Anti-Money Laundering (AML)

Anti-money laundering comprises laws, controls, and risk-based processes used to prevent, detect, investigate, and report suspected financial crime.

Anti-money laundering (AML) comprises the laws, regulations, institutional controls, and risk-based processes used to prevent, detect, investigate, and report suspected money laundering and related financial crime. AML requirements depend on the jurisdiction, regulated activity, institution type, customer, product, and transaction.

AML is not one identity check, sanctions search, software product, or reporting form. It is an operating framework that connects governance, risk assessment, customer due diligence, monitoring, investigation, reporting, recordkeeping, training, testing, and remediation.

Key Takeaways

  • Money laundering is prohibited conduct; AML is the control and regulatory framework used to address the risk.
  • A risk-based approach applies stronger measures where risk is higher and proportionate measures where risk is lower.
  • Customer identification, beneficial ownership, sanctions screening, transaction monitoring, and suspicious-activity reporting answer different questions.
  • An automated alert is not a finding of money laundering and should not replace documented investigation.
  • AML obligations vary across banks, broker-dealers, insurers, money services businesses, casinos, investment advisers, and other covered businesses.
  • More alerts or reports do not automatically mean a program is more effective.
  • AML decisions can affect access to financial services, so controls should avoid unsupported assumptions and indiscriminate de-risking.

AML vs. Money Laundering

TermWhat it describesMain evidence
Money launderingConduct involving property connected to crime under applicable lawSource, ownership, transaction trail, purpose, concealment, knowledge, and intent
AMLLegal duties and controls used to identify and mitigate laundering riskRisk assessment, policies, customer files, monitoring, investigations, reports, testing, and governance
Counter-terrorist financingControls addressing funds or assets linked to prohibited terrorist purposesSource and destination, purpose, network, official information, and applicable reporting or sanctions rules
Sanctions complianceControls addressing restrictions on parties, regions, property, goods, or transactionsList data, identity resolution, ownership, licenses, prohibitions, and transaction facts

A firm can have an AML program even when no laundering is ultimately found. Conversely, a policy manual alone does not demonstrate that controls work in practice.

The Risk-Based AML Cycle

An AML program should connect risk understanding to actual control decisions:

  1. Assess risk. Identify how customers, products, services, delivery channels, transactions, and geographies could be misused.
  2. Design controls. Set policies, ownership, data, systems, procedures, thresholds, escalation paths, and records proportionate to identified risk.
  3. Know the relationship. Identify and verify customers and relevant beneficial owners, understand purpose and expected activity, and assign risk appropriately.
  4. Monitor and investigate. Review activity, screening results, changes in customer facts, and alerts using current context.
  5. Report and respond. Follow applicable suspicious-activity, currency, sanctions, or other reporting and action requirements.
  6. Test and improve. Use independent testing, quality assurance, management information, issue tracking, and remediation to assess effectiveness.

The cycle is continuous. A customer initially assessed as lower risk can change ownership, products, geography, or transaction behavior. A higher-risk customer can also have well-understood, legitimate activity that is supportable with appropriate controls.

Core Program Components

The precise legal components differ, but an operating AML framework commonly includes:

ComponentPractical purposeEvidence of operation
GovernanceAssign accountability and oversightApproved policies, reporting lines, committee records, issue escalation
Risk assessmentIdentify exposure and prioritize resourcesMethodology, data, assumptions, risk results, change process
Customer due diligenceUnderstand identity, ownership, purpose, and expected activityVerified records, ownership information, risk rationale, review history
ScreeningIdentify potential sanctions, watch-list, or internal restrictionsList versions, match logic, disposition evidence, escalation
Transaction monitoringIdentify activity requiring reviewScenarios, thresholds, data lineage, alerts, tuning records
Investigation and reportingResolve alerts and meet applicable obligationsCase files, rationale, approvals, regulatory reports, confidentiality controls
TrainingEquip relevant staff for their responsibilitiesRole-based curriculum, attendance, assessment, updates
Independent testingEvaluate design and operating effectivenessScope, samples, findings, management responses, validation
RecordkeepingPreserve required evidence and traceabilityRetention schedule, source records, access controls, retrieval tests

Not every business is subject to identical rules or required to use the same technology. Controls should be derived from the law and risk, not copied from another institution’s checklist.

Customer Due Diligence and Ongoing Monitoring

Know Your Customer is common industry language for identity and customer-understanding processes. Customer due diligence is broader than collecting identification at account opening.

A useful customer record can address:

  • who the customer and relevant beneficial owners are;
  • who controls the relationship and can transact;
  • the nature and purpose of the account or service;
  • expected products, volumes, counterparties, and geographies;
  • source of funds or wealth where relevant to the identified risk;
  • applicable restrictions, licenses, or exemptions; and
  • when changes or activity require review.

Enhanced Due Diligence means additional measures for identified higher-risk facts. It should not be an undefined label attached to an entire nationality, industry, or customer class.

Worked Example: A Trading Company With New Activity

A small importer opens an account and provides ownership records, expected suppliers, projected monthly turnover, and invoices supporting its business. Six months later, transaction volume triples, payments begin arriving from unrelated individuals, and funds are rapidly sent to new counterparties in countries outside the original trade routes.

The changes should prompt review, but they do not prove laundering. An analyst could:

  1. confirm whether ownership, control, products, or business strategy changed;
  2. reconcile sales, purchase, shipping, customs, and tax records to the payments;
  3. identify why individuals rather than commercial customers are funding the account;
  4. review the new counterparties and ultimate beneficiaries;
  5. compare transaction timing and value with actual goods and invoices;
  6. evaluate whether the customer’s explanation is supported or contradicted;
  7. document the case decision and applicable escalation; and
  8. follow current reporting and confidentiality requirements.

A reasonable explanation might be a new marketplace sales channel. Alternatively, false invoices and unrelated third-party payments may support a different conclusion. The evidence, not the alert label, determines the disposition.

Alerts, Investigations, and SARs

Transaction-monitoring and screening systems produce leads for review. Their performance depends on complete data, appropriate scenarios, thresholds, segmentation, list quality, identity resolution, and investigator judgment.

An investigation should preserve:

  • the triggering activity and rule;
  • the relevant customer and ownership facts;
  • linked accounts, parties, devices, and transactions;
  • the time period and complete funds flow;
  • supporting and contradictory records;
  • the customer’s explanation where obtained appropriately;
  • the analyst’s reasoning, escalation, and approval; and
  • the applicable reporting or no-report decision under internal procedures.

In the United States, covered institutions may have Suspicious Activity Report obligations under the Bank Secrecy Act and implementing regulations. Rules differ by institution type and fact pattern. SARs and information revealing their existence are subject to confidentiality restrictions; staff must not tell a customer whether a SAR was filed.

Risk-Based Does Not Mean Risk-Free

The FATF risk-based approach directs countries and covered sectors to identify, assess, and understand risk and apply measures proportionate to it. It does not require equal treatment of every relationship, nor does it promise that all financial crime will be prevented.

Risk-based also does not mean automatically terminating broad categories of customers. Wholesale de-risking can reduce financial access and move activity away from transparent regulated channels. Where risk can be managed, institutions should apply appropriate controls; where it cannot be managed, the response should follow applicable law and documented policy.

Measuring AML Effectiveness

Counts alone can mislead. A large number of alerts can reflect poor calibration, while a low number can reflect weak detection. Useful management information can examine:

  • data completeness and timeliness;
  • alert quality and conversion patterns;
  • investigation age and backlog;
  • consistency of dispositions;
  • regulatory-report timeliness and quality;
  • screening false positives and match resolution;
  • overdue customer reviews;
  • control exceptions and repeat findings;
  • remediation progress; and
  • whether risk-assessment changes alter controls.

Metrics should support questions about coverage, quality, timeliness, and outcomes. They should not create pressure to file reports or close cases without evidence.

Common Mistakes

  • Treating AML, KYC, sanctions screening, and transaction monitoring as synonyms.
  • Assuming completion of onboarding checks makes ongoing monitoring unnecessary.
  • Using one transaction threshold for every customer and product.
  • Treating all alerts as suspicious or all closed alerts as false positives.
  • Collecting documents without assessing whether they explain ownership, purpose, and activity.
  • Ignoring data lineage, missing fields, duplicate customers, and system coverage.
  • Measuring success only by alert or SAR volume.
  • Applying enhanced due diligence to broad groups without an evidence-based risk rationale.
  • Telling a customer that a SAR was or was not filed.
  • Relying on old guidance, old sanctions lists, or proposed rules as if they were current final requirements.

U.S. Context

The U.S. Bank Secrecy Act and its implementing regulations establish reporting, recordkeeping, and program obligations for specified financial institutions. The USA PATRIOT Act expanded AML requirements and, for covered institutions, identifies minimum program elements such as internal controls, a designated compliance function, training, and independent testing.

The Anti-Money Laundering Act of 2020 further changed the U.S. framework. Implementation continues through regulations, exemptions, guidance, and other official actions. Firms should distinguish enacted law, final rules, proposed rules, agency guidance, and enforcement expectations rather than treating every announcement as an effective obligation.

Authoritative Sources

This article provides general AML education. It is not legal advice, a compliance program, or a decision about any customer, transaction, report, or regulated institution.

FAQs

What is the difference between AML and money laundering?

Money laundering is prohibited conduct involving property connected to crime. AML is the body of laws, controls, and processes used to identify and mitigate that risk.

Does KYC complete the AML process?

No. Customer identification is one component. AML also includes risk assessment, beneficial-ownership review, ongoing monitoring, investigation, reporting, governance, training, testing, and remediation where applicable.

Does an AML alert mean a SAR must be filed?

Not automatically. An alert requires review under the institution’s procedures. The reporting decision depends on the facts and the current rules for that institution and jurisdiction.
Browse Regulation