Anti-money laundering comprises laws, controls, and risk-based processes used to prevent, detect, investigate, and report suspected financial crime.
Anti-money laundering (AML) comprises the laws, regulations, institutional controls, and risk-based processes used to prevent, detect, investigate, and report suspected money laundering and related financial crime. AML requirements depend on the jurisdiction, regulated activity, institution type, customer, product, and transaction.
AML is not one identity check, sanctions search, software product, or reporting form. It is an operating framework that connects governance, risk assessment, customer due diligence, monitoring, investigation, reporting, recordkeeping, training, testing, and remediation.
| Term | What it describes | Main evidence |
|---|---|---|
| Money laundering | Conduct involving property connected to crime under applicable law | Source, ownership, transaction trail, purpose, concealment, knowledge, and intent |
| AML | Legal duties and controls used to identify and mitigate laundering risk | Risk assessment, policies, customer files, monitoring, investigations, reports, testing, and governance |
| Counter-terrorist financing | Controls addressing funds or assets linked to prohibited terrorist purposes | Source and destination, purpose, network, official information, and applicable reporting or sanctions rules |
| Sanctions compliance | Controls addressing restrictions on parties, regions, property, goods, or transactions | List data, identity resolution, ownership, licenses, prohibitions, and transaction facts |
A firm can have an AML program even when no laundering is ultimately found. Conversely, a policy manual alone does not demonstrate that controls work in practice.
An AML program should connect risk understanding to actual control decisions:
The cycle is continuous. A customer initially assessed as lower risk can change ownership, products, geography, or transaction behavior. A higher-risk customer can also have well-understood, legitimate activity that is supportable with appropriate controls.
The precise legal components differ, but an operating AML framework commonly includes:
| Component | Practical purpose | Evidence of operation |
|---|---|---|
| Governance | Assign accountability and oversight | Approved policies, reporting lines, committee records, issue escalation |
| Risk assessment | Identify exposure and prioritize resources | Methodology, data, assumptions, risk results, change process |
| Customer due diligence | Understand identity, ownership, purpose, and expected activity | Verified records, ownership information, risk rationale, review history |
| Screening | Identify potential sanctions, watch-list, or internal restrictions | List versions, match logic, disposition evidence, escalation |
| Transaction monitoring | Identify activity requiring review | Scenarios, thresholds, data lineage, alerts, tuning records |
| Investigation and reporting | Resolve alerts and meet applicable obligations | Case files, rationale, approvals, regulatory reports, confidentiality controls |
| Training | Equip relevant staff for their responsibilities | Role-based curriculum, attendance, assessment, updates |
| Independent testing | Evaluate design and operating effectiveness | Scope, samples, findings, management responses, validation |
| Recordkeeping | Preserve required evidence and traceability | Retention schedule, source records, access controls, retrieval tests |
Not every business is subject to identical rules or required to use the same technology. Controls should be derived from the law and risk, not copied from another institution’s checklist.
Know Your Customer is common industry language for identity and customer-understanding processes. Customer due diligence is broader than collecting identification at account opening.
A useful customer record can address:
Enhanced Due Diligence means additional measures for identified higher-risk facts. It should not be an undefined label attached to an entire nationality, industry, or customer class.
A small importer opens an account and provides ownership records, expected suppliers, projected monthly turnover, and invoices supporting its business. Six months later, transaction volume triples, payments begin arriving from unrelated individuals, and funds are rapidly sent to new counterparties in countries outside the original trade routes.
The changes should prompt review, but they do not prove laundering. An analyst could:
A reasonable explanation might be a new marketplace sales channel. Alternatively, false invoices and unrelated third-party payments may support a different conclusion. The evidence, not the alert label, determines the disposition.
Transaction-monitoring and screening systems produce leads for review. Their performance depends on complete data, appropriate scenarios, thresholds, segmentation, list quality, identity resolution, and investigator judgment.
An investigation should preserve:
In the United States, covered institutions may have Suspicious Activity Report obligations under the Bank Secrecy Act and implementing regulations. Rules differ by institution type and fact pattern. SARs and information revealing their existence are subject to confidentiality restrictions; staff must not tell a customer whether a SAR was filed.
The FATF risk-based approach directs countries and covered sectors to identify, assess, and understand risk and apply measures proportionate to it. It does not require equal treatment of every relationship, nor does it promise that all financial crime will be prevented.
Risk-based also does not mean automatically terminating broad categories of customers. Wholesale de-risking can reduce financial access and move activity away from transparent regulated channels. Where risk can be managed, institutions should apply appropriate controls; where it cannot be managed, the response should follow applicable law and documented policy.
Counts alone can mislead. A large number of alerts can reflect poor calibration, while a low number can reflect weak detection. Useful management information can examine:
Metrics should support questions about coverage, quality, timeliness, and outcomes. They should not create pressure to file reports or close cases without evidence.
The U.S. Bank Secrecy Act and its implementing regulations establish reporting, recordkeeping, and program obligations for specified financial institutions. The USA PATRIOT Act expanded AML requirements and, for covered institutions, identifies minimum program elements such as internal controls, a designated compliance function, training, and independent testing.
The Anti-Money Laundering Act of 2020 further changed the U.S. framework. Implementation continues through regulations, exemptions, guidance, and other official actions. Firms should distinguish enacted law, final rules, proposed rules, agency guidance, and enforcement expectations rather than treating every announcement as an effective obligation.
This article provides general AML education. It is not legal advice, a compliance program, or a decision about any customer, transaction, report, or regulated institution.