What is AML?
Money laundering is the process by which proceeds of crime — drug trafficking, fraud, corruption, sanctions evasion, terrorism financing — are made to appear legitimate. AML is the regulated response: a layered set of obligations on financial institutions, designated non-financial businesses and professions (DNFBPs), and increasingly on crypto and gaming firms, to detect, prevent and report it.
The UN estimates 2–5% of global GDP — up to USD 2 trillion annually — is laundered each year. AML programmes are the front line of defence, and supervisors expect them to be risk-based, proportionate and demonstrably effective.
The 3 stages of money laundering
1. Placement
Illicit cash enters the financial system — through deposits, cash-intensive businesses, or money mules.
2. Layering
Funds are moved through complex chains of transactions, shell companies and jurisdictions to obscure their origin.
3. Integration
Laundered funds re-enter the legitimate economy as investments, real estate or business revenue.
The 5 pillars of an AML programme
- A designated AML/MLRO compliance officer with authority and independence
- Risk-based internal policies, controls and procedures
- Ongoing employee training and awareness
- Independent audit and assurance of the AML programme
- Customer Due Diligence (CDD), including beneficial ownership and ongoing monitoring
Who must comply with AML laws
AML obligations apply far beyond banks. Most jurisdictions cover:
Banks, EMIs and payment institutions
Crypto-asset service providers (CASPs / VASPs)
Investment firms, brokers and asset managers
Insurance and pension providers
Gaming and gambling operators
Lawyers, notaries, accountants, auditors
Real estate agents and developers
Trust & corporate service providers
High-value goods dealers (art, precious metals)
Core AML controls
KYC & identity verification
Verify who the customer really is at onboarding and on trigger events.
KYB & beneficial ownership
Identify the natural persons who ultimately own or control legal entities (UBOs).
Sanctions, PEP & adverse-media screening
Continuously screen all parties against authoritative risk data.
Risk scoring
Assign a dynamic risk rating per customer based on geography, product and behaviour.
Transaction monitoring
Detect suspicious patterns in real time using rules and behavioural analytics.
Suspicious Activity Reporting (SAR/STR)
File timely reports to the national FIU with full evidence trail.
Recordkeeping
Retain customer and transaction records for 5+ years as required by law.
Independent testing & audit
Periodic third-party review of programme effectiveness.
Key AML regulations
FATF 40 Recommendations
Global AML/CFT standard adopted by 200+ jurisdictions.
EU AMLR, AMLD 6 & AMLA
Single EU rulebook plus a new EU-level supervisor (AMLA) effective from 2027.
US Bank Secrecy Act & USA PATRIOT Act
Foundational US AML regime enforced by FinCEN, OCC and OFAC.
UK Money Laundering Regulations 2017
Risk-based AML duties for UK regulated firms, supervised by the FCA.
MiCA (EU 2023/1114)
Brings crypto-asset service providers fully into the EU AML perimeter.
FATF Travel Rule
Originator/beneficiary information must travel with crypto and wire transfers.
New to the terminology?
Look up STR, CTR, UBO, EDD, Travel Rule and 30+ other AML terms in plain language.
AML trends in 2026
- EU AMLA stands up — harmonised supervision across Member States
- Perpetual KYC replaces periodic refresh cycles
- AI-assisted alert triage to reduce false positives
- Beneficial ownership transparency tightens globally
- Sanctions complexity rises — Russia, Iran, dual-use goods
- Crypto Travel Rule enforcement scales under MiCA and FATF
Frequently asked questions
AML basics
What does AML stand for?
AML stands for Anti-Money Laundering — the framework of laws, regulations and controls designed to prevent criminals from disguising illegally obtained funds as legitimate income.
What is money laundering in simple terms?
Money laundering is the process of making proceeds of crime look like legitimate income, typically through three stages: placement (cash enters the system), layering (transactions obscure the origin) and integration (funds re-enter the legitimate economy).
What is the difference between AML and KYC?
AML is the broader regulatory regime to prevent money laundering and terrorist financing. KYC (Know Your Customer) is one specific control within an AML programme — verifying the identity and risk profile of customers.
What is the difference between AML and CFT?
AML targets the laundering of proceeds of crime; CFT (Counter-Financing of Terrorism) targets the funding of terrorism, even when the funds themselves are legal in origin. Most regimes combine them as AML/CFT obligations.
Obligations and enforcement
Who has to comply with AML regulations?
Banks, fintechs, payment institutions, e-money issuers, crypto-asset service providers, gaming operators, real estate agents, lawyers, accountants, art dealers, trust and corporate service providers, and any business covered by national AML legislation.
What are the penalties for AML failures?
Penalties range from multi-million-dollar regulatory fines to criminal liability for officers, loss of operating licence, frozen correspondent banking and severe reputational damage. Global AML enforcement exceeded USD 6 billion in 2024.
How often should an AML programme be reviewed?
Risk assessments and the AML programme itself should be reviewed at least annually and after any material change in business model, products, geographies or regulatory expectations.
What is an MLRO and is it mandatory?
An MLRO (Money Laundering Reporting Officer) is the named senior individual responsible for the AML programme and for filing SARs/STRs with the national FIU. Most jurisdictions, including the EU and UK, mandate the role for regulated firms.
Process and terminology
What are the 3 stages of money laundering?
Placement (introducing illicit cash to the financial system), layering (moving funds through complex transactions to obscure origin) and integration (re-entering the legitimate economy as investments, real estate or business revenue).
What are the 5 pillars of an AML programme?
A designated compliance officer (MLRO), risk-based policies and procedures, ongoing employee training, independent audit and assurance, and Customer Due Diligence including beneficial ownership and ongoing monitoring.
What is a SAR / STR and when must it be filed?
A Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) is a confidential filing to the national FIU when a regulated firm knows or suspects funds are linked to crime or terrorism. Filing is required promptly after the suspicion is formed — and tipping-off the customer is a criminal offence.
What is the FATF Travel Rule?
FATF Recommendation 16 requires that originator and beneficiary information travels alongside wire transfers and, since 2021, alongside crypto-asset transfers above defined thresholds. EU enforcement is hardened by Regulation 2023/1113 and MiCA.
How long must AML records be kept?
Most regimes (FATF, EU AMLR, US BSA, UK MLRs) require AML records — KYC files, transaction data and SAR/STR evidence — to be retained for at least 5 years after the end of the business relationship or transaction.
What is perpetual KYC (pKYC)?
Perpetual KYC replaces fixed periodic refresh cycles with continuous, event-driven re-verification. Customer data is automatically re-checked whenever a relevant trigger occurs, reducing stale records and analyst workload.
Build an audit-ready AML programme.
ComplianceSuite unifies KYC, KYB, sanctions/PEP screening, risk scoring, transaction monitoring and SAR reporting in one platform — deployed in 48 hours.
