AML stands for anti-money laundering — the laws, regulations, and procedures that stop criminals from disguising illegally obtained money as legitimate funds. The UNODC estimates 2-5% of global GDP, roughly USD 800 billion to 2 trillion, is laundered every year, which is why regulated businesses are legally required to build a documented programme around screening, monitoring, and reporting, not just react to individual suspicious transactions.
Where did AML regulation come from?
The modern AML framework traces back to the US Bank Secrecy Act of 1970, which required financial institutions to report certain transactions and keep detailed records — originally aimed at organised crime and tax evasion rather than terrorism financing, which was folded in decades later. Nineteen years after the BSA, the Financial Action Task Force (FATF) was established as the intergovernmental body that now sets global AML/CTF standards through its 40 Recommendations, with national regulators — AUSTRAC in Australia, FinCEN in the US, the FCA in the UK — translating those standards into domestic law and enforcing them. FATF itself doesn't fine anyone directly; its main lever is the public "grey list" and "black list" of countries with strategic AML deficiencies, which makes it materially harder and more expensive for a listed country's banks to access global correspondent banking.
What does a documented AML programme actually contain?
Regulators generally expect the same structural components regardless of jurisdiction, often described as the programme's core pillars:
- A named AML/CTF compliance officer with the authority and seniority to act, not just a policy document with no owner.
- A written, risk-based AML policy setting out how the business identifies, assesses, and manages money-laundering and terrorism-financing risk across its customers, products, and delivery channels.
- Customer due diligence procedures, tiered by risk — standard checks for most customers, enhanced due diligence for higher-risk ones such as PEPs or customers in high-risk jurisdictions.
- Ongoing sanctions and PEP screening at onboarding and on a continuing basis, since watchlists change daily.
- Transaction monitoring to catch suspicious activity that due diligence alone wouldn't surface.
- A suspicious matter/activity reporting process to the relevant financial intelligence unit, with staff trained to recognise and escalate red flags.
- Independent review or audit of the programme's effectiveness, so gaps get found internally before a regulator finds them.
A business missing any one of these pillars typically fails an AML audit even if the others are strong — regulators assess the programme as a system, not a checklist of unrelated controls.
Why does AML compliance matter beyond avoiding penalties?
Non-compliance triggers real enforcement action — civil penalties, enforceable undertakings, and in serious cases the loss of a banking licence or correspondent banking relationships — but the underlying purpose is broader. AML controls protect a business from being unknowingly used to move criminal proceeds, and protect the wider financial system's integrity. A business with weak controls is a more attractive route for launderers, and once a bank is known (even informally, among correspondent banks) to have weak controls, other institutions become reluctant to deal with it at all — a phenomenon regulators call de-risking, and one of the more expensive, hard-to-reverse consequences of a poor AML track record.
How does AML fit with KYC and screening?
AML is the overall framework; KYC and sanctions screening are two of the controls that sit underneath it. An AML risk assessment is what ties these controls together — scoring each customer's risk so the right level of due diligence gets applied automatically rather than case by case.



