
AML/CFT Checks Explained: KYC, EDD, PEP, Sanctions and Adverse Media
AML/CFT checks are the controls used by obliged entities to identify customers, understand ownership structures, assess money laundering and terrorist financing risks, detect sanctions exposure and monitor business relationships for suspicious activity.
They are not limited to a single database search or identity check. A complete anti-money laundering check is a coordinated process covering:
- customer identification and verification;
- beneficial ownership;
- ownership and control structures;
- customer risk classification;
- politically exposed persons;
- targeted financial sanctions;
- enhanced due diligence;
- adverse media;
- source of funds and source of wealth;
- ongoing monitoring; and
- transaction and activity monitoring.
Under Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation, or AMLR, these checks form part of a risk-based customer due diligence framework. Obliged entities must be able to demonstrate that the checks they applied were appropriate for the risks associated with the customer, beneficial owner, business relationship or occasional transaction.
The AMLR generally applies from 10 July 2027. AMLA is developing additional Regulatory Technical Standards specifying how customer due diligence must be applied in practice, including the information and documents that obliged entities must collect. AMLA’s consultation on the draft CDD RTS closed on 8 May 2026 and the final standards remain part of the developing EU AML Single Rulebook.
What are AML/CFT checks?
AML/CFT checks are the individual verification, screening, risk assessment and monitoring activities through which an obliged entity establishes whether it can enter into or continue a customer relationship.
Their purpose is to enable the entity to answer five fundamental questions:
- Who is the customer?
- Who ultimately owns or controls the customer?
- Why does the customer require the product or service?
- What money laundering, terrorist financing or sanctions risks are associated with the relationship?
- Does the customer’s actual behaviour remain consistent with the information and risk profile obtained?
A compliant AML/CFT check does not end when a customer passes onboarding. The information must be kept up to date, risk indicators must be reassessed and transactions and activities must be monitored throughout the relationship.
AML/CFT checks at a glance
| AML/CFT check | Principal purpose |
|---|---|
| KYC identification | Establish who the customer is |
| Identity verification | Confirm identity through reliable and independent evidence |
| Corporate verification | Confirm the existence, legal form and authority of a legal entity |
| Beneficial ownership check | Identify the natural persons who ultimately own or control the customer |
| Customer risk assessment | Determine the individual ML/TF risk of the relationship |
| PEP screening | Identify politically exposed persons, family members and close associates |
| Sanctions screening | Detect designated persons and sanctioned ownership or control |
| Adverse media screening | Identify credible information indicating criminal, corruption or financial-crime risk |
| Source-of-funds check | Understand the origin of funds used in a transaction or relationship |
| Source-of-wealth check | Understand how a customer accumulated their overall wealth |
| EDD | Apply additional measures where higher risk is identified |
| Ongoing monitoring | Ensure information and behaviour remain consistent over time |
| Transaction monitoring | Detect unusual or potentially suspicious transactions |
1. KYC identification and identity verification
Know Your Customer, or KYC, is the foundation of the AML-check process.
Article 20 AMLR requires obliged entities to identify the customer and verify the customer’s identity. It also requires the identification of authorised representatives and verification that they are authorised to act on behalf of the customer.
For a natural person, the process normally requires information such as:
- full legal name;
- date of birth;
- place of birth;
- nationality;
- residential address;
- identification-document details;
- tax or personal identification numbers where applicable; and
- information concerning occupation or employment.
For a legal entity, the required checks generally include:
- legal name;
- legal form;
- registered office;
- registration number;
- governing law;
- constitutional documents;
- directors or members of the management body;
- authorised representatives; and
- ownership and control information.
The identity must be verified using reliable and independent documents, data or information. Depending on the customer and verification channel, this can include official identity documents, company registers, public registers, electronic identification means and qualified trust services.
AMLA’s draft CDD RTS under Article 28(1) AMLR is intended to specify more precisely which information and documents must be collected and how CDD requirements should be applied across the financial and non-financial sectors.
KYC is more than an identity check
Confirming that an identification document is genuine does not establish that a customer presents an acceptable AML risk.
A complete KYC assessment must also determine:
- what the customer does;
- why the customer requires the relationship;
- how the products or services will be used;
- which countries are involved;
- who owns or controls the customer;
- where relevant funds originate; and
- whether the expected activity is plausible.
2. Corporate and beneficial ownership checks
Where the customer is a company, partnership, foundation, trust or other organisation, AML/CFT checks must extend beyond the named legal entity.
The obliged entity must identify the natural persons who ultimately own or control the customer and must understand the customer’s ownership and control structure. Article 20 AMLR expressly requires the identification and reasonable verification of beneficial owners.
The assessment should include:
- direct shareholders;
- indirect shareholders;
- intermediate holding companies;
- voting rights;
- shareholder agreements;
- rights to appoint or remove management;
- veto or decision rights;
- nominee relationships;
- trusts or similar legal arrangements;
- other persons exercising control through formal or informal means.
A beneficial ownership check should not be reduced to copying information from a central register. Register information is an important source, but the obliged entity must still assess whether the recorded information is complete, plausible and consistent with other evidence.
Where information obtained during CDD conflicts with information held in a beneficial ownership register, the AMLR provides for discrepancy reporting requirements. The Regulation recognises that obliged entities may obtain relevant information from customers, public registers and other reliable sources.
Ownership and control are separate tests
A person may qualify as a beneficial owner because of an ownership interest. A person may also qualify because they exercise control through other means, even where they do not hold the relevant percentage of shares.
The control analysis should therefore be performed independently and in parallel with the ownership calculation.
3. Customer risk assessment
The result of the AML/CFT checks must feed into an individual customer risk assessment.
The risk assessment determines:
- whether the relationship can be accepted;
- whether standard or enhanced due diligence is required;
- which evidence must be obtained;
- what approval level is required;
- how intensively the relationship must be monitored; and
- how frequently customer information must be reviewed.
Relevant risk factors include:
Customer risk
- legal form;
- ownership complexity;
- cash intensity;
- use of intermediaries;
- unexplained nominee structures;
- high net worth;
- exposure to corruption;
- unusual business activity;
- non-resident status;
- opaque funding arrangements.
Product and service risk
- private banking;
- correspondent banking;
- crypto-asset services;
- trade finance;
- cross-border payment services;
- trust and company services;
- complex investment products;
- products supporting anonymity or rapid transferability.
Geographical risk
- high-risk third countries;
- jurisdictions subject to international monitoring;
- countries with high corruption exposure;
- sanctions-sensitive jurisdictions;
- secrecy jurisdictions;
- countries affected by conflict or organised crime.
Delivery-channel risk
- non-face-to-face onboarding;
- intermediated relationships;
- remote verification;
- reliance on third parties;
- opaque digital or platform-based distribution.
Transaction risk
- unusually large transactions;
- complex payment chains;
- unexplained cross-border flows;
- transactions inconsistent with the customer profile;
- rapid movement of funds;
- cash transactions;
- use of multiple unrelated counterparties.
No individual factor should automatically determine the final customer risk in every case. The entity should assess the combined effect of the relevant factors and document the rationale for the final classification.
4. PEP/ RCA screening
A politically exposed person, or PEP, is a person who is or has been entrusted with a prominent public function.
PEP screening must cover more than the named customer. It should also determine whether the following persons fall within the relevant definitions:
- beneficial owners;
- persons acting on behalf of the customer;
- family members of PEPs (relatives); and
- persons known to be close associates of PEPs (close associates).
The AMLR requires specific measures for occasional transactions and business relationships involving PEPs:
- approval from senior management before establishing or continuing the relationship or carrying out the occasional transaction;
- adequate measures to establish source of wealth and source of funds; and
- enhanced ongoing monitoring.
The same framework applies to relevant family members and persons known to be close associates.
A PEP is not automatically a criminal
PEP status is a risk factor, not evidence of criminal activity. The AMLR expressly rejects the refusal of a relationship solely because a person has been identified as a PEP, family member or close associate.
The entity must assess the actual risk, taking account of factors such as:
- the public function held;
- the country and institution involved;
- the level of authority;
- access to state funds;
- corruption exposure;
- duration and recency of the function;
- business interests;
- family and associate connections;
- expected account or transaction activity.
Former PEPs
Where a person ceases to hold a prominent public function, the obliged entity must continue to assess the residual risk arising from the former position.
Risk-sensitive measures must continue until the specific PEP-related risk no longer exists and for at least 12 months after the person ceased to hold the relevant function.
Recommended PEP workflow
- Screen the customer and beneficial owners.
- investigate potential matches.
- Determine whether the function qualifies as a prominent public function.
- Identify relevant family members and close associates.
- Assess the specific PEP risk.
- Establish source of funds and source of wealth.
- Obtain senior management approval.
- Apply enhanced monitoring.
- Document the decision and review date.
5. Sanctions screening
Sanctions screening determines whether a customer, beneficial owner, authorised representative, counterparty or other relevant person is subject to targeted financial sanctions.
The AMLR requires obliged entities to check whether customers or beneficial owners are subject to targeted financial sanctions. For legal entities and legal arrangements, the check must also consider whether sanctioned persons own or control the entity.
The screening population may include:
- customers;
- beneficial owners;
- directors;
- authorised representatives;
- trustees;
- settlors;
- protectors;
- beneficiaries;
- counterparties;
- transaction parties;
- payers and payees;
- intermediaries;
- connected legal entities.
Sanctions screening is not purely risk-based
AML/CFT risk management is generally risk-based. The legal obligation to freeze funds and not make funds or economic resources available to a designated person is, however, rule-based.
The AMLR confirms that the risk-based treatment of sanctions-evasion risk does not replace the binding obligation to freeze assets and prevent funds or assets from being made available to sanctioned persons or entities.
A customer with a low AML/CFT customer-risk rating must therefore still be screened appropriately against applicable sanctions lists.
Ownership and control screening
Sanctions checks should not be limited to exact name matches against listed persons.
The entity must assess whether a legal entity is:
- directly owned by a sanctioned person;
- indirectly owned through one or more entities;
- jointly owned by sanctioned persons;
- controlled by a sanctioned person;
- acting on behalf of or at the direction of a sanctioned person.
This requires reliable legal-entity data, ownership information and an operational control analysis.
Sanctions-screening process
A suitable sanctions process should include:
- authoritative sanctions-list feeds;
- regular list updates;
- customer and beneficial-owner rescreening;
- transaction screening where applicable;
- matching rules and transliteration;
- false-positive resolution;
- escalation of potential matches;
- asset-freezing and rejection procedures;
- reporting and notification procedures;
- complete audit trails.
6. Adverse media screening
Adverse media screening is the identification and assessment of credible public information that may indicate exposure to money laundering, predicate offences, terrorist financing, corruption, fraud, sanctions evasion or other relevant financial crime.
The AMLR does not define adverse media as a standalone universal screening obligation using that exact expression. However, it requires obliged entities to understand and assess relevant customer risks, to use reliable information and to monitor business relationships.
The Regulation recognises media, civil-society reporting, academic sources and publications from international bodies as possible credible and reliable sources of information concerning typologies, emerging risks and criminal activity, including corruption.
Adverse media therefore supports several regulatory purposes:
- customer risk assessment;
- verification of customer representations;
- PEP risk assessment;
- source-of-wealth assessment;
- identification of predicate-offence exposure;
- event-driven customer review;
- enhanced due diligence;
- suspicious transaction assessment.
What should adverse media screening cover?
Relevant categories may include credible allegations, investigations, charges, convictions or regulatory actions concerning:
- money laundering;
- fraud;
- bribery and corruption;
- tax crimes;
- organised crime;
- drug trafficking;
- human trafficking;
- environmental crime;
- cybercrime;
- terrorist financing;
- sanctions evasion;
- asset misappropriation;
- embezzlement;
- market abuse;
- illegal gambling;
- trafficking in illicit goods.
Not every negative article is relevant
Adverse media should not be treated as a simple positive-or-negative result.
The entity should assess:
- reliability of the source;
- seriousness of the allegation;
- proximity of the person to the conduct;
- stage of proceedings;
- date and continuing relevance;
- corroboration by other sources;
- possible mistaken identity;
- connection with the customer relationship;
- potential impact on the customer risk rating.
Anonymous blogs, duplicated content and unverified allegations should not be assigned the same evidential weight as court decisions, regulatory notices or reporting from established investigative sources.
Recommended adverse media classification
| Classification | Example | Typical response |
|---|---|---|
| Irrelevant | Unrelated person with a similar name | Close as false positive |
| Low relevance | Old allegation without corroboration | Document and monitor |
| Material concern | Credible current investigation | Reassess customer risk |
| High concern | Strong evidence of relevant criminal conduct | Apply EDD and escalate |
| Suspicion | Information supports knowledge, suspicion or reasonable grounds | Consider FIU reporting |
Adverse media screening should not replace independent analysis. Automated tools may identify potential results, but trained personnel should assess relevance, credibility and risk.
7. Enhanced due diligence
Enhanced due diligence, or EDD, is required where a higher money laundering or terrorist financing risk is identified or where the AMLR prescribes enhanced measures for a specific situation.
Article 34 AMLR requires EDD in the circumstances specified by the Regulation and in other higher-risk cases identified through the customer-risk assessment.
Situations that may require EDD include:
- PEP relationships;
- customers connected with certain high-risk third countries;
- cross-border correspondent relationships;
- high-risk crypto-asset relationships;
- unusually complex transactions;
- unusually large transactions;
- unusual transaction patterns;
- transactions without an apparent economic or lawful purpose;
- residence-by-investment applicants;
- certain high-risk wealth-management relationships;
- other higher-risk situations identified by the obliged entity.
Possible EDD measures
Depending on the risk, EDD may include:
- obtaining additional customer information;
- obtaining additional beneficial ownership information;
- obtaining further information on the purpose and intended nature of the relationship;
- establishing source of funds;
- establishing source of wealth;
- obtaining reasons for planned or completed transactions;
- obtaining senior management approval;
- increasing the frequency of customer reviews;
- increasing the frequency or depth of transaction scrutiny;
- limiting products, services or transaction types;
- requiring the first payment from an account in the customer’s name;
- strengthening approval or escalation requirements.
The selected measures must correspond to the specific risk. Simply marking a customer as “high risk” without changing the controls applied does not constitute effective EDD.
EDD must be evidenced
The customer file should show:
- why the customer was classified as high risk;
- which risk factors were identified;
- which EDD measures were selected;
- why those measures were considered sufficient;
- which evidence was obtained;
- who approved the relationship;
- how ongoing monitoring was enhanced;
- when the case must be reviewed again.
8. Source of funds and source of wealth
Source of funds and source of wealth are related but distinct AML checks.
Source of funds
Source of funds concerns the origin of the specific money or assets involved in a transaction or business relationship.
Examples include:
- salary;
- business income;
- sale proceeds;
- inheritance;
- loan proceeds;
- dividends;
- investment redemption;
- property sale;
- insurance payout.
Evidence may include bank statements, sale agreements, payslips, tax documents, audited accounts, probate records or loan agreements.
Source of wealth
Source of wealth concerns how the customer accumulated their overall wealth.
Examples include:
- long-term business ownership;
- professional earnings;
- inheritance;
- investments;
- real estate;
- family wealth;
- company sale;
- entrepreneurship.
Source-of-wealth evidence should support the plausibility of the customer’s broader economic position, not merely the immediate payment.
For PEPs, the AMLR expressly requires adequate measures to establish both source of funds and source of wealth.
9. Ongoing monitoring
AML checks continue after onboarding.
Ongoing monitoring should determine whether the customer’s transactions and activities remain consistent with:
- the entity’s knowledge of the customer;
- the purpose of the relationship;
- the customer’s business or occupation;
- the expected transaction profile;
- the customer-risk classification;
- source-of-funds information;
- geographical exposure.
Relevant changes should trigger reassessment. Examples include:
- ownership changes;
- new directors or representatives;
- new PEP status;
- sanctions designation;
- new adverse media;
- changes in products or services;
- expansion into new countries;
- unexpected transaction activity;
- changes in occupation or business;
- doubts concerning existing identification data.
A strong monitoring framework combines:
- periodic customer reviews;
- event-driven reviews;
- PEP and sanctions rescreening;
- adverse media updates;
- transaction monitoring;
- case investigation;
- escalation and suspicious transaction reporting.
10. When must AML/CFT checks be performed?
AML/CFT checks are generally required:
- before establishing a business relationship;
- when carrying out relevant occasional transactions;
- where linked transactions reach an applicable threshold;
- where money laundering or terrorist financing is suspected;
- where doubts arise concerning previously obtained information;
- throughout an existing relationship;
- when a relevant event changes the customer’s risk.
AMLA’s draft RTS under Article 19(9) AMLR provides criteria for identifying business relationships, occasional transactions and linked transactions. AMLA stated that distinguishing these categories is fundamental because CDD is always required for a business relationship, while threshold rules apply to certain occasional transactions.
11. What happens when AML checks cannot be completed?
Where an obliged entity cannot complete the required CDD measures, it should not treat the missing information as a minor administrative deficiency.
Depending on the circumstances, the AMLR can require the entity to:
- refrain from establishing the relationship;
- refrain from executing the transaction;
- terminate an existing relationship;
- apply legally permitted alternative restrictions; and
- consider whether a suspicious transaction report is required.
The entity should document:
- the missing information;
- attempts to obtain it;
- customer explanations;
- escalation steps;
- the final decision;
- the reason for the decision;
- consideration of FIU reporting.
12. Common weaknesses in AML checks
Screening without investigation
A screening result is not a completed AML check. Potential matches must be investigated, resolved and documented.
Checking only the customer name
PEP and sanctions checks should also cover beneficial owners, representatives and other relevant connected persons.
Accepting register information without challenge
Register information should be compared with organisational documents, ownership evidence and other reliable sources.
Treating PEP status as an automatic rejection
PEP status requires enhanced risk management, not automatic de-risking.
Using adverse media as an automatic scoring trigger
The relevance and credibility of the information must be assessed before it changes the customer-risk rating.
Applying EDD only on paper
EDD must produce additional evidence, approvals or monitoring measures corresponding to the identified risk.
Ignoring event-driven changes
Periodic review dates do not remove the need to reassess the customer when material new information emerges.
Failing to document false positives
A closed sanctions, PEP or adverse-media alert should retain enough information to demonstrate why it was not a true match.
AML/CFT checks implementation checklist
| Control area | Minimum requirement |
|---|---|
| Customer identification | Collect all required identity information |
| Verification | Use reliable and independent evidence |
| Legal entities | Verify existence, legal form and representation |
| Beneficial ownership | Identify and verify natural persons who own or control the customer |
| Ownership structure | Document direct and indirect ownership chains |
| Control analysis | Assess control through means other than ownership |
| Purpose | Establish the purpose and intended nature of the relationship |
| Business profile | Understand business, occupation or employment |
| Customer risk | Complete and document an individual risk assessment |
| PEP screening | Screen customers, beneficial owners, family members and close associates |
| PEP controls | Apply approval, source-of-funds, source-of-wealth and enhanced monitoring |
| Sanctions | Screen customers, connected persons and relevant transaction parties |
| Ownership and control | Assess sanctioned ownership and control |
| Adverse media | Use credible sources and assess relevance |
| Source of funds | Establish the origin of specific funds where required |
| Source of wealth | Establish how overall wealth was accumulated where required |
| EDD | Apply risk-specific additional measures |
| Monitoring | Implement periodic and event-driven reviews |
| Transactions | Monitor activity against the expected customer profile |
| Escalation | Define investigation and approval responsibilities |
| Reporting | Consider suspicious transaction reporting where required |
| Evidence | Retain a complete audit trail of checks and decisions |
Frequently asked questions
What is an AML/CFT check?
An AML check is a verification, screening, risk assessment or monitoring measure used to identify and manage money laundering, terrorist financing and sanctions risks.
Is KYC the same as AML/CFT?
No. KYC is a central part of AML/CFT compliance, but AML also includes customer-risk assessment, EDD, PEP and sanctions screening, ongoing monitoring, transaction monitoring and suspicious transaction reporting.
What is included in an AML background check?
An AML/CFT background check may include identity verification, company verification, beneficial ownership analysis, PEP screening, sanctions screening, adverse media, source-of-funds checks and customer-risk assessment.
Are PEP checks mandatory?
Obliged entities must have procedures to determine whether customers, beneficial owners or other relevant persons are PEPs, family members or known close associates. Where a PEP relationship is identified, the AMLR requires senior management approval, source-of-funds and source-of-wealth measures and enhanced ongoing monitoring.
Is adverse media screening mandatory?
The AMLR does not establish a universal standalone screening requirement using the specific term “adverse media screening”. However, reliable media and other public information can be relevant to customer-risk assessment, EDD and ongoing monitoring. The need and intensity of screening should be determined through the entity’s risk-based framework.
What is the difference between PEP and sanctions screening?
PEP screening identifies persons associated with prominent public functions and determines whether enhanced controls are required. Sanctions screening identifies persons or entities subject to legally binding restrictions, including asset-freezing and prohibitions on making funds or economic resources available.
Does a sanctions match always mean the customer is listed?
No. A screening alert may be a false positive caused by a similar name or other matching attributes. The alert must be investigated using identifiers such as date of birth, nationality, address, identification number and ownership information.
When is enhanced due diligence required?
EDD is required in specific situations prescribed by the AMLR and in other higher-risk cases identified by the obliged entity. Measures must be proportionate to the higher risks identified.
How often should AML checks be repeated?
Checks should be repeated at risk-based intervals and whenever material new information or relevant changes arise. PEP, sanctions and adverse-media information may require more frequent or event-driven rescreening.
AML/CFT checks must form one connected control process
Effective AML/CFT checks are not a collection of unrelated database searches.
They form a connected process that begins with identification and continues through:
- verification;
- beneficial ownership;
- customer-risk assessment;
- PEP and sanctions screening;
- adverse media;
- EDD;
- source-of-funds and source-of-wealth checks;
- ongoing monitoring; and
- suspicious activity escalation.
The quality of the process depends not only on whether a check was performed, but also on whether:
- the correct persons were checked;
- reliable information was used;
- alerts were investigated;
- the customer risk was reassessed;
- appropriate measures were applied; and
- the decision was documented in an auditable manner.
Obliged entities preparing for the AMLR should therefore assess their AML checks as an end-to-end operating model covering governance, data, screening technology, investigation workflows, approvals, monitoring and control testing.
Are your AML/CFT checks ready for the AMLR?
An AML/CFT check framework assessment can determine whether your KYC, beneficial ownership, EDD, PEP, sanctions and adverse-media processes meet the requirements of the EU AML Regulation.
The assessment should examine:
- legal and procedural requirements;
- screening populations;
- data quality;
- beneficial ownership and control logic;
- alert management;
- customer-risk classification;
- EDD evidence;
- monitoring triggers;
- documentation; and
- design and operating effectiveness.