Skip to main content
Category: Whistleblowing and Reporting

Anti-Money Laundering

Also known as: AML, anti money laundering, AML/CFT
Simply put

Anti-money laundering (AML) refers to the laws, regulations, and procedures designed to prevent criminals from making illegally obtained money appear legitimate. Money laundering is the process of disguising the criminal origins of funds so they can be used as if they were lawfully earned. AML measures aim to detect and deter this activity, and are often paired with efforts to combat the financing of terrorism (CFT).

Formal definition

Anti-Money Laundering (AML) denotes the legislative, regulatory, and enforcement framework, together with the associated organizational controls and procedures, established to prevent, detect, and report the processing of proceeds derived from criminal activity in a manner intended to obscure their illicit origin. Money laundering itself is generally described as a multi-stage process (commonly framed as placement, layering, and integration) by which illegally obtained assets are converted or moved to appear legitimate. The scope and specific obligations of AML regimes vary by jurisdiction, sector, and entity type, and in many frameworks AML is addressed alongside Combating the Financing of Terrorism (CFT); accountability for AML programs typically sits with a designated compliance function under board and senior management oversight, though the precise allocation of duties depends on applicable law and the organization's structure. This entry is educational and does not constitute legal, audit, or compliance advice.

Why it matters

Money laundering undermines the integrity of the financial system by allowing the proceeds of crime to circulate as if lawfully earned. Because launderers typically move funds through a multi-stage process to obscure their illegal origins, financial institutions and other regulated entities can become unwitting conduits for illicit funds. AML frameworks exist to interrupt this process, and effective programs are central to an organization's ability to demonstrate financial integrity to regulators, counterparties, and the wider market.

For boards and senior management, AML is significant because accountability for the compliance program typically sits under their oversight, even though day-to-day execution rests with a designated compliance function. The scope and specific obligations of AML regimes vary by jurisdiction, sector, and entity type, so what constitutes an adequate program in one setting may fall short in another. This variability makes it important for governance professionals to understand which requirements are binding law in their operating jurisdictions and how those obligations map to the entity's structure and risk profile.

AML is frequently addressed alongside efforts to combat the financing of terrorism (CFT), reflecting the shared objective of preventing the misuse of the financial system for criminal or illicit purposes. Because obligations differ across jurisdictions and continue to depend on applicable law, organizations generally treat AML/CFT not as a static checklist but as an ongoing program subject to oversight, review, and adjustment as circumstances change.

Who it's relevant to

Boards and senior management
Boards and senior management generally hold oversight responsibility for the AML program, even where execution is delegated to a compliance function. The precise allocation of duties depends on applicable law and the organization's structure, so directors typically need to understand how the entity's AML obligations map to its jurisdictions and lines of business.
Compliance functions
Accountability for the AML program typically sits with a designated compliance function, which is responsible for implementing the controls and procedures that prevent, detect, and report the processing of criminal proceeds. The scope of these obligations varies by jurisdiction, sector, and entity type.
Regulated financial institutions and other obligated entities
Financial institutions and other entities subject to AML obligations must implement measures to prevent their services from being used to disguise the criminal origins of funds. Because AML is often paired with combating the financing of terrorism (CFT), many such entities operate integrated AML/CFT programs, though specific requirements differ across jurisdictions.
Internal audit and assurance functions
Assurance functions may be relied upon to evaluate whether the AML program's controls are appropriately designed and operating as intended. Their role is distinct from the compliance function that owns and executes the program, and the exact division of responsibilities depends on applicable law and organizational structure.

Inside AML

Customer Due Diligence (CDD)
The process of identifying and verifying the identity of customers and, where applicable, their beneficial owners, and understanding the nature and purpose of the relationship. Enhanced due diligence (EDD) is typically applied to higher-risk customers, products, or geographies. The specific requirements vary by jurisdiction, sector, and entity type.
Risk-Based Approach
A method under which an institution assesses its money laundering and terrorist financing risks and allocates resources and controls proportionately. Many AML regimes, and guidance from bodies such as the Financial Action Task Force, generally expect firms to tailor controls to assessed risk rather than apply uniform measures.
Transaction Monitoring
Ongoing surveillance of customer activity to detect patterns that may indicate money laundering, typically using rules, thresholds, or analytics. This is generally an operational, first- and second-line activity, distinct from the board's oversight role.
Suspicious Activity Reporting
The obligation, in many jurisdictions, to report suspicious transactions or activity to a designated financial intelligence unit or regulator. Reporting thresholds, formats, and confidentiality requirements differ by jurisdiction and are typically a binding legal requirement for covered entities.
Sanctions and Watchlist Screening
Screening customers and transactions against applicable sanctions lists and politically exposed person (PEP) references. While often integrated with AML programs, sanctions compliance is generally a distinct legal regime with its own requirements.
Governance and Accountability
The allocation of responsibilities for the AML program, which may include a designated compliance officer or money laundering reporting officer, management ownership of controls, and board or committee oversight of program adequacy. The precise structure depends on jurisdiction and entity type.
Recordkeeping and Training
Maintaining records of customer identification, transactions, and reports for periods specified by applicable law, and providing staff training appropriate to their roles. Retention periods and training expectations vary by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about AML.

Is anti-money laundering the same thing as anti-fraud or anti-bribery compliance?
No. Although these areas often sit within the same broader financial crime function and can share tools and data, they address different risks and typically rest on different legal regimes. Anti-money laundering (AML) generally concerns the detection and prevention of the process by which the proceeds of criminal activity are made to appear legitimate, along with related obligations such as customer due diligence, sanctions screening, and suspicious activity reporting. Anti-fraud efforts focus on preventing and detecting deception that causes loss, while anti-bribery and corruption programs address improper inducements. The specific obligations, owning functions, and applicable statutes vary by jurisdiction, sector, and entity type, so overlapping controls should not be treated as interchangeable.
Does having an AML program guarantee that an institution will not be used for money laundering?
No. AML frameworks are generally risk-based rather than guarantees of prevention. Even a well-designed program that is operating effectively reduces, but does not eliminate, residual risk. Regulators and standard-setters in many jurisdictions typically expect institutions to take reasonable, proportionate measures calibrated to their assessed risk, not to achieve a zero-failure outcome. The presence of a program should not be confused with its operating effectiveness, and periodic independent testing is generally used to assess whether controls work as designed. This entry is educational and not legal, audit, or compliance advice.
Which function typically owns AML activities, and where does board accountability sit?
Ownership generally depends on how the organization has structured its lines of defense. Front-line business units commonly own and execute day-to-day controls such as customer onboarding and transaction monitoring as a first-line responsibility, while a compliance function typically sets policy, provides oversight, and challenges the first line as a second-line role. Internal audit generally provides independent assurance over the framework as a third line. The board, often through a designated committee, typically retains oversight of the program rather than operating it, and specific role allocation varies by jurisdiction, sector, and entity type. Some regimes require a named responsible officer for AML, so the precise accountability structure depends on applicable requirements.
How should an organization decide the intensity of customer due diligence?
Under many risk-based regimes, the depth of due diligence is generally calibrated to the assessed risk of the customer, product, geography, and delivery channel. Lower-risk relationships may attract simplified measures where permitted, while higher-risk relationships typically call for enhanced due diligence, which can include additional identity verification, source-of-funds or source-of-wealth inquiries, and closer ongoing monitoring. What is permitted or required varies by jurisdiction and sector, and the determination often depends on facts and the organization's own risk assessment and professional judgment. This is a general description and not a substitute for tailored compliance advice.
How can a program distinguish control design from operating effectiveness in transaction monitoring?
Control design generally refers to whether a monitoring control is capable, in principle, of detecting the risks it is meant to address, for example whether monitoring rules or models are mapped to identified risks and calibrated to relevant thresholds. Operating effectiveness generally refers to whether the control actually functions as intended over time, for example whether alerts are generated, reviewed, escalated, and dispositioned consistently and on time. Organizations typically assess design through review of methodology and coverage, and assess operating effectiveness through testing of actual outcomes over a period. Treating the two as interchangeable can obscure whether a well-designed control is failing in practice.
What is the typical role of independent testing in an AML program?
Independent testing generally provides objective assurance over whether the AML framework is both appropriately designed and operating effectively, separate from the functions that own and manage the controls. In many structures this assurance is provided by internal audit or an equivalent independent party, and in some cases external specialists are used. Testing typically evaluates areas such as risk assessment, customer due diligence, screening, monitoring, and reporting processes, and reports findings to the board or a designated committee to support its oversight. The required frequency, scope, and independence standards vary by jurisdiction, sector, and entity type, and depend on applicable requirements and the organization's judgment.

Common misconceptions

AML compliance is fully achieved by adopting a single global framework or standard.
AML requirements are set by binding law and regulation that vary significantly by jurisdiction, sector, and entity type. Bodies such as the Financial Action Task Force issue recommendations and guidance that inform national regimes, but they are generally not themselves directly enforceable law, and firms must comply with the specific rules applicable to them.
AML is solely the responsibility of the compliance function.
AML controls are typically executed operationally by first-line business units, monitored and advised on by a second-line compliance function, and independently tested by internal audit as a third line. The board or a relevant committee generally holds oversight responsibility for program adequacy, while day-to-day execution sits with management. These roles should not be conflated.
Filing a suspicious activity report resolves the institution's obligations for that matter.
Reporting is one component of an AML program. In many jurisdictions firms must also continue appropriate due diligence, monitoring, and recordkeeping, and may face separate obligations regarding the ongoing relationship. Whether and how to act further depends on the facts, applicable law, and professional judgment.

Best practices

Adopt a documented risk-based approach that assesses money laundering and terrorist financing risk across customers, products, geographies, and channels, and align controls proportionately to the assessed risk.
Clearly define and document the allocation of AML responsibilities across the first, second, and third lines, distinguishing management's ownership of controls from the board or committee's oversight role.
Confirm the specific binding obligations applicable to the entity in each relevant jurisdiction, since customer due diligence, reporting, recordkeeping, and retention requirements vary by jurisdiction, sector, and entity type.
Periodically evaluate both the design and the operating effectiveness of transaction monitoring, screening, and due diligence controls, rather than assuming that a control's existence demonstrates it is working.
Provide role-appropriate training and maintain records sufficient to evidence customer identification, monitoring decisions, and any reports filed, in line with applicable retention periods.
Engage qualified legal, compliance, or audit professionals for jurisdiction-specific requirements and fact-dependent judgments, treating educational guidance as a starting point rather than a substitute for advice.