Anti-Money Laundering (AML)
Anti-money laundering, usually shortened to AML, is the body of law, regulation and internal controls requiring financial firms to detect, prevent and report attempts to disguise the origin of criminal proceeds. It is an obligation placed on the firm, not a product the firm can buy.
Also called: AML compliance
Anti-money laundering is not one control. It is a stack of them, imposed by law on firms that handle other people’s money, covering the whole life of a customer relationship: identifying who the customer is, understanding what they should plausibly be doing, watching what they actually do, checking them against government lists, and reporting what looks wrong to the national financial intelligence unit. Counter-terrorist financing duties usually travel in the same rules, which is why the pairing AML/CFT is so common.
The individual pieces have their own names. Know Your Customer and customer due diligence cover onboarding and the ongoing risk picture. Transaction monitoring and sanctions screening cover activity. The AML program is the documented structure that holds them together and assigns responsibility for each.
What the law requires depends entirely on where the firm is regulated. In the United States the obligations sit under the Bank Secrecy Act and the rules FinCEN writes beneath it. The European Union works through its money laundering directives, transposed country by country. The United Kingdom has its own regulations. FATF sets the international standard all three broadly follow, but it is a standard, not a statute.
In practice
Anti-money laundering is an obligation placed on the firm, not a product the firm can buy. Outsourcing the tooling — monitoring, screening, identity checks — does not outsource the legal responsibility, and no vendor contract moves it.
Example
A payments firm buys a well-regarded monitoring platform and switches it on. Six months later a regulator asks why nine hundred alerts are unreviewed. The vendor contract covers uptime and detection rules; nothing in it makes the vendor answerable for the firm’s failure to look at the output. The tooling was bought. The obligation never moved.
Commonly confused with
| Term | How it differs |
|---|---|
| AML Program | The program is one firm’s documented controls; anti-money laundering is the wider legal regime those controls exist to satisfy. |
| Counter-terrorist financing | CTF targets the destination and purpose of funds that may be entirely lawful in origin, while AML targets money that is already criminal proceeds. |
See also
- AML ProgramAn AML program is the documented set of controls a regulated firm must maintain to detect and deter money laundering. In the United States it is conventionally described as four pillars: written policies and procedures, a designated compliance officer, staff training, and independent review. Other regimes frame the same components differently.
- Bank Secrecy ActThe Bank Secrecy Act is the 1970 United States statute, heavily amended since, that requires banks, money services businesses and other financial institutions to keep records, register where applicable, report large cash transactions and suspicious activity, and maintain an anti-money-laundering program.
- Know Your CustomerKnow Your Customer, or KYC, is the process of identifying and verifying a customer before a business relationship starts and keeping that understanding current while it lasts, so a firm knows who it is actually dealing with. Identity verification is the first step of KYC, not the whole of it.
- Transaction MonitoringTransaction monitoring is the ongoing review of customer activity — automated rules and models plus human investigation — against what the firm expected that customer to do and against known laundering patterns. Activity that does not fit produces an alert for someone to work.
- FATFThe Financial Action Task Force, or FATF, is the intergovernmental body that sets the international standards for anti-money-laundering and counter-terrorist financing, assesses countries against them, and maintains the lists — informally the grey list and the black list — that drive country risk ratings across the industry.
