• Jul 14, 2026
  • 10 min read

AML Policy Explained: A Step-by-Step Guide to AML Compliance

Learn how to create an AML compliance policy covering CDD, MLRO duties, SAR filing, and audits, and get a free FINRA template to help you get started.

Financial crime continues to grow at an unprecedented scale. Nasdaq Verafin’s 2026 Global Financial Crime Report estimated that illicit financial activity reached $4.4 trillion globally in 2025, an increase of $1.3 trillion from 2023. 

Businesses can become conduits for illicit funds without even knowing they are participating in criminal activity. However, AML-obliged businesses are responsible for preventing this from happening: they are legally required to implement adequate AML controls and monitor for suspicious activity. Failures in these areas expose them to criminal risks, regulatory scrutiny, enforcement action, and significant fines.

This underlines the need for AML policies that translate regulatory requirements into controls employees can apply in practice.

What is an AML policy?

An anti-money laundering (AML) policy is a combination of measures to stop criminals from disguising illegally obtained money as legitimate income. Implementation is mandatory for financial institutions and overseen by regulatory authorities such as FinCEN and FINRA in the US, the FCA in the UK, BaFin in Germany, MAS in Singapore, the COAF in Brazil, and Argentina’s CB.

AML policies are designed to establish a general framework for company systems and controls to combat money laundering and terrorist financing. They should determine qualities such as AML risk appetite, tolerances, unacceptable customer types, prohibited actions, employee responsibilities, employee rights, and qualification levels.

The AML policy must be approved by the company’s senior management and reviewed regularly.

AML policy vs AML program

An AML policy is sometimes interchangeable with an AML compliance program. The policy sets out what the organization intends to do, while the program includes the people, processes, technology, training, testing, and oversight used to put those commitments into practice.

A business may have a well-written AML policy but still fall short in its AML program if it lacks the staff, technology, procedures, or oversight needed to apply it effectively.

Suggested read: AML Compliance Program: The Essential Guide

Why AML policies matter for your business

A clear AML policy helps businesses have a consistent approach to combating financial crime. This is particularly important for AML-obliged industries, including banks and other financial institutions, payment and crypto businesses, gambling operators, real estate businesses, and certain legal and accounting professionals. These businesses are legally required to implement AML measures and monitor for suspicious activity.

Not only do AML policies protect your business, customers, and the wider financial system from the risks of criminal abuse, but they also safeguard you from huge regulatory fines if money laundering or other failures are detected during an audit. Without one, employees may apply checks differently, miss warning signs, or fail to escalate suspicious activity.

International AML regulatory landscape

National rules vary, but most are influenced by a shared international AML framework, namely the standards set by the Financial Action Task Force (FATF). 

The FATF is a global anti-money laundering and counter terrorist financing watchdog. The FATF issues global standards to prevent money laundering, and local AML regulations are usually based on them.

These help regulated businesses, which are generally expected to assess exposure to money laundering and terrorist financing risks, conduct customer due diligence (CDD), monitor suspicious activity, maintain records, train staff, and report concerns to relevant authorities.

FATF global standards

The FATF sets the principal international standards for combating money laundering, terrorist financing, and proliferation financing. Its 40 Recommendations provide a foundation for national AML regulations, covering areas such as:

  • Risk assessments and the risk-based approach
  • Customer and beneficial-owner identification
  • Recordkeeping and suspicious transaction reporting
  • Regulation of financial institutions and certain non-financial businesses
  • International cooperation and information sharing

The Recommendations are not laws. Countries implement them through their own legislation and regulatory systems. The FATF then assesses jurisdictions through mutual evaluations, examining both whether the necessary rules exist and whether they work effectively in practice.

Suggested read: AML High-Risk Countries: FATF Grey List, Jurisdiction Risks, and Compliance Best Practices (2026)

Regional AML regulations: EU, US, and beyond

Jurisdictions around the world have their own legislation, regulators, reporting systems, and AML requirements. 

In the European Union, for example, AML rules are undergoing further harmonization through the AML/CFT legislative package adopted in 2024. This includes a directly applicable AML Regulation, the Sixth Anti-Money Laundering Directive, and the creation of the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). The main AML Regulation applies from July 10, 2027, while AMLA is preparing to begin direct supervision of selected high-risk financial institutions in 2028.

The package is intended to create a more consistent EU approach. Until its provisions apply, businesses must continue to follow the existing EU and national rules relevant to them. In parallel, AMLA is drafting RTS and Guidelines, secondary legislation that will provide more detailed interpretation and operational guidance on the AMLR's provisions.

In the United States, the Bank Secrecy Act and its implementing regulations form the basis of the federal AML regime. Depending on the type of financial institution, an AML compliance program may need to include internal controls, a designated compliance officer, employee training, independent testing, CDD, recordkeeping, and suspicious activity reporting.

In Singapore, the Monetary Authority of Singapore issues sector-specific AML/CFT requirements for financial institutions. These cover areas like risk assessment, CDD, ongoing monitoring, recordkeeping, suspicious transaction reporting, and internal controls.

Brazil’s AML framework is based on Law No. 9,613, with requirements set by the regulators responsible for each sector. Covered businesses must identify customers, maintain records, and report suspicious transactions to the Council for Financial Activities Control.

In Argentina, meanwhile, Law No. 25,246, which forms the basis of the country’s AML framework, was substantially amended by Law No. 27,739 in 2024. The reforms strengthened the risk-based approach, customer and beneficial-owner checks, suspicious transaction reporting requirements, and UIF supervision, and also added virtual asset service providers as obliged entities.

Suggested read: Customer Due Diligence (CDD): The Process and Its Types

Who needs an AML policy?

Whether a business needs a formal AML policy depends on its activities, location, customer base, and the AML regulations that apply to it. Financial institutions, such as banks, and other AML-obliged businesses may be required to establish and maintain AML policies. Depending on the jurisdiction and the activities they perform, these may include crypto operators, money service businesses, law firms, casinos, tax advisors, and forex brokers. The specific requirements vary by jurisdiction and the applicable AML regulations.

AML risk assessment and the risk-based approach

An AML risk assessment identifies where and how a business may be exposed to money laundering, terrorist financing, and related financial crimes. It provides the foundation for a risk-based AML compliance program, as recommended by the FATF, helping the organization focus its resources and controls on the areas of greatest concern.

Under a risk-based approach, businesses identify, assess, and understand their exposure to money laundering and terrorist financing, and then apply controls proportionate to the level of risk. The risk-based approach is central to FATF global standards.

Suggested read: Inside AML Investigations: Spotting and Reporting Financial Crime

Step-by-step AML policy guide

An AML policy template can provide a useful starting structure. However, the final document must reflect your business’s products, customers, geographic exposure, regulatory obligations, and risks.

Step 1: Draft an AML policy 

Begin by drafting the overall AML policy and defining its purpose, scope, and governance. The policy should provide a high-level framework for your organization's AML compliance program and explain how the business will prevent, detect, and report money laundering and terrorist financing.

At a minimum, the policy should cover:

  • the purpose and objectives of the AML policy
  • the scope of the policy, including the entities, business units, employees, and activities it applies to
  • key roles and responsibilities, including AML governance and oversight
  • applicable laws, regulations, and regulatory guidance
  • the organization's risk-based approach to AML compliance
  • how breaches of the AML policy will be identified, investigated, and addressed
  • requirements for regular policy reviews and independent audits of the AML program

The policy should also refer employees to the organization's detailed AML procedures, including customer due diligence, identity verification, transaction monitoring, sanctions and PEP screening, suspicious activity reporting, employee training, and recordkeeping.

Step 2: Appoint a money laundering reporting officer/establish AML governance

Where required, appoint a suitable money laundering reporting officer (MLRO) to oversee compliance with AML regulations, including systems and controls against money laundering, receive disclosures of suspicious activity, and decide whether to make external suspicious activity reports.

The MLRO should have sufficient authority, independence, resources, and access to relevant business information. Their responsibilities may include:

  • Overseeing AML controls and risk assessments
  • Receiving internal reports of suspicious activity
  • Deciding whether external AML reporting is required
  • Coordinating regulatory inspections and audits

Step 3: Conduct risk assessment

The policy should require the business to identify and assess its exposure to money laundering and terrorist financing risks. Risk assessments should consider factors such as customers, products and services, delivery channels, transactions, and geographic exposure.

The results should determine the level of customer due diligence, transaction monitoring, and other AML controls applied throughout the business. Risk assessments should be reviewed periodically and whenever significant changes occur.

Step 4: Establish customer due diligence procedures

Customer due diligence includes collecting and verifying relevant client information and identifying and assessing the criminal risk they pose. This process involves:

  • identifying the customer and verifying their identity
  • identifying the beneficial owner and verifying their identity
  • assessing and obtaining information on the purpose and intended nature of the business relationship or transaction

Regulated entities should implement CDD measures whenever: 

  • they start new business relationships
  • they carry out occasional transactions
  • there is suspicion of money laundering 
  • there is unreliable documentation
  • there are ongoing monitoring obligations

Businesses should also determine the extent of their CDD measures and ongoing monitoring on a risk-based approach, according to the type of customer, transaction, or business relationship. Businesses should determine whether a given customer requires simplified due diligence, customer due diligence, or enhanced due diligence

CDD also involves a standard procedure for checking clients through sanctions lists and adverse media. Companies should be aware of changes in sanctions regimes as soon as they occur. This can be done using an automated system that monitors updates to the sanctions regime. 

Before entering into a business relationship or opening an account for a client, financial companies must verify that they’re not onboarding someone listed as a target of financial sanctions legislation, such as someone on the US Specially Designated Nationals List (SDN), and confirm that there are no legal barriers to providing services. 

Step 5: Establish transaction monitoring and other ongoing procedures and controls

The policy should describe how customer activity and transactions are monitored throughout the business relationship to identify unusual or potentially suspicious behavior.

Monitoring procedures should explain:

  • which transactions are monitored
  • how alerts are generated and investigated
  • how monitoring is calibrated using a risk-based approach
  • when enhanced review is required
  • how monitoring supports ongoing customer due diligence

Where appropriate, automated transaction monitoring systems should be used to improve consistency and identify potential financial crime risks.

Handling Politically Exposed Persons

Politically exposed persons (PEPs) may be more exposed to corruption or bribery, although PEP status does not imply wrongdoing. PEP screening should cover the parties required by local law and may trigger senior approval, source-of-wealth or source-of-funds checks, enhanced monitoring, and more frequent review.

Sanctions screening and adverse media checks

Sanctions screening should compare relevant customers, beneficial owners, counterparties, and transactions against the lists that apply to the business. Procedures should cover onboarding, periodic rescreening, list updates, transaction screening, potential-match review, and escalation. The business may combine sanctions controls with PEP screening. 

Adverse media checks can also provide additional information about allegations, investigations, criminal conduct, or other risk indicators. Results should be assessed for credibility, relevance, severity, and recency. A negative article should not automatically result in rejection, particularly where the identity match or reliability of the information is uncertain.

Step 6: Establish reporting procedures to financial intelligence units

The policy should identify the relevant financial intelligence unit, such as FinCEN in the US or the UK Financial Intelligence Unit, and explain how disclosures are submitted.

Internal AML reporting procedures should specify what employees report, who reviews it, applicable deadlines, urgent escalation routes, and confidentiality or anti-tipping-off requirements.

Step 7: Maintain records 

The policy should specify which AML records must be retained, where they are stored, who may access them, and how long they must be kept in line with applicable regulations. It should also explain how records are protected, retrieved when requested by regulators or other competent authorities, and securely disposed of once the applicable retention period expires.

Step 8: Provide AML training and raise staff awareness

The policy should ensure that employees are aware of how to deal with money laundering for AML compliance. Role-specific AML training should cover topics such as:

  • the risks of ML/TF
  • relevant laws and their obligations
  • the responsibilities of the firm’s MLRO
  • how the firm deals with potential money laundering or terrorist financing transactions or activity.

Step 9: Conduct regular independent AML audits

An independent AML audit should:

  • examine and evaluate the effectiveness of the current AML policy
  • make recommendations in relation to this policy
  • monitor the company’s compliance with those recommendations

The reviewer should be sufficiently independent from the activities being examined and should assess governance, risk assessment, CDD, screening, monitoring, reporting, training, and recordkeeping.

Common AML policy mistakes

Most AML programs fail in a handful of ordinary, repeatable mistakes that may seem minor on their own but become significant when identified together during an examination or audit. The most common are:

Using a generic template as-is. A policy downloaded and left unedited describes a company that doesn't exist. If it doesn't reflect your actual products, customers, and geographies, it isn't a risk-based program, and a supervisor can usually tell at a glance that the underlying risk assessment was never really done.

Leaning too hard on automation. Monitoring tools scale the work, but they don't replace judgment. Rules drift out of date, thresholds go untuned, and alerts pile up unread while everyone assumes the system has it covered. The technology is only as good as the people reviewing what it flags.

Leaving ownership vague. When it isn't clear who reviews, who escalates, and who signs off, the honest answer is usually no one. Accountability gaps are among the first things an audit exposes, and "we assumed another team had it" is not a defense.

Treating onboarding as a one-off. Identity checks done at sign-up quickly become stale. Customers land on sanctions lists, beneficial ownership changes, transaction patterns shift. Without ongoing due diligence, you're compliant with who your customer was, not who they are now.

Training that's generic or rare. An annual e-learning module clicked through at speed doesn't prepare frontline staff to spot a red flag in the moment. Training has to be specific to people's roles and current with the typologies fraudsters are actually using.

Filing SARs late or thin. A suspicious activity report that arrives too late, or without the detail the FIU needs to act on, can be a compliance failure in its own right. Timeliness and quality both count, not just the fact that something went in.

Filing audit findings and forgetting them. An independent review is only useful if something changes because of it. When the same gaps resurface year after year, regulators stop reading them as oversights and start reading them as a culture that tolerates them.

How often should an AML policy be updated?

There is no single review schedule that applies to every business. As a practical baseline, many organizations review their AML policy at least annually and update it whenever significant changes affect their risks or regulatory obligations.

An earlier review may be necessary after:

  • Changes to AML laws, regulations, or regulatory guidance
  • Launches of new products or services
  • Entry into a new country or customer market
  • Changes to the organization’s ownership, structure, or risk appetite
  • Emergence of new money laundering or terrorist financing methods (which evolve constantly)
  • Findings from an independent audit or regulatory inspection.

AML penalties and regulatory fines

Breaches of AML regulations can lead to financial penalties, public censures, business restrictions, loss of authorization, mandatory remediation, individual prohibitions, or criminal referral. Regulators may act even without proof that a firm knowingly laundered funds if its systems and controls were inadequate.

In December 2025, the UK Financial Conduct Authority fined Nationwide Building Society £44.1 million (approx. $58.2 million) for inadequate financial crime controls. The regulator found weaknesses in the firm’s customer due diligence, risk assessments, and transaction monitoring, which prevented it from effectively identifying and managing money laundering risks.

Consequences can also include reputational harm, loss of commercial relationships, increased regulatory oversight, and ongoing exposure to financial crime.

Suggested read: Same Rule, Different Worlds: Regional Approaches to Travel Rule Implementation

AML policy template

An AML policy template can help a business organize its AML framework, but it should be treated as a starting point. The policy must be adapted to the organization’s legal obligations, customer base, products, geographic exposure, and risk assessment.

FINRA, for example, provides a free AML template designed to help small firms develop the written program required under the US Bank Secrecy Act and FINRA Rule 3310.

However, the FINRA template is designed for small US broker-dealers. Businesses in other sectors or jurisdictions should not assume that it satisfies their requirements without substantial adaptation and, where appropriate, professional legal or compliance advice.

AML policy FAQ

  • What is an AML compliance policy?

    An AML compliance policy explains how a business prevents, detects, and reports suspected money laundering and related financial crime. It defines the organization’s responsibilities, controls, risk approach, and reporting procedures.

  • What should an AML policy include?

    An AML policy should cover risk assessment, customer due diligence, identity and beneficial ownership checks, transaction monitoring, sanctions and PEP screening, suspicious activity reporting, staff training, recordkeeping, and independent testing. It should also link these requirements to clear AML procedures that employees can follow in practice.

  • What should an AML policy for crypto and fintech companies include?

    Crypto and fintech companies should tailor their policies to structural and operational risks. Structural risks come from features of the business model, including pseudonymous transactions, self-hosted wallets, cross-border reach, decentralized services, and complex ownership arrangements. Operational risks arise from how services and controls function in practice, including remote onboarding, rapid transaction flows, sanctions and wallet screening, linking on-chain activity to customer information, and reliance on automated monitoring. Where Travel Rule requirements apply, the AML policy should also explain how originator and beneficiary information is obtained, validated, securely transmitted, and retained.

  • Who is required to have an AML policy?

    Businesses covered by applicable AML regulations are generally required to maintain written policies, although the precise scope varies by jurisdiction and sector. Banks, payment providers, money service businesses, crypto companies, investment firms, casinos, and certain professional service providers may all face specific AML requirements.

  • What is a money laundering reporting officer?

    A money laundering reporting officer, or MLRO, is the person responsible for overseeing an organization’s AML framework and receiving internal reports of suspicious activity. The MLRO may also decide whether reporting is necessary and act as a key contact for regulators and senior management.

  • How often should an AML policy be reviewed?

    As a practical baseline, an AML policy should usually be reviewed at least annually and whenever material regulatory, operational, or risk changes occur. Findings from an AML audit, regulatory inspection, or changes to the wider AML compliance program should also trigger an earlier review.