loader image

The 6 signs your AML PCPs are out of date

Lisa Simms
Lisa Simms

Director and Founder of AMLCC and AMLCC Consult

When was the last time you gave your AML policies, controls and procedures (PCPs) more than a passing glance?

If you’re like many busy regulated professionals, it’s probably been a while. After all, once the policies, controls and procedures have been discussed, written, signed off and stashed in the compliance folder, it’s easy to assume it’s sorted. And you have your day job to do.

But AML compliance doesn’t work like that. Criminal methods evolve fast. Regulations shift. Supervisors tighten expectations. And what passed muster last year might fall flat today.

That means your AML policies, controls and procedures might not just be out of date. They could be putting your business at risk. Here are the 6 signs that you need to relook at them now.

1. You haven’t reviewed them in the last 12 months

The first and most obvious sign: if your written AML PCPs haven’t had a formal review in the last year, they’re overdue. 

FATF’s Recommendation 18 requires countries to ensure regulated businesses keep their policies, controls and procedures effective and current. Most supervisors interpret this as a minimum of an annual review, even if nothing has changed.

If that review hasn’t happened in the last 12 months:

  • you might be missing changes to regulations or guidance;
  • your written policies may not reflect your actual risk exposure or internal controls;
  • you’re potentially falling short of what Recommendation 18 requires of you.

What to do: Set a formal review schedule. Document it. Assign responsibility. If you’re using AMLCC, the system flags when reviews are due and guides you through the update process.

2. Your written PCPs are full of generic content or copied templates

Your AML policy document could be 30 pages long but say almost nothing specific. Effective AML comes from how well the policy reflects how your business identifies and manages its risk.


If your written AML policy is based on a downloaded template, with no reference to your firm’s structure, client base or service risks, it’s unlikely to get past an inspection.

To tailor your AML PCPs, you need to align them with your:

  • business’ size, services and client base;
  • delivery channels (online, face-to-face, intermediaries);
  • geographical risk exposure;
  • staff structure and experience;
  • day-to-day operational realities.

A templated approach that doesn’t reflect your actual business activities won’t stand up to scrutiny.

What to do: Rewrite or rebuild your written policy to match your risk assessment. Use tech like AMLCC to link your policies, controls and procedures directly to your risk profile, creating an integrated and evidence-based document.

3. Your policies, controls and procedures aren’t aligned with your risk assessment

Strong AML PCPs are built on your business’ risk assessment. It’s common for businesses to update their risk assessment periodically, especially when services change or new client types come on board. But if your written policies haven’t been updated at the same time, they’re likely missing important context.

Your AML framework should clearly show how your business identifies, assesses and responds to the risks outlined in your risk assessment. 

If your client base has shifted and you’re seeing more layered ownership structures, PEPs or high-net-worth individuals, that should be directly reflected in the controls and procedures your firm has in place.

Supervisors want to see that your AML policies, controls and procedures are driven by your business’ real inherent risk, not theory.

What to do: Revisit your AML policies, controls and procedures whenever your risk profile changes. Make sure there’s a clear link between what you know about your clients and how you’re managing those risks in practice. 

If you’re using AMLCC, you can easily add any additional procedures you have put in place to the relevant section of your PCPs and update all staff on those changes automatically.

4. They don’t cover digital or remote working risks

Has your business, like many, shifted to more remote or hybrid working? Have you increased use of digital onboarding, e-signatures or cloud-based document sharing? If so, your AML policies, controls and procedures must reflect that.

Money laundering risk has changed. Criminals are actively exploiting remote environments, using fake IDs, deepfake tech, spoofed documents and untraceable messaging apps. 

If your policy document was written when most interactions were face-to-face, it won’t cover these new risks.

Some of the signs your PCPs are behind the times are that they have:

  • no guidance on verifying identity remotely;
  • no mention of cyber risk or data security in AML processes;
  • no controls for monitoring online communication channels.

What to do: Update your risk assessment to include technology-related risks, and make sure your AML policies, controls and procedures follow suit. Include procedures for remote CDD, digital verification tools and secure record-keeping.

5. Your team don’t know what they are

This one’s simple to diagnose. Ask your staff, especially those in client-facing or compliance roles, if:

  • they know your AML policies, controls and procedures and what’s in your written AML policy;
  • they are happy they have digested and understood all AML training;
  • they can summarise their responsibilities;
  • they know the escalation procedure for suspicious activity.

If the answer is no to any of these then your PCPs and training might as well not exist.

FATF’s Recommendation 18 requires you to ensure that staff are aware of them, understand them and receive regular training. A PDF no one’s read won’t protect your firm or demonstrate compliance.

What to do: Build awareness into your training programme. Use practical examples and make the content relevant to each role. Platforms like AMLCC let you track staff understanding and acknowledge policy updates.

6. They haven’t been tested

When was the last time you tested whether your AML PCPs actually work under pressure? Because until they come up against a real suspicious client, an internal breach or a supervisory visit you don’t know how effective your AML really is. 

FATF’s Recommendation 18 requires countries to make sure businesses have an independent audit function to test their AML systems. Many supervisors expect this at least annually, and they can be carried out internally or by an external reviewer. 

For internal audits, someone senior, but not normally involved in day-to-day AML activity, should carry out the review.

What to do: Introduce periodic testing and audits. Simulate submitting an internal report of suspicious activity. Review files for compliance. Test whether your staff can follow procedures under pressure. Record outcomes and update your policies where gaps are found.

Why this matters now

The regulatory bar is getting higher everywhere. FATF’s own evaluations are shifting focus towards effectiveness and outcomes rather than whether a policy document simply exists. Supervisors around the world are following suit. 

If your AML policies, controls and procedures are not current, specific, and embedded in your day-to-day operations, you’re running a real compliance risk.

But more than that, you’re leaving your business vulnerable to being used by criminals, and that undermines trust in the entire sector.

How AMLCC can help

Keeping AML policies, controls and procedures current is a challenge, especially when regulations are always moving. That’s where AMLCC comes in.

The platform gives you everything you need to:

  • create and maintain a tailored, regulation-ready AML Policy;
  • link your policy directly to your risk assessment;
  • stay aligned with the latest legislation and sector-specific guidance;
  • educate and track staff awareness, with built-in training and functionality for all staff to acknowledge their awareness and understanding of all PCP updates;
  • provide evidence of compliance to your supervisor.

Most importantly, AMLCC is constantly updated by experts. So your PCPs can stay live, not static.

If any of the six signs in this article ring true for you, it’s time to act. Don’t wait for a visit or an incident to expose the gaps. Reviewing and updating your AML policies, controls and procedures now is not only good governance, it’s good business.

Explore all of AMLCC’s interconnected tools

The one-stop AML solution

We know AML

We’re internationally recognised AML experts
We work with most accountancy supervisors and the Law Society
Bespoke AML consultancy available for all sectors

The one-stop AML solution

We know AML

We’re internationally recognised AML experts
We work with most accountancy supervisors and the Law Society
Bespoke AML consultancy available for all sectors

What others have said

“We had the man from the ICAEW here yesterday to carry out a QAD practice review. We got a clean bill of health – not a single action point…That is in no small measure due to AMLCC so I just wanted to say ‘thank you’”

“Thank you for such a perfect and informative [solution]. You have given me a clear direction for my AML training and CPD.”

“I just wanted to say ‘thank you’ to you, Richard, and all the team at AMLCC for providing a service that really does minimise the burden of AML compliance.”

“What a refreshing pleasure working with a company who actually listens to the feedback from their customers and communicates with them!”

“Your team they have been excellent from the moment Fiona did a demo for me with only 15 minutes notice, and thoroughly going through the AMLCC product, answering the many questions I had! It was at this point at which I made up my mind this is the sort of business I want to work with for my AML.”

Making compliance easier

AMLCC newsroom
Scroll to Top