loader image

8 steps to a compliant AML policy

Richard Simms
Richard Simms

Director and Founder of AMLCC and AMLCC Consult

8 steps to a compliant AML policy

Your anti-money laundering (AML) policy isn’t just paperwork. It’s the backbone of your firm’s compliance framework. The document that explains how you identify, assess and manage money laundering risks.

Supervisors are increasingly focused on assessing whether a businesses AML policies, controls and procedures (PCPs) actually work.

Effective AML is measured by outcomes, not paperwork, which means showing that your business understands its AML risk, acts on it proportionately and can prove it with real-life results.

If your AML policy document and your AML PCPs are outdated, copied from a template or missing key details, that gap shows immediately.

Whether you’re updating your AML policies or building them from scratch, here’s a practical guide to what needs to be included and how to keep it fit for purpose.

1. Link your policy to your business-wide risk assessment

Every AML policy should be built on your firm’s business-wide risk assessment. This assessment identifies where and how your business could be used for money laundering, terrorist financing or proliferation financing.

Your policy must then explain how you manage those risks in practice. For example:

Client risk: How you assess and categorise different client types

Service risk: How high-risk services (like company formation or conveyancing) are handled

Geographic risk: How you manage exposure to high-risk jurisdictions

Delivery channels: How you address risks from online or non-face-to-face onboarding

If the risks in your policy don’t reflect your actual client base or services, supervisors will view it as generic and therefore non-compliant.

2. Define clear roles and responsibilities

Supervisors expect to see that your AML policy spells out who does what. That means identifying key roles and their duties, such as:

Money Laundering Reporting Officer (MLRO): Responsible for receiving internal reports of suspicious activity and reporting them to law enforcement, where they think it’s necessary.

Deputy MLRO (if applicable): Steps in when the MLRO is unavailable.

Senior management: Accountable for ensuring AML systems are effective.

All staff: Responsible for following the policy and reporting concerns. Listing these roles demonstrates that compliance isn’t theoretical, it’s operational.

3. Outline your customer due diligence (CDD) process

This section should explain how your business verifies clients’ identities and the steps you take for:

Standard due diligence: Verifying ID, proof of address and beneficial ownership

Enhanced due diligence (EDD): What triggers it and what extra checks you carry out

Ongoing monitoring: How you keep client information current and identify unusual activity

Simplified due diligence (SDD): When and how it can be applied (and the justification for doing so)

Documenting your approach ensures staff follow a consistent process and gives regulators evidence that you’re managing risks proportionately.

4. Include your approach to training and awareness

An effective AML policy makes it clear that AML knowledge is part of business’ culture. FATF’s Recommendation 18 expects regulated businesses to train staff regularly and keep evidence of it.

Your policy should outline:

  • how often AML training takes place;
  • which roles receive which type of training;
  • how you test understanding (e.g. online assessments or scenario discussions);
  • how training completion is recorded.

5. Explain your internal reporting and escalation process

Clear escalation pathways prevent hesitation and protect both the employee and the business from regulatory breaches. Every staff member should know exactly what to do if they have a suspicion. 

Your policy must set out:

  • how to make an internal report to the MLRO;
  • what happens once a report is made;
  • how the MLRO assesses whether to submit an external report to the relevant agency;
  • the importance of confidentiality and the prohibition on ‘tipping off’.

6. Cover record-keeping and data retention

Your policy should explain how AML records are stored, secured and retained. Under FATF’s Recommendation 11, AML-related records must be kept for at least five years after a client relationship or transaction ends.

Make sure your policy covers:

  • what’s recorded (risk assessments, ID documents, internal and external reports, training records);
  • where and how the data is stored;
  • how access is controlled;
  • when and how data is securely deleted.

7. Build in regular reviews and version control

Policies go out of date faster than many realise. Changes to legislation, new risk types or shifts in your client base can make yesterday’s approach obsolete.

Set out in your document:

  • how often reviews take place (at least annually, or when risks change);
  • who is responsible for reviewing and approving updates;
  • how changes are communicated and acknowledged by staff.

8. Make it practical, not theoretical

Supervisors are quick to spot template policies. The most compliant businesses go further, making their policy document a living guide that’s linked directly to their actual PCPs and shows how decisions are made in practice. 

To achieve this:

  • avoid vague statements like “We take a risk-based approach” and instead describe how you apply it;
  • reference specific forms, systems or workflows used in your business;
  • ensure the tone reflects your size, services and structure.

How AMLCC helps you get it right

Keeping your AML PCPs aligned with your business’ risks is easier said than done, especially when regulations keep changing.

The AMLCC platform takes the complexity out of it by helping you:

  • build a tailored AML policy linked to your Business Risk Assessments;
  • keep automatic audit trails of changes and approvals;
  • track staff AML Training and acknowledgements;
  • stay aligned with the latest legislation and sector guidance.

An AML Policy is more than a compliance checkbox. It’s your evidence that your business understands its risks, takes them seriously, and manages them responsibly.

A strong policy does three things:

  1. Explains your risks clearly
  2. Describes your processes transparently
  3. Proves you act on them consistently

Get those three right, and keep the policy live and tailored, and that’s effective AML: a document that shows the inherent risk you found, what you’ve done to mitigate it and how those mitigations have worked in practice. 

Explore AMLCC’s AML Policy and other features.

The one-stop AML solution

We know AML

We’re internationally recognised AML experts
We work with most accountancy supervisors and the Law Society
Bespoke AML consultancy available for all sectors

The one-stop AML solution

We know AML

We’re internationally recognised AML experts
We work with most accountancy supervisors and the Law Society
Bespoke AML consultancy available for all sectors

What others have said

“We had the man from the ICAEW here yesterday to carry out a QAD practice review. We got a clean bill of health – not a single action point…That is in no small measure due to AMLCC so I just wanted to say ‘thank you’”

“Thank you for such a perfect and informative [solution]. You have given me a clear direction for my AML training and CPD.”

“I just wanted to say ‘thank you’ to you, Richard, and all the team at AMLCC for providing a service that really does minimise the burden of AML compliance.”

“What a refreshing pleasure working with a company who actually listens to the feedback from their customers and communicates with them!”

“Your team they have been excellent from the moment Fiona did a demo for me with only 15 minutes notice, and thoroughly going through the AMLCC product, answering the many questions I had! It was at this point at which I made up my mind this is the sort of business I want to work with for my AML.”

Making compliance easier

AMLCC newsroom
Scroll to Top