What is an AML Policy?

An AML policy is a board-approved document that sets out how a business prevents, detects, and reports money laundering and terrorist financing.

An AML policy defines what must happen across the compliance program. It sets the standards for customer due diligence, sanctions screening, transaction monitoring, and suspicious activity reporting. It also assigns ownership, so every requirement has someone accountable for it.

An AML policy is the written backbone of a risk-based program. Policies state what must happen, procedures explain how, and controls prove that it did. Regulators expect the policy to reflect a firm's actual risks and the current rules in every market where it operates, including evolving money laundering threats.

What should an AML policy include?

An AML policy should cover every pillar of the compliance program. A typical master AML policy includes the following.

  • Scope and definitions
  • Risk appetite statement and guiding principles
  • Enterprise risk assessment methodology
  • KYC and beneficial ownership standards
  • Enhanced due diligence triggers
  • Sanctions screening
  • Transaction monitoring and investigations
  • Suspicious activity reporting
  • Staff training
  • Record keeping and retention
  • Governance and change control

Firms operating in several countries usually add local addenda to the master AML policy. These cover jurisdiction-specific rules such as reporting thresholds, filing portals, and deadlines in markets like the US, UK, EU, and Singapore.

Who approves and maintains an AML policy?

The MLRO or head of compliance usually drafts and owns the AML policy, while the board or executive team formally approves it. Legal and business leaders are consulted during drafting, and internal audit is kept informed.

An AML policy should be reviewed at least once a year. Firms also update it outside that cycle when regulations change, and any material change goes back to the board for approval. Version control with a unique ID for each release shows regulators and auditors how the AML policy has evolved. Staff typically confirm they have read each update through a read-and-sign process.

What is the difference between an AML policy and AML procedures?

An AML policy states what must happen, while AML procedures explain how staff carry it out. For example, an AML policy might require enhanced due diligence for politically exposed persons. The matching procedure would list the documents to collect, the systems to use, who signs off, and how quickly the review must be completed.

Controls sit alongside both and prove the work was done. Preventive controls stop risk at the door, such as a KYC completeness check at onboarding. Detective controls catch problems after the fact, such as rules that flag structuring or transaction monitoring alerts. Corrective controls respond to what was found, such as exiting a customer relationship or filing a suspicious activity report.