AML (anti-money laundering)
AML (anti-money laundering) is the set of laws, controls and checks financial institutions use to detect, prevent and report money laundering activity.
AML (anti-money laundering) refers to the laws, regulations, policies and internal controls that financial institutions use to detect, prevent and report attempts to disguise the origin of criminally obtained funds. An AML programme combines customer due diligence, transaction monitoring, screening and regulatory reporting to stop illicit money from entering the financial system.
Money laundering is the process of making proceeds from crime β fraud, corruption, tax evasion, drug trafficking, human trafficking β appear to come from a legitimate source. AML is the counter-discipline: everything an institution does to make that process difficult, detectable and reportable.
AML obligations apply far beyond commercial banks. Microfinance institutions, SACCOs, credit unions, mobile money operators, payment processors, insurers, foreign exchange bureaus, casinos, real estate agents, lawyers and accountants are all treated as reporting entities in most jurisdictions.
Why AML Matters
AML exists because the financial system is the main channel through which criminal proceeds are moved and legitimised. Its purpose is both preventive and investigative.
- Regulatory obligation. AML compliance is a legal requirement, not a best practice. Failures carry fines, licence suspension, director liability and, in serious cases, criminal prosecution.
- Financial crime disruption. Reports filed by institutions give financial intelligence units the raw data used to trace and freeze criminal proceeds.
- Institutional risk. Being used as a laundering conduit β knowingly or not β creates reputational damage, correspondent banking de-risking and loss of funding partners.
- Country risk. Jurisdictions with weak AML enforcement can be placed under increased international monitoring, which raises the cost of cross-border payments for every institution operating there.
The Three Stages of Money Laundering
AML controls are designed around the three recognised stages of the laundering cycle.
1. Placement
Illicit cash enters the financial system β deposits below reporting thresholds, cash-intensive businesses, prepaid instruments, mobile wallets, or loan repayments made in cash. This is the stage at which criminal funds are most exposed and most detectable.
2. Layering
Funds are moved through a series of transactions designed to break the audit trail: transfers between accounts, cross-border wires, shell companies, early loan settlements, currency conversions and purchases of financial instruments.
3. Integration
The now-distanced funds re-enter the economy as apparently legitimate wealth β property, business investment, luxury assets or loan collateral. At this point the money is difficult to distinguish from clean capital.
Core Components of an AML Programme
Most regulatory frameworks require the same structural elements, often described as the pillars of AML compliance.
Institutional risk assessment
A documented assessment of the money laundering and terrorist financing risks the institution faces, based on its customers, products, delivery channels, transaction types and geographies. Every other control is calibrated against this assessment.
Customer due diligence (CDD) and KYC
KYC (Know Your Customer) is the identification and verification step: collecting and validating identity documents, addresses, business registration details and beneficial ownership information. CDD extends this to understanding the purpose of the relationship and the customer's expected transaction behaviour.
Enhanced due diligence (EDD) applies to higher-risk relationships β politically exposed persons, complex ownership structures, high-value cash activity, or customers in high-risk jurisdictions. It requires additional verification, source-of-funds and source-of-wealth evidence, and senior approval.
Simplified due diligence (SDD) may be permitted for demonstrably low-risk products, such as small-value group loans or basic savings accounts, where regulation allows.
Screening
Customers and counterparties are screened against sanctions lists, terrorist designation lists, PEP (politically exposed person) databases and adverse media. Screening is performed at onboarding and re-run periodically or when lists change.
Transaction monitoring
Ongoing review of account and payment activity against expected behaviour. Monitoring rules typically flag structuring below thresholds, rapid movement of funds, unexplained third-party repayments, early loan settlement in cash, dormant accounts becoming active, and transactions inconsistent with a stated income profile.
Reporting
Where activity cannot be explained, the institution files a suspicious transaction report (STR) β called a suspicious activity report (SAR) in some jurisdictions β with the national financial intelligence unit. Many countries also require currency or cash transaction reports (CTRs) above a fixed threshold regardless of suspicion. Tipping off the customer that a report has been filed is a criminal offence in most frameworks.
Governance, training and independent testing
A designated AML compliance officer with sufficient seniority and independence, board-approved policies, documented procedures, periodic staff training, and independent audit or review of the programme's effectiveness.
Record keeping
Customer identification records, transaction records and internal reports are typically retained for five to ten years after the relationship ends, and must be retrievable for regulators and law enforcement.
The Risk-Based Approach
Modern AML regulation is built on a risk-based approach (RBA): institutions allocate compliance effort in proportion to assessed risk rather than applying identical checks to every customer. Low-risk, low-value relationships receive proportionate controls; high-risk relationships receive enhanced scrutiny.
The risk-based approach is also what makes financial inclusion possible. Rigid, uniform documentation requirements exclude customers who lack formal identity documents or address proof, which is a significant concern in markets served by microfinance institutions and SACCOs. Tiered KYC β where account limits scale with the level of verification provided β is the standard regulatory response.
AML vs KYC vs CFT
These terms are related but not interchangeable.
- AML β The full framework for preventing, detecting and reporting money laundering.
- KYC β The customer identification and verification component within AML.
- CDD β Ongoing understanding of the customer and their expected activity.
- CFT / CTF β Countering the financing of terrorism β usually regulated alongside AML as "AML/CFT".
- CPF β Countering proliferation financing, increasingly bundled into the same obligations.
The key distinction between AML and CFT: money laundering disguises illegitimate funds as legitimate, while terrorist financing may route legitimate funds toward illegitimate ends. Detection logic differs, but the control set largely overlaps.
Global and Regional AML Frameworks
- FATF (Financial Action Task Force) β the intergovernmental standard-setter. Its 40 Recommendations form the basis of national AML law in most countries, and its evaluation process assesses both technical compliance and effectiveness. Jurisdictions with strategic deficiencies may be placed on the increased monitoring list (commonly called the grey list) or the high-risk list.
- FATF-style regional bodies β including ESAAMLG in Eastern and Southern Africa, GIABA in West Africa, MENAFATF and APG, which conduct mutual evaluations at regional level.
- National regimes β such as the US Bank Secrecy Act and USA PATRIOT Act administered by FinCEN, the EU Anti-Money Laundering Directives and AML Regulation, and the UK Money Laundering Regulations.
- Financial intelligence units (FIUs) β the national bodies that receive STRs, analyse them and disseminate intelligence to law enforcement.
Listing status, thresholds and reporting formats change regularly. Institutions should confirm current requirements with their national regulator or FIU rather than relying on general reference material.
AML in Lending and Credit
Lending is often assumed to be lower risk than deposit-taking, but credit portfolios carry specific laundering typologies:
- Loan-back schemes β illicit funds are placed offshore or with a related party and returned as an apparently legitimate loan.
- Early settlement in cash β a loan is drawn down and repaid quickly in cash, producing a clean paper trail of "loan repayment".
- Third-party repayments β repayments consistently made by parties with no established relationship to the borrower.
- Over-collateralisation β criminal proceeds pledged as security, with default used deliberately to transfer the asset.
- Group lending abuse β nominee borrowers used to disaggregate larger sums into individually unremarkable amounts.
Effective controls in a credit context therefore include source-of-funds checks on collateral and prepayments, monitoring of repayment channels, and beneficial ownership verification for corporate and group borrowers.