authority
Plaintiff
CLSA Premium New Zealand Ltd (formerly KVB Kunlun New Zealand Ltd)
Defendant
Procedural Posture
Civil Enforcement for Breaches of the Anti Money Laundering and Countering Financing of Terrorism Act 2009 / Penalty Hearing and Judgment (penalty Determination)
Legal Issues
- 1 Whether KVB failed to comply with CDD obligations
- 2 Whether KVB failed to terminate relationships when CDD could not be completed
- 3 Whether KVB failed to report suspicious transactions in time or at all
Ratio Decidendi
Court concluded KVB committed four civil liability acts (failure to conduct/enhanced CDD, failure to terminate when CDD could not be completed, failure to report suspicious activity on nine occasions including very late or missing reports, and failure to keep full records due in part to third-party retention). Starting points adopted were CDD $400,000, termination $50,000, reporting $200,000, records $350,000 (global starting point $1,000,000). A 23% discount was applied for admissions and cooperation. No discount for prior good character was available given prior FMA warning and ineffective remediation. Overlap between CDD and termination was recognised but a distinct penalty for...
Court Disposition
Judgment entered against defendant for four civil liability acts; pecuniary penalty of NZD 770000 imposed; costs awarded to plaintiff on scale 2B
Orders
- Pecuniary penalty of NZD 770000 imposed on CLSA Premium New Zealand Ltd payable to the Financial Markets Authority
- Judgment entered against defendant for the four civil liability acts alleged under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009
Full Case Text
Judgment text and source record
1 paragraphs
FINANCIAL MARKETS AUTHORITY v CLSA PREMIUM NZ LTD [2021] NZHC 2325 [6 September 2021]IN THE HIGH COURT OF NEW ZEALANDAUCKLAND REGISTRYI TE KŌTI MATUA O AOTEAROATĀMAKI MAKAURAU ROHECIV-2020-404-000920[2021] NZHC 2325UNDER the Anti-Money Laundering and CounteringFinancing of Terrorism Act 2009BETWEEN FINANCIAL MARKETS AUTHORITYPlaintiffAND CLSA PREMIUM NEW ZEALANDLIMITEDDefendantHearing: 5 July 2021Appearances: S S McMullan and L N Wilson for PlaintiffJ S Cooper QC, I Rosic and S T Coupe for DefendantJudgment: 6 September 2021JUDGMENT OF EDWARDS JThis judgment was delivered by me on 2021 at am / pmpursuant to r 11.5 of the High Court Rules.Registrar/Deputy RegistrarSolicitors/Counsel:Meredith Connell (Office of the Crown Solicitor), AucklandGilbert Walker, AucklandJ S Cooper QC, Auckland[1] CLSA Premium New Zealand Ltd is a licenced derivatives issuer. Prior to5 December 2019, it was known as KVB Kunlun New Zealand Ltd (KVB) and isreferred to as such in this judgment.[2] KVB is a reporting entity under the Anti-Money Laundering and CounteringFinancing of Terrorism Act 2009 (Act).1 The Financial Markets Authority (FMA) isthe supervisor responsible for enforcing compliance with the Act.2[3] KVB has admitted non-compliance with the Act and consents to judgmentbeing entered against it. This judgment is concerned with the penalty that should beimposed for that non-compliance.[4] The admitted non-compliance relates to four civil liability acts3 committedbetween April 2015 and November 2018. Those four civil liability acts are:(a) failure to conduct customer due diligence (CDD);(b) failure to terminate existing business relationships when CDD couldnot be completed;(c) failure to report suspicious transactions/activity; and(d) failure to keep records.[5] The FMA seeks a global penalty of $1.2m for all four breaches. KVB says apenalty of $420,000 is appropriate. The key differences between them relate to anassessment of the gravity of the breaches and the extent of overlap between each ofthe civil liability acts.1 Anti-Money Laundering and Countering Financing of Terrorism Act 2009, s 5 definition of"reporting entity".2 Section 130(1)(b).3 Section 78 defines "civil liability act".Agreed facts[6] The factual basis for the civil liability acts is set out in a comprehensive agreedstatement of facts dated 18 February 2021. What follows is a summary of the facts setout in that agreed statement.[7] KVB provides derivatives trading services by enabling customers to undertaketrades on retail trading platforms. KVB opens an account for a customer, who willdeposit funds with KVB. Those funds are then made available for trading throughKVB's online platform.[8] At the relevant times, the executive directors of KVB were Ms Zhang,Mr Huang, and Mr Liu. The non-executive independent directors were Mr Noakesand Mr Pearson. None of the directors are associated with KVB any longer.[9] During the relevant period (2015 to 2018), KVB had a business relationshipwith between 21,000 and 37,000 customers each year. It undertook between 63,000and 83,000 transactions annually, with a gross value of between NZD 228m andNZD 652m. Approximately 95 per cent of KVB's customers were resident in, or hada connection with, China during this period. The remaining five per cent werepredominantly Australian and New Zealand residents.[10] As required by the Act, KVB had a risk assessment and an anti-moneylaundering and countering the financing of terrorism (AML/CFT) complianceprogramme. KVB completed its compliance programme on 1 May 2013.PricewaterhouseCoopers (PwC) subsequently reviewed the programme later thatmonth and KVB amended the programme on 31 January 2014 to incorporate PwC'srecommendations.[11] Later that year, on 20 June 2014, the FMA issued a formal warning to KVB,stating it had reasonable grounds to believe that KVB had engaged in conductconstituting a civil liability act under the Act.4 That warning related, amongst otherthings, to KVB's compliance officer not being a KVB employee and the failure to4 The warning was issued under s 80.implement amendments to the risk assessment aspect of KVB's complianceprogramme. The FMA required KVB to undertake a special audit of its riskassessment and AML/CFT programme.5[12] KVB responded by engaging Grant Thornton to undertake a special audit.Grant Thornton's report was issued in August 2014. Amendments were made toKVB's compliance programme as a result. In late 2014, KVB represented to the FMAthat it would demonstrate a strong risk and compliance culture.[13] Further reviews of KVB's compliance programme by KVB, andGrant Thornton, took place in 2015. No amendments were required. Updates to thecompliance programme were made in 2016. The Board appointed a Risk, Audit andCompliance Committee (RACC) which was responsible for overseeing KVB'scompliance and internal control functions. That committee comprised the independentdirectors and one of the executive directors.[14] Although the RACC had primary oversight over compliance matters, theparties agree that the executive directors nevertheless involved themselves incompliance related issues. The extent of that involvement saw two compliancemanagers employed by KVB leave their positions following disagreements betweenthem and the directors of KVB regarding the extent of KVB's compliance with itsobligations under the Act. One of those employees was asked to resign by a directorwho told him KVB needed someone "bendier" as their head of compliance.6[15] The FMA conducted an onsite inspection of KVB on 26 and 27 March 2018.The purpose of the inspection was to review compliance with the Act. On 1 May 2018,the FMA sent KVB a letter setting out its findings from the inspection. That letteridentified, among other things, inadequacies in KVB's transaction monitoringpractices, and an under-resourced and inexperienced compliance team. The letter also5 Required under s 59(2).6 The director to whom this statement is attributed disputes that he made the statement and hassought to file an affidavit in this proceeding. For the purposes of the penalty hearing, the identityof the director making the statement is irrelevant. It only matters that a director did make thestatement as alleged, and as recorded, in the agreed statement of facts. I have not had regard tothe content of the affidavit in fixing the pecuniary penalty.highlighted a lack of transparency and clarity in KVB's CDD methodology, and poorrecord-keeping systems.[16] A notice under s 132 of the Act was sent at the same time. That notice requiredKVB to produce certain records and documents. Two further notices were issuedunder s 25 of the Financial Markets Authority Act 2011 in May and July 2019, with afinal s 25 notice issued on 19 November 2019.[17] Some of the documents sought were provided by KVB. However, it wasunable to respond in full because it could not get access to its records and customerinformation which were held by a third party. That third party refused to provideaccess to the documents. KVB's parent company commenced litigation against thethird party in Hong Kong and was successful in obtaining an order preventing thedestruction of its records. Substantive proceedings were filed soon after and were notresolved as at the date of the hearing in this Court.[18] The FMA issued legal proceedings on 23 June 2020. The four civil liabilityacts relate to transactions undertaken by 10 different customers, totallingapproximately NZD 49.5m. Of this amount, approximately NZD 40.8m relates todeposits made by two customers.[19] KVB accepts that it has not complied with its obligations under the Act and ithas cooperated with the FMA to seek to resolve the proceeding.Statutory framework[20] The Act was passed in 2009 but did not come into force until 2013. Section 3sets out the following purposes of the Act:(a) to detect and deter money laundering and the financing of terrorism;and(b) to maintain and enhance New Zealand's international reputation byadopting, where appropriate in the New Zealand context,recommendations issued by the Financial Action Task Force; and(c) to contribute to public confidence in the financial system.[21] The Act imposes obligations on reporting entities. These were summarised byToogood J in Department of Internal Affairs v Ping An Finance (Group) New ZealandCompany Ltd (Ping An) as follows:7(a) Subpart 1 addresses customer due diligence obligations which mustbe observed before a reporting entity can carry out a transaction forthat customer, prescribing a hierarchy of standards (simplified,standard and enhanced) depending on the nature and circumstances ofthe customer.(b) Subpart 2 places a statutory duty on a reporting entity to convey to theCommissioner of Police information that comes to its attention inrespect of which it has reasonable grounds to suspect it may berelevant to the investigation or prosecution of money laundering, orthe enforcement of the Misuse of Drugs Act 1975, the TerrorismSuppression Act 2002, the Proceeds of Crime Act 1991, or theCriminal Proceeds (Recovery) Act 2009.(c) Subpart 3 specifies that reporting entities must keep records relatingto every transaction, with strict requirements of details to allow theready reconstruction of transactions and the identification andverification of the persons involved.(d) Subpart 4 provides that every reporting entity must have a complianceprogramme and a compliance officer and sets minimum standards forsuch programmes.[22] The specific obligations in relation to each of the four civil liability acts at issuein this case are considered further on in this judgment.[23] Non-compliance with the Act's requirements constitutes a "civil liability act",as defined in s 78. Section 79 sets out the possible responses to a civil liability act.The imposition of a pecuniary penalty is the most serious of these responses.Approach to fixing a penalty[24] Section 90 sets out the maximum pecuniary penalty for each of the civilliability acts. The maximum penalties relevant in this case are:(a) failure to conduct CDD: $2m;7 Department of Internal Affairs v Ping An Finance (Group) New Zealand Company Ltd [2017]NZHC 2363, [2018] 2 NZLR 552 [Ping An] at [21].(b) failure to terminate existing business relationships when CDD couldnot be completed: $1m; and(c) failure to keep records: $2m.[25] There is no statutory maximum for failure to report suspicious transactions/activity. In Ping An, Toogood J adopted a notional ceiling of $2m.8 It was set as a"practical guideline" but not as a court-legislated maximum.9 I adopt that approach.[26] Section 90(4) provides that in determining the appropriate pecuniary penalty,the court must have regard to all relevant matters, including:(a) the nature and extent of the civil liability act; and(b) the likelihood, nature, and extent of any damage to the integrity orreputation of New Zealand's financial system because of the civilliability act; and(c) the circumstances in which the civil liability act occurred; and(d) whether the person has previously been found by the court inproceedings under this Act to have engaged in any similar conduct.[27] The approach to determining the quantum of a pecuniary penalty under the Actwas set out in Ping An.10 It has been adopted in the four subsequent cases.11 Thosesteps are:(a) Starting point. Assess the seriousness of the civil liability acts in orderto set a starting point based on the seriousness of the non-compliance,and the aggravating and mitigating factors relating to it.(b) Aggravating and mitigating factors. Consider aggravating andmitigating factors relating to the circumstances of the reporting entity,8 Ping An, above n 7, at [86].9 At [86].10 At [88].11 Department of Internal Affairs v Qian Duoduo Ltd [2018] NZHC 1887 [QDD]; Department ofInternal Affairs v Jin Yuan Finance Ltd [2019] NZHC 2510 [Jin Yuan]; Department of InternalAffairs v OTT Trading Group Ltd [2020] NZHC 1663 [OTT]; and Reserve Bank of New Zealandv TSB Bank Ltd [2021] NZHC 2241 [RBNZ v TSB].to determine whether these warrant imposition of a higher or lowerpenalty.(c) Admissions and cooperation. Deduct from the starting point anyadmission of liability or cooperation with the authorities.(d) Totality. Step back from the penalty and undertake a totality assessmentby looking at the number of separate breaches to ensure there is nooverlap between the penalties imposed for different types of non-compliance, and consider whether the total penalty imposed fairly andadequately reflects the overall extent of non-compliance.[28] Other factors that may be relevant to the overall assessment include the extentto which the conduct was initiated or condoned by officers or senior management ofthe reporting entity, and whether steps were taken to ensure compliance with the Act,including policies and education of officers and employees.12[29] Deterrence and denunciation are important principles in fixing a pecuniaryprinciple. Toogood J in Ping An described deterrence as the "overriding objective".13[30] At the time of the hearing, there had been four decisions imposing pecuniarypenalties under the Act.14 Muir J had regard to the penalties set in each of the fourdecisions in Financial Markets Authority v ANZ Bank New Zealand Ltd (FMA vANZ).15 Although that case involved a different statutory regime, the parties are agreedthat the Judge's summary of the penalty orders made is nevertheless relevant to thiscase. The Judge characterised the various penalties as falling along the followingscale:16(a) between 50 and 70 per cent of the available maximum for conductinvolving:12 Ping An, above n 7, at [102]; and QDD, above n 11, at [27]–[28].13 Ping An, above n 7, at [92].14 Ping An, above n 7; QDD, above n 11; Jin Yuan, above n 11; and OTT, above n 11. .15 Financial Markets Authority v ANZ Bank New Zealand Ltd [2021] NZHC 399.16 At [80] (footnotes omitted).(i) "serious, systemic deficiencies in complying with amultiplicity of obligations under the Act" in circumstancesshowing a disregard of the Act's requirements.(ii) long-term noncompliance with the Act, despite prioroversight and warnings from the Department of InternalAffairs and despite the company having had ample evidencethat the transactions' processed were suspicious.(ii) "brazen" contraventions of the enhanced due diligencerequirements occurring across a significant volume oftransactions.(b) between 25 and 33 per cent of the available maximum for conductinvolving significant contraventions, but in circumstances whichsuggested that a defendant had made at least some attempt to complywith their obligations; and(c) between 6 and 11 per cent of the available maximum for conductinvolving inadvertent breaches by a company which was unaware thatit was substantially noncompliant.[31] The judgment in Reserve Bank of New Zealand v TSB Bank Ltd (RBNZ v TSB)was delivered after the hearing and the parties did not have an opportunity to makesubmissions on it.17 A penalty of $3.5m was imposed in that case. The non-compliance arose under the Act but was different in kind to the civil liability acts inthis case. The analysis regarding the quantum of discount for admissions andcooperation is of relevance, however, and is considered further at [86]–[88] of thisjudgment.Starting point[32] The FMA submits that the global starting point should be $1.5m, or 21 per centof the available maximum of $7m, calculated as follows:(a) failure to conduct CDD: $600,000;(b) failure to terminate existing business relationships when CDD couldnot be completed: $100,000;(c) failure to report suspicious transactions/activity: $250,000; and17 RBNZ v TSB, above n 11.(d) failure to keep records: $550,000[33] The FMA submits that this global starting point is consistent with the secondcategory in FMA v ANZ which relates to conduct involving "significantcontraventions, but at least some attempt to comply with obligations."[34] KVB says that the overall starting point proposed by the FMA is too high. Itsays the breaches fall within, or slightly above, the third category of FMA v ANZ andthe starting point should be no higher than $600,000, calculated as follows:(a) failure to conduct CDD: $250,000;(b) failure to terminate existing business relationships when CDD couldnot be completed: no separate penalty to be imposed as this civilliability act overlaps with the first;(c) failure to report suspicious transactions/activity: $150,000; and(d) failure to keep records: $200,000.Failure to conduct customer due diligence[35] A reporting entity is required to conduct CDD in the followingcircumstances:18(a) if the reporting entity establishes a business relationship with a newcustomer:(b) if a customer seeks to conduct an occasional transaction or activitythrough the reporting entity:(c) if, in relation to an existing customer, and according to the level ofrisk involved,—(i) there has been a material change in the nature or purpose ofthe business relationship; and(ii) the reporting entity considers that it has insufficientinformation about the customer:18 Anti-Money Laundering and Countering Financing of Terrorism Act, s 14.(d) any other circumstances specified in subsection (2) or in regulations.[36] Standard CDD requires a reporting entity to obtain verified informationrelating to the customer's identity, the nature and purpose of the proposed businessrelationship, and sufficient information to determine whether the customer should besubject to enhanced CDD.19[37] Enhanced CDD is required in a variety of circumstances. Relevantly, it isrequired whenever a customer seeks to conduct a transaction through the reportingentity which is complex, or unusually large, or is part of an unusual pattern oftransactions that have no apparent or visible economic or lawful purpose.20 It is alsorequired whenever a suspicious activity report must be filed.21 In addition to standardCDD, enhanced CDD requires verified information relating to the source of thecustomer's funds or wealth.22 Enhanced CDD must be carried out before establishinga business relationship or conducting the occasional transaction or activity, except incertain circumstances which are not applicable to this case.23[38] KVB admits failing to obtain standard CDD in relation to one customer in thatit failed to obtain information regarding the nature and purpose of the proposedbusiness relationship with that customer. The parties agree that this is an isolatedbreach.[39] The more serious breaches relate to failures to undertake enhanced CDD inrelation to 12 transactions undertaken by the 10 identified customers. The 12transactions ranged in value from approximately NZD 277,000 to NZD 34.9m. Thetotal value of the 12 transactions was NZD 49.5m, with NZD 40.8m relating to twocustomers.[40] Standard CDD had been undertaken for these customers, and some requestswere made in relation to some of the transactions (for example, source informationwas sought from five of the 10 customers). However, the failure to obtain any19 Sections 15–17.20 Section 22(1)(c). Ping An, above n 7, at [34].21 Section 22A.22 Section 23(1)(a).23 Section 24(2) and (3).evidence of source of wealth or source of funds for some of the transactions, and theinadequate information obtained when it was sought, is particularly concerning.[41] The scale of the non-compliance is relevant to the gravity assessment. Thebreaches occurred in connection with 10 customers out of the 21,000 to 37,000customers that KVB had each year. The total value of the non-compliant transactions(NZD 49.5m) is a fraction of the company's annual transactions each year which hada gross value of up to NZD 652m per annum.[42] Mr McMullan submits that the non-compliance is likely to be more widespreadand the sample of customer files and transactions must be treated as representative ofKVB's overall compliance with the Act.[43] That raises an issue about the process by which the non-compliant transactionswere identified. The FMA identified half of the 10 customers as a result of informationit received from third parties. The other five customers were selected from KVB'sOctober 2016 and June 2017 Unusual Transaction Reports provided to the FMA. TheFMA did not have any reason to suspect there were compliance issues relating to thoseaccounts at the time they were selected.[44] Using samples to measure the extent of non-compliance is a valid investigativetechnique. I accept that it is unrealistic to expect the FMA to interrogate every fileheld by a reporting entity. However, the number of files selected, and the process bywhich they were identified, is not adequate to treat the 10 customer files asrepresentative of overall compliance. That does not mean, however, that it can beconcluded that KVB was compliant in relation to all but a small handful oftransactions. There is no evidence adduced by KVB to suggest that is the case.[45] If gravity were assessed solely on scale, then KVB's non-compliance would besignificantly less serious than the comparator cases. In Ping An, there was a failure toperform CDD in 1,569, out of 1,588, transactions worth $105.4m, and a failure toundertake enhanced CDD in 519 transactions. In Department of Internal Affairs vQian Duoduo Ltd (QDD), the failures to carry out enhanced CDD was in relation to796 transactions worth $120.7m. In Department of Internal Affairs v Jin Yuan FinanceLtd (Jin Yuan), the failures related to 55,097 transactions worth $278.5m. InDepartment of Internal Affairs v OTT Trading Group Ltd (OTT), despite $196m worthof transactions occurring during the relevant period, one of the reporting entities neverundertook enhanced CDD.[46] However, the number and value of the non-compliant transactions are not theonly factors to be taken into account in assessing the seriousness of the breach. Thewider circumstances in which the breach occurred are also relevant.[47] Those circumstances include the fact that KVB had an AML/CFT assessmentand compliance programme, AML/CFT policies, dedicated compliance officers andstaff, and a subcommittee overseeing compliance with the Act. That makes KVB'snon-compliance with CDD requirements less serious than if it had none of thesemeasures in place. However, the mitigating effect of those features is tempered by thefollowing:(a) KVB had previously received a formal warning in June 2014 from theFMA in relation to its AML/CFT programme. Despite improvementsbeing made, a further letter sent from the FMA on 1 May 2018identified various compliance issues including a lack of transparencyand clarity in KVB's due diligence methodology.(b) The effectiveness of the RACC was also diminished by theexecutive directors involving themselves in matters of compliance.This interference included:(i) A direction in June 2017 to suspend collecting information fromcustomers on the source of wealth and source of funds while adecision was taken on the threshold which would trigger therequirement for enhanced CDD. Significantly, the businesscontinued in the meantime.(ii) One of the directors interfering directly with the accountopening procedure for one of the customers by makingrepresentations as to the bona fides of the source of thecustomer's funds or wealth.(c) The resignation of two compliance managers over the relevant perioddue to disagreements between them and directors of KVB. Thestatement from one of the directors that a "bendier" compliance officerwas required is particularly concerning.(d) The correspondence chain for one customer indicates that, in the faceof customer refusal to provide the information sought, KVB waswilling to accept inadequate information, including objectivelysuspicious information, so to retain that customer's business.[48] Taken together these features suggest that KVB's due diligence non-compliance was not inadvertent; did not arise out of any misunderstanding as to itsobligations; or occur as a result of erroneous advice. If the extremely high value natureof two of the transactions (totalling NZD 40.8m) is added to the mix, then there is aclear inference that CDD requirements were subordinated to the continuation ofKVB's relationship with high worth customers.[49] This makes KVB's non-compliance more serious than in QDD, despite thelarger number and value of non-compliant transactions in that case. In QDD, Powell Jfound that the reporting entity had not intended to breach the Act, did not intend tomaximise profit over compliance, and was acting in reliance on AML/CFT advisorrecommendations at the time.24 I consider a starting point substantially higher thanthe $175,000 adopted in that case for a failure to undertake enhanced CDD iswarranted in this case.[50] However, KVB's non-compliance was not as serious as Ping An, Jin Yuan, orOTT. All those cases involved a greater volume of transactions, worth a higher value,and factors that indicated a complete disregard for compliance obligations. A startingpoint substantially less than the starting points adopted in those cases (between $1.3mand $1.4m) is warranted.24 QDD, above n 11, at [59], [65] and [134].[51] Due diligence is the cornerstone of the AML/CFT regime. As Lang J observedin OTT, it is only through due diligence that the AML/CFT regime is able to safeguardNew Zealand's reputation in financial communities.25 Taking into account the natureand circumstances of KVB's non-compliance, I adopt a starting point of $400,000.Failure to terminate existing business relationships when customer due diligencecould not be completed[52] Section 37 places a prohibition on establishing or continuing an existingbusiness relationship, or carrying out occasional transactions if adequate CDD cannotbe completed. The maximum penalty prescribed by the Act is $1m.[53] The FMA submits that a starting point of $100,000 should be adopted for thiscivil liability act. KVB says no penalty should be imposed as the conduct thatunderpins this civil liability act is the same conduct underpinning the failure to conductCDD.[54] In support of KVB's position, Ms Cooper QC submits that the requirements ins 37 flow directly from the Act's CDD requirements. She says that it is the failure inrelation to CDD that leads to a failure to terminate. She also places reliance on s 74(2)of the Act:74 One penalty only rule(2) If a person is or may be liable to more than 1 civil penalty under thisPart in respect of the same or substantially the same conduct, civilpenalty proceedings may be brought against the person for more than1 civil penalty, but the person may not be required to pay more than 1civil penalty in respect of the same or substantially the same conduct.[55] Ms Cooper emphasises that the one penalty rule does not require the conductto be exactly the same, but only substantially the same. She says that the conductunderpinning the first and second civil liability acts meets this threshold.25 OTT, above n 11, at [61].[56] This argument was accepted and applied in Jin Yuan.26 Woolford J adoptedstarting points of $1.3m for failing to conduct CDD, and $500,000 for entering into orcontinuing a business relationship where there was unsatisfactory evidence of identity.However, based on the one penalty rule in s 74, the Judge found the penalties wouldbe conflated because they related to much the same conduct.27 The total effectivepenalty for both breaches was therefore set at $1.3m.[57] I agree with Ms Cooper that the two obligations are clearly linked. Onefollows the other. It is difficult to see how there could be a breach of the CDDrequirements, if the business relationship was immediately terminated in compliancewith s 37. On the other hand, the nature of the obligation imposed on the reportingentity is different. The CDD requirements oblige reporting entities to obtain certaininformation; the s 37 requirement obliges the reporting entity to terminate arelationship. Each obligation is provided for in a separate statutory provision and non-compliance constitutes a separate civil liability act for which there is a distinctstatutory penalty. That all suggests that the conduct or act underpinning the statutoryobligation is different.[58] The distinction is exemplified by considering the difference in culpabilitybetween a customer relationship that is terminated one month after it should have been,and one that is terminated a year down the track. The longer a customer relationshipis allowed to continue where there has been inadequate CDD, the greater theAML/CFT risk. That difference in culpability suggests that the nature of the conductunderpinning s 37 is not always the same, or substantially the same, as the conductunderpinning the CDD requirements may require separate recognition by way ofseparate penalty. Ultimately, the decision to apply the one penalty only rule, and theextent of the conflation of penalties, will necessarily be a fact-specific exercise.[59] In this case, the failure to terminate the relationship meant that furthersubstantial transactions were undertaken on at least two occasions, some of whichwere also suspicious. On both these occasions, the relationships should have been26 Jin Yuan, above n 11. The one penalty only rule was also applied in QDD, above n 11. However,QDD is of limited assistance in this case due to the different civil liability acts involved.27 Jin Yuan, above n 11, at [41].terminated six months earlier. Although there is substantial overlap in the failure toundertake CDD, I consider a separate and distinct penalty is required to mark thatparticular conduct.[60] Assessed on a standalone basis, I would have imposed a penalty of $150,000for this breach. But, given the interrelationship with the failure to conduct CDD, Iadopt $50,000 as the starting point for this civil liability act.Failure to report suspicious transactions/activity[61] The Act requires reports to be made in a specified form within three workingdays of forming the requisite suspicion.28 The touchstone for the reportingrequirement is a "suspicious activity", which incorporates the more limited definitionof a "suspicious transaction" which existed prior to the amendment to the Act in11 August 2017.29[62] A suspicious activity is where a person conducts or seeks to conduct atransaction through a reporting entity, and the reporting entity has reasonable groundsto suspect that the transaction or proposed transaction may be relevant to theinvestigation or prosecution of any person for money laundering, or for a criminaloffence, or relevant to the enforcement of certain prescribed statutes.[63] The requirement was triggered in KVB's case because the transactions wereconducted through KVB, and it had reasonable grounds to suspect the transactionswere relevant to a qualifying investigation or offence.[64] KVB breached this requirement on nine occasions. On six of those occasions,a suspicious activity report was not forwarded at all. Late reports were filed on threeseparate occasions: 13, 114, and 175 days late respectively.[65] The requirement to file a report within the prescribed timeframes is central tothe detection and deterrence of money laundering and terrorism funding. Reports filedafter the three-day timeframe make detection more difficult. The failure to file any28 Anti-Money Laundering and Countering Financing of Terrorism Act, s 40(3).29 Section 39A.reports at all, and the filing of reports more than 100 days late, are serious breaches ofthe Act's requirements.[66] Aggravating that breach is the fact that one of the executive directors at thetime tried to prevent a suspicious activity report being made on at least one occasion.That related to deposits made by one customer totalling USD 23.5m. Although areport was eventually filed (114 days late), the director's conduct elevates theseriousness of KVB's non-compliance.[67] Counsel agree that KVB's conduct is not as serious as the breaches in Ping Anand Jin Yuan. In Ping An, the reporting entity failed to file a single report incircumstances where 173 should have been filed. In Jin Yuan, the reporting entityforwarded 32 suspicious activity reports out of 25,988 transactions that occurred overthe relevant period. There were also attempts to conceal certain accounts from thesupervisor in that case. Penalties of $1.3m were imposed in each case for thosebreaches.[68] The FMA submits that a starting point of $250,000 should be adopted for thisbreach. KVB seeks a starting point no higher than $150,000. Having regard to theprinciple of deterrence, I adopt a starting point of $200,000, being 10 per cent of thenotional maximum of $2m.Failure to keep records[69] Record keeping is central to the Act's purpose. Subpart 3 of pt 2 of the Actprescribes the way in which reporting entities are required to maintain recordsobtained for the purpose of compliance with the Act.[70] Specifically, KVB was required to keep for five years:(a) records reasonably necessary to enable every transaction that isconducted through it to be readily reconstructed at any time;3030 Anti-Money Laundering and Countering Financing of Terrorism Act, s 49.(b) records that enable the nature of the evidence used for CDD andverification to be readily identified at any time after a businessrelationship has terminated;31 and(c) copies of reports made of suspicious activities.32[71] Together, the requirements in subpt 3 require reporting entities to maintainrecords in such a way as to enable them to be viewed immediately on request, or withina reasonable time having regard to the request. That interpretation was endorsed inOTT, with Lang J finding that any "other interpretation would severely hamper the[supervisor's] ability to monitor compliance with other aspects of the regime".33[72] KVB has some, but not all, of the records required to enable transactionsundertaken prior to August 2019 to be reconstructed at any time. Similarly, it hassome, but not all, records that were reasonably necessary to enable the nature of theevidence used for customer identification (including the customer's source of fundsand/or wealth) and verification to be readily identified at any time. Significantly, KVBdoes not have any copies of reports of suspicious activities made between 11 August2017 and August 2019.[73] I agree with Mr McMullan's submission that KVB's failure to maintain itsrecords in such a way as to enable them to be viewed immediately on request, or withina reasonable time, represents a serious failure of its obligations under the Act. Thelack of understanding about how its own records are stored aggravates that failure.[74] KVB accepts the non-compliance in this area but says the failures are due to athird-party service provider refusing to provide access to its own records. KVB hasbeen forced to commence legal proceedings in Hong Kong in an effort to get themreturned (as discussed at [17] of this judgment).[75] Reporting entities must ensure that arrangements with third parties allow themto meet their obligations under the Act. To that extent, KVB must take responsibility31 Section 50.32 Section 49A.33 OTT, above n 11, at [78].for its state of affairs. Nevertheless, the fact that the non-compliance is due to the actsof a third party, and all reasonable steps have been taken to obtain the documents,including filing legal proceedings, mitigates KVB's non-compliance to some extent.[76] These circumstances make KVB's non-compliance less serious than in OTT.In that case, while both reporting entities did not entirely fail to keep the recordsrequired by the Act, no records at all were available for certain periods. Lang Jadopted a starting point of $500,000 to reflect these factors and the degree of overlapwith breaches of other obligations. I consider a starting point less than $500,000 iswarranted in this case. But I also consider the breaches to be more serious than theunintentional breaches in QDD warranting a higher starting point than the $120,000adopted in that case.[77] Standing back and considering the circumstances of this civil liability act in itsentirety, I adopt a starting point of $350,000.Aggravating and mitigating factors[78] The parties agree that there are no aggravating factors particular to KVB whichrequire an uplift to the starting point.Previous good character[79] KVB says it should get a discount for previous good character given it has notpreviously been found by a Court to have engaged in similar conduct.[80] Section 90(4)(d) of the Act requires a court to take into account whether areporting entity has previously been found "by a court in proceedings under this Act"to have engaged in any similar conduct. Previous proceedings against a reportingentity for similar conduct would be an aggravating factor in determining penalty. Butit does not follow that the absence of prior proceedings means a discount for previousgood character is available.[81] In this case, KVB was issued a formal warning on 20 June 2014, and it wasalso required to undertake a special audit of its risk assessment and AML/CFTprogramme. Although the non-compliance highlighted in that notice was different inkind to the current civil liability acts, the fact of the notice is indicative of a sub-standard approach to compliance with the Act prior to the issue of this proceeding.[82] It is true that the conduct the subject of the notice was not determined by aCourt, but nor was it challenged by KVB at the time. Indeed, the agreed statement offacts indicates that KVB responded by engaging Grant Thornton to undertake a specialaudit and, in late 2014, it represented to the FMA that it would demonstrate a strongrisk and compliance culture. That representation was not realised, however, as thecurrent proceedings show.[83] A discount for previous good character cannot be justified in light of that priorhistory and I decline to apply one.Admissions of liability and cooperation[84] The parties agree that KVB has engaged constructively, resolved allegationsagainst it and cooperated in reaching agreement relating to the factual basis for thebreaches.[85] Mr McMullan proposes a discount of 20 per cent but submits that a discountof no more than 25 per cent is available in reliance on the Supreme Court's decisionin Hessell v R.34 That case concerns discounts for guilty pleas in the criminal field.Ms Cooper submits that Hessell is not relevant and the line of cases under theCommerce Act, where discounts of 30 per cent or more are applied for admissions ofliability and cooperation, provide better guidance in this area.[86] In RBNZ v TSB, Mallon J referred to principles arising out of both Hessell andother civil regulatory cases (including those under the Commerce Act) in determiningthe quantum of discount to apply in that case.35 I follow Mallon J's approach. Thatmeans that all principles are relevant and there is no cap at 25 per cent.34 Hessell v R [2010] NZSC 135, [2011] 1 NZLR 607.35 See RBNZ v TSB, above n 11, at [48]–[52].[87] The application of a discount recognises the savings in time and resource inavoiding a disputed hearing and reflects the public interest in that approach. Discountsof 25, 20 and 15 per cent were applied in RBNZ v TSB, QDD and Jin Yuan,respectively. I consider this case to fall somewhere between RBNZ v TSB and QDD.In the former, the 25 per cent discount reflected the reporting entity's full cooperation,including agreement with the supervisor on the appropriate penalty. In the latter, therewas agreement on everything but the penalty. And, as noted by Mallon J, the fact thatthe defendant had inaccurately represented the nature of its relationship with sixmoney remitters meant that the cooperation was not as full as it was in RBNZ v TSB.36[88] In this case there has been an admission of liability, agreement to the statementof facts, and cooperation with the FMA. The only matter not agreed is the penalty, butthere is no suggestion that KVB has made misrepresentations or misled the FMA. Inlight of the discounts applied in QDD and RBNZ v TSB, I apply a discount of23 per cent for admissions of liability and cooperation.Subsequent improvements in compliance[89] KVB has undertaken significant steps to strengthen its compliance with the Actand other regulatory obligations. They include:(a) revisions to its AML/CFT programme and risk assessment which havebeen audited by a third party;(b) hiring compliance staff who have completed AML/CFT training;(c) putting in place new IT service arrangements; and(d) installing an entirely new board of directors, including two newindependent non-executive directors.36 RBNZ v TSB, above n 11 at [46].[90] These steps do not, in and of themselves, warrant a separate discount. AsPowell J observed in QDD, substantive compliance was what was required by the Actin any event.37[91] However, as Ms Cooper submits, these steps indicate that KVB's admissionsand cooperation with the FMA are genuine and not merely designed to secure a lesserpenalty. To that end, these subsequent steps bolster the application of a 23 per centdiscount.Totality[92] The result of the above analysis is a pecuniary penalty of $770,000, constructedas follows:(a) global starting point: $1,000,000 comprising:(i) failure to conduct CDD: $400,000 (20 per cent of maximumpenalty);(ii) failure to terminate existing business relationships when CDDcould not be completed: $50,000 (five per cent of maximumpenalty);(iii) failure to report suspicious transactions/activity: $200,000 (10per cent of maximum penalty);(iv) failure to keep records: $350,000 (17.5 per cent of maximumpenalty);(b) discount of 23 per cent for admissions and cooperation.[93] The global starting point already accounts for the overlap between the first andsecond civil liability acts. I do not consider a further adjustment to any of the startingpoints is required.37 QDD, above n 11, at [162].[94] A penalty of $770,000 represents 11 per cent of the available maximum. Thisplaces KVB's conduct at the very top of the third category of the scale set out in FMAv ANZ. Given the scale, nature and circumstances of KVB's non-compliance, I amsatisfied that this penalty accurately reflects the gravity of the breaches and reflectsthe principles of deterrence and denouncement. A further adjustment for totalitypurposes is not required.Result[95] Judgment is entered against the defendant for the four civil liability acts and apecuniary penalty of $770,000 is imposed.[96] By consent, the FMA is awarded costs on a scale 2B basis.___________________Edwards J