AML Control
Pronunciation: A-M-L kun-TROHL
Definition
An AML control is a policy, process, system, or review designed to prevent, detect, investigate, or report money-laundering risk. An Anti-Money Laundering control is a specific measure within a broader compliance program. Examples include customer identification, sanctions screening, risk rating, transaction monitoring, enhanced due diligence, case investigation, recordkeeping, and suspicious activity escalation or reporting. Controls may be preventive, detective, or corrective and should correspond to identified products, customers, channels, jurisdictions, and transaction risks.
Overview
An Anti-Money Laundering control is a specific measure within a broader compliance program. Examples include customer identification, sanctions screening, risk rating, transaction monitoring, enhanced due diligence, case investigation, recordkeeping, and suspicious activity escalation or reporting.
Controls may be preventive, detective, or corrective and should correspond to identified products, customers, channels, jurisdictions, and transaction risks. A control’s design alone is insufficient if data are incomplete, thresholds are inappropriate, alerts are ignored, or staff lack authority.
Organizations should document ownership, frequency, evidence, exceptions, and expected outcomes for each control. Testing and monitoring must confirm that the control operates effectively, while findings lead to remediation, tuning, training, or changes in risk acceptance.
An AML control is a policy, process, system, or review designed to prevent, detect, investigate, or report money-laundering risk. An AML control is effective only when it addresses a defined risk, operates consistently, produces evidence, and receives meaningful follow-up.
Implementation of AML Control should map a policy, process, system, or review designed to prevent, detect, investigate, or report money-laundering risk to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for policy, process, and system should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the AML Control context and policy, process, and system should trigger reassessment instead of silent reuse of an outdated conclusion.
Assurance work for AML Control should sample records involving policy, process, and system, test whether stated procedures operated in practice, and keep corrective actions open until a qualified reviewer verifies closure.
Key Takeaway
An AML control is effective only when it addresses a defined risk, operates consistently, produces evidence, and receives meaningful follow-up.
Sources
- FATF Documentation: Virtual Assets — FATF (2026-07-30)
- FATF Documentation: Fatf Recommendations — FATF (2026-07-30)