Compliance fundamentals · 9 min read

    Anti-Money Laundering (AML)

    Anti-Money Laundering (AML) is the global framework of laws, regulations and controls that prevents criminals from disguising illegally obtained funds as legitimate income. For regulated firms it translates into a programme of risk assessment, customer due diligence, screening, transaction monitoring and reporting — overseen by a designated compliance officer and tested by independent audit.

    What is AML?

    Money laundering is the process by which proceeds of crime — drug trafficking, fraud, corruption, sanctions evasion, terrorism financing — are made to appear legitimate. AML is the regulated response: a layered set of obligations on financial institutions, designated non-financial businesses and professions (DNFBPs), and increasingly on crypto and gaming firms, to detect, prevent and report it.

    The UN estimates 2–5% of global GDP — up to USD 2 trillion annually — is laundered each year. AML programmes are the front line of defence, and supervisors expect them to be risk-based, proportionate and demonstrably effective.

    The 3 stages of money laundering

    1. Placement

    Illicit cash enters the financial system — through deposits, cash-intensive businesses, or money mules.

    2. Layering

    Funds are moved through complex chains of transactions, shell companies and jurisdictions to obscure their origin.

    3. Integration

    Laundered funds re-enter the legitimate economy as investments, real estate or business revenue.

    The 5 pillars of an AML programme

    • A designated AML/MLRO compliance officer with authority and independence
    • Risk-based internal policies, controls and procedures
    • Ongoing employee training and awareness
    • Independent audit and assurance of the AML programme
    • Customer Due Diligence (CDD), including beneficial ownership and ongoing monitoring

    Who must comply with AML laws

    AML obligations apply far beyond banks. Most jurisdictions cover:

    Banks, EMIs and payment institutions

    Crypto-asset service providers (CASPs / VASPs)

    Investment firms, brokers and asset managers

    Insurance and pension providers

    Gaming and gambling operators

    Lawyers, notaries, accountants, auditors

    Real estate agents and developers

    Trust & corporate service providers

    High-value goods dealers (art, precious metals)

    Core AML controls

    KYC & identity verification

    Verify who the customer really is at onboarding and on trigger events.

    KYB & beneficial ownership

    Identify the natural persons who ultimately own or control legal entities (UBOs).

    Sanctions, PEP & adverse-media screening

    Continuously screen all parties against authoritative risk data.

    Risk scoring

    Assign a dynamic risk rating per customer based on geography, product and behaviour.

    Transaction monitoring

    Detect suspicious patterns in real time using rules and behavioural analytics.

    Suspicious Activity Reporting (SAR/STR)

    File timely reports to the national FIU with full evidence trail.

    Recordkeeping

    Retain customer and transaction records for 5+ years as required by law.

    Independent testing & audit

    Periodic third-party review of programme effectiveness.

    Key AML regulations

    FATF 40 Recommendations

    Global AML/CFT standard adopted by 200+ jurisdictions.

    EU AMLR, AMLD 6 & AMLA

    Single EU rulebook plus a new EU-level supervisor (AMLA) effective from 2027.

    US Bank Secrecy Act & USA PATRIOT Act

    Foundational US AML regime enforced by FinCEN, OCC and OFAC.

    UK Money Laundering Regulations 2017

    Risk-based AML duties for UK regulated firms, supervised by the FCA.

    MiCA (EU 2023/1114)

    Brings crypto-asset service providers fully into the EU AML perimeter.

    FATF Travel Rule

    Originator/beneficiary information must travel with crypto and wire transfers.

    New to the terminology?

    Look up STR, CTR, UBO, EDD, Travel Rule and 30+ other AML terms in plain language.

    Frequently asked questions

    AML basics

    What does AML stand for?

    AML stands for Anti-Money Laundering — the framework of laws, regulations and controls designed to prevent criminals from disguising illegally obtained funds as legitimate income.

    What is money laundering in simple terms?

    Money laundering is the process of making proceeds of crime look like legitimate income, typically through three stages: placement (cash enters the system), layering (transactions obscure the origin) and integration (funds re-enter the legitimate economy).

    What is the difference between AML and KYC?

    AML is the broader regulatory regime to prevent money laundering and terrorist financing. KYC (Know Your Customer) is one specific control within an AML programme — verifying the identity and risk profile of customers.

    What is the difference between AML and CFT?

    AML targets the laundering of proceeds of crime; CFT (Counter-Financing of Terrorism) targets the funding of terrorism, even when the funds themselves are legal in origin. Most regimes combine them as AML/CFT obligations.

    Obligations and enforcement

    Who has to comply with AML regulations?

    Banks, fintechs, payment institutions, e-money issuers, crypto-asset service providers, gaming operators, real estate agents, lawyers, accountants, art dealers, trust and corporate service providers, and any business covered by national AML legislation.

    What are the penalties for AML failures?

    Penalties range from multi-million-dollar regulatory fines to criminal liability for officers, loss of operating licence, frozen correspondent banking and severe reputational damage. Global AML enforcement exceeded USD 6 billion in 2024.

    How often should an AML programme be reviewed?

    Risk assessments and the AML programme itself should be reviewed at least annually and after any material change in business model, products, geographies or regulatory expectations.

    What is an MLRO and is it mandatory?

    An MLRO (Money Laundering Reporting Officer) is the named senior individual responsible for the AML programme and for filing SARs/STRs with the national FIU. Most jurisdictions, including the EU and UK, mandate the role for regulated firms.

    Process and terminology

    What are the 3 stages of money laundering?

    Placement (introducing illicit cash to the financial system), layering (moving funds through complex transactions to obscure origin) and integration (re-entering the legitimate economy as investments, real estate or business revenue).

    What are the 5 pillars of an AML programme?

    A designated compliance officer (MLRO), risk-based policies and procedures, ongoing employee training, independent audit and assurance, and Customer Due Diligence including beneficial ownership and ongoing monitoring.

    What is a SAR / STR and when must it be filed?

    A Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR) is a confidential filing to the national FIU when a regulated firm knows or suspects funds are linked to crime or terrorism. Filing is required promptly after the suspicion is formed — and tipping-off the customer is a criminal offence.

    What is the FATF Travel Rule?

    FATF Recommendation 16 requires that originator and beneficiary information travels alongside wire transfers and, since 2021, alongside crypto-asset transfers above defined thresholds. EU enforcement is hardened by Regulation 2023/1113 and MiCA.

    How long must AML records be kept?

    Most regimes (FATF, EU AMLR, US BSA, UK MLRs) require AML records — KYC files, transaction data and SAR/STR evidence — to be retained for at least 5 years after the end of the business relationship or transaction.

    What is perpetual KYC (pKYC)?

    Perpetual KYC replaces fixed periodic refresh cycles with continuous, event-driven re-verification. Customer data is automatically re-checked whenever a relevant trigger occurs, reducing stale records and analyst workload.

    Build an audit-ready AML programme.

    ComplianceSuite unifies KYC, KYB, sanctions/PEP screening, risk scoring, transaction monitoring and SAR reporting in one platform — deployed in 48 hours.