AML/CFT Explained

AML/CFT Explained: Anti-Money Laundering and Counter Terrorist Financing

AML/CFT stands for anti-money laundering and countering the financing of terrorism. The term describes the laws, supervisory arrangements, risk-management measures and operational controls used to prevent criminals and terrorists from misusing the financial system and other sectors of the economy.

AML and CFT are closely connected, but they address different financial-crime risks:

  • AML focuses on identifying and preventing the concealment or use of proceeds generated by criminal activity.
  • CFT focuses on identifying and disrupting funds or other assets used to finance terrorist acts, terrorists or terrorist organisations.
  • CPF, or counter-proliferation financing, concerns the financing of the proliferation of weapons of mass destruction and the evasion of related targeted financial sanctions.

The Financial Action Task Force, or FATF, establishes the principal international standards in this field. Its 40 Recommendations cover AML/CFT policies, money laundering, terrorist financing, proliferation financing, preventive controls, beneficial ownership, competent authorities and international cooperation. More than 200 jurisdictions have committed to implementing the FATF Standards through the FATF global network.

Within the European Union, the AML/CFT framework is being substantially harmonised through Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation, or AMLR. The Regulation establishes directly applicable requirements for obliged entities and generally applies from 10 July 2027.

What does AML/CFT mean?

AML/CFT is an umbrella term covering the measures used to protect financial systems and the broader economy from:

  • money laundering;
  • terrorist financing;
  • related predicate offences;
  • misuse of legal entities and legal arrangements;
  • sanctions evasion;
  • proliferation-financing risks.

The FATF describes the purpose of an effective AML/CFT framework as protecting financial systems and the wider economy from money laundering, terrorist financing and proliferation-financing threats, thereby strengthening financial-sector integrity and contributing to public safety and security.

AML/CFT measures apply not only to banks. Depending on the applicable legal framework, they can also apply to:

  • payment institutions;
  • electronic money institutions;
  • investment firms;
  • insurance undertakings;
  • asset managers;
  • crypto-asset service providers;
  • auditors and accountants;
  • tax advisers;
  • lawyers and notaries;
  • real estate professionals;
  • trust and company service providers;
  • gambling operators;
  • dealers in specified high-value goods;
  • other designated non-financial businesses and professions.

The precise scope depends on the relevant national or supranational legislation. Under the EU AMLR, the categories of obliged entities are set out in Article 3.

AML/CFT at a glance

TermMeaningPrimary objective
AMLAnti-money launderingPrevent the concealment and use of criminal proceeds
CFTCountering the financing of terrorismPrevent funds or assets from supporting terrorists and terrorist activity
CPFCounter-proliferation financingPrevent financing connected with weapons proliferation and related sanctions evasion
MLMoney launderingProcessing criminal proceeds to conceal their illegal origin
TFTerrorist financingFinancing terrorist acts, terrorists or terrorist organisations
PFProliferation financingFinancing connected with the proliferation of weapons of mass destruction
KYCKnow Your CustomerIdentify and understand customers and relevant connected persons
CDDCustomer due diligenceIdentify, verify, assess and monitor customers and relationships
EDDEnhanced due diligenceApply additional measures in higher-risk situations
FIUFinancial Intelligence UnitReceive and analyse suspicious transaction or activity reports

1. What is money laundering?

Money laundering is the process through which criminals conceal or disguise the illegal origin, ownership, movement or use of proceeds generated by criminal activity.

The underlying criminal activity is commonly referred to as a predicate offence. FATF-recognised categories of predicate offences include, among others:

  • organised crime;
  • trafficking in human beings;
  • drug trafficking;
  • corruption and bribery;
  • fraud;
  • tax crimes;
  • environmental crime;
  • smuggling;
  • cybercrime-related offences;
  • market manipulation;
  • insider trading.

Money laundering may involve sophisticated cross-border corporate structures, but it can also occur through relatively simple activities, such as depositing illicit cash into a business account or buying assets with criminal proceeds.

The three stages of money laundering

Money laundering is often explained through three stages.

Placement

Placement is the introduction of criminal proceeds into the financial or economic system.

Examples include:

  • depositing cash;
  • purchasing monetary instruments;
  • using cash-intensive businesses;
  • buying high-value goods;
  • converting cash into crypto-assets.

Layering

Layering involves transactions or structures intended to distance the funds from their criminal origin.

Examples include:

  • multiple transfers between accounts;
  • cross-border payments;
  • shell companies;
  • false invoices;
  • rapid conversion between assets;
  • complex ownership structures.

Integration

Integration occurs when the funds re-enter the legitimate economy in a form that appears lawful.

Examples include:

  • real estate;
  • business investments;
  • loans;
  • luxury assets;
  • securities;
  • apparently legitimate commercial income.

These stages are a useful explanatory model, but actual laundering schemes do not always follow a clear or linear sequence.

2. What is terrorist financing?

Terrorist financing is the financing of terrorist acts, terrorists or terrorist organisations. This is the definition used in the FATF Glossary.

Unlike money laundering, terrorist financing does not necessarily involve proceeds generated by crime. Funds may originate from:

  • legitimate salaries;
  • business revenue;
  • donations;
  • charitable collections;
  • state support;
  • criminal proceeds;
  • crowdfunding;
  • misuse of non-profit organisations;
  • transfers through informal financial systems.

The central concern is not only where the money came from, but how it is intended to be used.

Terrorist-financing cases may involve relatively small amounts. FATF guidance notes that assessing TF risk can be particularly difficult because terrorist activity may be supported through low-value funds or assets and through a wide variety of sectors and transfer mechanisms.

Examples of terrorist-financing activity

Potential terrorist-financing methods can include:

  • funding travel or accommodation;
  • purchasing equipment;
  • supporting recruitment;
  • financing propaganda;
  • supporting terrorist organisations;
  • transferring funds to conflict zones;
  • using charities or informal value-transfer systems;
  • using crypto-assets or online platforms;
  • concealing payments through third parties.

Not every payment to a high-risk location or non-profit organisation is suspicious. The activity must be assessed in context, including the customer profile, counterparties, destination, stated purpose and wider risk indicators.

3. Money laundering vs. terrorist financing

Money laundering and terrorist financing frequently use similar channels, products and techniques. Their underlying financial logic is nevertheless different.

IssueMoney launderingTerrorist financing
Origin of fundsUsually criminal proceedsMay be legitimate or criminal
Main purposeConceal the illegal origin or ownership of assetsSupport terrorists, terrorist organisations or terrorist acts
Typical amountsCan be small or very largeMay involve relatively small amounts
Financial directionOften focuses on integrating criminal proceedsOften focuses on moving funds toward a terrorist purpose
Detection challengeIdentifying proceeds and concealment techniquesIdentifying the intended use and network connections
Common controlsCDD, beneficial ownership, transaction monitoring, source-of-funds checksCDD, sanctions screening, network analysis, geographic and behavioural monitoring

Although the risks differ, FATF notes that both are often assessed and managed using overlapping information flows between public authorities and private-sector institutions.

This is why organisations usually operate one integrated AML/CFT framework rather than completely separate AML and CFT systems.

4. What is proliferation financing?

Proliferation financing concerns the provision or movement of funds or financial services connected with the proliferation of nuclear, chemical or biological weapons and their means of delivery.

The FATF Standards address not only money laundering and terrorist financing but also the financing of proliferation of weapons of mass destruction. Current FATF terminology therefore increasingly refers to AML/CFT/CPF.

For obliged entities, proliferation-financing controls are particularly connected with:

  • targeted financial sanctions;
  • sanctions ownership and control;
  • trade finance;
  • dual-use goods;
  • shipping and maritime activity;
  • intermediary companies;
  • complex payment chains;
  • sanctions-evasion typologies.

Proliferation-financing risk should not be treated as identical to ordinary sanctions screening. Organisations must consider the risk of breach, non-implementation or evasion of relevant targeted financial sanctions and apply risk-based mitigating measures in addition to complying with binding asset-freezing obligations.

5. The FATF AML/CFT framework

The FATF is the international standard-setting body for combating money laundering, terrorist financing and proliferation financing.

Its Recommendations form a comprehensive framework that countries are expected to adapt to their legal, administrative and financial systems. The FATF Standards comprise:

  • the 40 Recommendations;
  • Interpretive Notes;
  • definitions in the FATF Glossary.

The current Recommendations were originally adopted in 2012 and have been updated regularly, most recently in October 2025.

The seven areas of the FATF Recommendations

The FATF groups its Recommendations into seven broad areas:

  1. AML/CFT policies and coordination
  2. Money laundering and confiscation
  3. Terrorist financing and proliferation financing
  4. Preventive measures
  5. Beneficial ownership and transparency
  6. Powers and responsibilities of competent authorities
  7. International cooperation

Technical compliance and effectiveness

A country can have detailed AML/CFT laws without achieving effective outcomes.

FATF assessments therefore examine two distinct dimensions:

Technical compliance

Whether the required laws, regulations and institutional arrangements exist.

Effectiveness

Whether those measures operate in practice and achieve the required outcomes.

The FATF Methodology places significant emphasis on effectiveness and whether countries genuinely implement and use their laws, regulations and policies.

The same distinction is relevant to private-sector AML/CFT systems. An organisation may have a comprehensive policy but remain ineffective if:

  • CDD is incomplete;
  • ownership structures are not understood;
  • sanctions alerts are not investigated;
  • monitoring scenarios are inadequate;
  • suspicious activity is not escalated;
  • deficiencies are not remediated.

6. The risk-based approach

The risk-based approach, or RBA, is the central principle of the FATF Standards and the EU AML framework.

It requires countries, supervisors and obliged entities to:

  1. identify their ML/TF risks;
  2. assess and understand those risks;
  3. apply controls proportionate to the risks identified;
  4. allocate greater resources to higher-risk areas.

FATF explains that a risk-based approach allows resources to be prioritised and allocated efficiently to the areas of greatest exposure.

What the risk-based approach does not mean

The risk-based approach does not permit an organisation to:

  • ignore mandatory legal requirements;
  • remove controls solely to reduce costs;
  • treat all customers within a sector identically;
  • apply simplified due diligence without a documented lower-risk assessment;
  • use risk ratings as a substitute for professional judgement;
  • automatically terminate all higher-risk relationships.

Risk-based controls must remain proportionate, documented and capable of being explained to supervisors and auditors.

7. The EU AML/CFT framework

The European Union’s new AML/CFT framework consists of several interconnected legal instruments.

EU Anti-Money Laundering Regulation

Regulation (EU) 2024/1624 establishes directly applicable AML/CFT obligations for obliged entities. Its official title concerns the prevention of the use of the financial system for money laundering or terrorist financing.

The AMLR covers areas including:

  • internal policies, procedures and controls;
  • business-wide risk assessment;
  • compliance functions;
  • customer due diligence;
  • beneficial ownership;
  • simplified due diligence;
  • enhanced due diligence;
  • PEPs;
  • ongoing monitoring;
  • suspicious transaction reporting;
  • record retention;
  • group-wide controls.

6th Anti-Money Laundering Directive

Directive (EU) 2024/1640, commonly referred to as AMLD6, governs matters requiring implementation through Member State systems, including:

  • national supervision;
  • Financial Intelligence Units;
  • beneficial ownership registers;
  • cooperation between authorities;
  • institutional and enforcement arrangements.

AMLA Regulation

Regulation (EU) 2024/1620 established the Authority for Anti-Money Laundering and Countering the Financing of Terrorism.

AMLA is a decentralised EU agency whose functions include:

  • directly supervising selected high-risk cross-border financial entities;
  • coordinating and supporting national supervisors;
  • assisting national FIUs;
  • developing technical standards and guidelines;
  • promoting consistent implementation of EU AML/CFT rules.

AMLA is based in Frankfurt am Main. It became legally established in June 2024, and the transfer of the EBA’s AML/CFT mandates to AMLA was completed on 1 January 2026. Existing EBA AML/CFT guidelines and standards remain in force until replaced by AMLA.

Transfer of Funds Regulation

Regulation (EU) 2023/1113 establishes information requirements for transfers of funds and certain crypto-assets.

Together, these instruments form the principal components of the new EU AML/CFT Single Rulebook.

8. Core elements of an AML/CFT program

An effective AML/CFT framework should connect governance, risk assessment, customer controls, monitoring, reporting and independent assurance.

Governance

The management body should establish:

  • clear accountability;
  • adequate staffing and technology;
  • defined reporting lines;
  • escalation arrangements;
  • management information;
  • oversight of deficiencies.

Business-wide risk assessment

The organisation should identify and assess risks arising from:

  • customers;
  • products and services;
  • transactions;
  • countries;
  • delivery channels;
  • legal structures;
  • new technology;
  • outsourcing;
  • targeted financial sanctions.

Written policies and procedures

Policies should define mandatory standards. Procedures should translate those standards into operational steps.

Typical documents include:

  • customer acceptance policy;
  • CDD procedure;
  • beneficial ownership procedure;
  • PEP procedure;
  • sanctions procedure;
  • EDD procedure;
  • monitoring procedure;
  • suspicious transaction reporting procedure;
  • record-retention procedure.

Customer due diligence

CDD should establish:

  • customer identity;
  • representative authority;
  • beneficial ownership;
  • ownership and control structure;
  • purpose and intended nature;
  • expected activity;
  • customer risk;
  • relevant source-of-funds information.

Screening

Relevant screening may include:

  • PEPs;
  • family members and close associates;
  • targeted financial sanctions;
  • adverse media;
  • high-risk jurisdictions;
  • internal watchlists.

Ongoing monitoring

Monitoring should cover:

  • customer information updates;
  • transaction and activity monitoring;
  • changes in ownership;
  • changes in risk;
  • sanctions events;
  • PEP changes;
  • unusual behaviour.

Suspicious transaction reporting

The framework should define:

  • internal escalation;
  • investigation;
  • decision-making;
  • FIU reporting;
  • confidentiality;
  • tipping-off restrictions;
  • post-report controls.

Training

Training should reflect employee roles and responsibilities. Management, onboarding staff, investigators, relationship managers, technology teams and internal auditors may require different content.

Independent testing

Independent assurance should assess:

  • design effectiveness;
  • operating effectiveness;
  • data quality;
  • control coverage;
  • investigation quality;
  • remediation.

9. Customer due diligence in AML/CFT

CDD is not limited to checking a passport or company register.

A complete CDD process seeks to understand:

  • who the customer is;
  • who owns or controls the customer;
  • why the relationship is required;
  • what activity is expected;
  • where funds originate;
  • where funds will be sent;
  • whether the customer presents PEP or sanctions exposure;
  • which level of monitoring is appropriate.

Standard due diligence

Standard CDD applies the normal measures required for the identified risk.

Simplified due diligence

SDD may be applied only where a lower risk is established and the law permits reduced measures. It does not mean no due diligence.

Enhanced due diligence

EDD applies where higher risk is identified or where legislation requires additional measures.

EDD may involve:

  • additional customer information;
  • stronger verification;
  • source-of-funds evidence;
  • source-of-wealth evidence;
  • senior management approval;
  • increased monitoring;
  • more frequent review.

10. Beneficial ownership

Criminals and terrorists may misuse companies, partnerships, trusts, foundations and other structures to conceal ownership, control or movement of assets.

Beneficial ownership controls therefore seek to identify the natural persons who ultimately:

  • own the customer;
  • control the customer;
  • benefit from the relationship;
  • exercise control through other means.

An AML/CFT assessment should not rely exclusively on information recorded in a beneficial ownership register. The obliged entity should understand the complete ownership and control structure and resolve material inconsistencies.

Beneficial ownership and transparency form one of the seven principal areas of the FATF Recommendations.

11. PEP controls

A politically exposed person is a person entrusted with a prominent public function.

PEP controls are intended to manage the increased risk of:

  • bribery;
  • corruption;
  • misuse of public funds;
  • influence peddling;
  • concealment of assets.

The framework should identify relevant:

  • customers;
  • beneficial owners;
  • family members;
  • known close associates;
  • former PEPs with continuing residual risk.

PEP status does not mean that a person is involved in criminal conduct. It is a risk factor requiring proportionate enhanced controls.

12. Targeted financial sanctions

Targeted financial sanctions are legally binding restrictions imposed on designated persons or entities.

Relevant controls can include:

  • sanctions-list screening;
  • ownership and control analysis;
  • asset freezing;
  • rejection or blocking of transactions;
  • reporting to competent authorities;
  • prevention of sanctions evasion.

Sanctions controls are related to AML/CFT risk management but should not be treated as identical to it. Risk-based assessment does not replace a binding prohibition on making funds or economic resources available to a designated person.

13. Transaction monitoring

Transaction monitoring is the review of customer activity to determine whether it remains consistent with:

  • the customer profile;
  • expected behaviour;
  • known income or turnover;
  • business purpose;
  • geographical exposure;
  • source and destination of funds;
  • customer risk classification.

Potential indicators include:

  • rapid movement of funds;
  • unexplained cash activity;
  • transactions involving unusual counterparties;
  • use of multiple intermediaries;
  • activity inconsistent with known business;
  • transaction splitting;
  • sudden cross-border payments;
  • circular transactions;
  • funnel-account behaviour.

An alert is not the same as a suspicion. Alerts must be investigated and considered together with the wider customer and transaction context.

14. Financial Intelligence Units

A Financial Intelligence Unit receives, analyses and disseminates financial intelligence arising from suspicious transaction or activity reports.

FIUs form a central part of national AML/CFT systems. They operate separately from private-sector obliged entities and may exchange information with:

  • law-enforcement authorities;
  • prosecutors;
  • supervisors;
  • tax authorities;
  • customs authorities;
  • other FIUs.

Under the new EU framework, AMLA supports and coordinates FIUs, including cooperation on cross-border cases and information exchange.

15. The role of AMLA

AMLA is intended to improve the consistency and effectiveness of AML/CFT supervision across the European Union.

Its principal responsibilities include:

  • direct supervision of selected high-risk financial-sector entities operating across borders;
  • indirect support for supervision in financial and non-financial sectors;
  • development of regulatory and implementing technical standards;
  • issuance of guidelines;
  • coordination of national FIUs;
  • facilitation of joint cross-border analysis;
  • management of FIU.net.

AMLA does not replace every national supervisor or FIU. It sits at the centre of an integrated European system designed to improve supervisory convergence and cross-border cooperation.

16. AML/CFT risks by sector

Different sectors are exposed to different financial-crime methods.

Banks

Relevant risks may include:

  • cash;
  • correspondent banking;
  • trade finance;
  • cross-border payments;
  • private banking;
  • complex corporate structures.

Payment institutions

Risks may include:

  • rapid transfers;
  • agents;
  • cross-border remittances;
  • third-party funding;
  • merchant acquiring;
  • fragmented transaction data.

Crypto-asset service providers

Risks may include:

  • pseudonymous transfers;
  • mixers;
  • high-risk wallets;
  • rapid cross-border movement;
  • darknet exposure;
  • sanctions evasion.

Real estate

Risks may include:

  • high-value assets;
  • complex corporate buyers;
  • third-party funding;
  • overseas ownership;
  • rapid resale;
  • opaque beneficial ownership.

Risks may include:

  • company formation;
  • client accounts;
  • asset management;
  • trust structures;
  • property transactions;
  • professional concealment.

Gambling

Risks may include:

  • cash;
  • rapid deposits and withdrawals;
  • account transfers;
  • collusion;
  • use of third parties;
  • conversion of illicit funds into apparently legitimate winnings.

A risk-based framework should reflect the actual vulnerabilities of the relevant sector rather than applying a generic control model.

17. Common AML/CFT red flags

No single indicator necessarily establishes money laundering or terrorist financing. Multiple indicators, unusual context or implausible explanations may justify further review.

Common red flags include:

  • reluctance to disclose beneficial ownership;
  • inconsistent customer information;
  • unexplained use of intermediaries;
  • complex structures without economic rationale;
  • activity inconsistent with known income;
  • rapid movement of funds;
  • repeated cash transactions;
  • transfers involving high-risk jurisdictions;
  • unexplained third-party payments;
  • transactions lacking an apparent lawful purpose;
  • use of several accounts or entities without clear reason;
  • adverse media concerning relevant criminal conduct;
  • connections with sanctioned persons or entities.

Indicators should be assessed in context and documented through a structured investigation process.

18. AML/CFT and de-risking

A risk-based approach does not require organisations to avoid all higher-risk customers, sectors or countries.

Wholesale termination or refusal of entire categories of customers can create:

  • financial exclusion;
  • reduced transparency;
  • movement toward unregulated channels;
  • concentration of risk;
  • loss of useful financial intelligence.

A more appropriate approach is to:

  • assess individual risk;
  • apply proportionate controls;
  • obtain additional evidence;
  • restrict specific products where justified;
  • enhance monitoring;
  • decline or terminate relationships only where risks cannot be managed or CDD cannot be completed.

19. AML/CFT technology

Technology supports AML/CFT compliance through:

  • digital identity verification;
  • company and register checks;
  • beneficial ownership analysis;
  • PEP and sanctions screening;
  • adverse media screening;
  • customer risk scoring;
  • transaction monitoring;
  • case management;
  • suspicious transaction reporting;
  • management reporting.

Technology does not transfer regulatory accountability away from the obliged entity.

The organisation should understand:

  • data sources;
  • matching logic;
  • thresholds;
  • model limitations;
  • false-positive handling;
  • access controls;
  • system changes;
  • audit trails;
  • vendor dependencies.

Automated decisions should remain subject to appropriate governance, explainability and human oversight.

20. AML/CFT effectiveness testing

The existence of controls does not demonstrate that the AML/CFT framework works.

Design effectiveness

Design testing asks whether a control is capable of addressing the relevant risk.

Examples:

  • Does the PEP procedure cover beneficial owners?
  • Does the transaction-monitoring rule address the stated typology?
  • Does the customer-review process include event-driven triggers?
  • Does the sanctions process assess ownership and control?

Operating effectiveness

Operating testing asks whether the control was performed correctly and consistently.

Examples:

  • Were customers screened when required?
  • Were alerts investigated on time?
  • Was EDD supported by evidence?
  • Were overdue reviews escalated?
  • Were suspicious matters reported promptly?

Outcome effectiveness

Outcome testing considers whether the overall system achieves meaningful risk reduction.

Examples:

  • Are material risks identified?
  • Are suspicious cases detected?
  • Are high-risk relationships subject to stronger controls?
  • Are weaknesses remediated?
  • Does management receive reliable information?

This reflects the FATF principle that AML/CFT requirements must be implemented effectively rather than treated as a tick-box exercise.

21. AML/CFT implementation checklist

Control areaMinimum requirement
ScopeIdentify all in-scope entities, services and activities
GovernanceAssign management and operational accountability
Risk assessmentAssess ML, TF and relevant sanctions risks
PoliciesMaintain approved and current written standards
ProceduresTranslate requirements into operational processes
Customer identificationIdentify and verify customers
RepresentativesVerify authority to act
Beneficial ownershipIdentify ownership and control through other means
PurposeUnderstand the purpose and intended nature of relationships
Customer riskComplete an individual risk assessment
PEPsIdentify and manage PEP-related risks
SanctionsScreen relevant persons, ownership and transactions
SDDApply only where lower risk is established
EDDApply additional measures to higher-risk cases
MonitoringMaintain current customer information
TransactionsDetect unusual and potentially suspicious activity
ReportingEscalate and report suspicions to the FIU
RecordsPreserve complete and auditable evidence
TrainingProvide role-specific AML/CFT training
TechnologyMaintain reliable data, systems and access controls
OutsourcingRetain accountability and oversight
Group controlsApply consistent group-wide standards
AssuranceTest design and operating effectiveness
RemediationCorrect and validate identified weaknesses

22. Common AML/CFT compliance weaknesses

Treating AML and CFT as identical risks

The two risks overlap but differ in source, purpose, transaction profile and indicators.

Relying on a generic risk assessment

The assessment does not reflect the organisation’s actual customers, products, channels, countries and controls.

Focusing only on customer identity

The organisation verifies identity but does not understand ownership, control, purpose, expected activity or source of funds.

Applying the same controls to every customer

The process does not distinguish between lower, standard and higher-risk relationships.

Screening without investigation

Alerts are generated but not resolved through reliable analysis and evidence.

Monitoring only financial transactions

Non-transactional events, ownership changes, new adverse media or sanctions developments are ignored.

Treating policies as evidence of effectiveness

Written documents exist, but controls are not implemented or tested.

Closing findings without validation

Remediation actions are marked complete without confirming that the underlying weakness has been corrected.

Frequently asked questions

What does AML/CFT stand for?

AML/CFT stands for anti-money laundering and countering the financing of terrorism.

Is CFT the same as counter-terrorist financing?

Yes. CFT is commonly used to mean countering the financing of terrorism or counter-terrorist financing.

What is the difference between AML and CFT?

AML focuses mainly on criminal proceeds and attempts to conceal their illegal origin. CFT focuses on funds or assets intended to support terrorist acts, terrorists or terrorist organisations. Terrorist funds may originate from legitimate or illegal sources.

What is AML/CFT/CPF?

AML/CFT/CPF means anti-money laundering, countering the financing of terrorism and counter-proliferation financing. FATF uses this wider terminology because its Standards also address financing connected with the proliferation of weapons of mass destruction.

Who sets international AML/CFT standards?

The FATF sets the principal international AML/CFT standards through its 40 Recommendations and related Interpretive Notes and Glossary.

What is the risk-based approach?

The risk-based approach requires organisations to identify and understand their ML/TF risks and apply controls proportionate to those risks.

Is KYC the same as AML/CFT?

No. KYC and customer due diligence are central components of AML/CFT, but the wider framework also includes governance, risk assessment, monitoring, suspicious transaction reporting, sanctions controls, training and independent testing.

What is an FIU?

An FIU is a national Financial Intelligence Unit that receives and analyses suspicious transaction or activity reports and disseminates relevant intelligence to competent authorities.

What is AMLA?

AMLA is the EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism. It supports supervisory convergence, coordinates FIUs, develops regulatory standards and will directly supervise selected high-risk cross-border financial entities.

When does the EU AML Regulation apply?

Regulation (EU) 2024/1624 generally applies from 10 July 2027.

AML/CFT is an integrated risk-management framework

AML/CFT is not a single check, policy or software tool.

It is an integrated framework designed to prevent the misuse of financial and economic systems for:

  • laundering criminal proceeds;
  • financing terrorism;
  • evading targeted financial sanctions;
  • financing weapons proliferation.

An effective AML/CFT system connects:

  • management governance;
  • business-wide risk assessment;
  • customer due diligence;
  • beneficial ownership;
  • PEP and sanctions controls;
  • ongoing monitoring;
  • transaction monitoring;
  • suspicious transaction reporting;
  • data and technology;
  • training;
  • independent assurance.

The system must address the distinct characteristics of money laundering and terrorist financing while using shared information, systems and controls where appropriate.

For organisations operating in the European Union, the AMLR and the developing AMLA Single Rulebook make this integrated approach increasingly important. Obliged entities should be able to demonstrate not only that formal requirements have been implemented, but that their AML/CFT systems identify and mitigate risks effectively in practice.

Is your AML/CFT framework ready for the EU AML Regulation?

An AML/CFT framework assessment can identify weaknesses in:

  • governance and accountability;
  • business-wide risk assessment;
  • customer due diligence;
  • beneficial ownership;
  • PEP and sanctions controls;
  • terrorist-financing risk;
  • transaction monitoring;
  • suspicious transaction reporting;
  • data and technology;
  • control effectiveness.

Leave a Reply

Your email address will not be published. Required fields are marked *