A

AML (Anti-Money Laundering)

Quick Answer

AML, or Anti-Money Laundering, refers to laws, regulations, controls and procedures designed to prevent, detect and address the misuse of financial systems for money laundering. AML frameworks commonly include customer due diligence, record keeping, transaction monitoring, suspicious-transaction reporting and risk-based controls applied by regulated financial institutions and other covered entities.

How does AML work?

Money laundering involves attempts to disguise or obscure the criminal origin of funds or other assets so they appear legitimate. AML frameworks are intended to make it more difficult for criminals to use financial institutions and other businesses to process or conceal illicit proceeds.

The Financial Action Task Force, or FATF, sets international standards for combating money laundering, terrorist financing and proliferation financing. Its Recommendations cover areas such as preventive measures, beneficial ownership, supervision, financial intelligence and international cooperation. The current FATF Recommendations were last updated in June 2026.

A central part of AML is customer due diligence (CDD). FATF Recommendation 10 requires financial institutions, within applicable national frameworks, to identify customers, verify their identities using reliable and independent information, and take reasonable measures to identify and verify beneficial owners.

AML systems may also require institutions to monitor business relationships and transactions and report activity considered suspicious to the relevant authority or financial intelligence unit under applicable law.

Key features of AML

Several elements commonly form part of an AML framework:

  • Customer identification and verification: Financial institutions may be required to establish who their customers are and verify identity using reliable information.

  • Beneficial ownership checks: Institutions may need to determine who ultimately owns or controls a legal person or arrangement rather than relying only on its registered name.

  • Risk-based approach: FATF standards emphasise identifying and understanding money-laundering and terrorist-financing risks so resources and controls can be proportionate to those risks.

  • Transaction and relationship monitoring: Ongoing monitoring can help identify behaviour that differs from the expected nature or risk profile of a customer relationship.

  • Suspicious-transaction reporting: Where legal requirements are met, institutions may have obligations to report suspicious activity to the relevant authority.

  • Record keeping and internal controls: AML frameworks can require institutions to retain specified information and maintain procedures, controls and governance intended to support compliance.

Simple AML example

Suppose a financial institution receives an application from a new customer.

As part of its AML process, the institution may:

  1. obtain the customer's identification information;

  2. verify that information using reliable documentation or data;

  3. establish relevant information about the purpose and expected nature of the relationship;

  4. assess the customer's money-laundering risk;

  5. apply ongoing monitoring appropriate to that risk.

If later transactions appear inconsistent with the information held about the customer or raise other relevant warning signs, the institution may conduct further review and take any action required under applicable AML rules.

This example is illustrative. The exact legal requirements, thresholds, documentation and reporting obligations differ by jurisdiction and type of institution.

Potential benefits and uses

AML measures are intended to protect financial systems from misuse by criminals and to help authorities detect and disrupt illicit financial flows.

Effective AML frameworks may help:

  • reduce opportunities to process proceeds of crime through legitimate financial systems;

  • provide financial intelligence that can support investigations;

  • improve transparency concerning customers and beneficial owners;

  • help institutions identify and manage higher-risk relationships;

  • support the integrity of financial markets and financial institutions.

FATF describes the broader objective of AML and related measures as protecting financial systems and economies from threats associated with money laundering, terrorist financing and proliferation financing.

Risks, limitations and common misconceptions

A common misconception is that AML and KYC, or Know Your Customer, mean exactly the same thing. They are related but not identical. Customer identification and due diligence are components of a broader AML framework, which can also include risk assessment, transaction monitoring, reporting, record keeping and internal controls.

Another misconception is that passing an identity check means a customer can never present money-laundering risk. AML is generally an ongoing process, and risk can change as circumstances or transaction patterns change.

AML controls also do not guarantee that all financial crime will be detected. Risk-based systems prioritise attention and resources according to assessed risk, but criminals can adapt their methods and attempt to circumvent controls. FATF therefore updates its standards and guidance as threats evolve.

AML rules are also jurisdiction-specific. FATF establishes international standards, but individual countries implement those standards through their own laws, regulations and supervisory frameworks. Requirements should therefore not be assumed to be identical across all markets.