What is Anti-Money Laundering?
Anti-money laundering (AML) is the set of laws, regulations, and controls that stop criminals from disguising illegal funds as legitimate income.
AML works at two levels. Governments pass laws that make money laundering a crime and place obligations on businesses that handle money. Financial institutions and other regulated firms then build compliance programs to meet those obligations. These programs verify who customers are, watch how money moves, and report suspicious activity to authorities.
The goal is to cut criminals off from the financial system. Laundering lets drug traffickers, fraudsters, and corrupt officials spend and reinvest their proceeds. Strong AML controls make that harder at every stage, from the first deposit to the final purchase.
AML is a global effort. The Financial Action Task Force (FATF) sets international standards, and more than 200 jurisdictions have committed to following them. Each country then writes its own laws and appoints regulators to enforce them.
What are the main components of an AML program?
An AML program combines several core controls that work together.
- Know your customer (KYC) and customer due diligence (CDD) to verify identity and assess risk at onboarding
- Enhanced due diligence (EDD) for higher-risk customers such as politically exposed persons
- Sanctions and watchlist screening against lists like OFAC and the UN Security Council list
- Transaction monitoring to detect unusual patterns in customer activity
- Suspicious activity reporting to the national financial intelligence unit
- Record keeping, usually for at least five years
- Ongoing risk assessment, staff training, and independent testing
Most regulators expect this program to be risk-based. Firms put the most effort into the customers, products, and regions that carry the highest risk instead of applying identical checks to everyone.
Who needs to comply with AML regulations?
Any business that regulators see as a possible channel for illicit funds must comply. Banks were the original focus, but the scope has widened considerably.
- Banks, credit unions, and digital banks
- Payment processors, money transmitters, and remittance providers
- Crypto exchanges and other virtual asset service providers
- Brokerages, investment firms, and trust companies
- Casinos and online gaming operators
- Real estate agents, precious metals dealers, accountants, and lawyers in many jurisdictions
Exact obligations vary by country and business type. A fintech operating in several markets often has to meet different rules in each one.
What are the key AML laws and regulators?
A handful of frameworks shape AML rules around the world.
- FATF Recommendations, the global baseline most national laws follow
- The Bank Secrecy Act in the United States, administered by FinCEN
- The EU AML rulebook, with the new Anti-Money Laundering Authority (AMLA) coordinating supervision across member states
- The UK Money Laundering Regulations 2017, supervised by the FCA and other bodies
- National regulators such as MAS in Singapore, AUSTRAC in Australia, and FINTRAC in Canada
What is the difference between AML and KYC?
KYC is one part of AML, not a separate discipline. KYC focuses on verifying a customer's identity and understanding who they are. AML is the broader program that includes KYC along with monitoring, screening, reporting, and governance. A firm can have strong KYC and still fail its AML obligations if it misses suspicious activity after onboarding.
What is the difference between AML and CFT?
AML targets money that comes from crime. Countering the financing of terrorism (CFT) targets money headed toward terrorism, which can come from legitimate sources. The two rely on largely the same controls, so regulators usually group them together as AML/CFT.
What happens when a company fails at AML?
Weak AML controls expose firms to heavy fines, criminal charges, and lasting reputational damage. TD Bank pleaded guilty in 2024 and agreed to pay about $3 billion over AML failures in the United States. Binance agreed in 2023 to pay more than $4 billion to resolve US charges that included AML violations. Regulators can also cap a firm's growth, appoint independent monitors, or revoke licenses. Individual compliance officers may face personal liability as well.
How does technology support AML compliance?
Manual review cannot keep pace with modern transaction volumes. AML software automates screening, monitoring, and risk scoring so analysts can spend their time on real risk. False positives are one of the biggest costs in compliance, since legacy rules-based systems flag far more legitimate activity than actual crime. Many teams now use AI to cut that noise and speed up investigations while keeping humans in control of final decisions.