When a jurisdiction's Citizenship by Investment (CIP) program faces international sanctions, your name screening and Customer Due Diligence processes need immediate updates. Antigua's standoff with the EU over its CIP program deadline of June 2028 isn't just a diplomatic issue; it's a compliance challenge your team must address in your procedures, screening logic, and risk rating frameworks.
This template provides a structured alert protocol for monitoring customers with passports from jurisdictions with threatened or sanctioned CIP programs. You can adapt it for any economic citizenship scheme facing regulatory pressure, not just Antigua.
Purpose of This Template
Use this template to document your institution's response when a CIP-issuing jurisdiction faces:
- Threatened visa restrictions from major economic blocs (EU, US, UK)
- FATF designation as a Non-Cooperative Country or Territory
- Public allegations of program abuse for money laundering
- Pending criminal investigations naming government officials
The template creates a repeatable process for risk assessment, customer communication, and enhanced monitoring. It complements your existing Country Risk Assessment and Customer Risk Rating procedures.
Prerequisites
Before implementing this template, ensure you have:
- Current CIP passport inventory: A list of all customers holding economic citizenship documents from any jurisdiction, not just Antigua.
- Access to your customer risk rating system: You'll need to trigger recalculations.
- Defined escalation authority: Know who approves enhanced due diligence decisions and customer exits.
- Monitoring rule configuration access: You may need to adjust transaction monitoring thresholds.
You should also understand FATF Recommendation 22 (Customer Due Diligence for designated non-financial businesses and professions) and your jurisdiction's requirements for ongoing due diligence.
The Template
CIP JURISDICTION ALERT PROTOCOL
Jurisdiction: [Name]
CIP Program: [Program name]
Alert Date: [Date]
Alert Trigger: [Sanction threat / FATF designation / Criminal investigation]
Compliance Owner: [Name, title]
SECTION 1: IMPACT ASSESSMENT
☐ Number of affected customers: [Count]
☐ Total exposure (deposits, credit, AUM): [Amount]
☐ Customer segments affected:
☐ Private banking
☐ Corporate banking
☐ Correspondent banking
☐ Payments / remittance
☐ Jurisdictional overlap: Does the customer also hold citizenship elsewhere?
SECTION 2: IMMEDIATE ACTIONS (Within 48 hours)
☐ Flag all affected customer records with alert code: [Code]
☐ Suspend new account openings for applicants holding this passport type
☐ Notify relationship managers: Use script below
☐ Escalate high-value relationships (>$[threshold]) to [Role]
SECTION 3: ENHANCED DUE DILIGENCE REQUIREMENTS
For each affected customer, obtain within [X] business days:
☐ Source of wealth documentation (refreshed within 12 months)
☐ Current proof of residential address (utility bill, tax filing)
☐ Beneficial ownership declaration (if corporate structure involved)
☐ Statement of economic activity in CIP jurisdiction (if any)
☐ Declaration of other citizenships held
☐ Updated PEP screening (cross-reference against jurisdiction's government officials)
If customer cannot provide satisfactory documentation within [X] days:
☐ Escalate to MLRO for exit decision
☐ File Suspicious Activity Report if facts warrant
SECTION 4: TRANSACTION MONITORING ADJUSTMENTS
Effective [Date], apply the following rules to affected customers:
☐ Lower cash transaction alert threshold to: $[Amount]
☐ Flag all wire transfers to/from [Jurisdiction] regardless of amount
☐ Flag all transactions involving [Jurisdiction]-registered entities
☐ Review historical transactions for past [X] months for:
- Structuring patterns
- Correspondent banking flows
- Third-party payments
- Rapid movement of funds
SECTION 5: CUSTOMER COMMUNICATION SCRIPT
Use this script when contacting affected customers:
"As part of our ongoing due diligence obligations, we're updating our records for customers holding [Jurisdiction] citizenship documents. This is a routine compliance requirement following [recent regulatory developments / international sanctions].
We'll need you to provide the following documents by [Date]:
- [List from Section 3]
Please note this doesn't affect your current banking services, but we can't process new transactions or account changes until we complete this review. If you have questions, contact [Compliance contact]."
SECTION 6: HISTORICAL RISK REVIEW
For jurisdictions with known money laundering history, review:
☐ Any customers with prior addresses in [Jurisdiction]
☐ Any beneficial owners connected to [Jurisdiction] government or CIP program
☐ Corporate entities registered in [Jurisdiction] (even if customer isn't a passport holder)
☐ Correspondent banking relationships with [Jurisdiction] banks
Cross-reference customer names against:
☐ Public reporting on [specific case, e.g., "Alex Saab Moran matter"]
☐ [Jurisdiction] government official lists
☐ Known CIP program facilitators and agents
SECTION 7: DECISION MATRIX
After enhanced due diligence, classify each customer:
GREEN: Continue relationship
- Satisfactory documentation provided
- No adverse findings in transaction review
- Customer holds alternative citizenship in low-risk jurisdiction
- Action: Return to standard monitoring; document file
YELLOW: Continue with enhanced monitoring
- Partial documentation gaps (non-material)
- Moderate transaction volume through [Jurisdiction]
- Action: Quarterly manual review for [X] months; maintain enhanced monitoring rules
RED: Exit relationship
- Cannot provide source of wealth documentation
- Adverse findings in transaction or PEP screening
- Refusal to cooperate with due diligence requests
- Action: Notify customer; file SAR if warranted; close accounts per policy
SECTION 8: REGULATORY REPORTING
☐ Document this alert and all actions in annual BSA/AML independent review
☐ If SAR filed, note case number: [Number]
☐ Prepare summary for Board/Senior Management: [Date]
☐ Update Country Risk Assessment to reflect [Jurisdiction] status change
Customization Tips
Thresholds: Adjust the exposure thresholds in Section 1 and monitoring amounts in Section 4 based on your institution's risk appetite and customer base size. A community bank might flag relationships over $500K; a global private bank might use $5M.
Timeframes: The "within 48 hours" and "within X business days" placeholders should reflect your institution's size and operational capacity. Smaller institutions might need 5-7 business days for enhanced due diligence collection; larger banks with dedicated KYC teams can move faster.
Monitoring rules: Section 4 assumes you have configurable transaction monitoring. If you're using a vendor system, work with your provider to implement jurisdiction-based rule logic. If you're monitoring manually, create a watch list and review transactions daily.
Historical review scope: Section 6 references "Alex Saab Moran" as an example because he previously used Antigua-registered banks for money laundering activities. Substitute the relevant typology or named case for whatever jurisdiction you're monitoring. Use only documented matters from public sources or your regulator.
Decision matrix: The Green/Yellow/Red classification in Section 7 should align with your existing customer risk rating methodology. If you use a numerical scale (1-5) instead of colors, adapt accordingly.
Validation Steps
After customizing and deploying this template, validate it by:
Test run: Pick three representative customers from your affected population (low, medium, high risk) and walk through Sections 1-7. Can you complete each checkbox? Do you have the data sources you need?
Relationship manager briefing: Share Section 5's customer communication script with your front-line staff. Do they understand when to use it? Can they answer likely customer questions?
Systems check: Confirm your transaction monitoring system can execute the rule changes in Section 4. If not, document the manual workaround and assign responsibility.
Escalation test: Identify one hypothetical RED case from Section 7. Walk through your institution's account closure process. Who approves? What's the timeline? Does Legal need to review?
Documentation audit: After 30 days, pull a sample of five affected customer files. Did the assigned compliance owner complete all required sections? Are decisions documented? This audit proves your process is working if a regulator asks.
The goal is a documented, repeatable process that you can execute consistently across your affected customer base and adapt when the next CIP jurisdiction faces sanctions pressure. Because there will be a next one.


