AML/CFT Compliance Program

AML/CFT Compliance Program: Governance, Policies, Controls and Checklist

An AML/CFT compliance program is the complete system through which an obliged entity identifies, assesses, manages and monitors its exposure to money laundering, terrorist financing and targeted-financial-sanctions risks.

It is not limited to a written AML policy or the appointment of an AML compliance officer. An effective program combines:

  • management accountability;
  • a business-wide risk assessment;
  • written policies and operational procedures;
  • customer due diligence;
  • beneficial ownership controls;
  • customer risk classification;
  • PEP and sanctions screening;
  • ongoing and transaction monitoring;
  • suspicious transaction reporting;
  • employee training;
  • data and technology controls;
  • independent testing; and
  • documented remediation of weaknesses.

Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation, or AMLR, establishes directly applicable requirements for obliged entities. It generally applies from 10 July 2027 and introduces a more harmonised European framework for AML/CFT governance, risk management, customer due diligence and internal controls.

An AML compliance program must therefore do more than reproduce legal requirements. It must translate those requirements into an operating model that is appropriately designed, consistently implemented and demonstrably effective.

What is an AML/CFT compliance program?

An AML/CFT compliance program is the structured combination of governance arrangements, risk assessments, policies, procedures, systems and controls used to prevent an organisation from being misused for money laundering or terrorist financing.

Its core purpose is to ensure that the obliged entity can:

  1. understand the financial-crime risks arising from its business;
  2. determine which controls are needed;
  3. apply proportionate customer due diligence;
  4. detect unusual or suspicious activities;
  5. comply with sanctions-related obligations;
  6. report relevant suspicions to the competent Financial Intelligence Unit;
  7. maintain reliable records; and
  8. demonstrate compliance to supervisors and auditors.

A mature AML compliance program connects the entity’s risk assessment with its operational controls. Higher risks should result in stronger customer due diligence, approval, monitoring and assurance measures. Lower risks may justify proportionate simplification only where this is legally permitted and properly documented.

AML/CFT compliance program at a glance

ComponentPrincipal objective
Management governanceEstablish accountability, direction and oversight
Business-wide risk assessmentIdentify inherent risks and evaluate control effectiveness
AML/CFT policiesDefine mandatory organisational principles and standards
AML/CFT proceduresTranslate policies into operational steps
Customer due diligenceIdentify customers, beneficial owners and relationship purposes
Customer risk assessmentDetermine the appropriate level of controls
PEP and sanctions controlsDetect heightened corruption and sanctions risks
Ongoing monitoringKeep customer information and risk assessments current
Transaction monitoringDetect unusual or suspicious activities
Suspicious transaction reportingEscalate and report relevant suspicions
Training and integrityEnsure competent and reliable employees
Data and technology controlsSupport accurate, complete and auditable processes
Independent auditTest design and operating effectiveness
RemediationCorrect identified weaknesses and prevent recurrence

1. AML/CFT governance and management responsibility

Effective AML/CFT compliance begins with clear responsibility at management-body level.

Article 11 AMLR requires obliged entities to appoint a member of the management body in its management function as the compliance manager. The compliance manager is responsible for ensuring compliance with the AMLR, Regulation (EU) 2023/1113 and relevant supervisory acts.

The compliance manager must ensure that:

  • internal policies, procedures and controls reflect the entity’s risk exposure;
  • those arrangements are implemented;
  • sufficient human and material resources are available;
  • significant or material weaknesses are reported and addressed; and
  • the management body receives adequate information about the AML/CFT framework.

The AMLR also requires the appointment of a compliance officer responsible for the day-to-day operation of the AML/CFT framework. The compliance officer should have sufficient authority, access to information and hierarchical standing to perform the role effectively.

Compliance manager vs. compliance officer

RolePrincipal responsibility
Compliance managerManagement-body accountability for AML/CFT compliance
Compliance officerDay-to-day operation of the AML/CFT framework
Business functionsApplication of controls within customer and transaction processes
Internal auditIndependent testing of the control framework
Management bodyApproval, oversight and challenge

The functions should be distinguished clearly in organisational documents, committee terms of reference and responsibility matrices.

Governance documentation should include

  • formal appointment decisions;
  • role profiles;
  • delegated authorities;
  • reporting lines;
  • committee structures;
  • escalation rules;
  • information rights;
  • conflict-of-interest arrangements;
  • succession and deputy arrangements;
  • resource and staffing decisions.

A nominal appointment without sufficient authority, staffing, data access or management support does not establish an effective compliance function.

2. Business-wide risk assessment

The business-wide risk assessment, or BWRA, is the foundation of the AML/CFT compliance program.

Article 10 AMLR requires obliged entities to identify and assess:

  • money laundering risks;
  • terrorist financing risks; and
  • risks associated with the non-implementation or evasion of targeted financial sanctions.

The assessment must be proportionate to the entity’s nature, size, risks and complexity. It must consider, among other matters:

  • customer types;
  • products and services;
  • transactions;
  • delivery channels;
  • geographical exposure;
  • relevant EU and national risk assessments;
  • sector-specific information;
  • supervisory publications;
  • the entity’s customer base;
  • new products and technologies.

AMLA’s 2026 draft guidelines describe the BWRA as a central component of the risk-based approach and emphasise that obliged entities must take ownership of their assessments. The draft framework is intended to provide minimum requirements applicable across financial and non-financial sectors while allowing proportionality based on size, business model and risk profile.

A robust assessment should distinguish between:

Inherent risk

The level of risk before considering the effect of controls.

Control environment

The policies, procedures, systems and controls used to mitigate the identified inherent risks.

Control effectiveness

The extent to which those controls are appropriately designed and operate consistently.

Residual risk

The risk remaining after the effect of the controls is considered.

Risk response

The actions required to accept, reduce, avoid or further monitor the residual risk.

Typical BWRA risk dimensions

  • customer risk;
  • product and service risk;
  • transaction risk;
  • geographical risk;
  • delivery-channel risk;
  • ownership and legal-structure risk;
  • outsourcing risk;
  • technology risk;
  • sanctions-evasion risk;
  • emerging-risk exposure.

The BWRA should not be a static narrative. It should determine the design and intensity of the entity’s controls, customer-risk methodology, monitoring framework, training plan, assurance activities and resource allocation.

3. Written AML/CFT policies, procedures and controls

Article 9 AMLR requires obliged entities to establish internal policies, procedures and controls that are proportionate to their business, risks, complexity and size.

The framework must be recorded in writing. Internal policies must be approved by the management body in its management function. Internal procedures and controls must be approved at least at compliance-manager level. Obliged entities must keep these documents current and improve them where weaknesses are identified.

Difference between a policy, procedure and control

ElementFunction
PolicyDefines mandatory principles, responsibilities and risk standards
ProcedureDescribes how a policy is implemented operationally
ControlPrevents, detects or corrects a specific risk or process failure
EvidenceDemonstrates that the control was performed
TestingDetermines whether the control is appropriately designed and effective

Example

An AML/CFT policy may require all beneficial owners to be identified and verified.

The corresponding procedure explains:

  • which information must be obtained;
  • which documents are acceptable;
  • how indirect ownership is calculated;
  • how control through other means is assessed;
  • when escalation is required.

The associated controls may include:

  • mandatory system fields;
  • a four-eyes review;
  • automated threshold calculations;
  • document-validity checks;
  • quality-assurance sampling.

Minimum AML/CFT policy framework

Depending on the business model, the policy suite should address:

  • AML/CFT governance;
  • business-wide risk assessment;
  • customer acceptance;
  • customer due diligence;
  • beneficial ownership;
  • customer risk classification;
  • simplified due diligence;
  • enhanced due diligence;
  • PEPs and close associates;
  • sanctions and asset freezing;
  • high-risk third countries;
  • source of funds and source of wealth;
  • ongoing monitoring;
  • transaction monitoring;
  • suspicious transaction reporting;
  • record retention;
  • data protection;
  • outsourcing;
  • group-wide controls;
  • employee integrity;
  • AML/CFT training;
  • quality assurance;
  • independent audit;
  • deficiency and remediation management.

The entity should maintain a central inventory identifying the owner, approver, legal basis, effective date, review date and relevant controls for each document.

4. Three-lines control structure

An AML/CFT compliance program should allocate controls across the operational business, compliance and independent assurance functions.

The AMLR expressly requires internal controls and an independent audit function to test internal policies, procedures and controls. Where there is no independent audit function, an external expert may carry out the testing.

First line: business and operations

The first line owns customer and transaction risks and performs operational controls.

Typical responsibilities include:

  • collecting customer information;
  • verifying documents;
  • understanding the purpose of relationships;
  • identifying beneficial owners;
  • conducting customer reviews;
  • investigating alerts;
  • escalating unusual activities;
  • applying restrictions.

Second line: AML/CFT compliance

The second line establishes the framework and independently monitors its application.

Typical responsibilities include:

  • developing policies and methodologies;
  • advising the business;
  • reviewing higher-risk cases;
  • performing compliance monitoring;
  • overseeing PEP and sanctions controls;
  • submitting suspicious transaction reports;
  • reporting to management;
  • tracking regulatory change.

Third line: internal audit

Internal audit independently assesses whether the governance, risk management and control arrangements are appropriately designed and operating effectively.

Internal audit should retain independence from the design, operation and monitoring of the controls it reviews.

5. Customer due diligence

Customer due diligence is one of the central operational components of an AML/CFT compliance program.

CDD should enable the entity to establish:

  • who the customer is;
  • who acts on the customer’s behalf;
  • who ultimately owns or controls the customer;
  • why the relationship is being established;
  • which products and services will be used;
  • what activity is expected;
  • which risks are associated with the customer;
  • whether additional measures are required.

AMLA’s draft CDD RTS under Article 28(1) AMLR is intended to harmonise how obliged entities apply CDD requirements, including the information and documents to be collected. The public consultation closed on 8 May 2026.

Core CDD controls

  • customer identification;
  • identity verification;
  • legal-entity verification;
  • representative-authority verification;
  • beneficial-owner identification;
  • ownership and control analysis;
  • purpose and intended-nature assessment;
  • business or occupation assessment;
  • PEP screening;
  • sanctions screening;
  • individual customer-risk assessment;
  • documentation of the CDD decision.

The compliance program should define which evidence is acceptable, when enhanced evidence is required and what happens when required information cannot be obtained.

6. Customer risk classification

Customer risk classification translates the entity’s general risk framework into an individual assessment of each customer or business relationship.

The methodology should consider relevant factors relating to:

  • customer characteristics;
  • beneficial ownership;
  • legal and organisational structure;
  • products and services;
  • expected transactions;
  • delivery channels;
  • countries and regions;
  • PEP exposure;
  • sanctions exposure;
  • adverse media;
  • source of funds;
  • source of wealth.

The risk rating should determine:

  • the level of CDD;
  • approval requirements;
  • review frequency;
  • monitoring intensity;
  • evidence requirements;
  • escalation obligations.

Risk-rating controls

A sound methodology should include:

  • defined risk factors;
  • documented scoring logic;
  • weighting rules;
  • mandatory high-risk triggers;
  • override criteria;
  • approval requirements;
  • change-history records;
  • event-driven reassessment;
  • periodic validation.

Manual overrides should always include a documented rationale and independent approval.

7. Simplified and enhanced due diligence

Simplified due diligence

Simplified due diligence may be appropriate only where a lower risk has been identified and documented and where no statutory exclusion applies.

Simplification should affect the extent, timing or frequency of measures. It should not result in the complete omission of customer due diligence or monitoring.

A compliant SDD framework should define:

  • eligible customer and product types;
  • exclusion criteria;
  • minimum information requirements;
  • approval rules;
  • monitoring requirements;
  • review frequency;
  • exit triggers.

Enhanced due diligence

EDD is required in higher-risk situations and where the AMLR prescribes additional measures.

Depending on the risk, EDD may include:

  • additional customer information;
  • additional beneficial-ownership evidence;
  • additional information about the relationship;
  • source-of-funds verification;
  • source-of-wealth verification;
  • reasons for transactions;
  • senior-management approval;
  • increased monitoring;
  • more frequent reviews;
  • restrictions on products or transactions.

An EDD designation without additional controls is not effective enhanced due diligence.

The compliance program should record:

  • the risk requiring EDD;
  • the additional measures selected;
  • the evidence obtained;
  • the approving authority;
  • the enhanced monitoring applied;
  • the next review date.

8. PEP, sanctions and adverse-media controls

Politically exposed persons

The entity should have procedures to identify:

  • customers who are PEPs;
  • beneficial owners who are PEPs;
  • family members;
  • known close associates;
  • former PEPs with continuing residual risk.

The process should include:

  • screening;
  • match resolution;
  • risk assessment;
  • senior-management approval;
  • source-of-funds measures;
  • source-of-wealth measures;
  • enhanced ongoing monitoring.

PEP status is a risk factor and not, by itself, evidence of criminal conduct.

Targeted financial sanctions

Sanctions controls should cover:

  • customers;
  • beneficial owners;
  • directors;
  • authorised representatives;
  • relevant counterparties;
  • transaction parties;
  • sanctioned ownership and control;
  • potential circumvention structures.

The program should define:

  • applicable sanctions lists;
  • update frequencies;
  • matching logic;
  • transliteration rules;
  • investigation standards;
  • false-positive documentation;
  • escalation;
  • freezing and rejection actions;
  • reporting obligations.

Sanctions screening should be integrated into onboarding, customer updates and transaction processes.

Adverse media

Adverse-media screening can support:

  • customer-risk assessment;
  • EDD;
  • PEP assessment;
  • source-of-wealth analysis;
  • event-driven reviews;
  • investigation of unusual activity.

The entity should assess the credibility, relevance, recency and seriousness of the information rather than treating each negative article as an automatic adverse finding.

9. Ongoing monitoring and transaction monitoring

Ongoing monitoring ensures that the entity maintains a current and accurate understanding of its customers and detects unusual or suspicious activities.

Article 26 AMLR covers both the updating of customer information and the monitoring of transactions and activities.

AMLA’s draft guidelines under Article 26(5) are divided into general principles, customer-information updates and the transaction-and-activity-monitoring framework. The consultation opened on 3 June 2026 and remains open until 3 September 2026.

Ongoing monitoring should include

  • periodic customer reviews;
  • event-driven reviews;
  • customer-data updates;
  • beneficial-ownership updates;
  • PEP rescreening;
  • sanctions rescreening;
  • adverse-media review;
  • transaction monitoring;
  • activity monitoring;
  • risk-rating reassessment;
  • escalation of unusual behaviour.

Transaction-monitoring framework

The framework should be based on:

  • customer segmentation;
  • expected behaviour;
  • products and services;
  • transaction channels;
  • geographical exposure;
  • risk classification;
  • transaction values and frequencies;
  • known typologies;
  • historical activity.

Key monitoring controls

  • scenario and rule inventory;
  • threshold rationale;
  • customer coverage;
  • data completeness;
  • alert generation;
  • alert prioritisation;
  • investigation procedures;
  • decision standards;
  • escalation criteria;
  • backlog management;
  • quality assurance;
  • scenario calibration;
  • effectiveness testing.

Monitoring systems should not be evaluated solely by the number of alerts produced. The essential issue is whether the framework can identify material unusual or suspicious activity with an acceptable degree of completeness, accuracy and timeliness.

10. Suspicious transaction reporting

The compliance program must contain procedures for identifying, investigating, escalating and reporting suspicious activity.

The process should define:

  1. what constitutes unusual activity;
  2. when an internal escalation is required;
  3. who investigates the matter;
  4. who decides whether a report is required;
  5. how the decision is documented;
  6. how the report is submitted;
  7. what post-report restrictions apply;
  8. how tipping-off is prevented.

Required documentation

The case file should preserve:

  • the original alert or concern;
  • customer and transaction information;
  • investigation steps;
  • evidence reviewed;
  • analysis performed;
  • escalation history;
  • reporting decision;
  • reasons for reporting or not reporting;
  • relevant approvals;
  • post-decision controls.

The reporting decision should be based on the available facts and the applicable legal suspicion threshold, not on proof of a completed criminal offence.

11. Employee integrity and AML/CFT training

AML/CFT controls are only effective where employees understand their duties and are sufficiently competent and reliable.

The compliance program should include:

  • pre-employment integrity checks where legally permitted;
  • conflict-of-interest declarations;
  • role-specific training;
  • periodic refresher training;
  • training following legal or procedural changes;
  • competence testing;
  • escalation support;
  • records of completion.

Role-specific training

Different training content should be provided for:

  • management bodies;
  • compliance managers;
  • AML compliance officers;
  • customer onboarding teams;
  • relationship managers;
  • transaction-monitoring analysts;
  • sanctions teams;
  • legal functions;
  • technology and data teams;
  • internal audit;
  • outsourced service providers.

A generic annual e-learning course is unlikely to be sufficient for all roles.

12. AML/CFT data and technology controls

Modern AML/CFT compliance depends on complete, accurate, timely and traceable data.

The program should include controls over:

  • customer master data;
  • identification data;
  • beneficial-ownership data;
  • risk factors;
  • screening data;
  • transaction data;
  • alert data;
  • case-management data;
  • retention data;
  • regulatory reporting data.

Important technology controls

  • mandatory data fields;
  • data validation;
  • interface reconciliation;
  • duplicate detection;
  • sanctions-list update monitoring;
  • access controls;
  • segregation of duties;
  • workflow approvals;
  • change management;
  • system logging;
  • model validation;
  • backup and recovery;
  • vendor oversight.

Automation should support rather than obscure the compliance decision. Significant decisions should remain explainable and auditable.

13. Outsourcing and third-party reliance

Obliged entities may outsource certain operational activities, but they remain responsible for regulatory compliance.

Outsourcing arrangements should be governed by written agreements that define:

  • the outsourced service;
  • responsibilities;
  • data requirements;
  • performance standards;
  • audit and access rights;
  • incident reporting;
  • sub-outsourcing;
  • confidentiality;
  • business continuity;
  • termination and exit support.

The entity should retain the ability to:

  • understand the provider’s methodology;
  • monitor service quality;
  • challenge decisions;
  • obtain evidence;
  • access relevant data;
  • remediate deficiencies.

Core risk ownership and accountable decision-making cannot be transferred merely by contract.

14. Group-wide AML/CFT compliance

Groups should establish a consolidated view of AML/CFT risks across their entities, branches and relevant operations.

Articles 16 and 17 AMLR address group-wide frameworks, including cross-border structures and subsidiaries or branches in third countries. AMLA’s 2026 draft RTS cover organisational requirements, group information sharing and additional measures where third-country law affects implementation.

Group-wide framework components

  • group-wide risk assessment;
  • common minimum policies;
  • consistent customer-risk methodology;
  • information-sharing rules;
  • escalation arrangements;
  • consolidated management reporting;
  • oversight of local implementation;
  • group compliance monitoring;
  • group audit coverage;
  • third-country gap management.

Local entities may need supplementary procedures to address national legal requirements, but these should remain aligned with the group’s minimum standards.

15. Compliance monitoring and quality assurance

The compliance function should monitor whether policies, procedures and controls are implemented correctly.

Compliance monitoring may include:

  • thematic reviews;
  • file sampling;
  • transaction-alert reviews;
  • screening-quality reviews;
  • overdue-review analysis;
  • EDD documentation testing;
  • sanctions-response testing;
  • management-information validation;
  • remediation follow-up.

Quality assurance should focus on the performance of individual processes and decisions, while compliance monitoring should assess broader adherence to the regulatory framework.

Findings should be:

  • clearly described;
  • risk classified;
  • assigned to an owner;
  • given a due date;
  • subject to validation before closure;
  • reported to the appropriate management level.

16. Independent AML/CFT audit

The independent audit function provides objective assurance over the AML/CFT compliance program.

The AMLR requires an independent audit function to test internal policies, procedures and controls. Where the entity does not have such a function, testing may be performed by an external expert.

Design effectiveness

Design-effectiveness testing determines whether a control is capable of addressing the relevant risk.

Questions include:

  • Is the control linked to a defined risk?
  • Is responsibility assigned?
  • Is the frequency appropriate?
  • Are the required data available?
  • Are exceptions escalated?
  • Is evidence retained?

Operating effectiveness

Operating-effectiveness testing determines whether the control was performed consistently and correctly over a representative period.

Questions include:

  • Was the control performed when required?
  • Was it performed by an authorised person?
  • Was the result accurate?
  • Were exceptions investigated?
  • Was the evidence complete?
  • Were deficiencies remediated?

Typical audit areas

  • governance;
  • business-wide risk assessment;
  • policies and procedures;
  • CDD;
  • beneficial ownership;
  • customer-risk classification;
  • SDD and EDD;
  • PEPs;
  • sanctions;
  • transaction monitoring;
  • suspicious transaction reporting;
  • record retention;
  • training;
  • outsourcing;
  • group-wide controls;
  • data and technology.

17. AML/CFT management information

Management requires reliable information to oversee the program and challenge its effectiveness.

  • number of customers by risk category;
  • high-risk-customer population;
  • overdue customer reviews;
  • incomplete CDD cases;
  • PEP population;
  • unresolved sanctions alerts;
  • transaction-monitoring alerts;
  • alert backlog;
  • average investigation time;
  • suspicious transaction reports;
  • EDD cases awaiting approval;
  • quality-assurance error rates;
  • audit findings;
  • overdue remediation actions;
  • training completion;
  • staff vacancies and turnover.

Management information should show trends, ageing and exceptions rather than only total volumes.

18. AML/CFT compliance implementation roadmap

Phase 1: Establish governance

  • confirm the obliged-entity scope;
  • appoint the compliance manager;
  • appoint the compliance officer;
  • approve responsibilities;
  • establish committees and reporting;
  • allocate resources.

Phase 2: Complete the risk assessment

  • map the business model;
  • identify inherent risks;
  • assess controls;
  • determine residual risks;
  • approve risk responses;
  • align risk appetite.

Phase 3: Build the policy framework

  • prepare a document inventory;
  • map policies to AMLR requirements;
  • update procedures;
  • assign controls;
  • obtain required approvals.

Phase 4: Redesign customer controls

  • update identification requirements;
  • enhance beneficial-ownership analysis;
  • revise the customer-risk model;
  • define SDD and EDD;
  • update PEP and sanctions procedures.

Phase 5: Enhance monitoring

  • implement review schedules;
  • establish event triggers;
  • recalibrate transaction-monitoring rules;
  • improve alert workflows;
  • validate data coverage.

Phase 6: Train and implement

  • communicate new requirements;
  • provide role-specific training;
  • deploy systems and procedures;
  • document implementation evidence.

Phase 7: Test effectiveness

  • perform compliance monitoring;
  • conduct quality assurance;
  • complete independent audit testing;
  • remediate weaknesses;
  • obtain management sign-off.

AML/CFT compliance program checklist

AreaMinimum requirement
ScopeIdentify all obliged entities, services and branches
GovernanceAppoint a compliance manager and compliance officer
ResourcesProvide sufficient personnel, systems and budget
BWRAAssess ML, TF and targeted-financial-sanctions risks
Risk appetiteDefine acceptable and unacceptable risk exposure
PoliciesMaintain written, approved and current AML policies
ProceduresTranslate policies into operational instructions
ControlsAssign preventive, detective and corrective controls
Customer acceptanceDefine acceptance and rejection criteria
CDDIdentify and verify customers and representatives
Beneficial ownershipIdentify ownership and control through other means
Customer riskComplete individual risk assessments
SDDDefine eligibility, exclusions and monitoring
EDDDefine triggers, evidence, approval and monitoring
PEPsScreen and apply enhanced measures
SanctionsScreen persons, entities, ownership and transactions
Adverse mediaAssess reliable information proportionately
Ongoing monitoringUpdate customer information and risk
Transaction monitoringDetect unusual and suspicious activities
ReportingInvestigate and report relevant suspicions
RecordsRetain complete and auditable evidence
Data protectionProtect and lawfully process AML data
TrainingProvide role-specific and periodic training
OutsourcingRetain accountability and monitor providers
Group controlsEstablish consolidated policies and risk oversight
Quality assuranceReview decision and process quality
Compliance monitoringTest adherence to the regulatory framework
Internal auditTest design and operating effectiveness
RemediationRecord, prioritise and validate corrective actions
ReportingProvide meaningful information to management

Common AML/CFT compliance weaknesses

Policies are not connected to controls

A policy may state what is required without identifying how the requirement is implemented, evidenced and tested.

The risk assessment is generic

The BWRA may repeat industry risks but fail to reflect the entity’s actual customers, services, countries, transactions and controls.

Responsibilities are unclear

Tasks may be distributed across business, operations, compliance and technology without clear ownership or escalation.

High-risk customers receive no enhanced controls

A higher risk score must result in additional measures, approval and monitoring.

Customer data are not updated when circumstances change

Periodic reviews cannot replace event-driven updates triggered by material new information.

Screening produces alerts but no reliable audit trail

A screening tool is ineffective where alerts are closed without evidence, rationale or independent review.

Transaction-monitoring scenarios are not validated

Rules may continue operating without analysis of coverage, thresholds, false negatives or data completeness.

Compliance monitoring is confused with internal audit

The compliance function monitors adherence, while internal audit provides independent assurance. The same testing cannot simultaneously satisfy both functions where independence is required.

Findings are closed without validation

An action should not be closed solely because the owner states that remediation is complete. Closure should be supported by evidence and, where appropriate, effectiveness testing.

Frequently asked questions

What is an AML/CFT compliance program?

An AML/CFT compliance program is the governance, risk-management and control framework used by an obliged entity to comply with anti-money laundering and counter-terrorist-financing requirements.

What are the core components of AML/CFT compliance?

The core components are management governance, risk assessment, policies, procedures, customer due diligence, monitoring, suspicious transaction reporting, training, independent testing and remediation.

Who is responsible for AML/CFT compliance?

The management body retains ultimate responsibility. Under the AMLR, an obliged entity must appoint a management-body member as compliance manager and a compliance officer for the day-to-day operation of the framework.

Is an AML/CFT policy sufficient?

No. A policy must be supported by procedures, controls, trained employees, systems, evidence, monitoring and independent testing.

How often should an AML/CFT policy be reviewed?

Policies should be kept current and reviewed whenever regulatory, business, risk or control changes occur. The AMLR expressly requires obliged entities to update and improve policies, procedures and controls where weaknesses are identified.

What is the role of internal audit?

Internal audit independently tests whether the AML framework is appropriately designed and operating effectively. An external expert may perform this testing where an independent audit function is absent, subject to the applicable proportionality framework.

What is the difference between AML/CFT monitoring and AML/CFT audit?

AML monitoring is an ongoing compliance activity that evaluates adherence and identifies emerging weaknesses. AML audit is an independent assurance activity assessing the design and operating effectiveness of the overall framework.

When does the AMLR apply?

Regulation (EU) 2024/1624 generally applies from 10 July 2027.

AML/CFT compliance must operate as an integrated system

An effective AML/CFT compliance program is not a collection of policies, screening tools and annual training courses.

It is an integrated operating model connecting:

  • management accountability;
  • risk assessment;
  • customer due diligence;
  • risk classification;
  • PEP and sanctions controls;
  • ongoing and transaction monitoring;
  • suspicious transaction reporting;
  • data and technology;
  • compliance monitoring;
  • independent audit;
  • remediation.

Each control should be linked to a defined risk, assigned to a responsible owner, supported by reliable data, evidenced when performed and tested for effectiveness.

Obliged entities preparing for the AMLR should therefore assess both the formal design and the practical operation of their compliance programs. By 10 July 2027, they should be able to demonstrate not only that required policies exist, but that the complete AML/CFT control framework operates consistently and effectively.

Is your AML/CFT compliance program ready for the AMLR?

An AMLR compliance-program assessment can identify weaknesses in:

  • governance and responsibility;
  • business-wide risk assessment;
  • policies and procedures;
  • customer due diligence;
  • beneficial ownership;
  • PEP and sanctions controls;
  • transaction monitoring;
  • suspicious transaction reporting;
  • technology and data;
  • independent assurance.

Leave a Reply

Your email address will not be published. Required fields are marked *