A complete guide to AML compliance, covering who has to comply, the requirements by regime, what a programme contains, the full lifecycle from onboarding to record keeping, and where programmes fail.
When the Titanic sailed in April 1912, she carried more lifeboats than the law asked of her. The Board of Trade’s table topped out at 10,000 tons and asked for sixteen boats; White Star put twenty aboard, and the British inquiry later called that a number far in excess of the requirements. Those boats held roughly 1,176 people while more than 2,200 were aboard, so the rule was satisfied in full and still measured the wrong thing, which is why the Commissioner recommended counting passengers, not tonnage.
Compliance regimes fail the same way, which is why supervisors now grade the outcome and not the paperwork. According to the Financial Action Task Force (FATF), whose assessment methodology governs how national systems are reviewed, “the emphasis of any assessment is on effectiveness.” This guide covers AML compliance requirements, who they apply to, what a programme contains, and where documented programmes come apart.
What Is AML Compliance?
AML compliance is the set of laws, internal controls, and evidencing obligations that require a business to detect, prevent, and report money laundering and terrorist financing, and to demonstrate to a supervisor that it has actually done so. The last part of that definition does most of the work in practice, because a control that cannot be evidenced is treated by an examiner as a control that was not applied.
What Anti-Money Laundering Compliance Covers
Anti-money laundering compliance covers the full customer relationship rather than a single checkpoint at sign-up. It begins with understanding the risks a business is exposed to, extends through verifying customers and screening them against sanctions and politically exposed person lists, continues through monitoring their behaviour for as long as the relationship lasts, and ends with reporting suspicion and retaining the evidence.
According to the United Nations Office on Drugs and Crime, laundering typically follows placement, layering, and integration, although the agency notes that real cases may combine or repeat those stages rather than show all 3 stages of money laundering. Controls are therefore spread deliberately rather than concentrated at sign-up, since a programme weighted entirely toward onboarding will often miss the layering activity that only becomes visible once money moves.
AML, CFT, and the Terms Used Alongside Them
Several acronyms describe overlapping obligations and are frequently used interchangeably. AML refers to anti-money laundering, while CFT refers to countering the financing of terrorism, and the combined forms AML/CFT and AML/CTF appear because the two control sets overlap heavily and are usually run as one programme. In the United States, the same obligations are often described as BSA/AML compliance, after the Bank Secrecy Act that established them.
Who Has to Comply With AML Regulations?
AML regulations attach to what regulators call obliged entities, and that population has widened steadily rather than staying with banks. If your business holds, moves, converts, or safeguards other people’s money, you are almost certainly in scope somewhere.
The perimeter runs across regulated finance and well beyond it. Banks, payment institutions, electronic money firms, and investment businesses have been covered longest, while crypto asset service providers were pulled in over the past decade and now carry some of the fastest-moving obligations. Gaming operators, lenders, insurers, and money service businesses sit alongside them, and most regimes also capture designated non-financial businesses and professions, the category covering lawyers, accountants, trust and company service providers, estate agents, and dealers in high-value goods.
| Sector | Where the AML Pressure Concentrates |
| Banking | Large monitoring operations, frequent examination, legacy systems under review |
| Fintech and payments | High-volume onboarding where automation decides whether controls scale |
| Crypto and virtual assets | Travel rule obligations, wallet exposure, and the newest rulebooks |
| Gaming and gambling | Source-of-funds checks and rapid deposit and withdrawal cycles |
| Professional services and high-value dealers | Captured as DNFBPs, often with the least mature programmes |
Risk profiles differ sharply, but the obligations do not scale down. A smaller firm applies the same components proportionately rather than skipping them, which is what a risk-based approach means.
Why AML Compliance Matters
Beyond the legal duty, AML compliance decides whether a business keeps its licence and its banking relationships, which is why it tends to be treated as an operating requirement rather than a cost centre.
The scale of the underlying problem is genuinely uncertain. According to UNODC, the estimated amount laundered globally in one year is 2 to 5 percent of global GDP, or 800 billion to 2 trillion US dollars, although the agency is explicit that the clandestine nature of the activity makes the total difficult to estimate reliably. That figure is directional rather than precise, and its practical significance for a regulated business is that supervisors treat the sector as a permanent target rather than an occasional one.
Failure is expensive in more ways than the fine. Penalties regularly reach into the hundreds of millions, as Shufti’s review of record-breaking AML fines sets out, and the secondary consequences usually cost more. Persistent breaches can restrict a licence, banking partners withdraw correspondent relationships, remediation runs for years, and in several jurisdictions compliance officers and senior managers can be held personally accountable.
The requirements are also moving rather than settled. In the United Kingdom, the Money Laundering and Terrorist Financing (Amendment) Regulations 2026 were made on 9 June 2026 and amend the principal regulations across more than ninety separate effects, with most provisions in force from 30 June 2026 and enhanced due diligence for cryptoasset exchange providers, custodian wallet providers and correspondent relationships following on 1 February 2027. Any UK programme documented against the original 2017 text is therefore out of date in specific and examinable ways.
What Are the Main AML Compliance Requirements?
The main AML compliance requirements are consistent in substance across the major regimes, which is why FATF standards translate reasonably cleanly into national law. Wherever you operate, you will be asked for a documented risk assessment, customer due diligence, ongoing monitoring, sanctions screening and politically exposed person screening, suspicious activity reporting, record retention, training, and independent testing under a named officer.
| Regime | What It Requires | Status and Date | Primary Source |
| FATF (global standard setter) | Technical compliance with the 40 Recommendations, assessed separately from effectiveness, which is measured across eleven immediate outcomes and carries the emphasis in any assessment | Methodology adopted 22 February 2013, last amended June 2023 | FATF Methodology |
| United States (Bank Secrecy Act) | Internal policies, procedures and controls, a designated compliance officer, ongoing employee training, and an independent audit function to test programmes | In force, 31 U.S.C. § 5318(h) as amended by the Anti-Money Laundering Act of 2020 | 31 U.S.C. § 5318 |
| European Union | A single directly applicable rulebook covering due diligence, beneficial ownership and reporting, with a central authority directly supervising selected entities under a separate regulation | Rulebook applies from 10 July 2027, direct supervision from 2028 | Regulation (EU) 2024/1624 and Regulation (EU) 2024/1620 |
| United Kingdom | Risk assessment, policies and controls, due diligence and enhanced due diligence, reporting and record keeping under the 2017 regulations | In force and amended, most recently with effect from 30 June 2026 | SI 2017/692 |
The US wording warrants a closer look, because it does two different jobs. Section 5318(h)(1) puts four things on the institution as a hard duty, which are internal policies, a compliance officer, training, and an independent audit. Section 5318(h)(2)(B) then turns to the regulator instead, telling the Treasury and the federal supervisors what to weigh when they write the standards and when they examine a firm against them.
What they are told to weigh is that programmes should be “reasonably designed to assure and monitor compliance” and should be “risk-based”, which the section expands to include putting more attention and resources on higher-risk customers and activities than on lower-risk ones, consistent with the firm’s own risk profile. Therefore, the four components are the part you must have in place, while the way you aim them is what an examiner is told to weigh.
What Goes Into an AML Compliance Programme?
An AML compliance programme has seven working components, four of which appear in US law as an explicit statutory minimum. Each is a discipline in its own right, so the summary below is deliberately short and links through to the detail.
- Risk assessment: A documented, business-wide assessment of exposure across customers, products, delivery channels, and geographies, which sets the appetite everything else is calibrated against. See how a risk-based approach works in practice.
- Written policies, procedures, and controls: The documented translation of that appetite into operating rules, approved at board level and reconciled against the regulations currently in force.
- Customer due diligence and enhanced due diligence: Identity verification and risk rating for every customer, with stronger measures for higher-risk relationships.
- Ongoing transaction monitoring: Continuous review of customer activity against expected behaviour.
- Sanctions, PEP, and adverse media screening: Screening at onboarding and on an ongoing basis as lists change.
- Suspicious activity reporting and record keeping: Escalation, investigation, filing, and retention of the evidence and the reasoning behind each decision.
- Training, independent testing, and a named officer: Periodic training tailored to functional risk exposure, independent testing by qualified personnel, and a compliance officer with genuine authority to act.

Shufti’s knowledge base entry on the AML compliance program covers the framework in more depth, and the five pillars of anti money laundering compliance unpacks the statutory core.
How Does the AML Compliance Lifecycle Work?
The four operational components run as a sequence across the customer relationship rather than as separate projects, and most failures happen in the handoffs between them.
Customer Due Diligence at Onboarding
Customer due diligence establishes who the customer is, what they intend to do, and how much risk they carry, before access is granted. Standard measures cover identity verification and beneficial ownership for corporate customers, while enhanced due diligence applies to higher-risk relationships such as politically exposed persons, complex ownership structures, and customers in high-risk jurisdictions. The customer due diligence entry sets out the standard measures in full.
Sanctions, PEP, and Adverse Media Screening
Screening checks customers and counterparties against sanctions lists, politically exposed person databases, watchlists, and adverse media, at onboarding and continuously as those lists change. The difficulty is rarely coverage and almost always thresholds, since a setting tuned too tight buries analysts in false positives while one tuned too loose misses the match that mattered. Shufti’s guide to AML screening covers how the sources fit together.
Ongoing Transaction Monitoring
Transaction monitoring reviews activity against the behaviour a customer’s profile predicts, escalating what does not fit. A customer who passed onboarding cleanly may become a money mule months later, which is why regulators most often find this component deficient. The transaction monitoring guide covers rule design and alert triage.
Suspicious Activity Reporting
Where monitoring or an analyst raises a genuine suspicion, the obligation is to report it to the national financial intelligence unit, and the timing is part of the obligation rather than an administrative detail. Most regimes require filing as soon as practicable or without undue delay, and several bar the firm from telling the customer, which is the tipping-off prohibition.
What trips firms up is usually the internal path rather than the filing itself. A suspicion normally travels from the front line to the compliance officer, who decides whether it meets the threshold, and every step of that journey has to be evidenced with dates. A report that was correct in substance but sat in a queue for weeks is treated as a failure, because the intelligence reaches law enforcement too late to be useful.
Record Keeping and Retention
Record keeping is the component that decides whether everything above can be proven, and it is the one most often treated as an afterthought. Retention periods are set regime by regime, and five years is the common baseline. Regulation (EU) 2024/1624 is typical in requiring records to be kept for five years from the end of the business relationship or the date of an occasional transaction.
The scope matters more than the duration. Retaining a passport copy is straightforward, while retaining the reasoning behind a decision is what an examiner actually asks for, including why a customer was rated medium rather than high, why an alert was dismissed, why a threshold sat where it did, and who approved each call. Firms that store outcomes without rationale usually discover the gap during an inspection, when reconstructing the reasoning years later is no longer possible.
Why Documented AML Programmes Fail Inspection
Having a control is not the same as running it, and supervisors increasingly test the second thing. The clearest recent illustration comes from Ireland, where the Central Bank fined Coinbase Europe Limited €21,464,734 in an enforcement action published on 6 November 2025, reduced from €30,663,906 after a settlement discount and confirmed by the High Court on 12 January 2026. The firm was a licensed virtual asset service provider with a transaction monitoring system already deployed, and the breaches ran from April 2021 to March 2025.
The Central Bank attributed the fine to faults in the configuration of that monitoring system. Some 30,442,437 transactions went unmonitored over twelve months, amounting to over €176 billion and roughly 31 percent of the firm’s transactions in that window, and completing the monitoring then took almost three years. The eventual review produced 2,708 suspicious transaction reports carrying suspicions of money laundering, fraud, drug trafficking, cyber attacks, and child sexual exploitation, all reaching the authorities years later than they should have.
The rest of the settlement matters more than the headline figure. The firm also admitted failing to adopt internal policies, controls, and procedures to prevent and detect money laundering and terrorist financing, and failing to conduct additional monitoring on a further 184,790 transactions. The deployed system was therefore surrounded by a governance layer that was itself deficient, which is usually how a configuration fault survives undetected for a year and takes three more to remediate.
This pattern holds because the failure point in mature programmes is usually organisational rather than technical. Andrei Sribny of the AML Certification Center makes the point that the remaining gap is almost always created upstream through weak governance and unclear control ownership, where organisations rely on advanced tools while the policies have not been updated in years and ownership of key controls stays vague. In many such cases, he observes, verification does not break down because the system fails but because the organisation fails to use it properly.
Ownership is therefore the variable that matters most, and it is rarely a question of capability. Noor Ali of Bit Comply observes that the technical capability of modern risk engines already exists, so the gap is almost always governance rather than technology, and someone has to own it, document the rationale, obtain board sign-off, and explain to a regulator why a weighting changed. Where that ownership is diffused across compliance, risk, technology, and the vendor, nothing gets updated.
Ray Blake of The Dark Money Files, a former head of compliance and money laundering reporting officer, notes that recent actions have largely concluded that firms had appropriate systems and did the right things but did not do them consistently, reliably, or quickly enough. Therefore, the practical question is no longer whether each component exists, but whether each can be shown to have worked, on which dates, with which settings, and with what result.
AML Compliance Checklist
A useful AML compliance checklist asks two questions of every item rather than one. The first question is whether the control exists, and the second, which is where inspections are decided, is whether you could evidence that it worked during a specific period.
- Business-wide risk assessment completed, documented, dated, and approved, with a record of what changed since the previous version.
- Policies, controls and procedures written, board-approved, and reconciled against the regulations currently in force, not the version in force when they were drafted.
- A compliance officer appointed with defined authority, and evidence that the role has exercised it.
- Customer due diligence applied to every customer, with enhanced due diligence triggered by documented criteria, not analyst discretion.
- Screening configured against sanctions, politically exposed persons, and adverse media sources, with thresholds recorded and the rationale for any change retained.
- Transaction monitoring live, with tested confirmation that rules are firing as designed and coverage gaps are detected quickly.
- Suspicious activity reports filed within the statutory window, with the escalation timeline evidenced.
- Records retained for the required period, including the reasoning behind decisions and not only their outcomes.
- Training delivered and completion recorded, tailored to each function’s risk exposure.
- Independent testing commissioned, with findings tracked to closure and fed back into the risk assessment.
What Does the AML Compliance Process Look Like?
Building a programme is a loop rather than a launch, and the five steps below are ordered because each one calibrates the next. As Ray Blake describes it, the workable position sits at the intersection of routinely meeting regulatory expectations, not driving customers away with a poor experience, and earning a reasonable return, and it has to start with a decent whole-firm risk assessment against financial crime.
- Assess the risk: Map exposure across customers, products, jurisdictions, and channels, then record the reasoning behind each rating.
- Document policies and governance: Write the policies the assessment implies, define who owns each control, and appoint the officer who answers for the programme. This is the step that determines whether anything gets updated later.
- Apply due diligence and screening at onboarding: Verify identity, establish beneficial ownership, and set thresholds deliberately, since a vendor default is hard to defend when an examiner asks why it was chosen.
- Monitor and report continuously: Investigate alerts, rescreen as lists change, and file within the statutory window. Periodic testing of whether rules are actually firing belongs here rather than in the annual audit alone.
- Train, test, and improve: Route independent testing findings back into the risk assessment, because a programme that is never revised drifts out of alignment within a year or two.
KYC vs AML Compliance
Know Your Customer is the identity verification and due diligence process that establishes who a customer is and how risky they are, while AML compliance is the wider framework of law and controls that KYC sits inside.
| KYC | AML Compliance | |
| Scope | Customer identity and risk rating | The whole financial crime control framework |
| Timing | Mainly at onboarding, plus periodic review | Continuous, across the full customer lifecycle |
| Includes | Identity verification, CDD, EDD | KYC plus monitoring, screening, reporting, record keeping |
The full comparison, including where KYB fits, is covered in KYC vs AML.
Who Is Responsible for AML Compliance in a Company?
Legal responsibility sits with the business as a whole, but it is discharged through a named compliance officer, often titled the money laundering reporting officer, who owns the programme and reports to senior management. In most regimes, that appointment is a statutory requirement rather than a matter of structure, and the officer must hold genuine authority to escalate, restrict, and report.
Accountability does not stop there. Senior management and the board approve the risk appetite and the policies that follow from it, which is why the board sign-off Noor Ali describes matters when a weighting or a threshold changes. Operationally, most regulated firms distribute the work across three lines of defence, where the business owns the risk it creates, compliance and risk set and oversee the standards, and internal audit tests independently whether either is working.
How Shufti Helps Compliance Teams Evidence AML Decisions
The hardest part of an inspection is usually not showing that a control existed; it is showing why a specific decision was made on a specific date and being able to defend the reasoning behind it. Screening tools that return a match score without an explanation leave that burden with the analyst, and the record often ends up thinner than the examiner expects.
Shufti’s AML screening covers sanctions, politically exposed persons, adverse media, and watchlist screening sources for individuals and businesses, with match scoring that compliance teams calibrate to their own risk appetite rather than a vendor default. Scoring stays explainable at field level and tunable without an engineering ticket, so an analyst can see which elements drove a match, and a team can record why a threshold sits where it does at the time the decision is made.
Frequently Asked Questions
What are the main AML compliance requirements?
Every major regime requires a documented risk assessment, customer due diligence, ongoing transaction monitoring, sanctions and PEP screening, suspicious activity reporting, record keeping, staff training, and independent testing, all under a designated compliance officer.
Who is responsible for AML compliance in a company?
A designated compliance officer, often the money laundering reporting officer, owns the programme day to day. The board and senior management approve the risk appetite and policies, and in several jurisdictions both can be held personally liable for failures.
Is AML compliance a legal requirement?
Yes. For regulated businesses, it is a statutory duty, set out in instruments such as 31 U.S.C. § 5318(h) in the United States, the Money Laundering Regulations 2017 in the United Kingdom, and Regulation (EU) 2024/1624 across the European Union from July 2027.
Which businesses have to comply with AML regulations?
Banks, payment and e-money firms, investment businesses, crypto asset service providers, gaming operators, lenders, and insurers are all in scope, alongside designated non-financial businesses and professions such as lawyers, accountants, trust and company service providers, and high-value dealers.
How long do AML records have to be kept?
Retention periods are set by each regime and commonly run to five years after the relationship ends, or the transaction completes. Check the specific rule in every jurisdiction you operate in, since some require longer and supervisors can extend the period.















